Trust · Last updated 19 July 2026
Trust & security
Security is the floor everything else stands on. Here's how we protect your data and payments, how we govern new data processing, and how to reach us.
How we protect your data
Personal data is encrypted in transit (TLS 1.3) and at rest (AES-256). Sensitive fields — your email, phone, and name — are encrypted at the column level, and access to personal data is restricted and audited. No system is perfectly secure, but we hold ourselves to the standards expected of a payment-handling platform.
Payments & card data
Today you pay via EcoCash and InnBucks — mobile-money rails that never expose card or wallet credentials to us. Our PCI DSS scope is SAQ-A: we never receive, process, or store card numbers, CVVs, or PINs. When card payments arrive via ZimSwitch, they will run through the provider's own hosted page and stay off our systems.
Data-protection governance
Regulators
We build to the strictest of GDPR, POPIA, and Zimbabwe's Cyber and Data Protection Act (2021).
Impact assessments
New processing that touches personal data goes through a data-protection impact assessment before it is switched on.
Encryption
In transit (TLS 1.3) and at rest (AES-256), with sensitive fields encrypted per column.
Breach response
We investigate incidents promptly and notify affected people and regulators as the law requires.
Access, correct, delete, or object — start on our data-request page.
We publish the third parties that process data on our behalf, and where they operate.
Reporting a vulnerability
Found a security issue? Email security@263tickets.com. We acknowledge reports within two business days, and we won't pursue good-faith researchers who follow our responsible-disclosure policy.
Data-protection contacts
Our Information Officer, John Mugabe, oversees data protection and is your point of contact for privacy questions and complaints. Reach the data-protection team at privacy@263tickets.com, and see our privacy policy for the full detail of how we handle your data.