Privacy
Hibilet sells a product whose whole argument is that the audience belongs to the organiser and not to us. A privacy page is where that either holds up or does not, so this one is written to be read rather than to be survived.
Who controls what
Hibilet is operated by Savrum Solutions B.V., registered in the Netherlands (KvK 42032272), Balthasar Coymansstraat 10, 5751MV Deurne, Netherlands. Two different relationships run through this product and conflating them is the usual way these pages go wrong.
- Organisers
- When you sign up to sell tickets, we are the controller of your own account data: your name, your email, your login, your billing record, and the logs of what you did in the software.
- Ticket buyers
- When somebody buys a ticket to your event, you are the controller and we are your processor. Their data is collected for you, held on your behalf, and leaves with you. We do not sell it, we do not market to it, and we do not pool it across organisers to build anything of our own.
That second line is not a courtesy. It is the product: if we treated buyer data as ours, we would be the same business as everybody else on the page you came from.
What we hold
About organisers
- Account and contact details, and the members of staff you invite.
- Your account identifier at your payment provider, so charges can be made on your balance. Never your credentials.
- What you configured: events, tiers, prices, questions asked at checkout, branding, domains.
- Operational logs. Who changed a price, who refunded an order, who exported a list, and when.
About ticket buyers, on your behalf
- Name and email, and a phone number if your checkout asks for one.
- Whatever questions you chose to ask at checkout: dietary needs, access requirements, an address for a shipped item, a date of birth where the sale legally needs one. You decide these. We do not ask for anything you did not configure, and some of them may be special-category data, which is your responsibility to justify.
- Orders, reservations, refunds, and the order codes scanned at the door.
- Baskets that were filled and never paid for, including what was in them and what they were worth.
- Marketing consent state, and when and where it was given.
- Technical records of visits: a session identifier, timestamps, coarse device information.
How one person is recognised
This is the part most ticketing privacy pages do not mention, and it is the part that most deserves mentioning, because it is the mechanism the whole product is built on.
Hibilet links the visits, baskets and orders that belong to the same person into one record, so that somebody who browsed in March on a phone and paid in June on a laptop appears once rather than as three strangers. It does this on first-party signals inside your own storefront: a session identifier we set, and the email address given at checkout, which is what connects one session to another.
What it does not do: it does not fingerprint devices, it does not buy or enrich data from brokers, it does not track anybody across sites that are not yours, and it does not link a person across two different organisers. Two Hibilet customers selling to the same human hold two separate records of them, and neither can see the other.
Because resolution is what makes the abandoned-basket and repeat-buyer features work, it is also the thing to explain to your own buyers in your own privacy notice. We can tell you how it works; only you can tell them, because they are your customers.
Card details
We never see them. Card payments run through your payment provider on your own account. Card numbers, expiry dates and security codes go from the buyer to that provider and never touch our servers or our database. We hold the provider's identifier for the payment and the outcome, and nothing else.
This is also why we are not in the flow of funds. Money settles into your own balance on your provider's schedule, not ours, and we cannot hold it, delay it, or take it.
Consent and marketing
Marketing consent is recorded per person, with a timestamp and the place it was given. It is never assumed and never inherited from a purchase: buying a ticket is a contract, not permission to be emailed about the next one.
When a segment is built, in the query layer or by hand, people without consent are excluded before the count is produced, not filtered out at send time. That ordering matters: it means a count you are shown is a count you may actually contact, and you are never quoted an audience you are not allowed to reach.
Withdrawing consent is one action and takes effect immediately across every segment, including ones already built.
What the AI layer reads
The plain-language query feature turns a sentence into a query against your own data, and only yours. It reads your buyer records to answer the question and to draft a message. It does not read another organiser's data, and it does not have access to the internet at large.
Queries and their results are not used to train a general model. Where a third-party model provider processes the text of a query, that provider is listed as a subprocessor below and is contractually barred from training on it.
Nothing drafted is sent automatically. A draft sits in your outbox until a person presses send.
How long
- Buyer records
- For as long as you keep your account, because they are yours and the product is worthless without them. On closure, see below.
- Abandoned baskets
- Retained with their contents while they remain recoverable, then reduced to a counted statistic with no person attached.
- Financial records
- Kept as long as tax and accounting law requires, which is longer than anything else here and is not something either of us can shorten.
- Operational logs
- A rolling window, kept for security and for answering "who changed this".
- After you close your account
- Your data is exported to you on request, then deleted on a stated schedule except where the law requires us to keep a financial record.
Nothing in the product is hard-deleted the instant a button is pressed; rows are marked deleted and then removed. That is a deliberate engineering choice so that a mistake is recoverable, and it means "deleted" and "gone from every backup" are a short interval apart rather than the same moment.
Your rights
If you are in the UK or the EEA you have the right to ask for a copy of your data, to correct it, to have it deleted, to restrict or object to how it is used, and to complain to your data protection authority.
For ticket buyers: your relationship is with the organiser who sold you the ticket. They are the controller. Ask them, and we will help them answer you. If you cannot reach them, write to us and we will route it.
For organisers: export is not a support ticket and not a negotiation. Customers, orders, consent state and full purchase history come out on request in formats that load somewhere else, on any day you like, including the day you leave.
Who else sees it
The list is deliberately short, and every entry earns its place by doing something we could not do without.
| Who | What for | What they get |
|---|---|---|
| Your payment provider | Taking card payments on your own account | Payment data, directly from the buyer |
| Hosting and database | Running the thing | Everything, encrypted at rest |
| Email and SMS delivery | Sending what you send | Recipient address and message content |
| Model provider | The plain-language query layer | The text of a query and the data needed to answer it, with no training rights |
Where it lives
Data is held in the EEA by default. Where a subprocessor operates outside it, the transfer runs on Standard Contractual Clauses or an adequacy decision. Data residency in a specific country is available on Hibilet Pro.
Asking us
Write to info@hibilet.com. A person reads it.
Controlling entity: Savrum Solutions B.V., KvK 42032272, Balthasar Coymansstraat 10, 5751MV Deurne, Netherlands. Lead supervisory authority: Autoriteit Persoonsgegevens (Dutch Data Protection Authority).