Privacy Policy
Last updated: 13 August 2026
Aspen Consulting Limited ("we", "us", or "our") operates the Event Access Shopify App (the "App"). This policy explains how the App processes personal information when a Shopify merchant uses Event Access to configure events, issue digital tickets, deliver QR passes, and validate entry.
The merchant using Event Access is responsible for its event terms, refund policy, and customer privacy notices. We process customer data only to provide the App to that merchant.
Information we process
- Merchant and store information: Shopify store domain, store contact email, App subscription status, and configuration such as event settings and scanner PIN configuration.
- Order and purchaser information: Shopify order identifier, product and quantity, purchaser name and email address, and Shopify customer identifier where available.
- Attendee and ticket information: attendee name and email where assigned, ticket status, event details, secure pass token, QR validation data, and entry/exit scan history.
- Billing-usage information: ticket identifiers and billing-event records used to report the number of tickets issued to Shopify App Pricing. We do not receive or store the merchant's payment-card details.
How we use information
We use this information to configure events, create and assign tickets, generate and validate QR passes, record attendance, handle ticket invalidation following Shopify order cancellations or refunds, provide merchant support, and report ticket usage to Shopify for the App's selected pricing plan.
Service providers and disclosures
We do not sell personal information. We use Shopify to obtain authorised store and order information and to provide App Pricing. We use MongoDB Atlas to host App data, Railway to host the App, and Brevo to send transactional ticket, assignment, amendment, and service emails. These providers process data only as needed to provide their services to us.
Retention, access, and deletion
We keep personal information only for as long as it is needed to operate Event Access, support the merchant's event operations, meet applicable obligations, and resolve disputes. We respond to Shopify's mandatory privacy webhooks for customer data requests, customer redaction, and shop redaction.
- Customer data request: we compile the Event Access data associated with the customer and send a machine-readable export to the email address supplied in Shopify's authenticated request.
- Customer redaction: we remove customer and attendee identifiers, invalidate the associated pass credentials, and remove linked Event Access check-in records.
- Shop redaction: we remove Event Access ticket, event, scanner, billing-usage, and store records for the Shopify shop when Shopify sends the redaction request.
Security
Event Access uses encrypted connections in transit, secure random ticket and pass credentials, server-side QR validation, access controls in Shopify Admin, and hashed scanner PINs. A QR pass should be treated like a ticket credential and not shared publicly.
Your choices and contact
If you are an event attendee, contact the merchant from whom you purchased the ticket first. For questions about Event Access's own processing, contact us at contact@aspenconsulting.co.uk.
Aspen Consulting Limited
United Kingdom