by

48 Team

Exciting Events

N
E
S
W
Loading experience0%
Privacy Policy· Last updated March 2026

Your Privacy, Our Responsibility.

We believe privacy is a right, not a feature. Here's exactly how we handle your data — clearly, completely, and honestly.

01

Information We Collect

When you use BidBary, we collect information in the following ways:

Account Information: When you register, we collect your name, email address, phone number, and optionally a profile photo. Organizers additionally provide business name, bank/payment details for payouts, and identity verification documents.

Event & Transaction Data: We store records of tickets purchased, bids placed, events attended, and payments made — including amounts, timestamps, and event identifiers.

Usage Data: We collect device type, browser, IP address, pages visited, time on site, and click behaviour to improve platform performance and personalise your experience.

Communications: If you contact us via email or our contact form, we retain a record of that correspondence.

Cookies & Tracking: See Section 4 for details on how we use cookies and similar technologies.

02

How We Use Your Data

We use the data we collect for the following purposes:

  • To create and manage your account and authenticate your identity
  • To process ticket purchases, auction bids, and payouts to organizers
  • To send booking confirmations, QR tickets, event reminders, and important updates
  • To provide customer support and resolve disputes
  • To personalise event recommendations and search results based on your interests
  • To detect and prevent fraud, abuse, and policy violations
  • To analyse platform usage and improve our features
  • To comply with legal obligations

We do not use your data for automated decision-making that produces significant legal effects without human review.

03

Data Sharing & Third Parties

We never sell your personal data. We share limited data with third parties only where necessary:

Payment Processors: Your payment details are handled directly by our PCI-DSS-compliant payment partners (e.g. Stripe). BidBary never stores full card numbers.

Event Organizers: When you purchase a ticket or are approved for an invite-only event, the organizer receives your name and email to facilitate check-in. Organizers are contractually prohibited from using your data for marketing outside of BidBary.

Analytics Providers: We use anonymised, aggregated analytics services to understand platform usage. No personally identifiable information is shared.

Legal Requirements: We may disclose your data if required by law, court order, or to protect the rights and safety of BidBary or its users.

04

Cookies & Tracking

BidBary uses cookies and similar technologies to operate and improve the platform. Types of cookies we use:

Essential Cookies: Required for authentication, session management, and security. Cannot be disabled.

Functional Cookies: Remember your preferences (language, theme, saved events). Can be disabled, but may affect your experience.

Analytics Cookies: Help us understand how users navigate the platform. We use privacy-first analytics tools. These are anonymised and never shared with third parties for advertising.

You can manage cookie preferences in your browser settings. We do not use third-party advertising cookies or cross-site tracking.

05

Data Retention

We retain your personal data for as long as your account is active or as needed to provide our services. Specific retention periods:

  • Account data: Retained until you delete your account, plus a 30-day grace period for recovery
  • Transaction records: Retained for 7 years for financial and legal compliance
  • Event attendance records: Retained for 2 years after the event date
  • Support communications: Retained for 3 years from the date of the last interaction

Upon account deletion, all personal data is permanently removed from active systems within 30 days. Anonymised, aggregated data may be retained indefinitely.

06

Your Rights

Under GDPR and applicable privacy laws, you have the following rights:

  • Access: Request a copy of all personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Erasure: Request deletion of your personal data ("right to be forgotten")
  • Portability: Receive your data in a structured, machine-readable format
  • Objection: Object to processing based on legitimate interests
  • Restriction: Request that we limit processing of your data in certain circumstances

To exercise any of these rights, email privacy@bidbary.me. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority.

07

Security Measures

BidBary takes the security of your data seriously. Our measures include:

  • All data is encrypted in transit using TLS 1.2+ and at rest using AES-256
  • Payment data is handled exclusively by PCI-DSS Level 1 certified processors
  • Regular penetration testing and security audits by third-party specialists
  • Role-based access controls — staff only access data needed for their function
  • Two-factor authentication available and encouraged for all accounts

No system is perfectly secure. In the event of a data breach affecting your rights, we will notify you within 72 hours as required by GDPR.

08

Children's Privacy

BidBary is not intended for children under the age of 16. We do not knowingly collect personal data from children. If we discover that a user under 16 has provided us with personal data, we will delete it promptly. If you believe a child has registered on our platform, please contact us at privacy@bidbary.me.

09

Contact & DPO

For any privacy-related questions, data requests, or concerns, contact our Data Protection Officer:

Email: privacy@bidbary.me
Company: BidBary Technologies
Address: Baku, Azerbaijan

We aim to respond to all privacy inquiries within 5 business days.

Questions about this policy?

Reach out to our team directly.