1. Introduction

DopeTickets is a South African-based online ticket marketplace that enables independent businesses and event organizers to list and sell tickets to the public. As part of its operations, DopeTickets processes personal information and is committed to complying with the Protection of Personal Information Act (PoPIA).

2. Collection and Use of Personal Information

We collect personal information to perform the following functions:

1. Facilitate ticket purchases

2. Provide customer service and improve user experience

3. Detect and prevent fraud

4. Fulfill ticket-related services

5. Notify customers of any changes in ticket conditions or event details

6. Conduct permission-based marketing

3. How we Collect Data

DopeTickets primarily collects personal information directly from users. In specific scenarios, data may be collected from:

· Legacy systems, where the customer has provided consent

· Clients who have legitimate grounds to share data for service delivery

All data collected is used solely to fulfill our service obligations and improve user experience

4. Customer Rights

Customers have full control over their data, including the ability to:

· View and update their personal information

· Request deletion of their data from our system

All data is securely stored and processed within South Africa.

5. Sharing of Personal Information

With DopeTickets Clients

We share relevant customer data with clients strictly for the purpose of fulfilling ticket-related obligations. All sharing is:

· Governed by applicable laws and regulations

· Based on customer consent

· Limited to necessary information only

· Never includes confidential data unless explicitly authorized

With Third Parties

We do not share customer data with external parties unless:

· Required by law or court order

· Acting through authorized service providers (see below)

6. Communication with Customers

We only communicate with customers in relation to their ticket purchases and where required by law. This includes changes such as:

· Event cancellations

· Time, date, or venue changes

· Refund processes

· Requests for additional information

Marketing communications are strictly opt-in, and customers can update their preferences at any time. Clients are also required to obtain consent before sending marketing communications.

7. Refund and Returns Policy

The provision of goods and services by Dope Tickets is subject to availability. In cases of unavailability, Dope Tickets will refund the client in full within 30 days. Cancellation of orders by the client will attract a 3.5% administration fee

8. Third Party Service Providers

We use vetted third-party service providers who may process customer data on our behalf. Our guiding principles include:

1. Due diligence and risk assessment before onboarding

2. Data shared is minimal and necessary

3. Sensitive information is never shared without consent

4. Annual evaluations of data security practices

5. Providers must meet or exceed our security standards

In-store registrations handled by third parties fall under the same privacy commitments

9. Payment and Security Compliance

We do not store card details.

Payments on DopeTickets are processed via PayFast Merchant Solutions, a PCI DSS Level 1 certified provider for:

· Payment gateway services

· POS/card-present transactions

· E-commerce

· Clearing and settlement services

10. Data Security and Governance

· Data is hosted on secure, cloud-based infrastructure

· Access is restricted via VPN and Multi-Factor Authentication

· All sensitive information is encrypted and logged

· Only authorized personnel can access relevant data for support and ticket fulfillment

· Regular security testing (e.g., ImmuniWeb®) and malware protection

· Incident response processes are in place for any breach or irregular activity

11. Personnel Security

· All employees undergo background screening

· Contracts include confidentiality and data protection clauses

· Regular training on data privacy and security best practices is provided

12. Breach Notification & Compliance

We are committed to full compliance with PoPIA. In the event of a data breach:

· Affected clients and data subjects will be notified immediately

· If required, the Information Regulator will also be informed

© 2025 DopeTickets. All Rights Reserved.
A Product of