PRIVACY POLICY
Last update: 15 November 2023
This privacy policy (the "Policy") has been prepared by Shotgun, a
French société par action simplifiée, having its registered office at 6
Cité de l'Ameublement, 75011 Paris, registered with the French
Commercial and Companies registry of Paris under number 802 377 341, and
its subsidiaries, with the exclusion of Shotgun Brazil LTDA (hereafter,
"Shotgun").
Shotgun is a technology company operating an intermediation service
where event organizers can promote their events and sell tickets to
potential attendees looking to discover events and buy tickets. Shotgun
acts as a marketplace and ticketing solution, and operates as an
intermediary in the name of, and on behalf of event organizers.
The Policy describes the processing of personal data that Shotgun
conducts in order to fulfill its obligation of information as a data
controller within the scope of personal data protection regulations. It
is freely accessible on Shotgun's website:
https://support.shotgun.live/hc/articles/14330537455762
The Policy was originally written in French. This translation is
provided for convenience only, and the French version shall prevail in
case of a contradiction.
1. DEFINITIONS
-
Account: refers to the Users' personalized and
dedicated digital environment on the Platform.
-
Additional Service: refers to the services offered by
Shotgun in the Special Terms and to which the Organizer may subscribe
in addition to the Services.
-
Agreement: refers to the General Terms and Conditions
of Shotgun, as well as any other specific agreement between Shotgun
and a User for the use of the Platform and any agreement between
Shotgun and a User for the provision of the Services or additional
Services.
-
Application: refers to the "Shotgun" mobile
application for Clients, available on the Apple App Store and Google
Play Store.
-
Artist: refers to one or more natural or legal person
contributing to the Event.
-
Client: refers to any natural person over the age of
legal majority who purchases a Ticket on the Platform for private or
non-professional purposes.
-
Data Subject: refers to a Visitor, an Organizer, a
Client, a person invited by a Client to an Event, or a contact of a
Client or of an Organizer.
-
Data Processor: refers to a third-party company hired
by Shotgun in order to execute the processing of personal data as
described hereinafter.
-
Event: refers to any festival, concert, musical or
live performance organized and managed by an Organizer through the
Platform.
-
Organizer Application: refers to the "Shotgun Scan"
and "Shotgun Drawer" applications for Organizers, available on the
Apple App Store and Google Play Store.
-
Platform: refers either to the entire Website and
Application for Clients, or to the entire Website and Organizer
Application for Organizers.
-
Regulation: refers to the regulation (EU) 2016/679 of
the European Parliament and of the Council of 27 april 2016 on the
protection of natural persons with regard to the processing of
personal data and on the free movement of such data, as well as to the
French law n°78-17 of January 1978 (Loi relative à l'informatique, aux
fichiers et aux libertés) in its latest version in force.
-
Services: refers to the provision of the Platform and
the intermediation service for Tickets Sale, as well as for the
Cancellation or Transfer of Tickets.
-
Ticket: refers to the agreement concluded between the
Organizer and the Client that gives the Client the right to attend an
Event.
-
User: refers individually to a Client or an
Organizer, and, collectively, to Clients and Organizers.
-
Visitor: refers to any other party visiting the
Website.
-
Website: refers to Shotgun's website accessible at
https://shotgun.live, and its subdomains.
Unless circumstances request otherwise, definitions in the singular
include the plural, and vice versa.
2. DATA PROCESSING, PURPOSES AND LEGAL BASIS
N° |
Data Processing |
Purposes |
Legal Basis |
1 |
Prospection and analysis of Visitors |
Identify Visitors of the Website for marketing purposes, including
displaying the most appropriate content based on their activity
|
Consent |
2 |
Account creation |
Create Accounts in order of Users to use the Platform |
Performance of the Contract |
3 |
User login |
Identify Users when they access their Account in order to retrieve
the information related to their Account
|
Performance of the Contract |
4 |
Contract monitoring |
Monitor and store the proof of acceptance of General Terms &
Conditions, Special Terms, or any agreement between Shotgun and the
Users
|
Performance of the Contract |
5 |
Order management |
Monitor the proper execution of orders or subscriptions to waiting
lists, in order to ensure the Sale of Tickets.
|
Performance of the Contract |
6 |
Payments |
Process payments and manage payment issues |
Performance of the Contract |
7 |
Invoicing & Accounting |
Allow Shotgun to fulfil its obligations with regard to accounting
and taxes, to provide the necessary tax and accounting documents to
Users or authorities when applicable
|
Legal requirement |
8 |
Processing of support requests related to the Services |
Answer Users' support requests related to the provision of the
Services
|
Performance of the Contract |
9 |
Creation of User profiles |
Identify Client, Event or Organizer profiles based on statistical
methods in order to suggest more relevant content to Clients and
Additional Services to Organizers
|
Consent |
10 |
Newsletter |
Inform Users about content available on the Platform |
Consent |
11 |
Music library |
Inform Users interested by Events involving Artists that they listen
to, and allow Organizers gain insights into their community
|
Consent |
12 |
Prospection and sales |
Inform Users of the development of the Shotgun Services offering
|
Legitimate interest of Shotgun in processing these data |
13 |
Satisfaction surveys, improvement of the Platform and of the
Services
|
Identification of improvements of the Platform and of the Services,
notably via usage statistics satisfaction surveys
|
Legitimate interest of Shotgun in processing these data to improve
the Platform and the Services
|
14 |
Tax and social requirements |
Answer information requests from tax and social authorities
regarding sales and Users on the Platform
|
Legal requirement |
15 |
Litigation |
Allow Shotgun to organize its defense in case of litigation or
pre-litigation
|
Legitimate interest of Shotgun in processing these data to fight
potential litigations
|
16 |
Fraud |
Protect Shotgun and Users from fraud, including, but not limited to,
the use of stolen credit cards
|
Legitimate interest of Shotgun in processing these data to prevent
fraud
|
3. ROLE AND RESPONSIBILITIES OF SHOTGUN
3.1 Shotgun as data controller
Under the Regulation, Shotgun is data controller of the following
personal data:
-
General information on Users (login, name, first name, date of birth,
password, email addresses, telephone number);
-
Data Subjects login information (login, password, session start and
end time, IP address, location, session history, unique cookie
identifier);
-
Legal information related to the Organizer or to the Event (legal
entity name, responsible person name, company registration number,
live event license number, registration address, tax identification
number, name, date and location of Events, Artists, numbers of Tickets
sold, ticketing revenues, number of orders, Shotgun fees, refunds,
bank account associated with the Organizer account, and any other
document requested by Shotgun in order to confirm the truthfulness of
this information);
-
Client profile (past Events attended, followed Events, friends,
musical library and preferred Artists, if the Client has connected
their contact list, social media accounts or music streaming accounts
to their Shotgun account);
- Organizer profile (types of Events);
-
Client orders data (name and date of Event, quantity, type and price
of Tickets bought or resold, email address where the Ticket will be
sent, contact information of Client's guest if any);
-
Payment and invoicing data (billing address, payment method, banking,
transaction history);
-
User preferences when visiting the Platform (language and display);
-
Answers to satisfaction and other surveys by Data Subjects, if they
consented to sharing this data (satisfaction, comments, questions
regarding specific Events or the usage of the Platform);
-
Other personal data of Data Subjects in the context of support
requests (issues encountered by users, tracking of user sessions).
For any question related to the processing personal data by Shotgun, or
in order to exercise any of the right provided under the Regulation,
Data Subjects can contact Shotgun as follows:
- by completing the support form available on the Platform;
- by email, at support@shotgun.live;
-
by postal mail, at: Shotgun, Personal Data, 6 Cité de l'Ameublement,
75011 Paris, France.
3.2 Shotgun as Data Processor
Shotgun collects personal data on behalf of Organizers and / or Clients.
In that case, Shotgun also acts as Data Processor under the Regulation
for the following personal data:
- Organizers contacts uploaded to their Account;
-
Ticket purchase information (telephone number and date of birth for
the first purchase, additional information requested by Organizers,
including but not limited to the identity of guests of the Client);
-
Client contact information (name, first name, email address, telephone
number, additional information on Client and / or their guests);
-
Organizer contact information (depending on the information that
Organizers are willing to share with Clients: name, first name or
alias of the Organizer, telephone number, email address, social
network accounts);
-
Event information (name, first name or alias of the Artists, name,
date and location of the Event);
-
Data exchanged between Users through the platform (email address of
the Client and/or of the Organizer, content of the exchanges);
-
Data collected on the Platform by Organizers on Users in case they
consent to the use of trackers (number of visits on the Platform,
items added to cart, orders for Events organized by the Organizer).
Since Shotgun has no control over the means and purposes of data
processing carried out by Users, including Organizers, it acts as a data
processor within the meaning of the Regulation.
The manner in which the Organizer has entrusted it with the processing
of personal data has been subject to contractual provisions under the
Contract signed between Shotgun and the Organizer, in accordance with
the Regulation.
As a result, Users contacting Shotgun at the above address will be
redirected to the data controller responsible for their personal data
processing.
4. RECIPIENTS OF PROCESSED PERSONAL DATA (continued)
-
Daily Operations: third parties who provide digital
solutions used for Shotgun's daily operations, such as data hosting
solutions, client and prospect management, detection of software
errors or bugs, monitoring of the usage and proper functioning of the
Platform;
-
Maintenance Operations: third parties who have access
to the Shotgun technology in order to perform maintenance operations
or address technical issues in case of emergencies;
-
Marketing & Communication: third parties who offer
online marketing and advertising solutions.
-
Financial services: third parties who offer
specialized financial services, including payment processing services.
For the avoidance of doubt, it is hereby reminded that neither Shotgun,
nor its Data Processor engage in the sale of the personal data of Data
Subjects to third parties.
5. STORAGE OF PERSONAL DATA
The data of the Data Subjects are stored for the entire duration of the
relationship with Shotgun, in order to achieve the purposes described in
Article 2 and to enable Shotgun to fulfill its legal obligations.
6. DATA SUBJECT RIGHTS
6.1 Nature of Rights
In accordance with the Regulation, the Data Subject has rights as
provided by the Regulation, namely:
-
Right of access: any Data Subject can find out what
personal data Shotgun has about them and obtain a copy.
-
Right of rectification and erasure: any Data Subject
can request the correction of inaccurate or outdated personal data
about them, as well as their deletion.
-
Right to object and restrict processing: any Data
Subject can object to how Shotgun processes their personal data or
request that the processing concerning them be restricted, to the
extent possible and subject to compelling legitimate grounds that
Shotgun may have for continuing processing, such as legal obligations
in the fight against money laundering and the financing of terrorism.
-
Right to data portability: any Data Subject can
request Shotgun to send their personal data in a structured, commonly
used, and machine-readable format to transmit to another data
controller, if possible.
-
Right to file a complaint with a supervisory authority:
any Data Subject can contact the CNIL or any other competent
supervisory authority if they believe that Shotgun has not complied
with certain rules provided by the Regulation (information on how to
contact the CNIL is provided on their website).
6.2 Exercise of Rights
The exercise of rights provided by the Regulation is not without limit
(Shotgun is entitled not to respond to manifestly unfounded or excessive
requests), and each of them is subject to conditions imposed by the
Regulation. In this regard, the following points are to be noted:
-
Identity: any Data Subject must verify their identity
and provide the address at which they prefer to be contacted;
-
Response time: requests are processed by Shotgun
within a reasonable timeframe, taking into account complexity, the
number of requests, and the Regulation.
-
Free exercise: the exercise of rights is generally
free of charge. In cases where a request would entail significant
costs, the Data Subject may be required to cover the associated
expenses.
Requests that fail to comply with these principles will not be
processed.
7. DATA TRANSFERS
Personal data processed by Shotgun are hosted by Supabase, whose servers
are located in Germany.
Some of the personal data may be transferred outside the European Union,
including to the United States. In such a case, if transfers occur to
countries that do not benefit from an adequacy decision, Shotgun has
ensured that the relevant data processors and/or Shotgun subsidiaries
implement appropriate legal, technical, and organizational measures to
regulate any transfer of personal data, including the use of standard
contractual clauses developed by the European Commission.
Data Subjects can obtain a copy of personal data being transferred by
writing to the dedicated email address: support@shotgun.live.
8. COOKIES
A "cookie" is a tracking program deposited and read when visiting a
website, consulting an email, instaling or using software or a mobile
application, regardless of the type of device used (computer,
smartphone, e-reader, other smart device, etc.).
Under Article 82 of the Loi informatique et liberté, any subscriber or
user of an electronic communications service must be informed clearly
and comprehensively, unless they have been previously informed, by the
data controller or their representative:
-
of the purpose of any action aimed at accessing, by electronic
transmission, information already stored in their electronic
communications terminal equipment or entering information into this
equipment
- of the means available to oppose it
Such access or entries can only take place if the subscriber or user has
expressed their consent after receiving this information. Data Subjects
can withdraw their consent to the use of these trackers from the shotgun
website: https://shotgun.live/
It is also provided that these rules do not apply if access to
information stored on the user's terminal equipment or the entry of
information into the user's terminal equipment:
-
either has the exclusive purpose of enabling or facilitating
electronic communication,
-
or is strictly necessary for the provision of an online communication
service at the express request of the user.
Within the scope of this exception, Shotgun uses the following cookies:
-
Audience tracking cookies to measure the activity and traffic on the
Website. These cookies are stored for indefinite period.
-
Cookies storing language preferences of Visitors. These cookies are
stored for an indefinite period.
-
Cookies storing cookies consent preferences of Visitors. These cookies
are stored for an indefinite period.
9. SECURITY PROCEDURES
Shotgun takes all physical, logical, and organizational security
measures to ensure a high level of protection of personal data, and
notably to prevent these data from being altered damaged or disclosed to
unauthorized parties. Security procedures include, but are not limited
to:
-
Protection of access to databases where the personal data of Data
Subjects are stored with strong passwords;
-
Use of advanced password security solutions by all Shotgun employees;
-
Implementation of physical security measures to prevent intrusions in
company premises.
10. MODIFICATION OF THE POLICY
Shotgun may from time to time update this Policy, to reflect changes in
data processing purposes and methods due to the development of the
Platform, the Services and the Additional Services, or due to the
introduction of new regulations.
Data Subjects will be informed of changes to the Policy either by email
or by a communication on the Platform at least 15 days before any
material change to the Policy.