01Who we are
TicketWatch Sagrada (“TicketWatch”, “we”, “us”) operates an independent ticket-availability alerting service. We are the data controller for the personal data described in this policy.
We are not affiliated with, endorsed by, or connected to the Basílica de la Sagrada Família or its official ticketing provider.
For any privacy question, write to [email protected].
02What we collect
We keep the data set deliberately small. We collect:
- Contact details — the phone number you register for WhatsApp alerts, and an email address if you provide one.
- Your alert preferences — the dates, time ranges and visitor count you ask us to watch for.
- Payment metadata — a payment reference, amount, currency and status returned by our payment processor. We never see or store your full card number.
- Message records — the alerts we sent you and any replies you send us on WhatsApp, so we can support and troubleshoot your alerts.
- Technical logs — IP address, browser type, timestamps and error traces generated when you use the site or when our systems run.
We do not collect special-category data, and we do not ask for identity documents.
03Why we use it, and our legal basis
- To run the service you paid for — matching newly-released slots against your preferences and messaging you. Legal basis: performance of a contract.
- To take payment and handle refunds. Legal basis: performance of a contract and compliance with a legal obligation.
- To keep the service secure and working — abuse prevention, rate limiting, debugging. Legal basis: our legitimate interests.
- To meet accounting and tax obligations. Legal basis: compliance with a legal obligation.
We do not sell your data, we do not share it with advertisers, and we do not use it to build profiles or train models.
04WhatsApp messaging
Alerts are delivered over WhatsApp using the WhatsApp Business Platform (Meta). To send you a message, your phone number and the message content are processed by Meta under their own terms and privacy policy.
We only message you about the alerts you signed up for — no marketing, no third-party promotions. You can stop messages at any time by replying STOP in the WhatsApp thread or by emailing us.
05Who we share data with
We use a small number of processors, each with access limited to what their function requires:
- Meta Platforms — delivery of WhatsApp messages.
- Stripe — payment processing. Card details go directly to Stripe and never touch our servers.
- Hosting and infrastructure providers — storage and running of the application and its database.
We may also disclose data where we are legally required to, or where it is necessary to establish, exercise or defend legal claims.
06International transfers
Some of our processors operate outside the European Economic Area. Where data is transferred outside the EEA, it is protected by an adequacy decision or by Standard Contractual Clauses together with appropriate technical safeguards.
07How long we keep it
- Alert preferences and contact details — for the duration of your watch window, then deleted or anonymised within 90 days.
- Message records — up to 12 months, for support and dispute handling.
- Payment and invoice records — for as long as tax and accounting law requires, typically several years.
- Technical logs — typically 30 days.
You can ask us to delete your data sooner — see Data deletion.
08Your rights
Subject to local law, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or send it to another provider in a portable format. Where we rely on consent, you can withdraw it at any time.
Email [email protected] and we will respond within 30 days. If you are unhappy with our response, you have the right to complain to your local data protection authority.
09Cookies and analytics
We use a session cookie to keep you signed in and to protect forms against abuse. These are strictly necessary for the site to work. We do not use advertising cookies or third-party tracking pixels.
10Security
Data is transmitted over TLS and stored on access-controlled infrastructure. Passwords are stored hashed, and card data never reaches our systems. No system is perfectly secure, but we keep the amount of data we hold small precisely to limit the impact if something goes wrong.
11Children
The service is not directed at children under 16. If you believe a child has given us personal data, contact us and we will delete it.
12Changes to this policy
If we change this policy we will update the date at the top of this page. If the change is significant and affects data we already hold about you, we will tell you directly on the channel you registered with.