Legal
Privacy Policy
Last Updated: March 2026
Data Controller
Ephesus Tickets is the data controller responsible for your personal information. You can contact us at info@ephesus-tickets.com.
What We Collect
During the booking process, we collect: your full name, email address, phone number (optional), selected visit date, and ticket selections. We collect this information only when you actively submit it through our booking form.
Legal Basis for Processing
Under GDPR Article 6, we process your personal data on the basis of contract performance (Article 6(1)(b)) — your information is necessary to fulfill your ticket booking and deliver the service you requested. For any optional communications beyond order fulfillment, the legal basis is your explicit consent.
How We Use Your Data
We use your personal information to: purchase the official entry ticket on your behalf, send you a booking confirmation email, and contact you if there are any issues with your order. We do not use your data for marketing purposes unless you explicitly opt in.
Payment Data
All payment processing is handled securely by Stripe. We never see, store, or have access to your full card number, CVV, or other sensitive payment details. Stripe is PCI DSS Level 1 certified — the highest level of payment security certification.
Cookies
We use Google Analytics (via Google Tag Manager) to understand how visitors use our site — for example, which pages are most popular and how people navigate through the booking process. Analytics cookies are only set after you give consent via our cookie banner. You can withdraw your consent at any time using the “Cookie Settings” link in the footer. For more details on how Google processes this data, see Google's Privacy Policy.
Third-Party Services
We share your data with Stripe for payment processing and use Google Analytics (via Google Tag Manager) for site analytics, subject to your cookie consent. We do not sell, rent, or otherwise share your personal information with any other third parties.
Data Retention
We retain your booking data for the duration needed to fulfill your booking and handle any potential disputes or refund requests. After this period, your data is deleted or anonymized.
Your Rights (GDPR)
If you are in the European Union, you have the right to: access your personal data, request correction of inaccurate data, request deletion of your data, receive a copy of your data in a portable format, and withdraw consent at any time. To exercise any of these rights, contact us at info@ephesus-tickets.com.
Children
We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal information, please contact us and we will promptly delete it.
Changes to This Policy
We may update this privacy policy from time to time. Any changes will be posted on this page with an updated revision date.
Contact
For privacy-related questions or to exercise your data rights, contact us at info@ephesus-tickets.com.