Privacy Policy

Privacy Policy

Menta provides the technology that allows fans to resell tickets to other fans within the ticketing platform they already use. This notice explains what personal data Menta handles in connection with that service, and which company is responsible for each part of it. Some of our terms of service refer to the service as the Secondary Marketplace and others as the Secondary Resale Service. This notice covers both.

Last updated September 9, 2026
On this page
  1. 1Who we are
  2. 2Who controls your data
  3. 3The data we handle
  4. 4Data we control ourselves
  5. 5Cookies
  6. 6Who we share data with
  7. 7International transfers
  8. 8How long we keep data
  9. 9How we protect data
  10. 10Automated decisions
  11. 11Your privacy rights
  12. 12Children
  13. 13Changes
  14. 14Contact & representatives

Fans sell to fans. The ticketing platform runs your account. A regulated payment provider handles the money. Because of that, two other notices usually apply to you alongside this one:

  • the ticketing platform's privacy policy, which governs your account and your relationship with resale; and
  • the payment provider's privacy policy, which governs payments, seller onboarding, identity verification, and payouts.

Section 2 breaks down who is responsible for what.

01 Who we are

Menta Tickets Corp. ("Menta", "we", "us") is a corporation incorporated in the State of Florida, United States.

The fastest way to reach us about privacy, or to have us point your request to the right place:

  • Privacy contact: legal@mentatech.io
  • Postal address: 5200 Waterford District Dr, Suite 120, Miami, FL 33126, USA

If you are in the EEA, the UK, Canada (including Quebec), or Brazil, Section 14 has your local contact.

02 Who controls your data

Three different companies are responsible for different parts of your data.

Controller

The ticketing platform

Controls your account and your relationship with resale. For that data we act as its processor, handling data on its instructions to make resale work. Its privacy policy governs this data, and it is your first stop.

Payments

The payment provider

Payments are handled by regulated payment service providers, such as Stripe. The provider handles card details and carries out seller onboarding, identity and KYC/AML checks, sanctions screening, and payouts, under its own terms, and acts as controller for that processing. We do not carry out those checks, and we do not store your full card number or the identity documents you give the provider.

Operator

Menta

Operates the resale technology and, where agreed, acts as merchant of record for the collection of amounts due, as part of the service it provides to the platform. This covers charging the payment, settling with sellers, collecting fees, and handling refunds and chargebacks. Being merchant of record means Menta is the party of record before the payment provider for collecting and settling that payment. It does not mean Menta sells the ticket. The ticket is sold by the seller to the buyer, and Menta is not a party to that sale. Funds are held by the payment provider under its own regulatory authorisations. Depending on the territory, the platform may act as merchant of record instead.

There is also a small set of data we control in our own right: visitors to our websites, our business contacts, and the records we have to keep for our own legal, tax, and fraud-prevention duties. Section 4 covers it.

03 The data we handle to run resale

To operate resale for the platform we handle a limited set of data. Depending on the platform, the market and how you use the service, we may handle some or all of the following:

  • Identifiers and contact data: such as name, email address and, where the platform provides it, telephone number.
  • Account data: account identifiers and settings used inside the resale experience.
  • Transaction and ticket data: such as your resale listings and purchases, timestamps, amounts, fees, and event details including the event, its date and the ticket type.
  • Limited payment metadata: such as payment tokens and transaction metadata received from the payment provider. We do not receive or store full card numbers, and the identity and bank details you give the provider remain with the provider.
  • Device, browser and network data: such as IP address, device and browser type, and information from strictly necessary cookies and similar technologies. Section 5 explains this.
  • Support communications: what you send us, and our replies, when you contact support.

We use it to run your listings and purchases, complete and settle transactions, stop fraud and keep things secure, help you when you contact support, and sort out disputes and chargebacks, in each case to deliver the service to the platform and meet the law. Depending on how resale is set up with your ticketing platform, we handle much of this as the platform's processor, with the platform setting the purposes and its policy governing. Acting as merchant of record for the collection of amounts due is part of the service we provide to the platform, so we handle the resale transaction data involved in it on the platform's behalf and on its instructions. Separately, we keep or act on a narrow set of records for our own legal, tax and fraud-prevention obligations. Section 4 describes those.

04 Data we control for our own purposes

For a narrow slice, mostly our own corporate activity and our own records, we are the controller and this policy applies directly:

  • people who visit our websites or contact us directly;
  • our business contacts at ticketing platforms and partners; and
  • the limited records we must keep for our own legal, tax, accounting, fraud-prevention, and security duties, including when we act as merchant of record for the collection of amounts due in a transaction (keeping required tax and transaction records, acting on chargeback notices or fraud information received from the platform or the payment provider, including holding or reversing a payout, and protecting our own systems); and
  • reports submitted through our listing-report channel and the moderation records we keep to meet our own platform-accountability obligations, including under the EU Digital Services Act (Regulation (EU) 2022/2065).

To be clear about the boundary: running the resale marketplace, and acting as merchant of record within it, are services we provide to the ticketing platform, and we handle the transaction data involved on the platform's behalf. What we control in our own right is the limited set of records listed above, which we keep or act on in order to meet our own legal obligations and to manage our own risk.

If you are in the EEA or the UK, our legal bases for this are:

  • Legal obligation: tax, accounting, and regulatory record-keeping, including in our capacity as merchant of record, and our platform-accountability duties under the EU Digital Services Act.
  • Legitimate interests: preventing fraud losses we would bear, securing our systems, running our business, and managing and marketing our B2B relationships. We weigh these against your rights, and you can object.
  • Consent: non-essential cookies and marketing where consent is required. You can withdraw it at any time.

We do not seek to collect sensitive or special category data. Where we hold an identification number or financial account detail for the purposes described above, we apply additional safeguards to it and use it only for those purposes.

05 Cookies and similar technologies

In the resale flows

The buy and sell flows run on a web address provided by the ticketing platform, on a subdomain of the platform's own site. In those flows the resale module sets only cookies and similar technologies that are strictly necessary to provide the service, for purposes such as session management, security and fraud prevention. Because nothing beyond what is strictly necessary is set, no separate cookie banner of ours appears there.

We do not set marketing or advertising cookies in the resale flows. If the platform asks us to enable anything beyond what is strictly necessary, that technology is governed by the platform's own cookie notice and consent tools, not ours.

On our corporate website

Our website at mentatech.io is separate from the resale flows. There we use cookies that are necessary for the site to function and, where the law requires consent, optional analytics cookies that are set only after you accept them through the cookie banner on the site.

You can manage cookies at any time through your browser settings. This page stores only your language preference, and it stores it locally on your device. We do not use cookies or similar technologies to sell personal data or to carry out cross-context behavioural advertising, and we honour recognised opt-out signals such as Global Privacy Control where they apply.

06 Who we share data with

We share data only in these ways:

  • The ticketing platform: it receives the transaction information needed to deliver and manage the ticket and the event, under its own policy.
  • The event organizer or venue: where needed to validate entry, reissue or personalize a ticket, enforce the event's rules, or meet safety obligations, normally through the ticketing platform and under their own policies.
  • The payment provider, such as Stripe: for payments, seller onboarding, identity verification and payouts, under its own terms and privacy policy, as described in Section 2. We pass it only tokens and limited metadata.
  • Our subprocessors: trusted vendors that process data on our behalf to run the service: cloud hosting and infrastructure, analytics, communications (email, SMS), and fraud and security tooling. We keep a current list and share it on request.
  • Professional advisors: lawyers, accountants, auditors, and insurers, where reasonably necessary.
  • Legal and regulatory disclosures: courts, regulators, tax authorities, and law enforcement where required, or to comply with law, enforce our terms, protect rights, or stop fraud and abuse.
  • Business transfers: if we are involved in a merger, acquisition, financing, or sale of assets, data may move as part of that, subject to this policy or a successor.

Buyers and sellers remain anonymous to each other. We do not disclose the identity or contact details of one party to the other.

Our no-sale promise

We do not sell your personal data, and we do not share it for cross-context behavioral advertising. That holds whether or not you ever opt out.

As those terms are defined under U.S. state privacy laws.

07 International data transfers

We are based in the United States, and we and our providers process and store data in the United States and other countries, which may have different privacy laws than where you live.

  • Where we act as the platform's processor, transfers of your data are governed by the data processing terms between us and the platform, which include the EU Standard Contractual Clauses and the UK Addendum where required, with supplementary measures as needed.
  • Where we act as a controller (Section 4), the GDPR or the UK GDPR can apply to us directly, because we offer services to people in those regions, and we comply with it in that capacity. Where personal data is transferred to us from the EEA or the UK by another party, we put appropriate safeguards in place, such as the EU Standard Contractual Clauses and the UK Addendum, or rely on an adequacy decision where one applies.
  • Other countries. Where the law of your country requires a specific mechanism for an international transfer, such as your consent, a contractual undertaking, a registration or an authorisation, we rely on that mechanism as required before the transfer takes place.

Note for users in Canada

Your personal data is processed and stored in the United States and may be processed elsewhere. While outside Canada, it can be accessible to courts, law enforcement, and national-security authorities under those countries' laws. We use contractual and organizational safeguards to protect it. Contact our Privacy Officer (Section 14) for details, or a copy of the safeguards.

08 How long we keep your data

We keep personal data only for as long as we need it for the purposes described above. Where we handle data to run resale for the platform, we keep it for the term of our agreement with the platform, plus the limited additional time needed to meet legal, accounting, settlement, chargeback, dispute-resolution, and compliance requirements. After that, we delete it or anonymize it for good.

The exact periods depend on the type of data and on what the law requires, which can vary by country, and identity and payment records are kept by the payment provider under its own retention rules. Where we must keep something after we no longer use it actively, we isolate and protect it and delete it once it is no longer required. As a guide, transaction, invoicing, and tax records are kept for the statutory periods that apply to us and to the platform under tax and commercial rules, which vary by country, and where local law requires it we block data instead of erasing it while those periods run, deleting it afterwards.

09 How we protect your data

We use commercially reasonable technical and organizational measures to protect your data, sized to the risk and the state of the art: access controls on a least-privilege basis, multi-factor authentication for privileged access where supported, encryption in transit (and at rest where our systems support it), logging and monitoring, vulnerability management, backups, vendor due diligence, and an incident-response process. Full card numbers sit with the payment provider, not with us. If a personal data breach occurs, we notify as the law requires, and where we act as the platform's processor we notify the platform without undue delay, and within 72 hours of becoming aware, so it can meet its own obligations.

No system is ever 100% secure, so please help by keeping your login details to yourself.

10 Automated decisions

The payment provider carries out automated fraud and identity checks as part of the payments and seller onboarding it controls. We act on fraud and chargeback signals we receive from the ticketing platform and from the payment provider, and we carry out limited checks of our own, which may be automated or manual, to keep resale secure. We do not take decisions about you with legal or similarly significant effects by automated means alone, without a lawful basis and safeguards such as human review.

In the EEA, the UK and Quebec you have specific rights in relation to automated decisions, as set out in Section 11. Where the platform or the payment provider controls the processing, we pass your request to them.

11 Your privacy rights

How requests work

For most data about your use of resale, the ticketing platform is the controller, so contacting it directly is fastest. For payments, seller onboarding, identity and payouts, the payment provider is the right party. For data we control (Section 4), or if you would like us to route your request, contact us (Section 14) and we will help, pass it to the right party, and assist the controller as the law requires. We verify requests, you can use an authorized agent where allowed, and we will not treat you differently for exercising your rights. We respond within the time the law allows, normally within 30 days, and within 45 days for requests under U.S. state privacy laws, and we will tell you if we need longer.

11.1 United States (California and other states)

Depending on your state, you may have the right to know about and access your data, correct it, delete it, get a portable copy, opt out of the sale or sharing of personal data and of targeted advertising, limit the use of sensitive data, and appeal a decision on your request. These rights apply under the California Consumer Privacy Act (as amended by the CPRA) and comparable laws in states including Virginia, Colorado, Connecticut, Utah, and Texas, plus others as they come into effect over time. As noted above, we do not sell or share your data for cross-context behavioral advertising, and we honor signals like Global Privacy Control. You can contact the California Privacy Protection Agency or your State Attorney General.

11.2 European Economic Area and United Kingdom

Under the GDPR and UK GDPR, you have the right to access your data, correct it, have it erased, restrict or object to processing (including direct marketing and processing based on legitimate interests), data portability, withdraw consent where we rely on it, and not be subject to solely automated decisions with legal or similarly significant effects, except as permitted by law. Because we act as the platform's processor for most fan data, the platform (as controller) is usually the right party, and we assist it; for the narrow set of data we control in our own right, the legal bases are in Section 4 and you can come to us directly. You can complain to your local supervisory authority or the UK Information Commissioner's Office (ICO), though we would welcome the chance to help first. See Section 14 for our contact details.

11.3 Canada (including Quebec)

Under PIPEDA and Alberta's PIPA, you have the right to access and correct your data and to withdraw consent, subject to legal and contractual limits. We process data in Canada and abroad as described in Section 7, including in the United States. You can contact the Office of the Privacy Commissioner of Canada or, in Alberta, the Office of the Information and Privacy Commissioner of Alberta.

Quebec residents (Law 25). The following also applies:

  • Privacy Officer: the person responsible for protecting personal information at Menta is our privacy contact, legal@mentatech.io.
  • Consent and privacy by default: we collect, use, and disclose with consent where required, and our settings default to a high level of privacy.
  • Automated decisions: where a decision about you is made only by automated processing, you can be told that it was, obtain the information and main factors used, and ask for it to be reviewed. Where the platform or the payment provider controls that processing, we route your request to them.
  • Portability: you can receive the computerized personal information you gave us in a structured, commonly used format.
  • You can complain to the Commission d'accès à l'information du Québec (CAI).

11.4 Latin America and the Caribbean

In Brazil, under the Lei Geral de Proteção de Dados (LGPD), you can confirm and access your data, correct it, anonymize, block, or delete unnecessary or excessive data, obtain portability, learn who we share it with, and withdraw consent. Our data protection officer (encarregado) for Brazil is in Section 14, and you can contact the national authority, the ANPD.

Elsewhere in the region, comparable rights of access, correction, deletion, objection and withdrawal of consent apply under local law, and you can exercise them by contacting us (Section 14). The principal frameworks and supervisory authorities are:

  • Argentina: Ley 25.326 and Decreto 1558/01. Agencia de Acceso a la Información Pública.
  • Mexico: the applicable federal personal data protection legislation, including the rights of access, rectification, cancellation and opposition.
  • Colombia: Ley 1581 de 2012. Superintendencia de Industria y Comercio.
  • Chile: Ley 19.628, as amended, and Ley 21.719. Agencia de Protección de Datos Personales.
  • Uruguay: Ley 18.331. Unidad Reguladora y de Control de Datos Personales.
  • Ecuador: Ley Orgánica de Protección de Datos Personales. Superintendencia de Protección de Datos Personales.
  • Panama: Ley 81 de 2019. Autoridad Nacional de Transparencia y Acceso a la Información.
  • Costa Rica: Ley 8968. Agencia de Protección de Datos de los Habitantes.
  • Dominican Republic: Ley 172-13.
  • El Salvador: the Ley de Protección de Datos Personales.
  • Puerto Rico: United States federal law and Puerto Rico law apply. See Section 11.1.
  • Bolivia, Guatemala, Paraguay and other markets without a general data protection statute: constitutional privacy protections, consumer protection law and sector rules apply. We handle your request on the same basis as everywhere else described in this Section 11.

11.5 Asia-Pacific, Middle East and Africa

Rights of access, correction, deletion, objection and withdrawal of consent apply under local law, and you can exercise them by contacting us (Section 14). The principal frameworks and supervisory authorities are:

  • Australia: Privacy Act 1988 (Cth) and the Australian Privacy Principles. Office of the Australian Information Commissioner.
  • New Zealand: Privacy Act 2020. Office of the Privacy Commissioner.
  • Japan: Act on the Protection of Personal Information. Personal Information Protection Commission.
  • South Korea: Personal Information Protection Act. Personal Information Protection Commission.
  • Singapore: Personal Data Protection Act 2012. Personal Data Protection Commission.
  • Malaysia: Personal Data Protection Act 2010. Personal Data Protection Commissioner.
  • Thailand: Personal Data Protection Act B.E. 2562 (2019). Personal Data Protection Committee.
  • Indonesia: Law No. 27 of 2022 on Personal Data Protection.
  • Philippines: Data Privacy Act of 2012. National Privacy Commission.
  • Israel: Protection of Privacy Law, 5741-1981. Privacy Protection Authority.
  • Turkey: Law on the Protection of Personal Data No. 6698. Kişisel Verileri Koruma Kurumu.
  • South Africa: Protection of Personal Information Act, 2013. Information Regulator.
  • Ukraine: the Law of Ukraine On Personal Data Protection. Ukrainian Parliament Commissioner for Human Rights.

11.6 Any other jurisdiction

If your country is not named above, you still have whatever rights your local law gives you, and this Section 11 is not a limit on them. Contact us (Section 14) and we will identify the correct controller, handle the request ourselves where we control the data, pass it to the ticketing platform or the payment provider where they do, and respond within the period your local law allows. Where your local law gives you a right that is not listed anywhere in this Section 11, we will honour it to the extent it applies to us.

12 Children

Resale is for adults. It is not aimed at children, and we do not knowingly collect data from anyone under 18. If you think a minor has given us data, tell us (Section 14) and we will take steps to delete it.

13 Changes to this policy

We will update this page as our service, our technology, or the law changes. When we do, we will revise the "Last updated" date at the top, and for material changes we will let you know by reasonable means. It is worth a look from time to time.

14 Contact us and our representatives

Menta Tickets Corp.

A Florida corporation. 5200 Waterford District Dr, Suite 120, Miami, FL 33126, USA.

  • Privacy contact: legal@mentatech.io
  • Requests from the EEA or the UK: use our privacy contact above and we will handle your request directly.
  • Quebec (Law 25) person in charge and Brazil (LGPD) encarregado: our privacy contact above.
  • Other local contacts: where the law of a country where we offer the resale service requires us to designate a local representative, agent or contact point for data protection, we designate one and identify it here.

For data about your use of resale, please also contact the ticketing platform (the controller) and read its policy, and see the payment provider's policy for payments, seller onboarding and payouts.

This policy is published in English, with a Spanish translation provided for convenience. Additional translations may be provided where required by law. If any translation conflicts with the English version, the English version governs, except where local law requires another language to prevail.