stubwiseDeutsch

Terms of service

Dated 20 September 2026 · Version 2026-09-20.2

1. Service and eligibility

Stubwise provides event-ticketing software for merchants using Shopify. Merchants are responsible for their events, products, pricing, tax obligations, customer terms, refunds and the accuracy of attendee information. Stubwise is not the event organizer or the seller of admission.

2. Plans and billing

Starter is $19 per month or $190 per year and includes up to 500 tickets per calendar month. Pro is $49 per month or $490 per year with unlimited tickets and additional features. Both offer a 14-day trial. Shopify administers subscription authorization, billing, cancellation and applicable taxes. The plan shown in Shopify at subscription controls.

3. Fair use and ticket limits

If Starter exceeds 500 tickets in a month, already-paid orders continue to receive tickets. The merchant is prompted to upgrade; creation and activation of further events may be restricted in the following month. Do not use the service for unlawful events, abusive communications or unauthorized collection of personal data.

4. Availability and support

We design the service for reliable delivery and check-in, but email providers, networks and Shopify may be unavailable. Hosted tickets and offline check-in provide alternatives. Offline scans are provisional until synchronized and can conflict between devices. Contact support@stubwise.co for help seven days a week.

5. Ending use and data

You can uninstall the app through Shopify. Export required attendee records before uninstalling. Store data is scheduled for deletion beginning 30 days after uninstall, subject to lawful retention duties. The privacy policy explains data processing.

6. Contract, cancellation, liability and disputes

Stubwise is offered to merchants acting for their trade, business or independent profession. The software contract is between that merchant and Theo Fuhrmann, operating as Stubwise at the address in the provider information. A person activating the app for a merchant must be authorized to represent that merchant. These terms do not govern a buyer's purchase of admission from the merchant.

By selecting a plan and confirming activation after these terms have been made available, the merchant offers to enter the software contract. We accept by enabling the selected plan. The trial, billing interval and recurring price are those confirmed in Shopify. A charge requires the merchant's Shopify authorization; these terms do not authorize an additional charge.

The merchant may end use by uninstalling Stubwise in Shopify. Uninstalling stops future recurring billing cycles, but charges already incurred may remain payable. Any subscription cancellation date, credit or refund is determined through the applicable Shopify billing process and the merchant's statutory rights. Contact support@stubwise.co about disputed app charges. There is no automatic refund promise or exclusion of a refund otherwise owed. Either party retains the right to terminate for good cause under applicable law; a remediable breach normally requires an opportunity to remedy it before termination.

Liability, defect remedies and damages are governed by applicable statutory law. These terms impose no contractual fee-based liability cap and do not exclude statutory liability. Descriptions of third-party outages or provisional offline check-ins explain operational limits; they do not remove claims otherwise provided by law.

German law governs this software contract, subject to mandatory rules that remain applicable despite that choice. No exclusive court or compulsory arbitration is agreed. A merchant may contact support@stubwise.co to seek a resolution, without being required to complete that process before using available legal remedies.

Material changes to these terms require agreement. Posting new text on a website alone does not change an existing contract. The English and German versions are intended to have the same meaning; neither version automatically overrides mandatory rights.

7. Merchant processing agreement

This annex forms part of the software contract when accepted with it. It governs the processing of merchant customer data on the merchant's behalf.

A. Parties and instructions

The merchant identified in the accepted app contract is controller of its buyer and attendee data. Theo Fuhrmann, operating Stubwise, is processor for the ticketing operations below. Processing follows the merchant's documented instructions through app settings and verified support requests, including instructions about transfers. If an instruction appears unlawful, Stubwise informs the merchant and pauses that instruction for clarification. A legal processing obligation is disclosed before processing unless the law prohibits disclosure. Stubwise's own account, billing and security administration is described separately in the privacy notice.

B. Processing details

During the service, Stubwise receives, stores, organizes, displays, transmits, corrects, exports and erases data to issue and deliver tickets, collect guest details, validate admission and resolve related support requests. Subjects are buyers, attendees and merchant staff involved in those operations. Data comprises names, emails, shop/order/line/customer identifiers, event and date associations, custom answers, ticket codes, delivery/opening state, admission time/device labels and necessary support text. Payment-card data is not stored. Merchants must not request special-category or criminal-conviction data through custom questions without a separate documented arrangement and appropriate safeguards.

C. Confidentiality and security

Access is limited to authorized people bound to confidentiality. Stubwise maintains appropriate technical and organizational measures and reviews their effectiveness. The security annex below describes the implemented controls and their limits; it is not a guarantee that every endpoint copy is encrypted or that an independent certification exists.

D. Subprocessors and transfers

The merchant authorizes Cloudflare, Inc. for Workers hosting, D1/KV storage and email processing under its applicable DPA and subprocessor arrangements, and STRATO GmbH for the operator's support mailbox through STRATO Hosting Basic under the existing STRATO data processing agreement. STRATO receives original escalated support messages, which may contain sender-supplied personal information, and generic fallback alerts. Before adding another direct processor of merchant customer data, Stubwise provides its name, purpose and transfer information and obtains the merchant's specific written authorization. Equivalent processing obligations apply downstream, and Stubwise remains responsible for its processor obligations. Transfers outside the EEA require a valid applicable safeguard and documented instructions. No EEA-only hosting promise is made. Optional AI drafting through Anthropic remains disabled and is not authorized by this agreement. It may process merchant customer data only after the relevant provider, processing terms and transfer safeguards are documented and specifically authorized under this clause.

E. Assistance and incidents

Stubwise assists verified rights requests, security assessment and required impact-assessment or authority consultations using information available to it. A customer request concerning merchant-controlled data is passed to the merchant unless the merchant has authorized a response. Stubwise informs the merchant without undue delay after becoming aware of a personal-data breach, supplies available scope, consequences and mitigation information, and supplements it as facts become known. The merchant determines its own external notifications.

F. Return, deletion and verification

The merchant may request return in a commonly usable format or deletion of data processed on its behalf. Identifiable attendee data is scheduled for deletion beginning 90 elapsed days after its event date ends; verified erasure instructions and uninstall cleanup can apply earlier. Following termination, data is returned or deleted according to the merchant's choice, with ordinary scheduled uninstall cleanup beginning 30 days after uninstall, unless an applicable law requires retention. Cleanup proceeds in bounded batches and can finish after the relevant cutoff; these periods do not promise instantaneous deletion. Retained legal records and provider recovery copies remain restricted and are not reused for ticketing; erasure instructions must be reapplied before any restored data returns to service. Stubwise provides compliance information and permits relevant audits, including inspections by the merchant or its independent auditor, with reasonable notice where appropriate and confidentiality protection for other merchants. Nothing limits a competent authority's powers. This annex takes precedence over conflicting software terms for processing obligations.

8. Security and provider annex

These measures and limits apply to the processing agreement above. They do not promise uninterrupted service or independent certification.

Access

Merchants sign in through Shopify and can access only their own store's records. Staff links are limited to a store or event date and can be revoked. Door staff receive names and codes, not emails. Two-factor authentication protects the operator's Shopify, Cloudflare, GitHub and email accounts.

Storage

HTTPS endpoints; application encryption for Shopify access/session tokens; managed provider encryption for D1. Attendee fields remain readable to authorized database access. Browser offline data is not application-encrypted.

Device retention

Full guest lists expire 12 hours after their last complete fetch while the app executes; closed/suspended browsers clean up when the app next runs. Minimal pending scan code/device entries remain until synchronization.

Recovery

Provider recovery copies can remain after records are deleted from the active service. Restored data must be checked against erasure/expiry records before use. No completed restore exercise or independent certification is claimed.

Access records

Access to protected ticket, attendee and support records is logged with the type of access, time, affected record count and protected references to the authenticated actor and scope. The access log does not contain attendee names, email addresses, ticket access links or support message text. These logs are normally kept for 30 days; erasure requests can remove linked entries earlier.

Cloudflare, STRATO and optional providers

Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA provides hosting, storage and email processing under its applicable data processing addendum. Its services and subprocessors may process data outside the EEA. The relevant safeguards depend on the applicable provider agreement and transfer. No exclusively European hosting is promised.

Cloudflare data processing addendum

STRATO GmbH provides the operator's support mailbox through STRATO Hosting Basic under the existing STRATO data processing agreement. Original-message forwarding may include personal information supplied by the sender. App erasure does not remove external mailbox copies, trash, provider backups or local mail-client caches; those require separate deletion handling. The applicable provider terms and safeguards govern transfers, with no EEA-only promise. Optional Anthropic drafting remains disabled and requires the separate prior authorization described in section 7.D.

Back to Stubwise