Security
Security and data access
TicketCounts.io connects to Eventbrite and Universe through their own sign-in (OAuth), only reads what a report needs, and stores access tokens encrypted. It never sees your password or your buyers’ details, and you can disconnect or delete your account at any time.
Last updated
What can TicketCounts.io read?
Only what a ticket count report needs: which account you connected, your events and the number of tickets sold. It only reads your data; nothing is created or changed on your ticketing account. The table also shows what each sign-in approval allows: Eventbrite has no narrower scope, so its approval is broader than what the app uses.
| Platform | Access granted | Reads | Never reads |
|---|---|---|---|
| Eventbrite | Eventbrite does not offer narrower OAuth scopes, so the approval lets the app call the Eventbrite API as your user. TicketCounts.io only sends read requests (GET) and never creates or edits events, orders or ticket types. |
|
|
| Universe (a Ticketmaster company) | TicketCounts.io requests Universe's public OAuth scope and only runs GraphQL queries (reads); it never runs mutations that change your events. |
|
|
How are access tokens stored?
Encrypted with AES-256-GCM before they are written to the database, with a key kept outside the database. Each token is bound to its own connection record, and the database never hands token columns to a browser, including yours. Disconnecting an account deletes its tokens.
Encrypted at rest
Tokens are encrypted with a key held outside the database. In production the app will not start without it, and keys can be rotated.
Server side only
Only the server reads tokens, to fetch counts when a report is sent. Signed-in users can list their connections but cannot read the tokens.
Gone when you disconnect
Disconnecting deletes the stored tokens and pauses that account’s reports. Universe access is also revoked with Universe.
Who can see my reports and recipients?
Only you. Recipients get their own copy of the report email and never see the other addresses. Every table in the database has row-level security, so a signed-in account can read and change only its own rows. Changes to reports, schedules and billing go through the server, which checks the account on every request.
- Logos: served from a public address so email apps can show them, and stored in a folder per account that only you can change.
- Logs: access tokens, secrets and passwords are never written to logs, and email addresses are masked.
- Sign-in links: tokens from emails are moved out of page addresses before a page loads.
- Payments: card details go straight to Stripe and never reach our servers.
How are report recipients protected?
Each recipient gets their own copy, so nobody sees the other addresses. Every report has an unsubscribe link, plus one-click unsubscribe headers so mail apps can show their own unsubscribe button. Addresses that unsubscribe, hard-bounce or mark a report as spam stop getting reports automatically.
Unsubscribes are respected
Unsubscribing stops every report from that account to that address. The account holder is told and cannot add the address back; only the recipient can opt in again.
Bounces and complaints
Addresses that hard-bounce or mark a report as spam stop receiving reports automatically.
Clear sender
Reports come from “Organization via TicketCounts.io”, say who added the recipient, and replies go to that person.
What happens when I delete my account?
Deleting your account from the account page cancels any subscription, deletes your Stripe customer record and removes your logos and data: connections, reports, send logs and notifications. Deleted data disappears from our database backups when they expire, within 90 days. A few billing records with no report content are kept for a limited time, then deleted automatically.
While your account is open, operational records are trimmed on a schedule; send logs, for example, are kept for 13 months.
Which services process data for us?
These services run parts of the product, and each receives only the data it needs for its job; the table shows what each one does and which data it handles. Eventbrite and Universe are not listed: you connect them yourself, and TicketCounts.io only reads from them.
| Service | What it does | Data involved |
|---|---|---|
| Supabase (self-hosted) | Database, sign-in and logo storage. We run the open-source Supabase software on our own server, hosted by Hostinger International Ltd. in the United States (Boston, Massachusetts), not on Supabase’s cloud. | Your account, reports, recipient addresses, encrypted platform tokens, uploaded logos, send logs |
| Stripe | Subscriptions and payments. Card details are entered on Stripe’s checkout page and never reach our servers. | Your email, plan and billing status |
| Resend | Sending report and account emails, and reporting bounces and spam complaints back to us. | Recipient addresses and the content of each email |
| Google Analytics | Measuring visits to this website. | Pages viewed and device information. Tokens and unsubscribe links are kept out of page addresses. |
| Cloudflare | DNS, the network in front of the website, and forwarding email sent to ticketcounts.io addresses. | Request metadata such as IP addresses; email sent to those addresses |
How do I report a security issue?
Email support@elektronicgroup.com with “Security” in the subject. Include what you found, the steps to reproduce it and the page or email where you saw it. Please send only what is needed to show the problem, and never another person’s personal data or a working access token.
Questions
What access does TicketCounts.io get to my ticketing account?
You connect with the platform's own sign-in (OAuth), so TicketCounts.io never sees your password. It reads only what reports need: which account you connected, your events and the ticket types sold for them. It does not read attendee or buyer details and never edits your events. Stored access tokens are encrypted, and you can disconnect at any time.
Do recipients need an account?
No. Recipients just get the email. Each one receives their own copy, so nobody sees the other addresses. Every email has an unsubscribe link, and mail apps that support it show a one-click unsubscribe button. Free allows up to 2, Starter allows up to 10, Pro allows up to 25 and Venue allows up to 100 recipients per report.
Can I connect more than one Eventbrite or Universe account?
Yes. You can connect several accounts on each platform and choose which account and event each report uses.
Set the schedule once. The count goes out on its own.
Free for 1 active event report. New accounts get 14 days of Pro, no card needed.