Official tickets
Grandstand Tickets
Home Privacy Policy

Privacy Policy

Last updated: 26 March 2026

At Grandstand Tickets, we are committed to protecting your privacy and ensuring the security of your personal data. This privacy policy explains how we collect, use, store, and share your information when you visit our website or use our services. We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other applicable data protection legislation.

1. Who We Are

Grandstand Tickets is a ticket comparison and booking platform operated in the United Kingdom. We connect customers with verified third-party ticket suppliers to help you find the best prices for live sports events worldwide.

For the purposes of data protection law, Grandstand Tickets is the "data controller" — meaning we determine how and why your personal data is processed. If you have any questions about how we handle your data, please contact us via our contact page.

2. Information We Collect

We collect information in the following ways:

Information you provide directly

  • Account information: When you create an account, we collect your name, email address, and password.
  • Order information: When you place an order, we collect your full name, email address, phone number, billing address, and payment details. Payment card details are processed directly by our payment providers (Stripe and Airwallex) and are never stored on our servers.
  • Communication data: When you contact our support team, we collect the content of your messages, your email address, and any attachments you provide.
  • Newsletter preferences: If you subscribe to our newsletter, we collect your email address and sport preferences.

Information we collect automatically

  • Usage data: Pages visited, time spent on pages, click patterns, referral sources, and search queries.
  • Device information: Browser type and version, operating system, screen resolution, device type, and unique device identifiers.
  • Location data: Approximate location based on your IP address, used to display prices in your local currency and show relevant events.
  • Cookies and similar technologies: We use cookies, pixels, and local storage to provide essential website functionality, remember your preferences, and understand how our site is used. See Section 7 for full details.

3. How We Use Your Information

We use your personal data for the following purposes:

  • Order fulfilment: Processing your ticket orders, sending confirmation emails, coordinating ticket delivery with suppliers, and handling payment transactions.
  • Customer support: Responding to your enquiries, resolving order issues, and providing post-purchase assistance.
  • Account management: Maintaining your account, enabling order history, and saving your preferences for a faster checkout experience.
  • Personalisation: Showing you relevant events based on your browsing history, location, and sport preferences.
  • Marketing communications: With your consent, sending newsletters, special offers, and event announcements. You can unsubscribe at any time via the link in every email.
  • Website improvement: Analysing usage patterns to improve our website performance, user experience, and service offering.
  • Fraud prevention: Detecting and preventing fraudulent transactions and protecting both our customers and our business.
  • Legal compliance: Meeting our legal obligations, including tax reporting and responding to lawful requests from authorities.

4. Legal Basis for Processing

Under the UK GDPR, we process your personal data on the following legal bases:

  • Contract performance: Processing necessary to fulfil your ticket order and provide our services (e.g., payment processing, ticket delivery, order communications).
  • Legitimate interests: Processing necessary for our legitimate business interests, such as fraud prevention, website analytics, and improving our services — provided these interests do not override your rights.
  • Consent: Where you have given explicit consent, such as subscribing to our marketing newsletter or accepting optional cookies.
  • Legal obligation: Processing necessary to comply with our legal obligations, such as tax record-keeping and responding to lawful data requests.

5. How We Share Your Information

We do not sell, rent, or trade your personal data. We only share your information with trusted third parties when necessary to provide our services:

  • Ticket suppliers: We share your name and order details with the supplier fulfilling your tickets so they can process and deliver your order.
  • Payment processors: Stripe and Airwallex process your payment securely. They operate as independent data controllers under their own privacy policies.
  • Email service providers: We use trusted providers to send order confirmations, delivery updates, and marketing emails (where consented).
  • Analytics providers: We use services such as Google Analytics and Vercel Analytics to understand website usage. Data is aggregated and anonymised where possible.
  • Hosting and infrastructure: Our website is hosted on Vercel, and our database is managed by Supabase. Both providers maintain robust security and data protection standards.

All third-party processors are contractually required to handle your data securely and only for the purposes we specify. We conduct due diligence on our suppliers to ensure appropriate safeguards are in place.

6. International Data Transfers

Some of our service providers operate outside the United Kingdom. When we transfer personal data internationally, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner's Office (ICO), or transfers to countries recognised as providing adequate data protection.

7. Cookies & Tracking Technologies

We use the following categories of cookies:

  • Essential cookies: Required for the website to function correctly. These enable core features such as shopping cart, checkout, user authentication, and security. They cannot be disabled.
  • Functional cookies: Remember your preferences such as currency selection, language, and recently viewed events to provide a personalised experience.
  • Analytics cookies: Help us understand how visitors use our website by collecting anonymised usage data, including pages visited, time on site, and navigation paths.
  • Marketing cookies: Used to deliver relevant advertisements and measure the effectiveness of our marketing campaigns. These are only set with your consent.

You can manage your cookie preferences at any time through your browser settings. Please note that disabling certain cookies may affect website functionality.

8. Data Security

We take the security of your personal data seriously and implement appropriate technical and organisational measures, including:

  • 256-bit SSL/TLS encryption for all data transmitted between your browser and our servers
  • PCI DSS-compliant payment processing through Stripe and Airwallex — we never store your card details
  • Secure authentication with hashed passwords and session management
  • Regular security assessments and monitoring of our infrastructure
  • Access controls ensuring only authorised personnel can access personal data
  • Encrypted database storage with automated backups

While we take every reasonable precaution, no system is completely secure. We encourage you to use a strong, unique password for your account and to contact us immediately if you suspect any unauthorised access.

9. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes described in this policy:

  • Order data: Retained for 7 years after your last order, in accordance with UK tax and financial record-keeping requirements.
  • Account data: Retained for as long as your account remains active. If you request account deletion, we will erase your data within 30 days, except where retention is required by law.
  • Marketing data: Retained until you unsubscribe. We will also remove inactive subscribers after 24 months of no engagement.
  • Analytics data: Aggregated and anonymised analytics data may be retained indefinitely as it does not identify individuals.
  • Support communications: Retained for 3 years after the last interaction to maintain service quality and handle any follow-up queries.

10. Your Rights

Under the UK GDPR, you have the following rights regarding your personal data:

  • Right of access: Request a copy of the personal data we hold about you.
  • Right to rectification: Request that we correct any inaccurate or incomplete personal data.
  • Right to erasure: Request that we delete your personal data (the "right to be forgotten"), subject to any legal retention requirements.
  • Right to restrict processing: Request that we limit how we use your data in certain circumstances.
  • Right to data portability: Receive your personal data in a structured, commonly used, machine-readable format.
  • Right to object: Object to processing based on legitimate interests or for direct marketing purposes.
  • Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, please contact us via our contact page. We will respond to your request within one month. If you are not satisfied with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

11. Children's Privacy

Our services are not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us and we will promptly delete it.

12. Changes to This Policy

We may update this privacy policy from time to time to reflect changes in our practices, technology, or legal requirements. Any significant changes will be posted on this page with an updated "last updated" date. We encourage you to review this policy periodically. Continued use of our website after changes constitutes acceptance of the updated policy.

13. Contact Us

If you have any questions about this privacy policy or how we handle your personal data, please contact us via our contact page. We aim to respond to all enquiries within 48 hours.

Questions

Have a question?

Have a question about how we handle your data? Our team is happy to help.

Contact Us