Card data we never touch
Card details go straight to the payment processor — they never reach Jamrats servers. That means the heavy compliance work for card data sits with the processor (the people who do that for a living), not us.
Trust
Jamrats is a ticketing platform, but day-to-day we’re also a custodian of buyer emails, organizer payouts, and door-scan logs. Here is how we keep all three safe — and what we ask of you in return.
Card details go straight to the payment processor — they never reach Jamrats servers. That means the heavy compliance work for card data sits with the processor (the people who do that for a living), not us.
The third parties we rely on (payments, authentication, email delivery, hosting) are independently audited to enterprise security standards. We pick vendors on this criterion specifically.
Every page uses a secure, encrypted connection, and your stored data is encrypted too. Backups carry the same encryption.
Sign-in is handled by a specialist provider — multi-factor sign-in, sessions that refresh for safety, and no passwords stored on our side. Buyer ticket-recovery links rotate every time a new one is requested, so old links stop working.
Production access is limited to on-call engineers, protected by physical security keys. Access logs are kept for a year, and any access to live data is reviewed.
Found something?
If you’ve found a vulnerability, please report it privately. We don’t have a paid bounty program yet, but we acknowledge every report within two business days and credit researchers (with permission) on this page.
hello@jamrats.comPlease don’t test against live organizer events. Use your own test account or contact us first for access to a test environment.
Primary data lives in Canada (Toronto region). UK and EU buyer data stays on Stripe’s European servers to meet European privacy laws, and backups stay in the same region. We never move customer data across regions.
If we detect a security incident affecting your account or your buyers, we’ll notify you by email within 72 hours and post an incident report at /status.