Docs

Privacy

How TicketSquad decides who can see whose details - Open and Closed modes, what your buying group always sees, and what organisers can and can't read.

A lot of people asked the same question: who can actually see my details? TicketSquad works best for groups who know and trust each other - but plenty of Squads are bigger than that, and nobody wants to hand their home address to two hundred strangers months before a sale. So every event and community has a privacy setting, and the rules below hold everywhere in the product.

The two modes

  • Open is the default, built for groups of mates: every member of the event sees every member's details, exactly as if you never touched the setting.
  • Closed is built for bigger circles: what you share stays inside your own buying group, and members of other groups can't read it. (The app's own one-line descriptions of each mode appear right on the setting.)

Events inside a community can never be more open than the community itself - a Closed community means Closed events, full stop. A Closed event shows a small Closed badge; there's deliberately no "Open" badge, because Open is just the default state of the world.

The full mode-by-mode breakdown lives in Open vs Closed, and what Closed actually protects - with the exact who-sees-what table - in Closed events.

Five guarantees that hold in every mode

  1. Your own buying group always sees what they need. The whole point is that your group can buy each other's tickets - within your group you see each other's booking details. That never breaks.
  2. You can always see who's ready. Even in Closed mode, everyone can see whether people have filled in their info - so you can still chase the one person who hasn't, the night before the sale. You just can't see what they entered.
  3. Organisers can run the event without snooping. Coordinators and community admins can see who's ready and reach everyone by email - but not read personal details outside their own group. Being an admin isn't a licence to browse.
  4. Switching to private is instant; switching back asks first. Flip to Closed and details are hidden straight away. Going back to Open asks each person to confirm - it's their data, so it's their call.
  5. Sale day still works. In a Closed event, a group that got its tickets can be matched to help one group that didn't - just that group's details, just for the sale-day window. By default the access dies 24 hours after the sale starts (or as soon as every group has reported); a coordinator can extend a live window, and every extension is audited. The full mechanics are on the multiple-group fallback.

Sensitive fields - the per-question dial

Coordinators mark each custom question as sensitive or not. Sensitive answers (postcodes, registration numbers, ID) stay inside each buying group when the event is Closed; unmarked answers (coach pickup, travel plans, dietary needs) stay visible event-wide in every mode - that's a deliberate coordinator choice, not an accident. Whether a field is required is a separate question entirely: required decides whether you must answer, sensitive decides who sees it.