rmba

LEGAL

PRIVACY

What personal data rmba collects when you use the site and buy a ticket, why we hold it, who else sees it, and what you can ask us to do with it. Where the answer is unusual — the attendee list handed to a door we do not run, for instance — it is spelled out rather than folded into a general clause.

LAST UPDATED 2026-08-25

1. Who controls your data

The data user responsible for your personal data is T8 Technology Solutions Limited (registration no. 80976033), a company incorporated in Hong Kong, which operates rmba.

We handle personal data in accordance with the Personal Data (Privacy) Ordinance (Cap. 486) and the six data protection principles under it. rmba is directed at buyers in Hong Kong; we do not target the service at people in the European Union, the United Kingdom or elsewhere, and this policy is written to Hong Kong law rather than claiming compliance with regimes we are not built for.

For anything about this policy, or to make a request about your data, contact us through the support page or at support@rmba.io.

2. What we collect

Only what the platform needs to sell you a ticket and let you use it:

  • Your email address and the name you give at checkout. The name is required, because it is what appears on the ticket and on the attendee list the door works from.
  • Your orders and tickets — what you bought, for which event, when, at what price, and whether each ticket has been scanned.
  • Whether you have opted in to marketing email, and if so the date and the IP address the sign-up came from, kept as evidence that the consent was given.
  • If you sign in with Google, the account identifier the sign-in provider returns to us. We do not receive your password.
  • Basic technical data your browser sends when it loads the site, and server logs of requests.

We never see or store your card number. Payments go directly to our payment providers, and what comes back to us is a reference and an outcome.

We do not sell personal data, and we do not run advertising trackers or third-party analytics on the site.

We do not knowingly collect personal data from anyone under 18, and you must be 18 to hold an account. If you believe a child has given us data, tell us and we will remove it.

3. How we measure the site

Our analytics are first-party and deliberately shallow. We record which steps of the purchase flow were reached — a page was viewed, tickets were selected, checkout failed — against an identifier that lives in the browser tab and is destroyed when you close it.

That identifier is not a cookie, is not joined to your account, and cannot follow you between visits or across sites. We chose this instead of a hosted analytics product so that buyer behaviour never leaves our own database.

Three things we deliberately do not record, because they are what would make this data identifying: your IP address (the country is worked out and the address discarded), your browser's user-agent string, and the query string of the page you were on. What is kept is the path, a coarse device class, and the campaign parameters of a link you may have followed.

4. Why we hold it

  • To sell you a ticket, deliver it, and let the door verify it — this is the contract between us.
  • To email you about an order: confirmations, ticket links, and changes an organizer tells us about.
  • To keep financial and tax records of sales, which we are legally required to retain.
  • To detect and prevent fraud and abuse of the platform.
  • To send marketing email, only where you have opted in, and only until you opt out.

5. Who else sees it

The organizer of an event you bought a ticket for receives your name and email address, and the record of your tickets. They decide for themselves what to do with it and their own privacy policy applies to that.

At events where the door is run by the organizer or a partner rather than by rmba, we hand over an attendee list before the event so the gate can admit people. It contains the ticket codes, the ticket type, the order reference, and the buyer's name and email address. It is a file transferred deliberately to a named party for one event — not a live feed, and not open to anyone else.

Our service providers process data on our behalf under contract. We describe them by class rather than by name, because the specific supplier can change without the categories changing:

  • Payment providers, who process your card payment and hold the card details we never see.
  • Cloud hosting and storage providers, who run the servers, the database and the image storage.
  • Email delivery providers, who send order and marketing mail and report back deliveries, bounces and complaints.
  • Sign-in providers, where you choose to sign in with an existing account rather than a password.

A copy of every transactional email we send is retained in an internal archive mailbox. Those messages contain live ticket links, so access to it is restricted to the same small group that can reach the production systems.

We disclose data to authorities where we are legally required to.

6. Where it is held

Our systems run on cloud infrastructure hosted in Singapore. Some of our providers operate globally, so your data may be processed outside Hong Kong.

Where personal data is transferred outside Hong Kong, we do so only to providers engaged under contract to process it on our behalf, on terms requiring them to protect it to the standard this policy describes and to use it only for the purposes we have set. We do not transfer personal data to anyone for their own independent use, other than to the organizer of an event you bought a ticket for, which is described above.

7. How long we keep it

We give periods rather than say "as long as necessary", because a period is something you can hold us to:

  • Order, payment and ticket records — seven years. This is not our choice: the Inland Revenue Ordinance (Cap. 112) requires business records to be kept for that long, and a completed sale is one.
  • Site analytics — 180 days, after which rows are deleted automatically. This one runs on its own; it is not a policy someone has to remember to apply.
  • Your account and profile — for as long as you have an account, and until you ask us to delete it.
  • Marketing consent records — while you are subscribed. If you unsubscribe, we keep the record of that indefinitely, because forgetting an unsubscribe is how someone gets mailed again after asking us not to.

8. Your choices and rights

Under the Ordinance you have the right to ask whether we hold personal data about you, to be given a copy of it, and to have it corrected if it is wrong. We will answer a data access or correction request within 40 days, as the Ordinance requires. We may need to confirm who you are before we act on one.

Some of this you can do yourself, immediately, without asking us:

  • Unsubscribe from marketing email, from the link in any marketing message or from your account. It takes effect immediately. Order and ticket emails are not marketing and continue regardless — you need them to get in.
  • Change your display name and your marketing preference in your account.

Anything else — a copy of your data, a correction to your email address, or deletion — is done by a person when you ask us at the contact address above. We would rather tell you that than imply a self-service route that does not exist.

You can ask us to delete your account and we will. Two limits are worth stating plainly, because they are real: we cannot erase the accounting record of a completed sale, which we are required to keep for seven years, and we cannot withdraw your name from an attendee list an organizer already holds — that copy is theirs and you would need to ask them.

9. Security

The database is not reachable from the internet, application secrets are held in a managed secret store rather than in configuration, and ticket codes are signed so they cannot be forged.

Ticket links in email are bearer links: whoever holds one can open the ticket. Treat a forwarded confirmation as handing over the ticket itself.

No system is perfectly secure, and we cannot guarantee absolute security.

10. Changes to this policy

We update this policy as the platform changes. The date at the top moves when we do, and material changes will be notified to account holders by email.