Approved per device
An organiser approves every scanner separately. Its session and offline package are bound to one event, device and frozen scanner roster.
We use cookies to make your experience on this website better.
Clear about data
This notice explains in practical terms which data the Tickgetr website and mobile scanner use, why authorised scanners need event data, what is stored offline and how to ask a question or request deletion.
Last updated: 11 August 2026
An organiser approves every scanner separately. Its session and offline package are bound to one event, device and frozen scanner roster.
The offline package contains only the name and operational ticket fields for tickets assigned to its own entrance lane.
The device-bound offline package is encrypted by the app and expires no later than the frozen scanner roster.
This notice covers the Tickgetr website, organiser dashboard and the Tickgetr mobile scanner for Android and iOS.
An event organiser decides which attendee details are needed for its event. For an event-specific question, the organiser may therefore be the best first contact. Tickgetr handles the platform, account, ticket and scanning data needed to provide the service.
The app signs in through Firebase Authentication with an anonymous app user identifier. The scanner API verifies that identity and derives a separate, opaque device binding for the scanner roster. Firebase may also process technical authentication, integrity and security information such as IP address, user agent and app identifier.
The event code is used only to request access. Only after organiser approval does the device receive a short-lived scanner session and a device- and event-bound offline package.
An approved scanner keeps an AES-GCM-encrypted offline package in app storage. Its encryption key is held separately in the device's secure storage. The routing index contains no personal data; only tickets assigned to this device contain the display fields listed above.
A raw QR is used only briefly in memory to calculate a keyed hash locally. The app does not store or transmit the complete QR. Before showing a green offline result, it stores an encrypted pending attempt containing an opaque ticket reference and QR hash.
The manifest remains usable for at most twelve hours and never beyond the active scanner roster; temporary attendee data has a separate short TTL. After expiry, the app refuses offline green and removes expired manifest and attendee data. Pending scan attempts remain until server acknowledgement so an admission action is not silently lost.
Choosing End Session removes the session, enrollment binding and encrypted event cache from that device. Organisers should use managed, locked devices and end the session after entry closes.
Tickgetr uses Firebase Authentication and the infrastructure needed to host the website, API and event records. Firebase App Check uses Google Play Integrity on Android and Apple App Attest with DeviceCheck as a fallback on iOS to verify that a request comes from the genuine app. Google, Apple and Firebase may process technical app, device and integrity information for that purpose.
Other providers are used only when their feature is used, for example email support or payment handling on the website.
Event data is available to the organiser. An approved scanner device's offline package contains only operational ticket details for its assigned entrance lane; the event-wide attendee view is online-only and has a short retention period in the app. Do not share an enrolment code, scanner session or exported attendee list.
There is currently no single automatically enforced retention period for every server-side record. Retention follows the event and account lifecycle and the operational need to support tickets, scans, security and accounting. Records that must be kept for a documented obligation may not be removable immediately.
To request access, correction or deletion, email info@tickgetr.be with the subject Privacy request. Include only the email address, event name and order identifier needed to locate the record. Do not send passwords, active scanner codes or full QR codes. We may ask for proportionate verification before changing data.
This page is updated when the website, scanner app or its data flows materially change. Questions about this notice or an event data request can be sent to info@tickgetr.be.
Privacy request
Tell us which event or order your question concerns, but do not email passwords, active scanner enrolment codes or complete ticket QR codes.