EzEventzEzEventz
FeaturesPricingHow it works
Add app to Shopify
Legal

Privacy Policy

This policy explains what personal data the EzEventz app processes when it is installed on a Shopify store, how and why we process it, how long we keep it, and how it is deleted.

Last updated: 2026-09-11 · Applies to the EzEventz Shopify app and the pages under ezeventz.dilight.website.

1. Who we are

EzEventz is operated by DiLight Entertainment UG (haftungsbeschränkt) ("EzEventz", "we", "us"). For questions about this policy or about the data we process, contact us at privacy@dilight.website.

When EzEventz is installed on a merchant's Shopify store, the merchant is the data controller for their customers' and attendees' personal data, and EzEventz acts as a data processor on the merchant's behalf, processing store data only to provide the app's features. For our own account, billing and audit records, we act as the controller.

2. Data we process

EzEventz turns Shopify orders into event tickets, delivers those tickets, and checks attendees in at the door. To do that it reads and stores the minimum data needed:

  • Store & account data — your .myshopify.com domain, the OAuth access token issued at install (stored encrypted, never shown in plain text in the UI), your plan and billing status, and app settings (event and ticket-tier mappings, seat maps and seat reservations, ticket design, delivery-channel and check-in configuration).
  • Product data — the products and variants you map to events and ticket tiers, including our own metafields written back to your catalogue (issued / active / checked-in ticket counts).
  • Order data — for each order we process the order ID and number, line items, quantities, prices, financial and fulfilment status, and any per-line attendee attributes captured at checkout. Paid orders trigger ticket issuance.
  • Customer & attendee data — the buyer/attendee email address and name as supplied by Shopify, used to issue and deliver tickets and to identify an attendee at check-in.
  • Ticket & check-in data — issued ticket numbers, QR/barcode payloads, seat assignments, delivery records, and check-in / scan events (including timestamps).

We do not process payment card details. Access to store data is limited to the Shopify scopes granted at install: read_products, write_products, read_orders, read_customers, read_inventory, read_locations.

3. How we use data

  • Map products/variants to events and ticket tiers and issue tickets when an order is paid.
  • Generate QR / barcode ticket credentials and manage reserved-seat maps and seat holds.
  • Deliver tickets over the channels you enable (email, PDF, Apple Wallet, Google Wallet).
  • Scan and validate tickets for live check-in at the door, including re-entry rules where enabled.
  • Show real-time sales, capacity and check-in dashboards to the merchant.
  • Operate billing, enforce plan limits, keep audit logs, and provide support.

4. Legal basis (GDPR)

Where the GDPR applies, we process data on the basis of performance of a contract (Art. 6(1)(b)) with the merchant and our legitimate interest (Art. 6(1)(f)) in providing and securing the service. For customer and attendee personal data, the merchant's own privacy policy and legal basis govern the underlying processing; we act only on the merchant's documented instructions.

5. Sharing & sub-processors

We do not sell personal data. We share data only with the providers needed to run the service:

  • Shopify — the platform the app is installed on and the source of product, order and customer data.
  • Our hosting / infrastructure provider — to host the application and its data store.
  • Ticket-delivery and wallet providers you enable — the email channel, PDF generation, and the Apple Wallet / Google Wallet pass services used to deliver tickets.

6. Data retention

We keep store, order, ticket, attendee and check-in data only as long as needed to provide the service to the merchant — for example so tickets stay valid, seats stay reserved, and check-in history and audit logs remain available for the event and for reconciliation. Operational logs (audit and ticket-transition history) are capped and rotated. When the app is uninstalled, or on a Shopify shop/redact request, we purge the store's data as described below.

7. GDPR / data-deletion requests

EzEventz implements Shopify's three mandatory compliance webhooks (all delivered to a single signed endpoint and dispatched by topic):

  • customers/data_request — we record the request so the merchant can fulfil the data-subject access request; EzEventz cannot return store data inline.
  • customers/redact — we remove the identified customer's personal fields from that store's attendee and related records.
  • shop/redact — sent by Shopify after the store uninstalls the app (~48h later); we purge all of that store's data (orders, tickets, attendees, seat reservations, deliveries, settings and related records).

Store customers and attendees should direct data-subject requests to the merchant (the controller). Merchants can reach us at privacy@dilight.website for assistance.

8. Security

The app uses Shopify's OAuth for install, verifies every inbound webhook (including the GDPR compliance webhooks) with HMAC signatures, stores access tokens encrypted, and serves all traffic over TLS. The standalone door-scanner runs on its own top-level page authenticated by a short-lived scan token. Access to store data is scoped to the permissions granted at install.

9. Cookies

The embedded admin relies on Shopify App Bridge session tokens rather than tracking cookies. These marketing pages may set a small preference cookie to remember your chosen language. We do not use advertising cookies.

10. Changes to this policy

We may update this policy as the app evolves. Material changes will be reflected on this page with a new "Last updated" date.

11. Contact

DiLight Entertainment UG (haftungsbeschränkt) · privacy@dilight.website · dilight.website

← Back to EzEventz

EzEventzEzEventz
FeaturesPricingHow it worksPrivacy
Native Shopify app
© 2026 EzEventz by DiLight Entertainment UG (haftungsbeschränkt). Event ticketing for Shopify.
EzEventz is not affiliated with or endorsed by Shopify Inc. “Shopify” is a trademark of Shopify Inc.