Skip to content
Lippunet

Legal

Privacy policy

This privacy policy explains how the Lippunet service processes the personal data of ticket buyers and ticket holders, event organizer users, and website visitors, in accordance with the EU General Data Protection Regulation (GDPR) and the Finnish Data Protection Act.

Updated July 2026

Data controller and contact details

The data controller for the Lippunet service is FoxCodePlus Oy (Business ID 2939023-3). In matters concerning data protection, you can reach us by email at [email protected]. This policy covers the lippu.net online ticket shop, the management service for event organizers, and our marketing website.

Data on ticket buyers and ticket holders

When you buy tickets, we process your name, email address, phone number and preferred language; order details (tickets and add-on products purchased, prices, discount codes, payment method and the payment provider's reference); invoicing details; ticket holder names and answers to event-specific registration forms; ticket usage data (ticket scans at entry); messages sent to you with their delivery status (email and SMS); the status of your marketing consent; and any gift cards, waitlist sign-ups and survey responses. We never store your payment card number: the payment is processed by a payment service provider, and we only store the payment status and reference. We also process technical data, such as IP addresses, for security and abuse prevention.

Event organizer user accounts

For event organizer staff, we process the name, email address, user roles and organization memberships, the passkeys used for signing in (passkey credentials, no passwords) and the activity logs generated by use of the service, which are used to ensure security and traceability.

Website visitors and contact requests

When you submit the contact form, we process the information you provide (name, email address, phone number, organization, details about your event and your message) in order to respond to your inquiry and manage the customer relationship. The form is protected by automated bot protection, which processes your IP address to prevent abuse.

Where the data comes from

Data is primarily collected from you when you make a purchase, sign in or fill in a form. In addition, we receive payment status information from the payment service provider and ticket usage data from scanning devices at the event. We do not buy or collect your data from other sources.

Disclosure to the event organizer

When you buy a ticket, we disclose the data related to the order (buyer and ticket holder details and registration form answers) to the organizer of the event whose tickets you buy. For this data, the organizer acts as an independent data controller and is responsible for its own processing, such as using attendee lists at the event and its own marketing.

Processors and other recipients

We use carefully selected subcontractors who process data on our behalf under data processing agreements: payment service providers for payment processing, email and SMS delivery services for delivering messages, content delivery and security services for website delivery and protection, and server infrastructure located in the EU for running the service. If you pay with a cultural or sports benefit (e.g. ePassi, Smartum or Edenred), the payment is processed by the benefit provider you choose, acting as its own data controller. We disclose data to authorities only where required by law.

Transfers outside the EU

Data is stored primarily within the EU. Some of our subcontractors, such as payment service and web infrastructure providers, may process data partly outside the EU or EEA. In such cases, transfers are safeguarded as required by the GDPR, for example with standard contractual clauses approved by the European Commission or under the EU–US Data Privacy Framework.

Data retention periods

We retain data only for as long as necessary. Data belonging to accounting records, such as orders, payments and invoices, is retained for the six years from the end of the financial year required by the Finnish Accounting Act (1336/1997). Your basic account details are retained until you request their deletion. One-time sign-in codes are deleted within 30 days, expired sessions within 30 days of expiry, message contents are anonymized after 24 months, and abandoned shopping carts are deleted after at most 90 days. A self-service data export is available for download for 7 days.

Data security

All traffic to the service is encrypted (TLS). Access to personal data is restricted through role-based permissions, and staff sign in with strong passkeys. Processing actions are recorded in audit logs. When data is erased, it is anonymized so that records kept under statutory retention can no longer be linked to you.

Your rights

You have the right to access your data, rectify inaccurate data, request erasure of your data, restrict processing, object to processing, have your data transferred to another system, and withdraw any consent you have given at any time. You can exercise your rights by contacting us at [email protected]. We respond to requests within one month at the latest.

Downloading and erasing your data

You can download all your data in a machine-readable format and request erasure of your data as self-service on the ticket shop's My data and privacy page, or by email. Please note that the Finnish Accounting Act obliges us to retain data related to payment transactions for six years: upon erasure, this data is anonymized and can no longer be linked to you. If you hold valid tickets to an upcoming event or have an open invoice, erasure is possible only once the tickets have been used, refunded or transferred and the invoice settled.

Direct marketing

We send electronic direct marketing only with your consent, and you can withdraw your consent at any time via the link in every message. Your marketing opt-out remains in force even after your data is erased: on the suppression list we keep only a one-way identifier (hash) of the address, from which the address cannot be recovered but which prevents further messages from being sent.

Cookies

We use only cookies and similar technologies that are necessary for the service to function: maintaining your sign-in session, running the shopping cart, remembering language and theme preferences, and bot protection. We do not use advertising cookies and we do not share your browsing data with third parties for marketing purposes.

Automated decision-making and profiling

We do not make automated decisions that would have legal or similarly significant effects on you. Marketing may be targeted based on purchase history only if you have given marketing consent.

Right to lodge a complaint

If you believe that the processing of your personal data is not lawful, we hope you will contact us first so we can resolve the matter. You also have the right to lodge a complaint with a supervisory authority; in Finland, this is the Office of the Data Protection Ombudsman (tietosuoja.fi).

Changes to this policy

We update this policy as the service evolves. We will announce material changes in the service or by email. The date of the most recent update is shown at the top of this page.