Privacy Policy

Last updated: July 17, 2026

1. Introduction

Welcome to Lomeo (“Lomeo”, “we”, “our”, or “us”).

Lomeo is a Stripe App that helps merchants create and manage event tickets, ticket delivery, QR-code check-ins, and related event services.

This Privacy Policy explains what personal data Lomeo collects, why we collect it, how we use and retain it, and the rights you have regarding your personal data.

This Privacy Policy applies to merchants (Stripe users who install Lomeo) and attendees or end-users whose information is processed through events created using Lomeo.

Lomeo acts as a controller for merchant account information and data needed to operate and improve the Lomeo service. For attendee and customer data processed through events, Lomeo generally acts as a processor on behalf of merchants who use Lomeo to manage their events.

Payment transaction data is processed by Stripe through Stripe’s own payment infrastructure. Lomeo does not store or control payment card details.

2. Who This Privacy Policy Applies To

This Privacy Policy applies to merchants, which are businesses, organizations, or individuals who install and use Lomeo through the Stripe App Marketplace. It also applies to attendees and end-users, meaning individuals who purchase tickets, receive event-related communications, or otherwise interact with events managed through Lomeo.

3. Data We Collect

3.1. Data We Collect

When a merchant installs and uses Lomeo, we collect and store information necessary to provide the Service. This may include the Stripe account ID, business or account name, account email address, country or region information, and installation and activity timestamps.

Merchants may also configure email-related settings, such as sender name, sender address, and verified sending domains, for transactional communications.

3.2 Attendee and End-user Data

When merchants use Lomeo to create and manage events, we process the information necessary to provide ticketing and check-in functionality.

This may include attendee email addresses, ticket information, event-related information, transaction references provided through Stripe, and ticket status or check-in information.

Payment card details and financial payment information are processed directly by Stripe. Lomeo does not receive or store payment card data.

3.3 Operational Data

We collect limited operational records to maintain the reliability, security, and performance of the Service.

These records may include email delivery records, system processing logs, webhook processing records, and account synchronization records.

Operational data is retained only for the limited periods necessary for security, troubleshooting, and service reliability purposes.

3.4 Website Newsletter

If you subscribe through the “Stay updated” form on our website, we collect your email address to send occasional product updates and news about Lomeo.

We may also record the subscription date and the page where you subscribed.

Newsletter subscriber data is stored using services operated by us and our service providers. You may unsubscribe or request deletion at any time by contacting [email protected].

4. Legal Basis for Processing

Lomeo processes personal data based on the legal grounds described in Article 6 of the General Data Protection Regulation (GDPR).

Merchant account setup and operation are processed because this is necessary to provide the Service and perform our agreement with merchants under Article 6(1)(b).

Certain processing activities related to service operation, security, fraud prevention, and improving the reliability of the Service are based on our legitimate interests under Article 6(1)(f).

When Lomeo processes attendee information on behalf of merchants, the merchant determines the appropriate legal basis for collecting and using attendee data. Lomeo processes this information according to the merchant’s instructions.

Website newsletter subscriptions are processed based on consent provided through the subscription form under Article 6(1)(a).

5. Data Retention

We retain personal data only for as long as necessary to provide the Service, meet legal obligations, resolve disputes, and maintain security.

Attendee and ticket-related data is retained for up to one year after collection, unless a longer retention period is required for legal or operational reasons.

Email delivery and worker logs are retained for seven days.

System processing and account synchronization records are retained for thirty days.

Merchant account information after uninstall is retained for up to thirty days before deletion.

After the applicable retention period, personal data is securely deleted or anonymized where appropriate.

6. Data Sharing and International Transfers

Lomeo does not sell personal data.

To operate the Service, we may share personal data with trusted service providers that support our infrastructure and operations. These providers include Stripe for Stripe App infrastructure and payment processing, Postmark for transactional email delivery, Fly.io for application hosting and infrastructure, Supabase for database and storage infrastructure, and Google through Google Workspace services for newsletter subscriber management.

We do not share personal data with advertisers, data brokers, or third parties for marketing purposes.

Some service providers may process data outside the European Economic Area (EEA). Where personal data is transferred internationally, we rely on appropriate GDPR-compliant safeguards, such as adequacy decisions or Standard Contractual Clauses (SCCs), where required.

We may update our service providers from time to time as necessary to operate and improve the Service.

7. Merchant Responsibilities

Merchants using Lomeo are responsible for their own relationship with attendees and customers.

Merchants act as data controllers for attendee data they collect through their events. They are responsible for having a lawful basis for processing personal data, providing appropriate privacy information, handling attendee requests, and complying with applicable data protection laws.

8. Data Export

Merchants may export attendee and ticket-related records from Lomeo where export functionality is available.

Exported data remains the responsibility of the merchant, who must handle it in accordance with applicable privacy obligations.

9. Your Rights

Under applicable data protection laws, you may have rights including access, correction, deletion, restriction of processing, data portability, and objection to certain processing activities.

Merchants who have questions about their account data or wish to exercise their rights may contact us at [email protected].

Attendees and end-users should first contact the merchant or event organizer they interacted with, as they are usually the controller responsible for their personal data. If Lomeo receives a request directly, we may redirect it to the relevant merchant and provide assistance where legally required.

If you are located in the Netherlands and believe your rights have not been properly addressed, you may contact the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

10. Security

We use appropriate technical and organizational measures to protect personal data, including encrypted data transmission (TLS), access controls, least-privilege access practices, limited log retention, and security monitoring.

Lomeo does not store payment card information or directly process payment transactions.

11. Changes to This Privacy Policy

We may update these Terms from time to time. If we make material changes, we may provide notice through the website or the Service. By continuing to use Lomeo after updated Terms become effective, you agree to the revised Terms.

12. Governing Law and Contact

We may update this Privacy Policy from time to time.

The “Last updated” date reflects the most recent revision. If changes are significant, we may provide additional notice through the website or the Service.

Continued use of Lomeo after changes become effective means you acknowledge the updated Privacy Policy.

Contact: [email protected]