Privacy Policy
Last updated: June 2026
Introduction
Antara Events (“we”, “us”, “our”) operates the event ticketing platform at antara.events. This Privacy Policy explains how we collect, use, share, and protect your personal data when you use our services as a ticket buyer, event organizer, venue partner, or gate staff member.
We are committed to compliance with the Kenya Data Protection Act 2019 (DPA) and the regulations made under it. Our registered office is in Kenya.
Data Controller
Antara Events is the data controller for the personal data described in this policy. For questions or requests regarding your data, contact us at privacy@antara.events.
Data We Collect
Ticket Buyers
When you purchase a ticket, we collect your full name, phone number, and email address. No account is required. We use this data to:
- Deliver your tickets via WhatsApp and email
- Send order confirmations and event updates
- Provide customer support for your order
- Enable event organizers to manage attendance for their events
Event Organizers
When you register as an organizer, we collect:
- Contact details: email address, phone number, business name, display name
- Tax identification: KRA PIN
- Payout details: bank or M-Pesa account information, including account number, bank code, and account holder name
- KYC documents: KRA PIN certificate, national ID or passport, business registration certificate, and CR12 certificate (where applicable)
This data is used for identity verification, event management, and processing payouts.
Venue Partners
For partner venues, we collect the contact name, phone number, email address, physical address, and geographic coordinates. This data is used for venue management and event coordination. Venue accounts are created by Antara Events administrators only.
Gate Staff
We collect the phone number of gate staff to send magic link access for the ticket scanner. No account registration is required.
Payment Data
All payments are processed by Paystack, our payment processor. Paystack handles M-Pesa, card payments, and Apple Pay. Your card details and M-Pesa PIN are entered directly into Paystack's secure payment interface and never touch our servers.
We store only the Paystack payment reference, transaction amounts (ticket price, processing fees, and payable amounts), and timestamps. Paystack's own privacy policy governs how they handle your payment credentials.
Cookies and Tracking
We use only essential cookies required for the platform to function:
- Authentication cookies — HttpOnly, Secure, and SameSite=Lax. These maintain your login session and expire after 30 days of inactivity or 90 days from creation.
We do not use third-party tracking pixels, advertising cookies, or analytics services such as Google Analytics. We do not track you across other websites.
Third-Party Services
We share data with the following services to operate the platform:
| Service | Data Shared | Purpose |
|---|---|---|
| Clerk | Email, name | Authentication and sessions |
| Paystack | Email, payment amount | Payment processing |
| Resend | Email, name, event details | Ticket confirmation emails |
| WhatsApp Business API | Phone, name, ticket details | Ticket delivery via WhatsApp |
| Pusher | Event ID, scan results | Real-time gate sync |
| Supabase | KYC documents | Private document storage |
| Neon (PostgreSQL) | All records | Primary database |
| Upstash Redis | IP addresses (hashed) | Rate limiting |
| Photon / Komoot | Search queries, coordinates | Geocoding for venue selection |
| OpenStreetMap | Viewport coordinates | Map tile display |
Each of these services has its own privacy policy governing how they process your data. We only share the minimum data required for each service to function.
Data Sharing with Event Organizers
When you purchase a ticket, the event organizer receives your name, phone number, and email address for the purpose of managing their event. Organizers can export this attendee data. We require organizers to handle your data responsibly, but their use of your data after export is governed by their own practices.
Venue partners see only event names, dates, capacity, and attendance counts. They do not have access to buyer personal data or financial information.
Ticket and QR Code Data
Each ticket is assigned a unique code. Our anti-fraud QR codes rotate every 15 seconds using a cryptographic signature that is generated server-side. The signing secrets are never exposed to users or included in API responses. Check-in records (time, gate, and result) are stored to prevent duplicate entry and provide attendance reporting.
Data Retention
We retain your data for the following periods:
- Financial records and audit logs: 7 years (legal and regulatory requirement)
- Ledger entries: permanent, append-only (required for financial integrity)
- Database backups: 30 days
- Login sessions: 30 days idle, 90 days maximum
- One-time passwords: 5 minutes (single-use, then deleted)
- Magic links: 15 minutes for sensitive actions, 24 hours for ticket viewing
- KYC document access links: 1 hour (documents themselves retained while your organizer account is active)
How We Protect Your Data
We implement the following security measures:
- All data encrypted in transit using TLS
- Database encrypted at rest
- Cryptographically secure random number generation for all tokens and secrets
- Constant-time comparison for secret validation
- Security headers on all responses: Content Security Policy, HSTS, X-Frame-Options: DENY
- Rate limiting on all public endpoints
- No plaintext storage of one-time passwords, tokens, or secrets
- KYC documents stored in a private bucket with time-limited signed access URLs
Your Rights Under the Kenya Data Protection Act 2019
Under the DPA, you have the right to:
- Access your personal data that we hold
- Rectify inaccurate or incomplete personal data
- Erase your personal data (subject to legal retention requirements for financial records)
- Restrict the processing of your data in certain circumstances
- Data portability — receive your data in a structured, machine-readable format
- Object to the processing of your personal data
To exercise any of these rights, contact us at privacy@antara.events. We will respond within 30 days.
Data Breach Notification
In the event of a confirmed personal data breach, we will notify affected users and the Office of the Data Protection Commissioner within 72 hours, as required by the Kenya Data Protection Act 2019.
Children's Privacy
Our services are not intended for persons under the age of 18. We do not knowingly collect personal data from minors. If we become aware that we have collected data from a person under 18, we will take steps to delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via our website. We encourage you to review this page periodically. The “Last updated” date at the top of this page indicates when the policy was last revised.
Contact Us
If you have questions about this Privacy Policy or wish to exercise your data protection rights, contact us at: