Skip to main content

Glitch Privacy Policy

Last updated: 18 July 2026

1. About this Privacy Policy

This Privacy Policy explains how Boing Ltd collects, uses, stores and shares personal data in connection with:

  1. the glitchfestival.com website, referred to as the “Website”;
  2. Glitch Festival and other events promoted under the Glitch name;
  3. ticket purchases and Event attendance;
  4. email marketing and other communications;
  5. competitions, surveys and promotions;
  6. customer-service enquiries;
  7. Glitch social-media pages and advertising campaigns.

This Privacy Policy should be read together with the Glitch Website and Ticket Terms and Conditions and the separate Glitch Cookie Policy.

2. Who controls your personal data?

The data controller is:

Boing Ltd
Company registration number: C 73818
VAT number: MT 23042723
Registered office: 116, Constitution Street, Mosta, MST 9055, Malta
Email: support@glitchfestival.com

Boing Ltd operates and promotes events under the Glitch and Glitch Festival names.

In this Privacy Policy, Boing Ltd is referred to as “Glitch”, “we”, “us” or “our”.

3. What is personal data?

Personal data is information that identifies you or that can reasonably be connected to you.

It may include your name, contact details, ticket information, online identifiers, purchase history and communications with us.

Information that has been fully anonymised so that you can no longer be identified is not personal data.

4. Personal data we collect

The personal data we collect depends on how you interact with us.

4.1 Identity and contact information

This may include:

  1. your name and surname;
  2. email address;
  3. telephone number;
  4. postal address;
  5. country of residence;
  6. date of birth or age;
  7. gender, where requested;
  8. identification details where reasonably required for age, ticket or fraud verification.

4.2 Ticket and order information

This may include:

  1. ticket type;
  2. Event and Event date;
  3. order number;
  4. ticket barcode or ticket identifier;
  5. purchase date;
  6. ticket price;
  7. ticket-holder details;
  8. ticket personalisation information;
  9. ticket transfer or resale information;
  10. refund and cancellation information;
  11. attendance and ticket-scanning records;
  12. wristband or RFID identifiers.

Where a Purchaser provides personal data about another ticket holder, the Purchaser should ensure that the other person is aware of this Privacy Policy.

4.3 Payment information

Payments are normally processed by our authorised ticketing and payment providers.

We may receive limited payment information such as:

  1. payment status;
  2. payment method;
  3. transaction reference;
  4. partial or masked payment-card details;
  5. billing information;
  6. refund status.

We do not normally receive or store your complete payment-card number.

4.4 Event attendance information

When you attend an Event, we may process:

  1. ticket-scanning information;
  2. entry and exit information;
  3. wristband details;
  4. RFID or cashless-payment activity;
  5. age-verification information;
  6. customer-service requests;
  7. accessibility requests;
  8. lost-property reports;
  9. security and incident reports;
  10. complaints;
  11. photographs, audio and video recordings;
  12. CCTV footage where CCTV is operated at an Event.

4.5 Communications

When you contact us, we may collect:

  1. your name and contact details;
  2. the content of your message;
  3. attachments you send;
  4. your ticket order number;
  5. our response and communication history;
  6. information required to investigate or resolve your request.

4.6 Marketing information

This may include:

  1. whether you subscribed to a mailing list;
  2. when and how you subscribed;
  3. the wording shown when consent was collected;
  4. your marketing preferences;
  5. email delivery, opening and link-click information;
  6. Event or artist interests;
  7. previous Glitch ticket purchases;
  8. unsubscribe and suppression records;
  9. responses to marketing campaigns.

4.7 Website and device information

When you use the Website, we may collect:

  1. IP address;
  2. browser type;
  3. device type;
  4. operating system;
  5. approximate location derived from your IP address;
  6. pages visited;
  7. links selected;
  8. referral source;
  9. session dates and times;
  10. cookie and advertising identifiers;
  11. Website errors and diagnostic information;
  12. interactions with Website content.

Non-essential analytics and advertising technologies are subject to your cookie choices where consent is required.

4.8 Social-media information

When you interact with Glitch through social media, we may receive:

  1. your public profile information;
  2. your username;
  3. comments, messages and reactions;
  4. competition entries;
  5. content in which Glitch is tagged or mentioned;
  6. advertising and audience information provided by the social-media platform.

The relevant social-media company also processes your information under its own privacy policy.

4.9 Competition and survey information

Where you participate in a competition, giveaway, registration form or survey, we may collect:

  1. your name and contact details;
  2. your entry or response;
  3. eligibility information;
  4. preferred artists, Events or products;
  5. delivery details where a prize must be sent;
  6. information required to administer the promotion.

Additional privacy information may be provided for a particular competition or survey.

5. How we collect your personal data

We may collect personal data:

  1. directly from you;
  2. when you purchase or receive a ticket;
  3. when another Purchaser enters your details as a ticket holder;
  4. through See Tickets or Paylogic;
  5. through TicketSwap;
  6. when you subscribe to marketing;
  7. when you use the Website;
  8. through cookies and similar technologies;
  9. when you attend an Event;
  10. when you contact customer support;
  11. through competitions, surveys and registrations;
  12. through social-media platforms;
  13. through venues, contractors, security providers or other Event partners;
  14. from publicly available sources where lawful.

6. Why we use your personal data

We only process personal data where we have a lawful reason to do so.

6.1 Providing tickets and Event services

We process personal data to:

  1. process and administer ticket orders;
  2. issue and personalise tickets;
  3. confirm payments;
  4. validate tickets;
  5. manage ticket transfers and authorised resale;
  6. provide entry to Events;
  7. operate wristband, RFID and cashless systems;
  8. issue permitted refunds;
  9. communicate important Event information;
  10. provide customer support.

This processing is generally necessary to perform our contract with you or to take steps requested by you before entering into a contract.

6.2 Event operations, safety and security

We process personal data to:

  1. manage Event capacity and attendance;
  2. prevent ticket fraud and duplicated tickets;
  3. protect Attendees, staff, artists and property;
  4. investigate security incidents;
  5. enforce Event rules;
  6. manage medical or emergency situations;
  7. cooperate with venues and competent authorities;
  8. establish, exercise or defend legal claims.

This processing may be based on our legitimate interests, compliance with legal obligations, the protection of vital interests or the establishment and defence of legal claims.

6.3 Customer support

We use personal data to:

  1. respond to questions;
  2. resolve ticket issues;
  3. investigate complaints;
  4. provide accessibility assistance;
  5. manage lost property;
  6. maintain records of our communications.

This processing may be necessary to perform our contract with you or for our legitimate interest in providing effective customer service and maintaining accurate records.

6.4 Marketing

We may use your contact details and marketing preferences to send:

  1. Event announcements;
  2. lineup announcements;
  3. ticket-sale information;
  4. Glitch news;
  5. offers and promotions;
  6. information about similar Glitch events, products or services.

Where required, marketing is sent with your consent.

In limited circumstances permitted by law, we may contact existing customers about similar Glitch events or services. Every marketing email will provide a clear way to unsubscribe.

We will not require you to agree to marketing as a condition of purchasing a ticket.

6.5 Website analytics

Subject to your cookie choices, we use analytics information to:

  1. understand how the Website is used;
  2. measure Website traffic;
  3. identify popular pages and content;
  4. detect technical problems;
  5. improve Website design and performance;
  6. understand the effectiveness of campaigns.

This processing is based on consent where required for the use of non-essential cookies or similar technologies.

6.6 Advertising and campaign measurement

Subject to your cookie choices, we may use Google and Meta tools to:

  1. measure advertising conversions;
  2. understand whether advertisements lead to Website visits or ticket purchases;
  3. create advertising audiences;
  4. exclude existing purchasers from certain advertising;
  5. show more relevant Glitch advertisements;
  6. measure campaign reach and effectiveness.

This may involve profiling based on Website activity, ticket purchases, marketing interactions and advertising identifiers.

This processing is based on consent where required.

6.7 Event planning and business analysis

We may analyse aggregated or pseudonymised information to:

  1. understand attendance by country or region;
  2. forecast demand;
  3. plan Event capacity;
  4. improve transport and operational arrangements;
  5. evaluate marketing performance;
  6. prepare business, funding or tourism reports;
  7. improve future Events.

Where reasonably possible, reports and statistics are prepared using aggregated or anonymised information.

This processing is based on our legitimate interest in planning, operating and improving Glitch Events.

6.8 Legal and regulatory requirements

We may process personal data to:

  1. maintain accounting and tax records;
  2. respond to lawful requests from public authorities;
  3. comply with consumer, licensing, safety and security obligations;
  4. investigate fraud or criminal activity;
  5. establish, exercise or defend legal claims;
  6. comply with court orders and legal proceedings.

This processing is based on compliance with legal obligations or our legitimate interest in protecting our legal rights.

7. Special-category personal data

We do not normally request sensitive or special-category personal data.

However, such information may be processed where necessary in connection with:

  1. accessibility requirements;
  2. medical assistance;
  3. allergies or health-related requests;
  4. security or safeguarding incidents;
  5. legal claims.

Where special-category information is processed, we will rely on an appropriate legal condition, such as explicit consent, protection of vital interests, substantial public interest or the establishment, exercise or defence of legal claims.

Medical services at an Event may also be provided by independent medical professionals who process information under their own professional and legal responsibilities.

8. Event photography and filming

Photography, video and audio recording may take place at Glitch Events.

We may use Event recordings for:

  1. Event coverage;
  2. editorial purposes;
  3. historical and archival records;
  4. press and public relations;
  5. social-media content;
  6. future Event promotion;
  7. advertising;
  8. aftermovies and documentaries.

Crowd and atmosphere photography is generally processed on the basis of Glitch’s legitimate interest in documenting and promoting its Events.

Where an individual is the main and clearly identifiable subject of planned promotional content, additional permission may be requested where appropriate.

You may contact us if you have a reasonable concern about a specific photograph or recording in which you are clearly identifiable. We will consider the request in light of your rights, our legitimate interests, freedom of expression and the circumstances in which the recording was made.

9. Email marketing providers

We use Campaign Monitor and Klaviyo to manage mailing lists and send marketing communications.

These services may process:

  1. your name;
  2. email address;
  3. country or location information;
  4. subscription date and source;
  5. marketing preferences;
  6. purchase and Event-interest information;
  7. email delivery and engagement information;
  8. unsubscribe information.

We use this information to manage subscriptions, personalise communications, measure email performance and maintain unsubscribe records.

You may unsubscribe at any time using the link contained in each marketing email.

Unsubscribing from marketing does not prevent us from sending essential ticket, order, safety or Event information.

10. Ticketing providers

We use See Tickets and Paylogic to provide ticketing services.

They may process information required to:

  1. create and administer an order;
  2. process payments;
  3. issue tickets;
  4. personalise tickets;
  5. communicate order information;
  6. provide ticket support;
  7. prevent fraud;
  8. manage permitted refunds;
  9. verify ticket validity;
  10. provide us with attendance and sales information.

Depending on the particular processing activity, See Tickets or Paylogic may process personal data on our instructions or under their own legal responsibilities.

Their own terms and privacy notices also apply when you use their websites or services.

11. TicketSwap

TicketSwap is the authorised resale platform for Glitch tickets.

Where you use TicketSwap, it processes your information under its own privacy policy and platform terms.

We may exchange limited information with TicketSwap where necessary to:

  1. verify a ticket;
  2. facilitate an authorised transfer;
  3. cancel and reissue a ticket;
  4. prevent fraud;
  5. resolve a resale or admission issue;
  6. enforce ticket conditions.

TicketSwap may act as a separate data controller for the services it provides directly to its users.

12. Google services

Subject to your cookie choices, we may use Google services including:

  1. Google Analytics;
  2. Google Ads;
  3. Google Tag Manager;
  4. Google conversion and advertising tools.

Google may receive information such as:

  1. your IP address;
  2. browser and device information;
  3. Website activity;
  4. cookie and advertising identifiers;
  5. approximate location;
  6. advertising interactions;
  7. conversion information.

Google processes this information under its applicable service terms, data-processing terms and privacy policy.

Further details about the cookies and technologies used are provided in the Glitch Cookie Policy.

13. Meta services

Subject to your cookie choices, we may use Meta services including:

  1. the Meta Pixel;
  2. Meta advertising tools;
  3. advertising conversion measurement;
  4. custom and similar audience tools.

Meta may receive information such as:

  1. Website visits;
  2. pages viewed;
  3. ticket-purchase or conversion events;
  4. browser and device information;
  5. IP address;
  6. cookie and advertising identifiers.

Meta may connect this information with information held through Facebook, Instagram or other Meta services, subject to its own terms and privacy policy.

Further details are provided in the Glitch Cookie Policy.

14. Who we share personal data with

We may share personal data with:

  1. See Tickets and Paylogic;
  2. TicketSwap;
  3. Campaign Monitor;
  4. Klaviyo;
  5. Google;
  6. Meta;
  7. payment-service providers;
  8. Website hosting and technical-service providers;
  9. venues and Event-site operators;
  10. security and crowd-management providers;
  11. medical and first-aid providers;
  12. wristband, RFID and cashless-payment providers;
  13. transport and customer-service providers;
  14. photographers, videographers and production teams;
  15. professional advisers, accountants, auditors and insurers;
  16. public authorities, regulators, police and emergency services;
  17. courts and legal representatives;
  18. prospective purchasers or investors in connection with a genuine business restructuring, merger or sale.

We only share information that is reasonably necessary for the relevant purpose.

Depending on the service, a recipient may act as:

  1. a processor acting on our instructions;
  2. a separate data controller;
  3. a joint controller with Glitch.

Where a service provider acts as our processor, we require it to process personal data under appropriate contractual and security obligations.

We do not sell customer mailing lists or personal data to unrelated third parties.

15. International transfers

Some of our service providers operate or store information outside Malta or the European Economic Area.

This may include providers based in or using infrastructure located in the United States and other countries.

Where personal data is transferred outside the European Economic Area, we take reasonable steps to ensure that an appropriate transfer mechanism is used.

This may include:

  1. an adequacy decision issued by the European Commission;
  2. participation in an approved data-transfer framework;
  3. European Commission Standard Contractual Clauses;
  4. supplementary contractual, technical or organisational safeguards;
  5. another transfer mechanism permitted by applicable law.

You may contact us for further information about the safeguards used for a particular transfer.

16. How long we retain personal data

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected.

The retention period depends on the type of information and the legal or operational reason for keeping it.

Our general retention approach is as follows:

16.1 Ticket and order records

Ticket, order, payment and refund records may be retained for the period required under applicable accounting, tax, consumer and legal-limitation requirements.

16.2 Attendance and scanning information

Ticket-scanning, wristband and attendance information is retained for the period reasonably required for Event administration, fraud prevention, customer support and dispute resolution.

16.3 Customer-service records

Customer-service enquiries and complaints will generally be retained for up to three years after the matter is closed, unless a longer period is reasonably necessary.

16.4 Security and incident records

Security, accident and incident information may be retained for the duration required to investigate the incident and for any applicable legal-claim period.

16.5 Marketing information

Marketing information is retained until:

  1. you withdraw your consent;
  2. you object to the marketing;
  3. the information is no longer reasonably required;
  4. the mailing list is reviewed and inactive information is removed.

We may retain limited suppression information after you unsubscribe so that we can record and respect your request not to receive further marketing.

16.6 Cookie and analytics information

Cookie and analytics retention periods are explained in the Glitch Cookie Policy and may vary according to the technology and your consent choices.

16.7 Photographs and recordings

Event photographs and recordings may be retained as part of Glitch’s promotional, editorial and historical archive for as long as they remain relevant, subject to applicable rights and valid objections.

We may retain information for longer where required by law or where it is necessary for an investigation, dispute or legal claim.

At the end of the applicable period, personal data will be deleted, anonymised or securely archived where continued retention is legally required.

17. Data security

We use reasonable technical and organisational measures designed to protect personal data from:

  1. accidental loss;
  2. unauthorised access;
  3. misuse;
  4. alteration;
  5. disclosure;
  6. destruction.

These measures may include:

  1. access controls;
  2. password and account protections;
  3. secure connections;
  4. role-based staff access;
  5. service-provider agreements;
  6. backups;
  7. system monitoring;
  8. internal security procedures.

Access to personal data is limited to staff, contractors and service providers who reasonably require it for their work.

No internet transmission or electronic-storage system can be guaranteed to be completely secure.

18. Your rights

Subject to the conditions and exceptions in applicable law, you may have the right to:

  1. receive information about how your data is processed;
  2. request access to your personal data;
  3. request correction of inaccurate or incomplete data;
  4. request deletion of your personal data;
  5. request restriction of processing;
  6. object to processing based on legitimate interests;
  7. object at any time to direct marketing;
  8. withdraw consent at any time;
  9. receive certain information in a portable format;
  10. request that information be transferred to another controller where applicable;
  11. lodge a complaint with a supervisory authority;
  12. seek an effective judicial remedy.

Withdrawing consent does not affect the lawfulness of processing carried out before consent was withdrawn.

Some rights are not absolute. We may need to retain or continue processing information where required by law or where another valid legal basis applies.

19. Exercising your rights

To exercise a data-protection right, contact:

Email: support@glitchfestival.com
Postal address: Boing Ltd, 116, Constitution Street, Mosta, MST 9055, Malta

Please clearly describe your request and identify the information or interaction concerned.

We may request reasonable information to verify your identity before acting on a request.

We will respond within the period required by applicable data-protection law.

Requests are normally handled free of charge. A reasonable fee may be charged, or a request may be refused, where it is manifestly unfounded or excessive, as permitted by law.

20. Direct-marketing objections

You have the right to object to direct marketing at any time.

You may:

  1. select the unsubscribe link in a marketing email;
  2. update your preferences where a preference centre is available;
  3. contact support@glitchfestival.com.

We will process the unsubscribe request as soon as reasonably possible.

You may continue to receive operational communications relating to a ticket, order or Event because these are not marketing communications.

21. Automated decision-making and profiling

We may use limited profiling to:

  1. segment mailing lists;
  2. understand Event interests;
  3. measure advertising activity;
  4. create advertising audiences;
  5. personalise communications;
  6. identify potential ticket fraud.

We do not normally make decisions based solely on automated processing that produce legal effects or similarly significant effects for you.

Where this changes, we will provide the information and safeguards required by law.

22. Children

Glitch Events are generally restricted to persons aged 17 or over unless expressly stated otherwise.

The Website and marketing services are not intended to collect personal data from children under the age at which they may independently provide valid consent under applicable law.

We do not knowingly request marketing consent from a child who cannot provide valid consent without parental or guardian authorisation.

A parent or guardian who believes that a child has provided personal data to us without appropriate authorisation should contact support@glitchfestival.com.

23. External websites

The Website may contain links to websites and services operated by third parties.

We are not responsible for the privacy practices, security or content of those services.

You should review the privacy information provided by the third party before submitting personal data.

24. Complaints

Please contact us first where you have a concern about how we process your personal data.

You also have the right to lodge a complaint with the Maltese supervisory authority:

Office of the Information and Data Protection Commissioner
Floor 2, Airways House
Triq Il-Kbira
Tas-Sliema SLM 1549
Malta

Telephone: +356 2328 7100

Complaints may be submitted through the official Information and Data Protection Commissioner complaint procedure.

You may also be entitled to complain to the supervisory authority in the country where you live or work.

25. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes to:

  1. our Events and services;
  2. the personal data we process;
  3. our service providers;
  4. technology used on the Website;
  5. legal or regulatory requirements.

The updated version will be published on the Website with a revised “last updated” date.

Where a change materially affects how we use personal data, we will take reasonable steps to provide additional notice where required.

26. Contact

Questions about this Privacy Policy or the use of personal data may be sent to:

Boing Ltd
116, Constitution Street
Mosta, MST 9055
Malta

Email: support@glitchfestival.com