Trust center
Your data and your attendee data is of paramount importance to us.
If you have any queries or concerns please contact us at security@tito.io

Security
Security is something that we take very seriously at Tito. We always have. Both as a controller of our customers’ data and as a processor of our customers’ attendee data, it’s a responsibility we have never taken lightly.
From day 1 (11 years ago) we’ve leant on the secure framework of Ruby on Rails together with the powerful cloud infrastructe of AWS. It was overkill at the time given our size but we tend towards being a little overzealous where it counts.
Today we are ISO 270001:2022 certified and use a wide range of automated tools to make sure our security posture is as strong as it can be.
- Small team
- Data encryption at rest
- Continuous vulnerability scanning
- Yearly external pentests
Certification
In 2026 we gained our ISO 270001:2022 certification formalising and documenting the internal processes we’d been honing over the previous years.
Certification is far from a box-ticking exercise for us. We store and manage our data with the respect our customers deserve.
Privacy
In terms of what we do with our data, we simply hold it, store it and present it to perform the tasks our software does. If someone is buying a ticket from an organiser who uses Tito, they can do so safe in the knowledge that we are not doing anything with the data: we don’t share it, we don’t sell it, and we don’t try to claim it as our own.
General Data Protection Regulation (GDPR)
GDPR aligns with our core philosophy at Tito: respect people’s data.
In GDPR terms, for anyone who signs up to our service—event organisers and their teams—we act as the data controller. This means we are responsible for how the data is used, and for getting permission on how we use it.
For anyone who registers a ticket via Tito, we are the data processor for their data. Anything we do with this, we do on behalf of our customers, who act as the data controller.
GDPR affects how event organisers run their events. Both organisers in the EU and organisers outside of the EU who have EU-based customers. A lot of this boils down to transparency and being clear about what is done with data once it is submitted, and crucially, getting consent from the person submitting it.
- GDPR compliant
- Headquartered in the EU
- Hosted in the EU
Terms of Service
When signing up to use one of our platforms our Terms of Service is the contract to which you must agree. They describe who we are, how we will provide our services to you, and the contract that comes into existence between us.
Our terms of service also constitute a Data Progressing Agreement (DPA).
Sub-processors
As part of providing services to our customers, we share your Personal Data with the following third party service providers:
Amazon Web Services EU
AWS provides us with our cloud infrastructure: application servers, file storage, datastores, email services, application provisioning services.
Stripe EU
We use Stripe for billing. Stripe stores customer information, names, emails and details of fees on any payments processed by Stripe, as well as individual order details such as references and ticket types.
Intercom US
Intercom facilitates the communication cycle between our customer and our team, and allows us to figure out who is using our app and when. Tito Classic only.
Other services may store some personal information depending on features used.