stubwiseDeutsch

Privacy policy

Draft for owner review. This document must be approved before the public launch.

Last updated: 19 September 2026

1. Who is responsible

Stubwise is operated by Theo Fuhrmann, Moltkestraße 25, 40477 Düsseldorf, Germany. For privacy questions, contact support@stubwise.co or +49 174 6386022. Merchants remain responsible for their customer and attendee data; Stubwise processes event-ticketing data on their instructions.

2. Information we process

We process the store domain, store contact details, Shopify authorization credentials, subscription plan, event and date details, order and line-item identifiers, buyer name and email, attendee name and email, optional attendee answers, ticket codes, delivery status, check-in records and support messages. We do not store payment-card information. Door staff can see attendee names and ticket codes, but not email addresses.

3. Purposes and legal bases

We use this information to provide contracted ticketing services, deliver transactional tickets, collect attendee details, enforce ticket validity, provide support and meet legal obligations. The applicable bases for our own processing are contractual necessity, legal obligations, and legitimate interests in secure and reliable operation (GDPR Article 6(1)(b), (c) and (f)). Merchants must determine and communicate their own lawful basis for attendee processing and optional questions.

4. Hosting and service providers

The service uses Cloudflare Workers, D1, R2, KV and Email Service for hosting, storage and email delivery. Shopify provides the commerce platform, checkout, inventory and subscription billing. Personal data may be processed outside the European Economic Area; the final provider agreements and applicable transfer safeguards must be confirmed before launch.

If the operator enables optional support drafting through Claude Code, the support message subject and text, product facts, and a limited shop summary are sent to Anthropic. The summary contains the plan, language, recent event titles, delivery counts and latest check-in time. The prompt excludes attendee lists and access credentials, but a sender's message may contain personal information. Installation does not start this runner. Model-written replies require operator review before sending. The owner must review this optional processing and the provider account's retention and transfer terms before enabling it for merchant messages.

5. Storage and deletion

We keep operational information while the app is installed. Following uninstall, store data is retained for up to 30 days to support reinstall, then deleted. Customer and store erasure requests received through Shopify trigger deletion or anonymization of associated personal data. Data required by law may need a different retention period, which must be documented before launch.

6. Cookies, logs and ticket links

We use essential authentication cookies and security logs to run the app. We do not use tracking pixels in ticket emails. Opening a hosted ticket page records the first link opening to help merchants resolve delivery issues. The check-in app stores up to 500 attendee names and ticket codes locally for offline operation, with a 12-hour cache lifetime. Pending offline check-ins are stored until synchronization.

7. Your rights

Subject to applicable law, you may request access, correction, erasure, restriction, portability, or object to processing based on legitimate interests. Contact the event merchant for attendee data requests, or support@stubwise.co for requests concerning Stubwise. You may complain to a supervisory authority, including the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen.

8. Reminders and questions

You can opt out of event reminder emails on your ticket page. Transactional ticket delivery is necessary to provide the service. Please do not submit sensitive information through custom attendee questions unless the merchant has established a lawful need and appropriate safeguards.

Back to Stubwise