stubwiseDeutsch

Privacy policy

Dated 20 September 2026 · Version 2026-09-20.2

1. Who is responsible

Stubwise is operated by Theo Fuhrmann, Moltkestraße 25, 40477 Düsseldorf, Germany. For privacy questions, contact support@stubwise.co or +49 174 6386022. Merchants remain responsible for their customer and attendee data; Stubwise processes event-ticketing data on their instructions.

2. Information we process

We process the store domain, store contact details, Shopify authorization credentials, subscription plan, event and date details, order and line-item identifiers, buyer name and email, attendee name and email, optional attendee answers, ticket codes, delivery status, check-in records and support messages. We do not store payment-card information. Door staff can see attendee names and ticket codes, but not email addresses.

When a merchant accepts the terms and processing agreement, we record the store domain, a hash of the verified Shopify user identifier, the policy revision, language and acceptance time. This record documents the merchant's acknowledgment. The hash is a pseudonymous reference, not anonymous data; we do not copy the user's name, email, access token or IP address into this record.

3. Purposes and legal bases

We use this information to provide contracted ticketing services, deliver transactional tickets, collect attendee details, enforce ticket validity, provide support and meet legal obligations. The applicable bases for our own processing are contractual necessity, legal obligations, and legitimate interests in secure and reliable operation (GDPR Article 6(1)(b), (c) and (f)). Merchants must determine and communicate their own lawful basis for attendee processing and optional questions.

4. Hosting and service providers

The service uses Cloudflare Workers, D1, KV and Email Service for hosting, storage and email delivery. Shopify provides the commerce platform, checkout, inventory and subscription billing. Cloudflare's data processing addendum applies to its processing. Personal data may be processed outside the European Economic Area under applicable transfer safeguards. Optional providers and their transfer arrangements require separate review before use with merchant customer data.

If the operator enables optional AI-assisted support drafting, the support message subject and text, product facts, and a limited shop summary are sent to Anthropic. The summary contains the plan, language, recent event titles, delivery counts and latest check-in time. The prompt excludes attendee lists and access credentials, but a sender's message may contain personal information. Installing Stubwise does not enable this optional processing. Anthropic support drafting is currently disabled and has not been approved for merchant messages. Model-written replies require operator review before sending. The owner must review this optional processing and the provider account's retention and transfer terms before enabling it for merchant messages.

We send generic operational alerts and queue counts to ntfy. These alerts do not contain attendee lists or ticket access links. If push delivery fails, a generic alert may be emailed to the operator. Escalated support messages can be forwarded to the operator's support mailbox at STRATO GmbH, provided through STRATO Hosting Basic under the operator's existing data processing agreement. The original message may include personal information supplied by its sender. This original-message forwarding is separate from generic alerts. Forwarded mailbox copies require separate deletion handling and are not erased automatically when app records are deleted.

5. Storage and deletion

Identifiable attendee information is scheduled for deletion 90 days after the end of each event date. This includes buyer and attendee names and email addresses, customer links, form answers and identifying delivery records. Operational ticket counts and admission records remain after those identity fields are removed. Original public ticket codes are removed and replaced with new internal identifiers. Retained event and admission times may still be correlated with outside records; this is not a claim of complete anonymization, and further retention requires separate review. Shopify erasure requests and the uninstall deletion process can remove data earlier. After uninstall, remaining store data is scheduled for deletion beginning 30 days later. Cleanup runs in bounded batches and can finish after the applicable cutoff. Copies previously exported by a merchant, printed tickets and messages already delivered to external mailboxes are outside this cleanup and require their own deletion process.

Resolved support conversations, reply drafts and their related action and notification records are scheduled for deletion 90 elapsed days after resolution. Resolution is recorded explicitly; sending a reply alone does not start this period. Reopening a conversation clears its resolution date, and the period starts again only when it is resolved again. Unresolved requests are not deleted under this rule. The same period applies to support copies in the operator's STRATO mailbox, which the operator deletes manually, including related sent, archived and trash copies and local mail-client copies. App cleanup does not delete mailbox copies or provider backups. A documented legal obligation may justify retaining necessary evidence longer. An operator hold pauses routine support cleanup only; it does not override Shopify erasure requests or uninstall deletion. If a specific legal duty requires evidence after those deletions, the operator must assess and retain only the necessary material separately in restricted storage. There is no automatic legal-evidence export.

Merchant acceptance records remain while the store is installed, including records for previously accepted revisions. They are deleted with the store's app record through Shopify shop erasure or the scheduled uninstall cleanup beginning 30 days after uninstall. The separate 30-day access-log period and 90-day attendee period do not apply to these acceptance records. We do not maintain a separate contract-evidence archive after shop deletion.

6. Cookies, logs and ticket links

We use essential authentication cookies and security logs to run the app. We do not use tracking pixels in ticket emails. Opening a hosted ticket page records the first link opening to help merchants resolve delivery issues. Access to protected records is logged without copying their contents. Access logs are normally kept for 30 days.

The check-in app stores up to 500 attendee names and ticket codes in browser storage for offline use. This storage is not encrypted by the app. The full guest list expires 12 hours after its last complete download; deletion runs while the app is active or when it next resumes. Pending scans retain only the ticket code and device label until synchronization. Anyone holding a hosted ticket link can view the ticket details available on that page. Keep the link private. Voiding blocks admission and access to hosted ticket details. Reissue replaces the public code without resetting an existing admission; the previous code no longer works online. An offline device with an older cached guest list may still accept that code provisionally until synchronization. Contact the merchant if a link has been exposed. Previously viewed pages, printed tickets and delivered emails cannot be recalled.

7. Your rights

Subject to applicable law, you may request access, correction, erasure, restriction, portability, or object to processing based on legitimate interests. Contact the event merchant for attendee data requests, or support@stubwise.co for requests concerning Stubwise. You may complain to a supervisory authority, including the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen.

8. Reminders and questions

Confirming a reminder opt-out stops reminders to the email recipient associated with that link for all tickets in the same order. Tickets addressed to another guest remain unaffected. This does not cancel admission or erase a ticket. Necessary ticket delivery is separate from optional reminders.

You can opt out of event reminder emails on your ticket page. Transactional ticket delivery is necessary to provide the service. Do not submit special-category or criminal-conviction information through custom attendee questions unless the merchant has a lawful basis, a separate documented arrangement with Stubwise and appropriate safeguards.

Back to Stubwise