Draft — to be reviewed by a lawyer before publication

This text is a working draft. Items in [square brackets] are still to be completed.

Privacy Policy — InvitePro Tickets

Updated: 23 September 2026

This policy explains how [Company legal name] ("InvitePro", "we") collects, uses, stores and protects personal data through InvitePro Tickets, an online event ticketing service, under Tanzania's Personal Data Protection Act, 2022 and its regulations.

1. Who we are

The service is provided by [Company legal name], [Registered address], registration number [Company registration number]. Privacy questions: [Privacy email].

2. Our roles: organisers and buyers

For the account data of an organiser and their team (sales, gate staff, treasurer), InvitePro is the controller.

For the data of ticket buyers and attendees (names, phone numbers, e-mail addresses, transaction numbers and payment proof), the organiser selling the tickets is the controller. InvitePro processes it on the organiser's behalf and only on their instructions, to issue, deliver and check tickets.

3. What we collect

We collect:

  • Organiser account: name, e-mail, phone, company name, TIN (if given), password (stored as a hash).
  • Ticket orders: buyer name, phone, e-mail (optional), ticket types and quantities, amounts, transaction number and payment proof the buyer provides.
  • Tickets: a QR code per ticket, the attendee name and door check-in records.
  • Technical logs: IP address, browser and security-relevant activity.

4. How we use it

Only to provide the service:

  • showing the sales page, taking orders and letting the organiser confirm payments;
  • delivering tickets and order updates by SMS, WhatsApp or e-mail, and event reminders;
  • scanning QR tickets at the door and preventing a ticket from being used twice;
  • charging the InvitePro per-ticket fee from the organiser's wallet, issuing receipts and preventing fraud.

5. Payments

Buyers pay the organiser directly (M-Pesa, bank or other methods the organiser sets). InvitePro never holds buyers' money. Organisers top up a prepaid wallet for ticket fees through licensed payment providers.

6. Who we share data with

We do not sell personal data. We share it only with providers that help us run the service (SMS and WhatsApp gateways, e-mail, hosting and payments) under contracts that protect it. An organiser only sees the buyers of their own events.

7. Retention

180 days after an event ends (or is cancelled), buyers' and attendees' names, phone numbers and emails, payment screenshots, message copies and ticket images are erased; order numbers, amounts and statuses stay for the organiser's accounts, and financial records for as long as tax law requires. An organiser can ask us to delete an event or the account; we delete or anonymise the data within 30 days unless the law requires us to keep it. Backups are encrypted and kept for up to 60 days; if we restore one, we re-apply every erasure made after it.

8. Your rights

You may access, correct or ask for deletion of your data and object to certain uses. Buyers can contact the event organiser directly, or us at [Privacy email]. Reply STOP to opt out of promotional messages.

9. Security

We use HTTPS, hashed passwords, unguessable secret links for tickets and orders, per-member permissions and activity logs.

10. Contact

Questions or complaints: [Privacy email], [Registered address]. You may also complain to the Personal Data Protection Commission (PDPC).