Privacy policy
How BoxxTicket collects, uses, shares and protects personal data, in accordance with the Data Protection Act, 2012 (Act 843) of the Republic of Ghana.
Last updated: 29 April 2026.
1. Who is the data controller
BoxxTicket, headquartered in Accra, is the data controller for the personal data you provide on boxxticket.com. Where an event organiser receives your data for entry verification or communication, they become an independent controller for those purposes.
2. What data we collect
- Account data — full name, email, phone, encrypted password, and (for admins) TOTP secret.
- Order and ticket data — events purchased, tier, attendee names if you supply them, payment reference, and amount.
- Delivery data — the email address and phone number we send your ticket to.
- Technical data — IP address, browser user-agent, the time of each request, and ticket scan logs.
- Marketing data — only with your opt-in: city, interest categories, event reminder preferences.
We do not store full card numbers or PINs. Paystack handles payment instruments directly and we receive only a token reference.
3. Why we process it
- Performance of contract — issuing your ticket, delivering it via email and WhatsApp, validating entry.
- Legal obligation — tax records, fraud prevention, anti-money-laundering checks where applicable.
- Legitimate interest — securing the platform (rate-limiting, anomaly detection), reconciliation with payment providers, customer support.
- Consent — marketing emails, event reminders beyond the ones tied to a purchase, optional surveys.
4. Who we share it with
- The event organiser — name, email, phone, and ticket tier so they can verify entry and contact you about the show.
- Paystack — to process payment and reconcile settlements.
- Transactional email — tickets, receipts, password resets and verification links are sent over SMTP from our own mail server. Your email provider (Gmail, Outlook, Yahoo, etc.) handles the inbox.
- WhatsApp Business Cloud API (Meta) — to deliver tickets via WhatsApp where you have opted in.
- Cloudflare — DNS, CDN and DDoS protection at the network edge.
- Google reCAPTCHA — risk score on signup and sign-in, used to block automated abuse. Google receives the minimal data described in their Privacy Policy.
- Hosting and database — our self-managed Linux VPS, with scheduled encrypted backups to Cloudflare R2.
- Law enforcement — only where compelled by valid Ghanaian legal process.
We do not sell your personal data to advertisers. We do not share non-winners’ full personal data with organisers after a draw.
5. International transfers
Some of our processors (Paystack, Meta, Cloudflare) operate outside Ghana. Where personal data is transferred outside Ghana, we ensure the recipient offers an adequate standard of protection consistent with section 47 of Act 843, typically through standard contractual clauses or a recognised certification.
6. Retention
- Account data — for as long as your account is active.
- Order and ticket data — for the period required by Ghanaian tax and accounting law.
- Scan logs — for the duration of the event season and any reasonable fraud-investigation period after.
- Marketing consents — until you unsubscribe; the unsubscribe record itself is kept long enough to honour the opt-out.
7. Your rights
You have the right under Act 843 to:
- Access your personal data we hold about you.
- Correct inaccurate data.
- Have data erased where it is no longer needed for the purpose you provided it for.
- Restrict or object to processing.
- Receive a copy of your data in a portable format.
- Withdraw any consent you have given, without affecting prior processing.
- Lodge a complaint with the Data Protection Commission (Ghana) if you believe we have mishandled your data.
To exercise any of these rights, email [email protected]. We respond within the period set out in Act 843.
8. Security
We protect your data with encryption in transit (TLS 1.3 enforced via HSTS preload), encryption at rest for backups, password hashing using scrypt with per-user salt, mandatory two-factor authentication for admin accounts, and strict role-based access within our team. We log every administrative action to a hash- chained audit trail and verify its integrity daily.
9. Cookies
We use a single first-party cookie (bt_session) to keep you signed in. It is HttpOnly, Secure, and SameSite=Strict. We do not use third-party tracking cookies. Where we use privacy-respecting platform analytics, the choice is disclosed on this page when it is enabled.
10. Children
BoxxTicket is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has registered, contact us and we will delete the account.
11. Changes to this policy
We will publish updates at this URL with a new “Last updated” date. Material changes are announced by email to registered users.
12. Contact
Data protection questions: [email protected].