Privacy Policy
Effective date: 7 October 2026
1. Who we are
TopTicket ("TopTicket", "we", "us") is a platform for selling event tickets: the "TopTicket: Chiptalar dokoni" mobile app for iOS and Android, the website https://topticket.uz and the related services (the API at api.topticket.uz). Various venues and event organizers sell tickets through the platform.
Personal data operator:
- Name: TECH BUSINESS BROS LLC
- Taxpayer ID (TIN): 308144416
- Registered address: 6G/24 Turkiston Street, Yangiobod MFY, Kokand, Fergana Region, Uzbekistan
- Email for personal data matters: davronbekov.otabek@gmail.com
- Phone: +998 90 047 24 00
This Policy explains what data we receive, why, whom we share it with, how long we keep it and how you can control it. It applies to buyers and visitors of the app and the website. It does not apply to staff of venues and organizers using TopTicket's staff apps; separate rules apply to them.
2. What data we collect
2.1. Data you give us
- Phone number. Needed to sign in (with a one-time code sent by Telegram or SMS); it is the main identifier of your account. Sign-in is currently available for Uzbek numbers (+998).
- First and last name. Used in your profile and printed on tickets as the holder's name. Without a name, the ticket shows your masked phone number.
- Date of birth and gender — optional, for your profile.
- Email — optional; also the address you enter to receive PDF tickets by email.
- Profile photo (avatar) — optional.
- Interface language (Uzbek, Russian, English) and notification settings (concerts, promotions, orders, reminders, SMS copy of tickets).
- Support requests: subject, category, message text and attachments (up to 5 files per message).
- The recipient's phone number when you transfer a ticket to someone.
- The reason for a refund that you give in a refund request.
2.2. Data created as you use the service
- Orders: event, date, seats (sector, row, seat), ticket type, prices, discounts, service fee, promo code, order status, creation and payment time, language, the ticket holder's name and phone.
- Tickets: ticket number, status (valid, used, refunded, cancelled), the time and gate at which the ticket was scanned, transfer history.
- Payments and refunds: payment method (bank card through Multicard, Payme, Click, Uzum, Paynet), amount, status, the payment system's transaction ID, fiscal receipt data.
- Saved cards: the masked card number (e.g. 8600 •••• •••• 1234), the card network, the cardholder name (if the payment system provides it) and an encrypted card token issued by the payment system. We never receive or store the full card number, expiry date or CVV — you enter them only on the Multicard payment page. A card you used to pay on the Multicard page may be added to your saved cards; you can delete it in the app at any time.
- Favorites (events, venues, artists) and "notify me when sales open" subscriptions.
- Waitlist entries for sold-out sessions (number of places, status).
- In-app inbox notifications.
- Consents: which version of the Terms of Use and this Policy you accepted, when, and from which IP address and device.
2.3. Technical data
- App installation ID — a random code the app creates on first launch and keeps in the phone's secure storage. It is not an advertising ID or IMEI.
- Sign-in sessions: platform (iOS, Android, web), app version, device name, IP address, user agent, sign-in and last-activity times.
- Push token (Firebase Cloud Messaging on Android, the Apple Push Notification service on iPhone), platform, language and app version — to send notifications.
- IP address and device ID when an order is created — to protect against bots and scalpers.
- Server logs (request time, path, response code, request ID). We do not write phone numbers or email addresses in clear text, sign-in codes, passwords or tokens to logs.
2.4. Data from third parties
From payment systems: payment and refund status, the masked card number and card token (see 2.2), fiscal receipt data.
2.5. What we do not collect
We do not collect your location, contacts, gallery photos (other than files you attach yourself), biometrics or advertising IDs. The app contains no third-party advertising or analytics SDKs. We do not ask for calendar access: when you add an event to your calendar, the app opens your phone's standard calendar screen and you decide whether to save the event.
3. Why we use data
- Sign-up, sign-in, account security — phone, sign-in code, sessions, device, IP. Legal basis: your consent; performance of the contract (offer).
- Selling tickets: seat holds, payment, ticket issue — orders, tickets, payments, holder name and phone. Legal basis: performance of the contract.
- Entry to the event (QR check) — ticket number, seat, status, entry time. Legal basis: performance of the contract.
- Refunds, rescheduled and cancelled events — orders, payments, contacts. Legal basis: performance of the contract; consumer protection law.
- Fiscal receipts, accounting and tax — amounts, order contents, payment data. Legal basis: legal obligation.
- Service notifications (payment, reminders, reschedule or cancellation, refund, support reply) — push token, phone, language. Legal basis: performance of the contract.
- Marketing and news (new concerts, promotions) — push token, language, favorites. Legal basis: your consent (can be switched off in settings).
- Customer support — requests, attachments, orders. Legal basis: performance of the contract; your request.
- Preventing fraud, bots and resale — IP, device ID, hold history. Legal basis: legitimate interest; performance of the contract.
- Sales statistics for organizers — aggregated amounts and counts. Legal basis: legitimate interest.
- Transferring a ticket to someone else — the recipient's phone. Legal basis: performance of the contract; your instruction.
We do not sell your personal data, and we do not make decisions with legal effects for you based solely on automated processing. Automated limits (for example, a temporary block on holds after many unpaid orders) only serve to stop bots and lift automatically.
4. Whom we share data with
We share only what a specific task requires.
Organizers and venues. The event organizer (a venue or a promoter) receives order data for its own events: order number, seats, amounts, the ticket holder's name and phone — for entry, refunds and contacting you if the event changes. Promoters by default see only masked data (first name and an initial, masked phone, no email). The organizer is the party that receives the payment for tickets. Entry staff see the seat, ticket type and the holder's name when scanning; supervisors may also see the holder's phone number.
Service providers (processors):
- Multicard (Rahmat) — payment provider: the card payment page, saved cards, refunds, fiscal receipts. Through Multicard a payment may be sent to the Payme, Click, Uzum or Paynet app, in which case the system you choose processes it. When you add a card, Multicard receives your phone number; when you pay with a saved card, it receives your device's IP address and user agent (banks and payment systems require them to verify the card and the payment).
- Payme, Click — if an organizer accepts payments through them directly.
- The fiscal data operator and tax authorities — fiscal receipts (purchase contents and amounts) as the law requires.
- Telegram (the Telegram Gateway service) — delivery of sign-in and confirmation codes in Telegram; it receives your phone number and the code. If the code cannot be delivered in Telegram, it is sent by SMS.
- Eskiz (eskiz.uz) — SMS delivery: sign-in codes and important notices (reschedule, cancellation, refund).
- Google Firebase (Google LLC, USA) — the Firebase SDK in the app on Android and iPhone, and push notification delivery on Android; Apple Push Notification service (Apple Inc., USA) — push notification delivery on iPhone.
- Railway (Railway Corporation, USA; servers in the EU West region, Amsterdam, the Netherlands) — hosting of servers, the database, cache and file storage (S3-compatible storage for images and support attachments).
- Resend (USA) — sending emails, including PDF tickets to the address you enter.
- Cloudflare (Cloudflare, Inc., USA) — DNS for topticket.uz and, when the check is enabled, the "I'm not a robot" check (Cloudflare Turnstile) when you hold seats.
- Expo (650 Industries, Inc., USA) — delivery of app updates; checking for updates sends technical device data, not personal data from your account.
Public authorities — only on a lawful request and where the law of the Republic of Uzbekistan requires it.
5. Where data is stored; cross-border transfer
TopTicket's servers (API, database, cache, file storage) run with the provider Railway in a data center in Amsterdam (the Netherlands). Push notifications pass through Google and Apple servers, sign-in codes sent by Telegram through Telegram's servers, emails through Resend, and DNS and bot protection through Cloudflare. This is a cross-border transfer of your personal data. By accepting this Policy you consent to it. We choose providers that protect data reliably.
6. How long we keep data
- Account — while it exists. After deletion — see section 7.
- Sign-in sessions — up to 180 days from sign-in (up to 60 days without activity); records of ended sessions are deleted after 30 days.
- Orders, payments, refunds, fiscal receipts — at least 5 years after the transaction, as the tax and accounting law of the Republic of Uzbekistan requires, and then until we delete or anonymise them.
- Tickets and entry history — together with the order.
- Support requests — at least 5 years, then until we delete or anonymise them.
- Push tokens — while the app is installed and you are signed in; deleted with your account; invalid tokens are marked and no longer used.
- Internal notification queues — up to 7 days after sending (they hold IDs only, no names or phones).
- Unfinished file uploads — deleted within two days.
- Server logs — up to 30 days.
7. Deleting your account
You can delete your account in the app: Profile → Delete account, confirmed with a one-time code. If you have valid tickets for upcoming events, deletion becomes available once those events are over or the tickets are refunded, so that you do not lose an entry you paid for.
You can also email davronbekov.otabek@gmail.com with the subject "Delete my TopTicket account" and give the phone number of the account. To make sure the request is yours, we call or message that number. We reply within 3 business days and delete the account within 10 days of receiving the request.
Immediately on deletion:
- your phone number, first and last name, email, date of birth, gender and profile photo are erased;
- push tokens, favorites, inbox notifications and waitlist entries are deleted;
- saved cards are deleted (their tokens are revoked with Multicard and wiped);
- every session on every device is ended (device records are erased 30 days later);
- outgoing ticket transfers awaiting an answer are cancelled;
- your name, phone number, IP address and device ID are erased from orders, and the holder's name and phone from tickets for past events.
What is kept, and why:
- Orders, payments, refunds and receipts — no longer linked to your profile, but with amounts, dates, order and ticket numbers, as required for accounting, tax and refunds. They are kept for at least 5 years after the transaction, as the law requires, and then until we delete or anonymise them.
- Issued tickets and their entry scan records — together with the orders.
- Records of accepted documents and support requests — as proof of consent and of the request history, within the periods in section 6.
Deletion cannot be undone. If you sign in again with the same number, a new account is created without your previous data.
8. Cookies and similar technologies
The app stores on your device: sign-in tokens (in the secure iOS Keychain / Android Keystore), the installation ID, language and settings, and a ticket cache so tickets show without internet. This is needed for the app to work; it is removed when you sign out or uninstall the app.
The website topticket.uz uses only strictly necessary cookies and browser local storage (sign-in, language, a device ID for bot protection). When the "I'm not a robot" check is enabled, Cloudflare Turnstile may use its own strictly necessary data. We do not use advertising or analytics cookies, our own or third parties'.
9. Notifications and marketing
- Service notifications (order payment, refunds, event reschedule or cancellation) always arrive because they concern tickets you bought. Reschedule, cancellation and refund notices are also sent by SMS. An SMS with a link to your tickets after payment can be switched on in settings.
- Event reminders (24 and 3 hours before) and "sales are open" notices for favorites can be switched off in the app settings.
- Marketing messages (promotions, discounts) arrive only if you opted in; switch them off in the app settings or your phone's notification settings.
10. Children
The service is not intended for independent use by persons under 16. Parents or legal guardians buy tickets for children from their own accounts. If you learn that a child gave us data without parental consent, write to us and we will delete the account. Event age ratings (0+, 6+, 12+, 16+, 18+) are shown on the event page; the venue may check ID at entry.
11. How we protect data
- All traffic between the app, the website and our servers is encrypted (HTTPS/TLS).
- Saved-card tokens and payment-system secrets are stored encrypted in the database (AES-256, with keys kept separately from the database).
- Sign-in codes are valid for 3 minutes and stored only as a hash; attempts are limited.
- Ticket QR codes carry a cryptographic signature; when a QR code is reissued, the old code stops working.
- Organizer staff see only data for their own events and only within the rights granted to them; changes and data exports are recorded in an audit log.
- Phone numbers and email addresses are masked in server logs.
No system is perfectly secure. If a breach occurs that may affect your rights, we will notify you and the competent authority as the law requires.
12. Your rights
You have the right to:
- know whether we process your data and receive information about it;
- correct your data — name, email, date of birth, language and photo in your profile; your phone number in your profile, confirmed with a code;
- withdraw consent to marketing — in settings;
- delete your account — in the app or on request (section 7);
- withdraw consent to processing altogether — this means deleting the account, except for data we must keep by law;
- complain to the competent personal data authority or a court.
Send requests to davronbekov.otabek@gmail.com or to the address in section 1. We reply within 10 days of receiving a request, unless the law sets a shorter period. To protect your data we may ask you to confirm that the request is yours (for example, with a code sent to the account's number).
13. Changes to this Policy
We may update this Policy. A new version is published in the app and on the website with its effective date. If the changes are material, the app will ask you to accept the new version at your next sign-in.
14. Contact
- Operator: TECH BUSINESS BROS LLC, TIN 308144416
- Address: 6G/24 Turkiston Street, Yangiobod MFY, Kokand, Fergana Region, Uzbekistan
- Personal data email: davronbekov.otabek@gmail.com
- Customer support: davronbekov.otabek@gmail.com, +998 90 047 24 00, the "Help" section of the app
- Website: https://topticket.uz
Operator
- Company
- TECH BUSINESS BROS LLC
- TIN
- 308144416
- Registered address
- 6G/24 Turkiston Street, Yangiobod MFY, Kokand, Fergana Region, Uzbekistan