Legal
Privacy policy
What we collect, why we collect it, and what we do not do with it. We do not sell your data, we do not run advertising, and we do not upload your contacts.
In effect from 21 September 2026.
What we collect
When you sign up
Your phone number, which is how you sign in — we send a one-time code to it rather than asking you to keep a password. A display name and, if you add one, a photo. If you sign in with Apple or Google instead, we receive whatever that service gives us, which is usually a name and an email address.
When you buy a ticket
Which event, how many tickets, what you paid and when. We never see your card number or your wallet PIN. Card payments go directly to Stripe and birr payments directly to Chapa; we hold only the reference each gives back, enough to match a payment to a ticket and to refund it.
When you use the app
Events you save, follow or RSVP to; messages you send to a venue; and what you search for, which is kept so your recent searches are there next time. Crash and error reports, which are technical and are not tied to your name.
Your contacts, if you let us
If you turn on finding friends, your phone works out a one-way fingerprint of each contact's number and sends us only that. We never receive the numbers themselves, or names, or anything else from your address book, and a fingerprint cannot be turned back into a number. Turn it off and we delete the fingerprints.
If you host events or run a venue
Your business details, the account money is paid into, and — where the law requires us to check who you are — a government identity document. Identity documents are kept in a separate store from everything else, are readable only by the reviewer who is checking them, and every time one is opened it is recorded.
Why we collect it
- To let you in — the phone number is the account.
- To sell you a ticket, get you through the door, and refund you.
- To pay organizers and venues what they are owed.
- To show you events near you and things like the ones you have saved.
- To tell you a thing you bought a ticket for has changed or been cancelled.
- To stop fraud, and to meet rules we are required to meet.
Who it is shared with
We share the least that makes the product work, and with nobody else.
- Chapa and Stripe — to take payments and send money out. They are the ones holding card and wallet details, not us.
- The organizer and the venue of an event you are going to — your display name and that you hold a ticket, so the door knows to let you in. Not your phone number.
- The services that deliver our messages — the network that carries an SMS, and Apple and Google for push notifications.
- Our hosting and storage providers, who hold the data on our behalf and may not use it for anything of their own.
We do not sell your data. We do not share it for advertising. There is no advertising network in the app. We will hand data to a public authority only where a valid legal request requires it.
How long we keep it
- Your account, for as long as you have one.
- Tickets and payment records, for seven years after the event — tax and accounting rules require it, and this is the one thing deleting your account does not remove.
- Contact fingerprints, until you turn friend-finding off.
- Identity documents, for as long as the law requires the check to be kept.
- Searches and crash reports, for up to twelve months.
Your rights
You can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete your account. Write to hello@kistet.app from the number or address on the account and we will answer within 30 days.
Deleting your account removes your profile, your saved events, your messages and your contact fingerprints. It does not remove the record of a ticket you bought, for the reason above.
Keeping it safe
Everything travels encrypted, and is encrypted where it is stored. Identity documents sit in their own store behind a separate door. Access to production data is limited to the people who need it and is logged. If a breach affects you, we will tell you.
Children
ክስተት is not for people under 18. We do not knowingly collect anything from a child, and will delete it if we find we have.
Where your data lives
Our servers and databases are operated by providers outside Ethiopia, so your data is stored and processed abroad under contracts requiring them to protect it to the standard described here.
Changes
If we change this policy we will change the date at the top, and we will tell you in the app before anything material takes effect.
Asking us
Questions, requests and complaints all go to hello@kistet.app. ክስተት is responsible for the data described here.
Who we are
ክስተት is operated from Addis Ababa, Ethiopia. Our company registration details are being completed and will be published here. Until then, reach us at hello@kistet.app and we will answer with them.
