Privacy PolicySEATSHIFT B.V. Last updated: September 23, 2025 At SeatShift B.V., we value your privacy. This policy explains what personal data we collect, why we process it, how long we store it, and your rights under the General Data Protection Regulation (GDPR).
1. Who are we? SeatShift B.V.
Scheggertdijk 54
7218NB Almen, The Netherlands
KVK: 98062743
VAT: NL868343547B01
[email protected]
+31 6 31272749 2. What personal data do we process? We only collect what is strictly necessary: • Name and surname
• Email address
• Phone number
• Optional billing/shipping address
• Payment details via Stripe (we do not store these)
• Anonymized technical data via Google Analytics
• Ticket-specific data (e.g., name/email for personalized tickets)
3. Why do we use your data? Based on Article 6 of the GDPR: • Order and ticket processing – contract performance
• Customer service – legitimate interest
• Fraud prevention – legal obligation / legitimate interest
• Marketing (newsletter) – consent
• Website analysis (Google Analytics) – consent via cookies
4. Cookies and tracking We use cookies for: • Functional purposes (no consent needed)
• Analytics (Google Analytics – with consent)
• Marketing (with consent) Preferences can be managed via our cookie banner.
5. Newsletters and marketing We use Mailchimp (US) for email campaigns. Data is protected with SCCs. You can unsubscribe via the link in any email.
6. Data retention • Order data: 7 years
• Newsletter data: until you unsubscribe
• Inactive accounts: 2 years
• Analytics data: 14 months (anonymized)
• Ticket data: up to 1 year after the event
7. Sharing with third parties • Mailchimp (US)
• Google Analytics (US)
• Stripe (payments)
• Event organizers (for personalized tickets)
8. Your rights You have the right to access, correct, delete, restrict, object, and transfer your data. You may file a complaint with the Dutch Data Protection Authority.
9. Security We protect your data using: • SSL encryption
• Access controls and 2FA
• Regular updates We notify the DPA within 72 hours of any breach (and affected users if necessary).
10. Changes We may update this policy. Major changes will be communicated at least 30 days in advance.