Guestlist.pro Back
Legal

Privacy policy

Last updated: June 2026

1. Controller

The controller within the meaning of the GDPR for data processing on this platform is:

Veysi Yalcin
Platenstraße 12, 50825 Köln Email: privacy@guestlist.pro

2. What data we collect

Guestlist.pro processes personal data exclusively in connection with providing our Event management, ticketing, and guest list services. We distinguish between data from organizers (B2B customers) and guests/ticket buyers (end users).

2.1 Data from organizers

  • Account data: name, email address, phone number, company name upon registration
  • Payment data: bank details (IBAN) for automated payouts of ticket revenue
  • Usage data: login times, Events created, guest list statistics, scanner activity
  • Billing data: transaction history, fee statements, payout logs

2.2 Data from guests & ticket buyers

  • On ticket purchase: name, email address, selected ticket category, payment information (processed directly by Stripe — we do not store credit card data)
  • On guest list entry: name, number of companions (+1), VIP status, promoter assignment
  • On check-in: timestamp of entry, scanner location, QR code validation status
  • Community request: email address and name (only with active ticket-shop opt-in)

3. Purposes of processing

  • Contract performance (Art. 6 (1) lit. b GDPR): processing ticket sales, providing the guest list at the door, executing payouts to organizers
  • Legitimate interest (Art. 6 (1) lit. f GDPR): fraud prevention, live capacity monitoring, system security, platform optimization
  • Consent (Art. 6 (1) lit. a GDPR): community join request to the organizer

4. Payment processing & financial data

All payment transactions (ticket sales via Apple Pay, Google Pay, credit card, SEPA) are processed through Stripe, Inc. — a PCI DSS Level 1 certified payment provider. Guestlist.pro never has access to full credit card numbers or bank details of ticket buyers.

Organizer payouts are processed automatically via the Stripe Connect system. Payout amounts, fees (flat fee per ticket), and transaction histories are stored encrypted in our database and are visible to the organizer in the dashboard.

5. Real-time data processing (scanner & live dashboard)

When using our scanner feature, QR codes are validated in real time. The following data is processed:

  • Ticket ID and validation status (valid / already used / invalid)
  • Timestamp of the scan
  • Assignment to the respective entrance (for multi-door Events)

This data is transmitted in real time via encrypted WebSocket connections (wss://) and serves live capacity control. It is automatically anonymized after 90 days.

6. Disclosure of data to third parties

We disclose personal data only in the following cases:

  • Stripe, Inc. (USA) – payment processing. Legal basis: EU-US Data Privacy Framework
  • Hosting provider – server infrastructure in the EU (Frankfurt am Main)
  • Organizers – receive access to guest lists and ticket buyer data for their own Events (as independent controllers)

We do not disclose personal data to third parties for advertising purposes.

7. Cookies & tracking

Guestlist.pro uses only technically necessary cookies for session management and login status. We do not use tracking cookies, Google Analytics, or advertising pixels. Your privacy matters to us — we do not track you.

8. Retention period

  • Organizer account data: Until account deletion + 10 years statutory retention for invoicing data
  • Ticket purchase data: 6 years (commercial law retention for transactions)
  • Guest list entries: 90 days after the Event date, then automatic anonymization
  • Scanner logs: 90 days, then anonymized
  • Community request data: until consent is withdrawn or the organizer rejects/deletes the request

9. Your rights

You have the right at any time to:

  • Access your stored data (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure of your data, unless statutory retention obligations apply (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability – export of your data in a machine-readable format (Art. 20 GDPR)
  • Object to processing (Art. 21 GDPR)
  • Withdraw consent given with effect for the future

To exercise your rights, contact: privacy@guestlist.pro

10. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is: State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW).

11. Security

All data transfers are TLS-encrypted (HTTPS). Our systems are regularly checked for security vulnerabilities. Sensitive data such as passwords is stored exclusively as salted hashes (bcrypt). Payment data is never stored on our servers but tokenized directly by Stripe.

12. Currency of this policy

This privacy policy may be updated when the platform changes. You can find the current version at guestlist.pro/privacy.

© 2026 Guestlist.pro
AboutImprintPrivacyTerms