Back to home

Privacy and trust

Privacy Policy

How Vira Collective protects payment, QR ticket, form, security, and communication data across the web experience.

Last updated: June 2, 2026

This policy is prepared to give users clear information. Before production use, all third-party tools and retention periods should be added to the final list.
01

Privacy approach

Because Vira Collective operates closed-circle events, participant security, invitation control, and payment verification are managed in one flow. Each collected data field is limited to a specific operational purpose.

The core privacy principles are avoiding unnecessary form fields, showing door staff only what is needed for verification, and not storing payment card data inside the Vira Collective system.

02

Payment and financial data

Sensitive payment details such as card number, expiration date, and security code are not saved in Vira Collective infrastructure. Payment is handled through the secure iyzico payment screen.

Order records keep only the payment result information needed to track status, generate QR tickets, and allow ticket access by reference number.

03

QR tickets and door verification

A separate QR ticket is generated for each attendee. The QR code does not carry full name or contact details by itself; verification happens server-side. When scanned, door staff see limited information such as attendee name, ticket status, and repeated scan warning.

If the same QR code is scanned again, the system creates a security warning. These records may be used for entrance security and dispute review.

04

Cookies, logs, and technical records

The website may create technical records for core security, session handling, payment return flow, and performance monitoring. Authorized areas such as the admin panel and scanner can keep more detailed security logs.

If analytics or advertising cookies are added in production, cookie types, purposes, retention periods, and preference controls should be explained in a separate cookie notice.

05

Sharing and third parties

Personal data may be shared with payment, hosting, database, email delivery, PDF/QR generation, and operational support providers only to the extent required for the service.

Third-party sharing should be protected by contractual and technical limitations. Participant lists are not sold to advertisers or transferred for unrelated campaigns.

06

User control

Tickets can be looked up with a reference number and the contact detail used on the payment form. This adds a verification layer so tickets are not visible to anyone with only the reference code.

Users may contact the announced support channel for incorrect contact details, guest information updates, or support requests. Identity verification may be required for sensitive requests.