Privacy

Privacy Policy

This Privacy Notice describes how Verimly collects, uses, and shares your personal information when you organize events or buy tickets through the platform.

Last updated: July 13, 2026
Bidtofix Limited (trading as Verimly) — London, United Kingdom

Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our Services. Contact us at help@verimly.com.

Summary of Key Points

Who is responsible for your data?

Verimly is operated by Bidtofix Limited (UK). For your platform account we are the data controller. For data you provide when buying a ticket on an event storefront, the event organizer is the controller and we process that data on their behalf.

What do we collect?

Account details (name, email), workspace and event data, order and ticket data, and technical data such as IP address and browser information. We never see or store your full card number — payments are handled by Stripe.

Do we sell your data or use it for advertising?

No. We do not sell personal data, we do not buy data about you from third parties, and we do not run advertising or third-party analytics trackers on verimly.com.

Do we process any sensitive personal information?

No. We do not knowingly collect or process special categories of personal data.

Who do we share data with?

Only with the service providers needed to run the platform: Stripe (payments), Vercel (hosting and file storage), Neon (database), and Resend (email delivery). Each is bound by a data processing agreement.

How do you exercise your rights?

You can access, correct, or delete your data from your account settings, or contact us at help@verimly.com. We respond within one month.

01

Who We Are and What This Notice Covers

Verimly is an event ticketing platform operated by Bidtofix Limited, a company registered in England and Wales (company number 15945513), 85 Great Portland Street, London W1W 7LT, United Kingdom ("Verimly", "we", "us").

This Privacy Notice explains how we handle personal data when you use the Verimly platform — the verimly.com website, organizer dashboards and workspaces, point-of-sale tools, and the infrastructure behind public event storefronts.

Event storefronts are published by independent event organizers. When you buy a ticket or register for an event on a storefront, the organizer is the data controller for your data and this processing is described in that storefront's own privacy policy (linked in its footer). This notice explains our role in that processing in the "Our Roles" section below.

02

Our Roles: Controller and Processor

Where Verimly is the data controller

We act as the data controller — meaning we decide how and why data is processed — for:

Organizer accounts — registration details, workspace settings, billing and fee invoices, and dashboard activity of event organizers and their team members.

Platform operations — server logs, security monitoring, fraud prevention, and communications you have directly with us (for example support emails to help@verimly.com).

Where Verimly is a data processor

We act as a data processor — handling data only on the organizer's documented instructions — for personal data collected through event storefronts, including buyer names and email addresses, orders, tickets, seat selections, check-in records, and storefront visitor analytics.

For this data, the event organizer is the controller. If you are a ticket buyer and want to exercise your data rights over your order data, the fastest route is to contact the organizer of the event; you can also contact us and we will assist or forward your request to the organizer.

Payment processing

Card and payment data is collected and processed directly by Stripe, which acts as its own data controller for payment information under its privacy policy at stripe.com/privacy. Verimly never receives or stores full card numbers.

03

What Information Do We Collect?

Information organizers provide

When you create a Verimly account and workspace, we collect your name, email address, and password (stored only as a secure hash). As you use the platform we also store the content you create: workspace details, events, ticket types, seat maps, storefront content and settings, custom domain names, team member and point-of-sale personnel details, and your Stripe Connect account identifier and payout-related metadata (we do not store your bank details — those live with Stripe).

Information buyers provide

When you buy a ticket or register for an event on a storefront, we process — on the organizer's behalf — the name and email address you enter at checkout, your order details (event, ticket types, seats, products, amounts, currency), refund and dispute records related to your order, and your check-in status at the event. Buyers do not create accounts and no password is collected from buyers.

Information collected automatically

Like most online services, our servers automatically record technical information when the platform is used: IP address, browser type and version (user agent), referring URL, pages requested, and timestamps. This is used for security, debugging, and abuse prevention.

On event storefronts we also maintain an anonymous per-visit session record for the organizer's live analytics: a random session identifier, the page currently viewed, IP address, approximate location derived from it (country and city level), user agent, and referrer. This session is not linked to a buyer identity unless a purchase is completed, and is used to show organizers live visitor activity and abandoned checkouts for their own storefront.

What we do NOT collect

We do not collect or store full payment card numbers or CVC codes (handled entirely by Stripe). We do not collect special categories of personal data (such as health, religion, or biometric data). We do not buy data about you from data brokers or "enrich" your profile from external sources. We do not use precise GPS location. We do not place advertising trackers or third-party analytics on verimly.com.

04

How Do We Use Your Information?

We use personal data only for the following purposes:

  • To provide the platform — creating and managing accounts and workspaces, publishing storefronts, processing orders, issuing tickets with QR codes, managing seat selection and holds, and running check-in and point-of-sale tools.
  • To send transactional emails — order confirmations and e-tickets, refund and cancellation notices, and sign-in verification codes.
  • To collect our service fees from organizers and issue fee invoices.
  • To keep the platform secure — authenticating sessions, preventing fraud and abuse, monitoring for suspicious orders (including Stripe fraud warnings), and protecting the integrity of ticket sales.
  • To provide organizers with analytics about their own storefront — live visitor activity, sales, and abandoned checkouts.
  • To respond to support requests and legal or data-rights inquiries.
  • To comply with legal obligations, including accounting, tax, and responding to lawful requests from authorities.

We do not use your personal data for third-party advertising, we do not sell it, and we do not use it to train AI models.

06

Who Do We Share Your Information With?

We share personal data only where necessary to run the platform, with the following recipients:

  • Stripe (payments) — processes all payments, payouts, refunds, disputes, and organizer identity verification. Privacy policy: stripe.com/privacy.
  • Vercel (hosting & file storage) — hosts the platform and stores files such as uploaded images and private fee-invoice PDFs. Privacy policy: vercel.com/legal/privacy-policy.
  • Neon (database) — provides the managed PostgreSQL database where platform data is stored. Privacy policy: neon.tech/privacy-policy.
  • Resend (email delivery) — delivers transactional emails such as tickets, receipts, and verification codes. Privacy policy: resend.com/legal/privacy-policy.
  • Event organizers — if you buy a ticket, the organizer of that event has access to your name, email, order, and check-in data for their event, as the data controller of that data.
  • Google / Meta — only on storefronts where the organizer has connected Google Analytics or Meta Pixel, and only after you consent via the cookie banner on that storefront. These tools are never active on verimly.com itself.

We may also disclose personal data where required by law or to protect our rights, and in connection with a merger, acquisition, or sale of assets — in which case this notice will continue to apply to your data and we will notify you of any change of controller.

We do not sell or rent personal data to anyone.

07

International Transfers

Our service providers listed above may store or process data in the United States or other countries outside the UK and the European Economic Area.

Where personal data is transferred outside the UK or EEA, we rely on appropriate safeguards recognized under the UK GDPR and EU GDPR — including the EU Standard Contractual Clauses with the UK Addendum or the UK International Data Transfer Agreement, and, where applicable, the EU–US and UK–US Data Privacy Framework certifications of our providers.

You can request more information about the safeguards applied to your data by contacting help@verimly.com.

08

How Long Do We Keep Your Information?

We keep personal data only as long as needed for the purpose it was collected, then delete or anonymize it. Our retention periods by category:

Organizer accounts and workspaces — kept while your account is active. After account deletion, personal data is removed from active systems within 12 months, except records we must keep longer by law.

Orders, tickets, refunds, and fee invoices — kept for up to 7 years after the transaction, as required by accounting and tax law.

Storefront visitor sessions and abandoned carts — operational data used for live analytics and checkout recovery; kept for a short operational period and no longer than 12 months.

Server and security logs — kept for up to 12 months for security and abuse investigation.

Support correspondence — kept for up to 24 months after the inquiry is resolved.

Where deletion from backup archives is not immediately possible, data is isolated from further processing until backups expire.

09

Cookies and Similar Technologies

verimly.com uses only essential cookies: authentication session cookies and a cookie that remembers your consent choice. We do not use advertising or analytics cookies on the platform.

Event storefronts may additionally use analytics (Google Analytics) or marketing (Meta Pixel) cookies if the organizer has connected them — these are only loaded after you give consent via the cookie banner on that storefront.

For the full list of every cookie and browser-storage key we use, see our Cookie Notice at verimly.com/cookies.

10

How Do We Keep Your Information Safe?

We apply appropriate technical and organizational measures to protect personal data, including: encryption of data in transit (TLS) and at rest, passwords stored only as secure hashes, httpOnly authentication cookies, access controls that scope every workspace's data to its authorized members, private (non-public) storage for invoice documents, and payment handling delegated entirely to Stripe (PCI DSS Level 1 certified).

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a personal data breach that risks your rights, we will notify the relevant supervisory authority and, where required, affected individuals without undue delay.

11

Children

Verimly accounts may only be created by people aged 18 or over. The platform is not directed at children, and we do not knowingly collect personal data from children.

Ticket purchases require the legal capacity to enter into a contract. Age restrictions for attending a specific event are set by the event's organizer.

If you believe a child has provided us personal data, please contact help@verimly.com and we will delete it.

12

Your Privacy Rights

Under the UK GDPR and EU GDPR you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — have inaccurate data corrected.
  • Erasure — have your data deleted ("right to be forgotten"), subject to legal retention duties.
  • Restriction — limit how we process your data in certain circumstances.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests, including at any time to any direct marketing.
  • Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing.

To exercise these rights, use your account settings or email help@verimly.com. We will respond within one month. We may need to verify your identity before acting on a request. If you are a ticket buyer, requests about your order data may be handled together with, or forwarded to, the event organizer as controller.

If you are unhappy with how we handle your data, you can complain to the UK Information Commissioner's Office (ico.org.uk) or, if you are in the EEA, to your national data protection authority. Residents of other jurisdictions (such as California or other US states) may have similar rights under local law, which we will honor on request.

13

Updates to This Notice

We may update this Privacy Notice from time to time to reflect changes in the platform, in law, or in our providers. The "Last updated" date at the top shows the latest revision.

If we make material changes, we will notify you — for organizers, by email or a prominent notice in the dashboard — before the changes take effect. We encourage you to review this notice periodically.

14

How Can You Contact Us?

If you have questions or comments about this notice, or wish to exercise your data protection rights, you may email us at help@verimly.com or contact us by post at:

Bidtofix Limited (trading as Verimly)

85 Great Portland Street

London W1W 7LT

United Kingdom — Company No. 15945513

help@verimly.com

Questions?

If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at help@verimly.com or visit your account settings to review, update, or delete your personal information.