Operator
What it runs The suite, in detail

Privacy

Hibilet sells a product whose whole argument is that the audience belongs to the organiser and not to us. A privacy page is where that either holds up or does not, so this one is written to be read rather than to be survived.

Last updated 11 August 2026 Applies to hibilet.com and the Hibilet product

Who controls what

Hibilet is operated by Savrum Solutions B.V., registered in the Netherlands (KvK 42032272), Balthasar Coymansstraat 10, 5751MV Deurne, Netherlands. Two different relationships run through this product and conflating them is the usual way these pages go wrong.

Organisers
When you sign up to sell tickets, we are the controller of your own account data: your name, your email, your login, your billing record, and the logs of what you did in the software.
Ticket buyers
When somebody buys a ticket to your event, you are the controller and we are your processor. Their data is collected for you, held on your behalf, and leaves with you. We do not sell it, we do not market to it, and we do not pool it across organisers to build anything of our own.

That second line is not a courtesy. It is the product: if we treated buyer data as ours, we would be the same business as everybody else on the page you came from.

What we hold

About organisers

  • Account and contact details, and the members of staff you invite.
  • Your account identifier at your payment provider, so charges can be made on your balance. Never your credentials.
  • What you configured: events, tiers, prices, questions asked at checkout, branding, domains.
  • Operational logs. Who changed a price, who refunded an order, who exported a list, and when.

About ticket buyers, on your behalf

  • Name and email, and a phone number if your checkout asks for one.
  • Whatever questions you chose to ask at checkout: dietary needs, access requirements, an address for a shipped item, a date of birth where the sale legally needs one. You decide these. We do not ask for anything you did not configure, and some of them may be special-category data, which is your responsibility to justify.
  • Orders, reservations, refunds, and the order codes scanned at the door.
  • Baskets that were filled and never paid for, including what was in them and what they were worth.
  • Marketing consent state, and when and where it was given.
  • Technical records of visits: a session identifier, timestamps, coarse device information.

How one person is recognised

This is the part most ticketing privacy pages do not mention, and it is the part that most deserves mentioning, because it is the mechanism the whole product is built on.

Hibilet links the visits, baskets and orders that belong to the same person into one record, so that somebody who browsed in March on a phone and paid in June on a laptop appears once rather than as three strangers. It does this on first-party signals inside your own storefront: a session identifier we set, and the email address given at checkout, which is what connects one session to another.

What it does not do: it does not fingerprint devices, it does not buy or enrich data from brokers, it does not track anybody across sites that are not yours, and it does not link a person across two different organisers. Two Hibilet customers selling to the same human hold two separate records of them, and neither can see the other.

Because resolution is what makes the abandoned-basket and repeat-buyer features work, it is also the thing to explain to your own buyers in your own privacy notice. We can tell you how it works; only you can tell them, because they are your customers.

Card details

We never see them. Card payments run through your payment provider on your own account. Card numbers, expiry dates and security codes go from the buyer to that provider and never touch our servers or our database. We hold the provider's identifier for the payment and the outcome, and nothing else.

This is also why we are not in the flow of funds. Money settles into your own balance on your provider's schedule, not ours, and we cannot hold it, delay it, or take it.

What the AI layer reads

The plain-language query feature turns a sentence into a query against your own data, and only yours. It reads your buyer records to answer the question and to draft a message. It does not read another organiser's data, and it does not have access to the internet at large.

Queries and their results are not used to train a general model. Where a third-party model provider processes the text of a query, that provider is listed as a subprocessor below and is contractually barred from training on it.

Nothing drafted is sent automatically. A draft sits in your outbox until a person presses send.

How long

Buyer records
For as long as you keep your account, because they are yours and the product is worthless without them. On closure, see below.
Abandoned baskets
Retained with their contents while they remain recoverable, then reduced to a counted statistic with no person attached.
Financial records
Kept as long as tax and accounting law requires, which is longer than anything else here and is not something either of us can shorten.
Operational logs
A rolling window, kept for security and for answering "who changed this".
After you close your account
Your data is exported to you on request, then deleted on a stated schedule except where the law requires us to keep a financial record.

Nothing in the product is hard-deleted the instant a button is pressed; rows are marked deleted and then removed. That is a deliberate engineering choice so that a mistake is recoverable, and it means "deleted" and "gone from every backup" are a short interval apart rather than the same moment.

Your rights

If you are in the UK or the EEA you have the right to ask for a copy of your data, to correct it, to have it deleted, to restrict or object to how it is used, and to complain to your data protection authority.

For ticket buyers: your relationship is with the organiser who sold you the ticket. They are the controller. Ask them, and we will help them answer you. If you cannot reach them, write to us and we will route it.

For organisers: export is not a support ticket and not a negotiation. Customers, orders, consent state and full purchase history come out on request in formats that load somewhere else, on any day you like, including the day you leave.

Who else sees it

The list is deliberately short, and every entry earns its place by doing something we could not do without.

WhoWhat forWhat they get
Your payment providerTaking card payments on your own accountPayment data, directly from the buyer
Hosting and databaseRunning the thingEverything, encrypted at rest
Email and SMS deliverySending what you sendRecipient address and message content
Model providerThe plain-language query layerThe text of a query and the data needed to answer it, with no training rights

Where it lives

Data is held in the EEA by default. Where a subprocessor operates outside it, the transfer runs on Standard Contractual Clauses or an adequacy decision. Data residency in a specific country is available on Hibilet Pro.

Cookies

This website sets none. There is no analytics script on the page you are reading, no advertising pixel, and no consent banner, because there is nothing to consent to. The fonts are served from this domain rather than from Google, which is a privacy decision as much as a speed one.

The checkout is different, and honestly so: it sets one first-party identifier so that a basket survives a page reload and so that the person who comes back is recognised as the person who left. That is strictly necessary to sell somebody a ticket. It is not shared, and it is not used for advertising.

Asking us

Write to info@hibilet.com. A person reads it.

Controlling entity: Savrum Solutions B.V., KvK 42032272, Balthasar Coymansstraat 10, 5751MV Deurne, Netherlands. Lead supervisory authority: Autoriteit Persoonsgegevens (Dutch Data Protection Authority).