โš ๏ธ Test Site โ€” No current competitions are real
Ticket HiveTicket HiveCompetitions
๐Ÿ“œ Legalv3Effective 16 July 2026

Privacy Policy

Last updated 16 July 2026Back to top

Privacy Policy (v2, effective 9 July 2026)

โ–1. About this policy#

This Privacy Policy (v2, effective 9 July 2026) describes how Ticket Hive LTD ("we", "us", "our") collects, processes, secures and stores personal data. We are the data controller. The Information Commissioner's Office (ICO) is the supervisory authority for our processing. The previous version (v1) is available on request.

โ–2. What we collect#

  • Identity & contact: name, email, phone, address, date of birth.
  • Account: password hash, session cookies, two-factor settings where enabled.
  • Activity: ticket purchases, reservations, draws entered, draw history, free postal entries.
  • Payments: card-tokenised references held by our payment gateway; we never store full card numbers.
  • Website Credit: grant history, redemption history, removal history (see ยง7).
  • Play controls: pause / suspension / closure events with timestamps.
  • Harm signals: low-severity risk signals flagged on the account (see ยง9).
  • Marketing: opt-in / opt-out events.
  1. Lawful basis for processing (UK GDPR Art. 6)

We rely on:

  • 6(1)(b) Performance of a contract โ€” to administer your account, take payment, deliver prizes, and operate the Website Credit ledger.
  • 6(1)(f) Legitimate interest โ€” to prevent fraud, audit draws, and maintain platform security.
  • 6(1)(a) Consent โ€” for marketing and analytics cookies.
  • 6(1)(c) Legal obligation โ€” for HMRC-relevant financial record-keeping.

โ–4. How long we keep data#

  • Account profile data: while the account is active. Deletion within 30 days of a verified deletion request.
  • Payments ledger: 7 years after the last payment for HMRC (Companies Act record-keeping).
  • Audit log rows tied to compliance: 7 years.
  • Marketing consent events: until withdrawn + 2 years.
  • Cookie consent: 1 year.

โ–5. Sharing & third parties#

We do not sell or rent personal data. We share data with:

  • Payment processors (Stripe) for card handling.
  • Email delivery partners for transactional and (opted-in) marketing emails.
  • Cloud hosting and database providers with UK / EEA-based infrastructure.
  • Regulators and law-enforcement where required.

โ–6. International transfers#

  • Where data is transferred outside the UK, we rely on UK adequacy regulations or the relevant International Data Transfer Agreement / Standard Contractual Clauses.
  • Your data may be transferred outside the UK and EU to facilitate the prize payment and comply with applicable regulatory requirements, including anti-money laundering (AML) obligations. In such cases, we will ensure appropriate safeguards are in place to maintain a level of data protection equivalent to that required under UK and EU data protection laws.

โ–7. Website Credit account (data we store)#

  • Why: to administer the credit balance, run our regulatory obligations, and prevent fraud.
  • What: a running ledger of grants, redemptions, removals and forfeitures. Each row records the amount, the reason code, a related competition or payment where applicable, and the admin actor for any grant or removal.
  • Lawful basis: UK GDPR Art. 6(1)(b) โ€” performance of contract (the credit IS a contract right under ยง9 of the Terms).
  • Retention: 7 years from the date the balance returns to zero, alongside the payments ledger.
  • What we do not share: the balance or the ledger is never shared with any third party. It is visible only to the account holder and to Ticket Hive's support and finance staff on a role-restricted basis.
  • No third-party tracking: no third-party pixels, ad networks or analytics tools see this ledger.

โ–8. Your rights (UK GDPR)#

  • Right of access (Art. 15).
  • Right to rectification (Art. 16).
  • Right to erasure (Art. 17) โ€” subject to legal record-keeping (HMRC 7 years).
  • Right to restriction (Art. 18).
  • Right to data portability (Art. 20).
  • Right to object (Art. 21).
  • Right to withdraw consent at any time, where the basis is consent.

To exercise these rights, contact our DPO at `dpo@tickethive.uk` or use the in-app Account โ†’ Data controls.

โ–9. Harm-signal monitoring#

We may record low-severity risk signals on a player account where the platform detects:

  • Self-set monthly spend limit hit.
  • Disproportionate repeat entries within a short period.
  • Late-night activity past midnight local time.
  • Admin-flagged concerns from support interactions.

These signals are administrative data only. They are not shared externally, are visible only to our support and safeguarding staff, and are retained for 2 years.

โ–10. Cookies#

Our Cookie Policy (separate document) describes cookies in detail and lists the data they collect. Non-essential cookies are opt-in.

โ–11. Changes to this Privacy Policy#

We may update this policy; the version and effective date are at the top. Material changes will be communicated by email if you have an active account.

โ–12. Contact#

For any data-protection query, email `dpo@tickethive.uk` or write to the registered office.

Questions about this document? We're happy to help.