Toniq Live Limited
Effective Date: [DATE] Version: 2.0
This Privacy Policy explains how Toniq Live Limited ("Toniq," "we," "us," or "our"), a private company limited by shares incorporated in the Hong Kong Special Administrative Region (Certificate of Incorporation No. 80471059), collects, uses, discloses, transfers, and retains personal data in connection with the website at toniq.events and related services (the "Platform").
This Policy is issued in compliance with the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong ("PDPO") and constitutes our Personal Information Collection Statement for the purposes of Data Protection Principle 1(3). Where applicable, it also addresses our obligations under the Personal Data Protection Act B.E. 2562 (2019) of Thailand ("PDPA"), Law No. 27 of 2022 on Personal Data Protection of the Republic of Indonesia ("PDP Law"), the Privacy Act 1988 (Cth) of Australia, and Regulation (EU) 2016/679 ("GDPR") where you are located in the European Economic Area or the United Kingdom.
Data Controller. Toniq Live Limited is the data controller in respect of personal data processed for the operation of the Platform. Where an Organiser separately determines the purposes for which attendee data is used — for example, when sending marketing communications to its own audience — that Organiser acts as an independent controller in respect of that processing.
| Category | Data | When collected |
|---|---|---|
| Contact | Email address | At checkout; when signing in |
| Identity | Name; attendee names you assign to individual tickets | At checkout; when personalising tickets |
| Billing | Billing name and address, where required by the payment method | At checkout |
| Order communications | Contents of support enquiries and correspondence | When you contact us |
| Refund instructions | Destination wallet address for digital asset refunds | When requesting a refund |
| Organiser account data | Name, business details, contact details, team member details, payout details | On Organiser registration |
| Organiser uploads | Images, video, and event content uploaded to the Platform, including any personal data contained within them | When an Organiser configures an event |
| Bug reports | Page URL, browser details, and the reporting user's email address | When a bug is reported from the Organiser console |
| Category | Data | Purpose |
|---|---|---|
| Device and connection | IP address, browser type and version, operating system, device type, screen and viewport dimensions, language and locale settings | Security, fraud prevention, responsive display |
| Usage | Pages viewed, events viewed, checkout steps commenced and completed, timestamps, referring URL | Service operation, analytics, conversion measurement |
| Authentication | Session identifiers, cryptographically signed order-access authorisations stored as cookies, signed resume links | Order access control and account security |
| Time zone | Device time zone, determined in your browser | Display of event times in your local time |
We do not collect, receive, process, or store full payment card numbers, card expiry dates, or card security codes. Card data is captured directly by our payment processor within secure elements embedded in our checkout and is transmitted to that processor without passing through our systems. We receive only a payment reference, the last four digits of the card, the card brand, the transaction outcome, the amount, and the currency of charge.
Where you pay in digital assets, we process the blockchain network selected, the token selected, the deposit address generated for your transaction, the transaction hash, the amount received, and — where you connect a wallet — the public address of that wallet. Blockchain transaction data is recorded on a public, permanent, and immutable ledger which we do not control and from which data cannot be erased.
We do not knowingly collect: government identification numbers from ticket buyers; biometric data; data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, sex life, or sexual orientation; or personal data of children under the age of eighteen (18).
We do not record checkout sessions. Session replay is disabled across the Platform, and specifically within payment pages.
| Purpose | Data used | Legal basis (GDPR, where applicable) |
|---|---|---|
| Processing your ticket purchase and issuing tickets | Contact, identity, billing, payment reference | Performance of a contract |
| Sending transactional communications (order confirmation, tickets, receipts, invoices, refund notices, reservation reminders, material event changes) | Contact, identity, order data | Performance of a contract |
| Providing customer support | Contact, order data, correspondence | Performance of a contract; legitimate interests |
| Verifying access to orders and tickets | Authentication data, contact | Performance of a contract; legitimate interests in security |
| Processing refunds | Order data, wallet address or payment reference | Performance of a contract |
| Preventing fraud, abuse, and automated ticket purchasing | Device and connection, usage, order data | Legitimate interests; legal obligation |
| Investigating reports of unrequested authentication codes | Contact, authentication data | Legitimate interests in account security |
| Screening against sanctions and restricted-party lists | Identity, contact, country data | Legal obligation; legitimate interests |
| Measuring and improving the Platform | Usage, device data | Legitimate interests; consent where cookies are used |
| Advertising measurement and conversion attribution | Usage data, hashed identifiers | Consent only |
| Providing attendee lists to the Organiser of an event you attend | Name, email, ticket quantity | Legitimate interests; performance of a contract |
| Complying with legal, tax, accounting, and regulatory obligations | All categories as required | Legal obligation |
| Establishing, exercising, or defending legal claims | All categories as required | Legitimate interests; legal obligation |
Where we rely on legitimate interests, we have assessed that those interests are not overridden by your interests or fundamental rights. You may object to such processing as described in Section 8.
We disclose personal data only as set out below. We do not sell personal data, and we do not disclose personal data to third parties for their own independent marketing purposes.
When you purchase a ticket, we disclose your name, email address, and the number and category of tickets purchased to the Organiser of that event. The Organiser requires this data to administer admission, to manage capacity, and to communicate with attendees about the event.
The Organiser is an independent data controller in respect of that data. Its use of your data — including any marketing communications it sends — is governed by its own privacy policy and by its obligations under applicable law. We require Organisers to comply with applicable data protection law, but we do not control their processing. Marketing communications sent by an Organiser through the Platform must include an unsubscribe mechanism and are subject to frequency limits.
The following processors receive personal data in order to provide services to us. Each is engaged under a written agreement restricting its use of that data to the provision of the relevant service.
| Provider | Service | Data disclosed | Regulatory status |
|---|---|---|---|
| Stripe (Stripe, Inc. and its regional affiliates) | Card and local payment method processing; Apple Pay, Google Pay, Alipay, WeChat Pay, GrabPay, PayNow | Payment card data (collected directly by Stripe), transaction amount and currency, email address, billing details, device and fraud signals | Licensed payment institution / money transmitter in the jurisdictions in which it operates; PCI DSS Level 1 certified |
| Cobo (Cobo Global Limited and affiliates) | Digital asset wallet infrastructure and custody | Deposit addresses, transaction hashes, transaction amounts, order references | Holder of a Trust or Company Service Provider (TCSP) licence in Hong Kong SAR |
| Resend (Resend, Inc.) | Transactional and Organiser email delivery | Email address, name, message content, delivery and engagement metadata | Data processor; GDPR-compliant Data Processing Agreement in place |
| Supabase (Supabase, Inc.) | Database hosting and persistence | All stored Platform data | Data processor; SOC 2 Type II |
| PostHog (PostHog, Inc.) | Product analytics | Usage events, device and connection data, pseudonymous identifiers | Data processor; session recording disabled |
A current list of processors is maintained at toniq.events/subprocessors. We will provide reasonable notice of the addition of a new processor.
Where, and only where, you have given consent through our cookie banner, we transmit conversion and usage events to the following platforms, using identifiers supplied by the Organiser of the relevant event:
These platforms act as independent or joint controllers in respect of the data they receive. Their processing is governed by their own privacy policies. If you do not consent, no data is transmitted to any of them and no advertising or analytics cookie is set.
Organisers may supply only the numeric or alphanumeric identifier of their advertising account. Organisers cannot inject arbitrary script into the Platform. This restriction exists to prevent a compromised Organiser account from executing code within a buyer's checkout session.
We may disclose personal data:
(a) where required by law, court order, subpoena, or binding request of a competent regulator or law enforcement authority; (b) where necessary to establish, exercise, or defend legal claims; (c) to our professional advisers, auditors, and insurers, under obligations of confidentiality; (d) to a banking, custody, or payment partner conducting due diligence on Toniq, to the extent necessary and in aggregated or minimised form wherever possible; (e) in connection with a merger, acquisition, financing, or sale of assets, subject to the recipient being bound to treat the data in accordance with this Policy; and (f) where you have expressly consented.
Toniq is established in the Hong Kong SAR. Our service providers are located in a number of jurisdictions, including the United States, the European Union, and Singapore. Your personal data will therefore be transferred outside your country of residence.
Where personal data is transferred out of a jurisdiction that restricts such transfers, we rely on one or more of the following safeguards:
(a) Standard Contractual Clauses approved by the European Commission, incorporated into our agreements with processors; (b) your explicit consent, where obtained and where permitted as a transfer basis; (c) the necessity of the transfer for the performance of our contract with you; or (d) contractual undertakings equivalent to those recommended by the Hong Kong Privacy Commissioner for Personal Data.
You may request further information about the safeguards applied to a particular transfer by contacting privacy@toniq.live.
| Data | Retention period | Basis |
|---|---|---|
| Order and transaction records | Seven (7) years from the date of the transaction | Hong Kong tax and companies legislation; accounting requirements |
| Ticket and admission records | Two (2) years following the event | Dispute resolution; chargeback windows |
| Contact and account data | Duration of the account, plus two (2) years | Contract; dispute resolution |
| Support correspondence and bug reports | Three (3) years from closure | Dispute resolution; service improvement |
| Marketing consent records | Duration of the consent, plus three (3) years following withdrawal | Evidence of consent |
| Analytics data | Twenty-six (26) months | Data minimisation |
| Server and security logs | Twelve (12) months | Security; incident investigation |
| Authentication codes | Ten (10) minutes, or until invalidated by use, by five incorrect attempts, or by report | Security; data minimisation |
| Signed resume links | Forty-eight (48) hours after the end of the associated reservation | Security; data minimisation |
Data is deleted or irreversibly anonymised at the expiry of the applicable period, unless a longer period is required by law or the data is subject to a legal hold.
Blockchain records cannot be deleted. Transactions settled on a public blockchain are permanently recorded on that network. Deletion of our records does not and cannot remove data from any blockchain.
We maintain technical and organisational measures appropriate to the risk. Our security controls were last subject to a full internal review in August 2026. Current measures include:
Data in transit and at rest
Access to orders and tickets
Transaction integrity
Accounts
Uploads
General
No system is entirely secure. We do not warrant absolute security. You are responsible for maintaining the security of the email account through which your tickets are delivered and your orders are accessed.
Subject to the law applicable to you, you have the following rights:
| Right | Description |
|---|---|
| Access | To be told whether we hold personal data about you and to receive a copy |
| Correction | To have inaccurate or incomplete data corrected |
| Erasure | To have data deleted where it is no longer necessary, where consent is withdrawn, or where processing is unlawful |
| Restriction | To have processing restricted while a dispute about accuracy or lawfulness is resolved |
| Objection | To object to processing based on legitimate interests, and to object at any time to direct marketing |
| Portability | To receive data you provided in a structured, commonly used, machine-readable format |
| Withdrawal of consent | To withdraw consent at any time, without affecting the lawfulness of prior processing |
| Complaint | To lodge a complaint with a supervisory authority |
To exercise a right, contact privacy@toniq.live. We will respond within forty (40) days as required by the PDPO, or within any shorter period required by other applicable law. We may require verification of your identity before acting, and may charge a fee for access requests where permitted by law.
Limitations. Certain rights are qualified. We may decline erasure where retention is required for tax, accounting, anti-money-laundering, or legal-claim purposes. We cannot erase, alter, or reverse data recorded on a public blockchain.
Our use of cookies and similar technologies is described in the Cookie Policy. Non-essential cookies, including all analytics and advertising cookies, are set only where you have given consent, and consent may be withdrawn at any time through the cookie preferences control on the Platform.
Transactional messages — order confirmations, ticket delivery, receipts, invoices, refund notifications, reservation reminders, and notices of material change to an event you have booked — are sent as part of the performance of your purchase contract. These are not marketing and cannot be opted out of while you hold a valid ticket or an active reservation.
Organiser communications — an Organiser may send messages to attendees of its own event through the Platform, including pre-event information and promotional material. Such messages identify the Organiser, are subject to frequency limits, and include an unsubscribe mechanism. Unsubscribing from one Organiser's communications does not affect others.
Toniq marketing — we will send you marketing about Toniq only where you have opted in, or where permitted by applicable law on the basis of an existing customer relationship. Every such message includes an unsubscribe link.
The Platform is not directed to persons under the age of eighteen (18), and we do not knowingly collect personal data from such persons. If we become aware that we have collected personal data from a person under eighteen, we will delete it promptly. If you believe we hold such data, contact privacy@toniq.live.
We use automated processing for fraud detection, abuse prevention, and sanctions screening. These processes may result in an order being declined or an account being suspended. Where a decision producing legal or similarly significant effects is taken solely by automated means, you may request human review by contacting privacy@toniq.live.
We may update this Policy from time to time. The current version and its effective date are published on the Platform. Where a change materially affects how we use your personal data, we will provide notice by email or by prominent notice on the Platform before the change takes effect, and will obtain fresh consent where consent is the applicable legal basis.
Toniq Live Limited Hong Kong Special Administrative Region Certificate of Incorporation No. 80471059
Privacy and data protection: privacy@toniq.live General enquiries: support@toniq.live