Snapshot 11673
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Privacy Policy Privacy Policy Central Tickets (“CT”, “we” or “us”) is committed to protecting your privacy, including online, and ensuring transparency in how your data is collected, used, and stored. This Privacy Policy (the "Policy") explains the information we collect from you, how we use it, and your rights. By using our website or services, you agree to this Policy. This Privacy Policy (the “Policy”) (together with our terms of use and any other documents referred to on it) sets out what information we may hold about you if you provide it, and how that data will be used. No information will be shared more widely than is set out below unless it is required by law. Who Are We? CT is a limited company and acts as the "data controller" for the personal data you provide. We are registered with the Information Commissioner’s Office (ICO) under registration number ZA256756. Contact us at: Central Tickets Limited 71-75 Shelton Street Covent Garden London WC2H 9JQ You can contact our Data Protection Lead (DPL) via enquiries@centraltickets.co.uk Information We Collect from You We collect basic personal information such as your name, email address, and mobile number for ticket delivery and account verification purposes. Occasionally, we may collect your physical address for the delivery of paper tickets when required by venues. Additionally, we collect and store details of any access needs you report for the purpose of liaising with venues to ensure those needs can be accommodated for events you book tickets for. Access need information is classified as special category data and is stored separately from personal identifiable information (PII). For certain services, such as through our Tickets for Medics website, we may collect photographic ID to verify eligibility. Photographic ID is encrypted, stored separately from other personal data, and permanently deleted from our servers immediately after review. All personal data collected from our members and event organisers is securely stored and encrypted using the AES-256 standard, ensuring a high level of data protection. Passwords are encrypted with Bcrypt. Social Login (Apple and Google) If you choose to log in to or register with Central Tickets using a third-party service such as Apple or Google, we will receive only the basic personal information necessary to create and manage your account — typically your name and email address. If you opt to use Apple’s “Hide My Email” feature, we will receive a private relay email address that forwards communications to your actual inbox. We do not access or store any other data from your Apple or Google accounts, nor do we post on your behalf. Your credentials remain with the respective provider, and we never share this data beyond what is necessary to deliver our services. You may revoke our access at any time via your Apple ID or Google account settings. If you delete your Central Tickets account, all associated social login data will be permanently removed from our systems as part of our data deletion process. All data received through these login options is handled in strict accordance with this Privacy Policy and UK GDPR. For reference, you can view the respective third-party policies here: Apple Privacy Policy Apple Media Services Terms and Conditions Google Privacy Policy Google Terms of Service How We Use Your Information We use your data for the following purposes: To verify your account and provide the services you've requested, such as ticket bookings and delivery. To respond to queries or customer service requests. To create customer segments based on purchase and website/app behaviour to deliver personalised communications and offers. To analyse customer trends and purchasing patterns for business purposes. To ensure that any access needs you report are communicated to venues to accommodate your requirements. We may also process your information for legal, regulatory, or investigative purposes. This may involve consulting external services or the use of third-party tools, including AI-assisted services, to support internal analysis, verify information, safe-guard our interests or ensure compliance with legal obligations and applicable laws. Links to Other Websites and Partner Platforms Our website and app may contain links to other websites run by other organisations. This Privacy Policy applies only to our website and app, so we encourage you to read the privacy statements on the other websites you visit. We cannot be responsible for the privacy policies and practices of other sites even if you access them using links from our website. Additionally, if you linked to our website from a third-party site, we cannot be responsible for the privacy policies and practices of the owners and operators of that third-party site and recommend that you check the policy of that third-party site. Our third-party partner platforms: Sometimes, you will provide your information to our third-party partner platforms. For example, Ingresso, London Theatre Direct, and TTG/Encore, who we’ve teamed up with to sell tickets on our behalf. These platforms are run by other organisations. This Privacy Policy applies only to our website, so we encourage you to read the privacy statements on the other platforms you visit. CT is not responsible for the privacy policies and practices of other platforms. Data Sharing We do not sell your personal data or allow its use for marketing purposes by third parties. However, we may share your data in the following circumstances: Ticket Issuance: When venues issue e-tickets, we share your contact details with them to facilitate ticket delivery via email or SMS, and in such cases, we ensure a Data Processing Agreement (DPA) is in place to restrict data use exclusively for this purpose. However, when we issue tickets directly, we only share a list of names and ticket quantities with the venue, and no DPA is required. Third-Party Analysis: We may engage third-party services for customer data analysis, ensuring necessary Data Sharing Agreements are in place. Data will only be used for agreed purposes and will not include marketing. Lookalike Audiences: We may use aggregated customer data to build lookalike audiences for marketing, ensuring compliance with data privacy standards. Overseas Processing: Some of our staff and IT subcontractors who process your data may operate outside the UK. In these cases, Standard Contractual Clauses (SCCs) are included in contracts to ensure data protection standards are upheld. Service Providers: We may share your data with third-party service providers that facilitate our operations, such as email marketing platforms or IT service providers. These providers act on our behalf and are required to adhere to strict confidentiality and data protection standards. Data shared with these providers is used solely for the purpose of delivering the agreed-upon services. Legal & Regulatory Requirements: We may share personal data where necessary to comply with legal obligations, respond to lawful requests from regulatory authorities, or in connection with the establishment, exercise, or resolution of legal claims or investigations. This may include sharing data with legal advisors, regulators, insurers, or other authorised parties. Any such disclosures are limited to what is strictly necessary and are handled with due regard to confidentiality and data protection requirements. For transparency, you can view our current sub-processor notice here. Data Retention If you remain subscribed to our marketing communications, we will continue to process and retain your personal information indefinitely, unless you request deletion or we no longer need the data for the purposes for which it was collected. If you unsubscribe from marketing communications, we will delete your personal information six (6) years after the date you unsubscribed from marketing emails, the date of your last purchase, or your use of an affiliate site (whichever is later). Records related to blocked or deleted accounts are retained in an encrypted, minimised suppression list in line with ICO guidance. This ensures we have a record of actions taken and prevents the user’s details from being re-added inadvertently. If a member who has previously exercised their right to be forgotten under GDPR and has been added to the suppression list later re-registers with fresh consent, we will remove their details from the suppression list and consider their consent as renewed. This will allow the opening of a new account and the processing of their data in line with their updated preferences. We retain records of email exchanges for seven years from the date of the last message, comment, or action taken on any given email thread. Security Measures All personal data is securely encrypted at rest using the AES-256 standard, and protected in transit using SSL/TLS encryption. Passwords are encrypted using the Bcrypt standard. Photographic ID and sensitive data, including access needs information, are encrypted and securely stored separately from other personal identifiable information (PII). All payment transactions use SSL encryption and comply with PCI-DSS standards. EU-U.S. Data Privacy Framework Where necessary, data transfers between the EU/UK and the U.S. comply with the EU-U.S. Data Privacy Framework, ensuring your data is protected during international transfers. Your Rights You have the right to: Access, correct, or request deletion of your personal data. Object to specific uses of your data, including profiling. File a complaint with the ICO if you believe your data has been mishandled. If you would like to submit a subject access request, please complete this form and we will endeavour to respond within 30 days of receiving the required information. Cookies Policy What Are Cookies? Cookies are small files downloaded to your device to improve website functionality and user experience. Some are essential for site operation, while others, like analytics and personalisation cookies, require your consent. Types of Cookies We Use Essential Cookies Purpose: These cookies are necessary for the website to function properly, as they support core services such as maintaining website security and protecting against malicious traffic, enabling login sessions and user account access, and facilitating secure payment processing. These cookies are used automatically and cannot be turned off. Examples: Cloudflare cookies for security and performance. Payment gateway cookies for secure transactions. Performance & Analytics Cookies Purpose: These cookies help us understand how visitors use the site so we can improve its performance. They include measuring visits and traffic sources, as well as analysing user behaviour and content engagement. While turning these off won’t affect your experience directly, it limits our ability to enhance the website. Examples: Track user behaviour, session duration, page views, traffic sources. Personalisation & Preferences Purpose: These cookies are used to remember your choices and provide a more tailored experience, such as your selected theme (e.g., dark mode) or preferred layouts and filters (e.g., event types). Disabling them means your preferences may not be saved across sessions. Examples: Google Analytics for tracking user behaviour. Social Media & Retargeting Purpose: These cookies enable us to show you relevant ads on other platforms based on your activity and to track interactions for ad performance and retargeting purposes. Opting out won’t stop ads altogether, but the ones you see may be less relevant to you. Examples: Track user behaviour, session duration, page views, traffic sources. Trust & Reviews Purpose: These cookies help display genuine customer reviews and ratings by verifying the authenticity of reviews and showing trusted third-party review banners. Allowing this supports transparency and builds user trust, but it is entirely optional. Examples: Display verified customer reviews and trust banners. Managing Cookies You can disable cookies in your browser settings. However, doing so may affect site functionality. For details, refer to your browser's help documentation. Changes to the Privacy Policy We may update this Policy as required, and any changes will be reflected on this page. Contact Us: Central Tickets Limited 71-75 Shelton Street Covent Garden London WC2H 9JQ Email: enquiries@centraltickets.co.uk Last updated 20th May 2026