Privacy policy — GigSpares
Last updated: 30 August 2026.
What this covers
This is the privacy policy for GigSpares ("the Service", "we", "us"), a Telegram-based ticket resale alert service. It covers the Telegram bot, the gigspares.com website, and nothing else. It does not cover Ticketmaster, Telegram itself, or any payment processor — each has its own policy, and using the Service does not change what those third parties do with your data on their own platforms.
What we collect, and why — grounded in what the code actually stores
This is not a generic template. It lists what our database actually holds, field by field.
| We collect | Why | Table |
|---|---|---|
| Your Telegram handle and chat id | It is how the Service knows where to send an alert — there is no other account system. No email, no phone number, no name is asked for. | users, subscriber |
| The events you subscribe to, and any filters you set (e.g. price ceiling, seat type) | To know what to watch and when to alert you. | subscriptions |
| A record of each alert attempt — matched or not, delivered or not, and why | So that "did my alert actually arrive?" is a question we can answer, including when the answer is that it failed. | deliveries |
| Billing state, if you subscribe: your Telegram chat id, subscription period dates, price, and a append-only log of payments received | To know whether your subscription is active. No card number, expiry, or CVV is ever stored — see "Payment data" below. | subscriber, payment, entitlement_audit |
| The checkout email, if you buy through this website | So a paid subscription that never got connected to Telegram can be reclaimed by the person who paid — and for nothing else. It is never used to send you mail. | site_purchase |
What we do not collect
- No Ticketmaster account, login, or credentials. The Service does not log into Ticketmaster on your behalf and never asks you for your Ticketmaster password.
- No payment card data, ever. There is no card form on this website and none in the bot: checkout happens on Stripe's own pages, and Stripe is the controller of your card data under its own policy. The Service is not designed to see or store card details at any point. We store whether your subscription is active, what you paid and when, and — for a purchase made through this website — the email address you gave Stripe at checkout, kept so you can reconnect your subscription to Telegram if you lose the link.
- No browsing tracking on the marketing site. The site sends a
Content-Security-Policy: default-src 'none', loads no font, script, or pixel from anywhere external, and is checked automatically to issue exactly two same-origin requests per page load. No cookies, no analytics, no third-party requests. - No location, no device data, no contacts. None of these are requested by a Telegram bot in the first place.
How your data is used
Only to run the Service: matching your subscriptions against ticket availability, sending you the resulting alert, and diagnosing a failed delivery if one happens. It is not used for advertising, not profiled, and not sold. There are currently no analytics or usage-pattern reports built from this data beyond aggregate operational counts (for example, how many gigs are being watched).
Who else sees it
- Telegram, as the transport — any message the Service sends you passes through Telegram's own infrastructure, governed by Telegram's own privacy policy.
- Stripe, as the payment provider — for the payment step only, never your subscription list or alert history. Stripe is the controller of your card data under its own policy; what we receive back is confirmation that a payment happened, its amount and period, and the checkout email above.
- Nobody else. No data broker, no advertising network, no analytics vendor. We are a small independent operation, not a data business, and there is no commercial reason for your data to go anywhere.
How long we keep it
A subscription row exists for as long as you're subscribed. deliveries rows
(the alert-attempt audit trail) are kept for 180 days, then deleted
automatically — enforced in code and run daily, not just promised here. payment/
entitlement_audit rows are kept indefinitely, deliberately: they are the
append-only record required to reconstruct billing history honestly, and the
180-day window does not apply to them. 180 days is the published retention period for delivery records; it is chosen
to be long enough to investigate a disputed alert and no longer.
Your choices
- Stop anytime. Unsubscribing from an event, or stopping the bot entirely, is available from within Telegram at any time — no email, no form, no waiting period.
- Ask what we hold. Message the bot and ask; a human (not a script) will answer. We are small enough that a person reads it.
- Ask for deletion. Type
/deletein the bot yourself, any time — no waiting on a human. It's a two-step confirmation (so a stray tap can't wipe your account by accident) and it tells you up front exactly what goes: your chat id and username, your saved alerts, and your delivery history. If you've paid, the payment record itself is kept for accounting but your identity is stripped from it first. Nothing here needs a human in the loop.
Legal basis and jurisdiction
GigSpares is the data controller for the personal data described above. Data is stored on a single server inside the EEA and is not transferred outside it by us, though Telegram operates its own international infrastructure under its own policy.
Our legal bases: we process your Telegram chat id, your subscriptions and your filters to perform the contract you entered into with us — without them the Service cannot function. We keep delivery records and billing records for our legitimate interest in being able to prove an alert was or was not sent, and to meet our accounting obligations.
Your rights. Under the GDPR you have the right to access, correct, delete, restrict, object to, and port your data, and to complain to a supervisory authority — in Ireland that is the Data Protection Commission (dataprotection.ie). Access and deletion are self-service: see below.
Changes to this policy
If this policy changes materially, subscribers will be told via the Telegram bot, not silently updated on a page nobody re-reads.
Contact
hello@gigspares.com for any privacy question or request. For account actions the bot is faster: @GigSparesbot.