Irish-owned | 30+ years in business | Real customer support

Effective date: 01st August 2026
Last updated:  01st August 2026

1. Who We Are

Marathon Sports Travel provides access to sports tickets, event tickets, ticket-related services and, where offered, associated sports travel products.

For the purposes of applicable data protection law, the organisation responsible for the personal data described in this Privacy Policy is:

Marathon Sports Travel
Suite 40, Block 5
Northwood Court
Northwood Industrial Estate
Santry, Dublin 9
D09 T266
Ireland

Email: sports@marathonsportstravel.ie
Telephone: 01 475 5010

In most circumstances, Marathon Sports Travel acts as the data controller for personal data collected directly through our website, customer-service channels and booking processes. This means that we determine why and how that personal data is processed.

Our ticket supplier, ticketing technology provider, payment provider, event organiser, sports club, venue or another fulfilment partner may separately act as:

depending on the service being provided and the parties’ respective responsibilities.

Where another organisation independently determines how and why it uses your personal data, its own privacy notice will also apply.


2. Purpose of This Privacy Policy

This Privacy Policy explains:

This Policy has been prepared with reference to:

The GDPR and the Data Protection Act 2018 form the principal data-protection framework applicable to most commercial processing of personal data in Ireland. The Irish ePrivacy Regulations also apply to matters including cookies and electronic direct marketing.


3. What Is Personal Data?

Personal data is information relating to an identified or identifiable living individual.

Depending on how you interact with us, we may collect and process the categories of information set out below.

3.1 Identity information

This may include:

We will not request passport or identity-document information unless it is reasonably necessary for a particular service or supplier requirement.

3.2 Contact information

This may include:

3.3 Booking and ticket information

This may include:

3.4 Payment and financial information

This may include:

Payment-card details may be collected and processed directly by an authorised payment-service provider. Marathon Sports Travel should not ordinarily receive or retain the complete card number or security code where payment is handled through a secure third-party payment gateway.

3.5 Account information

Where customer accounts are available, this may include:

3.6 Customer-service and communications information

This may include:

Telephone calls will only be recorded if callers have been appropriately informed and a lawful basis exists.

3.7 Technical and website information

This may include:

The use of cookies and similar technologies is addressed separately in our Cookie Policy.

3.8 Marketing information

This may include:

3.9 Accessibility, health and special-category information

If you request wheelchair-accessible seating, mobility assistance, companion seating or another reasonable accommodation, you may voluntarily provide information that reveals or concerns your health.

Health information is a special category of personal data under GDPR and requires additional protection. We will seek to collect only the minimum information necessary to communicate and fulfil the requested assistance. We will rely on an appropriate GDPR Article 9 condition where special-category information is processed. 

Customers should not provide detailed medical records or information that is unnecessary for arranging the requested service.


4. How We Collect Personal Data

We may collect personal data:

4.1 Directly from you

For example, when you:

4.2 From the lead booker or another person

A lead booker may provide information about other ticket holders, travellers or group members.

If you provide another person’s personal data, you must:

Where practical, the lead booker should avoid providing sensitive or special-category information about another person unless that person has authorised it or there is another lawful basis for providing it.

4.3 Through our ticket-supplier API

We use an application programming interface, or API, to connect our website with one or more ticket suppliers or ticketing technology providers.

The API may enable our website to:

Depending on the technical configuration, some information entered on our website may be transmitted to the ticket supplier in real time. Information may also be returned by the supplier and displayed within our website or booking confirmation.

We do not use the API as a legal basis in itself. Each transfer and processing activity must have an appropriate lawful basis under GDPR.

4.4 From payment providers

We may receive payment confirmation, fraud indicators, transaction references and limited payment information from our payment provider.

4.5 From event and fulfilment partners

We may receive information from:

4.6 Automatically through the website

Certain technical information may be collected automatically through server logs, cookies and similar technologies.

Non-essential cookies must not be activated unless the required consent has been obtained. Further information is available in our Cookie Policy.


5. Why We Use Personal Data and Our Legal Bases

GDPR requires organisations to have a valid lawful basis for processing personal data. The available bases include consent, contractual necessity, compliance with a legal obligation, vital interests, public-interest tasks and legitimate interests, subject to the applicable conditions. 

We may use personal data for the following purposes.

5.1 Processing ticket searches, orders and bookings

We use personal data to:

Legal basis: Processing is necessary to take steps at your request before entering into a contract or to perform our contract with you.

If you do not provide the information required for the booking, we may be unable to process or fulfil your order.

5.2 Sharing information with our ticket supplier

We may transmit information through the API or other secure channels so that the supplier can:

Legal basis: Contractual necessity and, where applicable, our legitimate interests in operating an efficient, secure ticket-distribution service.

5.3 Taking and administering payments

We use payment and transaction information to:

Legal basis: Contractual necessity, compliance with legal obligations and legitimate interests in protecting our business and customers against fraud.

5.4 Communicating service and event information

We may contact you regarding:

Legal basis: Contractual necessity, legal obligations and legitimate interests in providing accurate and timely service information.

These operational communications are not marketing where their content is limited to administering or delivering the service.

5.5 Fraud prevention, security and misuse detection

We may process information to:

Legal basis: Legitimate interests in protecting customers, suppliers, event partners and our business, and compliance with legal obligations where applicable.

5.6 Legal, regulatory, tax and accounting compliance

We may retain and use information to:

Legal basis: Compliance with a legal obligation and legitimate interests in maintaining appropriate business records and protecting legal rights.

5.7 Customer service and complaint handling

We use personal data to answer questions, resolve problems, investigate complaints and communicate with the relevant supplier, venue, club, event organiser or payment provider.

Legal basis: Contractual necessity and legitimate interests in providing customer assistance and resolving disputes.

5.8 Website analytics and service improvement

Subject to cookie-consent requirements, we may use analytics information to:

Legal basis: Consent where cookies or similar non-essential technologies are used. In limited cases involving aggregated or non-cookie operational information, we may rely on legitimate interests.

5.9 Direct marketing

Where legally permitted, we may send information about:

The general rule under Ireland’s ePrivacy Regulations is that electronic direct marketing requires the recipient’s clear, affirmative consent, subject to limited provisions relating to existing customers and similar products or services. Marketing communications must provide an effective means of opting out. 

Legal basis: Consent or, where the conditions of the relevant existing-customer exception are fully satisfied, legitimate interests together with compliance with the ePrivacy Regulations.

You may unsubscribe at any time by:

We may retain a minimal suppression record after an unsubscribe request to ensure that further marketing is not sent to that address.

5.10 Accessible seating and special assistance

We may process limited health or accessibility information to arrange requested assistance or suitable seating.

Legal basis: Contractual necessity or legitimate interests may apply to ordinary accessibility requests. Where health information or another special category of personal data is processed, we will also identify an applicable condition under Article 9 GDPR, which may include explicit consent where appropriate.

You may withdraw explicit consent, but this will not affect processing that took place lawfully before withdrawal. Withdrawal may also mean that we cannot arrange the requested assistance where the information remains necessary.

5.11 Business administration and corporate transactions

Information may be used for audit, insurance, professional advice, business continuity or a proposed restructuring, merger, acquisition or transfer of business.

Legal basis: Legitimate interests in administering, protecting and developing our business, subject to appropriate confidentiality and data-protection safeguards.


6. Ticket Supplier and API Data Sharing

Our ticket supplier is an important part of the ticket-sales process. To complete your order, we may share:

The precise information shared will depend on the event, supplier, venue and booking requirements.

6.1 Responsibility for supplier processing

Where the supplier processes personal data solely on our documented instructions, it may act as our data processor.

Where the supplier determines its own purposes, such as:

it may act as an independent data controller.

Where legally required, we will maintain appropriate controller-processor terms, data-sharing arrangements or other contractual safeguards.

6.2 Supplier privacy information

Where a supplier acts as an independent controller, customers should also review that supplier’s privacy notice.

Ticket supplier: Travel Connections
Supplier privacy notice: https://www.travelconnectionleisure.com/privacy-policy/
Supplier location: United Kingdom
Supplier contact: BOOKINGS@TRAVELCONNECTIONONLINE.NET


7. Other Parties With Whom We May Share Personal Data

We may share personal data, where necessary and proportionate, with:

We do not sell personal data to third parties for their independent direct-marketing purposes.

All service providers acting as our processors must be subject to appropriate contractual obligations concerning confidentiality, security, lawful processing and assistance with data-protection compliance.


8. Payment Processing

Payments may be handled by a third-party payment-service provider.

Payment information entered into the payment interface may be collected directly by that provider and processed under its own privacy notice and security arrangements.

Payment provider: Stripe

We recommend that customers review the payment provider’s privacy information before completing a transaction.

Marathon Sports Travel will retain transaction records needed for booking administration, accounting, refunds, fraud prevention and legal compliance, but should not retain complete card security codes.


9. International Transfers

Our primary operations are based in Ireland. However, some ticket suppliers, clubs, event organisers, venues, payment providers, hosting providers or technology partners may be located outside Ireland or outside the European Economic Area.

Where personal data is transferred outside the EEA, we will ensure that a lawful transfer mechanism is used where required. Depending on the destination and recipient, this may include:

We will also consider whether additional technical, organisational or contractual safeguards are required.

You may contact us to request further information about the safeguards applicable to a particular transfer, subject to legitimate confidentiality and security restrictions. GDPR establishes specific conditions for transfers of personal data to third countries or international organisations. 


10. How Long We Retain Personal Data

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including for legal, accounting, tax, fraud-prevention and dispute-management requirements.

The actual period will depend on the type of record and the circumstances.

Our anticipated retention approach is as follows:

We may retain information for longer where:

Before publication, Marathon Sports Travel should ensure that these periods match its documented internal retention schedule and actual systems.


11. Data Security

We use appropriate technical and organisational measures designed to protect personal data against:

Measures may include:

No internet transmission or electronic storage system can be guaranteed to be completely secure. Customers should use strong passwords, keep account credentials confidential and notify us promptly if they suspect unauthorised account activity.


12. Personal Data Breaches

We maintain procedures for assessing and responding to suspected personal data breaches.

Where a breach presents a risk to individuals’ rights and freedoms, we will notify the Irish Data Protection Commission within the legally required timeframe where applicable. Where the breach is likely to result in a high risk to an affected individual, we will also communicate with that individual unless a lawful exception applies.


13. Your Data-Protection Rights

Subject to the conditions and exemptions under applicable law, you may have the following rights:

13.1 Right to be informed

You have the right to receive clear information about how your personal data is collected and used.

13.2 Right of access

You may request confirmation of whether we process your personal data and obtain a copy of that information.

13.3 Right to rectification

You may ask us to correct inaccurate personal data or complete information that is incomplete.

13.4 Right to erasure

You may request deletion of personal data in certain circumstances. This right is not absolute and may not apply where processing or retention is required by law, for contract administration or for legal claims.

13.5 Right to restriction

You may ask us to restrict the processing of personal data in certain circumstances.

13.6 Right to data portability

Where processing is based on consent or contract and carried out by automated means, you may be entitled to receive relevant personal data in a structured, commonly used and machine-readable format and to transmit it to another controller.

13.7 Right to object

You may object to processing based on our legitimate interests. We will stop the relevant processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms or the processing is required for legal claims.

13.8 Right to object to direct marketing

You have the right to object to direct marketing at any time. Once we receive a valid objection or unsubscribe request, we will stop using your information for that purpose.

13.9 Right to withdraw consent

Where processing is based on consent, you may withdraw it at any time. Withdrawal will not affect the lawfulness of processing undertaken before consent was withdrawn.

13.10 Rights relating to automated decision-making

You may have rights relating to decisions based solely on automated processing, including profiling, where such decisions produce legal or similarly significant effects.

13.11 Right to complain

You have the right to raise a concern with us and to lodge a complaint with the Irish Data Protection Commission.

The GDPR strengthens individual rights including access, rectification, erasure and data portability, subject to the conditions applying to each right


14. How to Exercise Your Rights

To exercise a data-protection right, contact:

Privacy Contact
Marathon Sports Travel
Suite 40, Block 5
Northwood Court
Northwood Industrial Estate
Santry, Dublin 9
D09 T266
Ireland

Email: sports@marathonsportstravel.ie

Please clearly describe your request and identify the booking, account or interaction concerned.

We may request reasonable evidence of identity before disclosing or changing personal data. This is to protect customers against unauthorised access or impersonation. We will not request more identity information than is reasonably necessary.

We will normally respond within one month of receiving a valid request. That period may be extended where permitted under GDPR for complex or multiple requests, in which case we will inform you of the extension and the reason for it.

Data-protection rights may be subject to legal restrictions or exemptions. If we cannot fully comply with a request, we will explain the reason unless the law prevents us from doing so.


15. Complaints to the Data Protection Commission

We encourage you to contact us first so that we can try to resolve your concern.

You also have the right to complain to:

Data Protection Commission
21 Fitzwilliam Square South
Dublin 2
D02 RD28
Ireland

Website: www.dataprotection.ie
Contact facility: Available through the Data Protection Commission website.

The Data Protection Commission is Ireland’s independent supervisory authority for GDPR and also has responsibilities under the Irish ePrivacy Regulations.


16. Cookies and Similar Technologies

Our website uses cookies and similar technologies for purposes including:

Strictly necessary technologies may operate without consent where they are essential to provide a service expressly requested by the user. Non-essential cookies and tracking technologies will only be used after obtaining the required consent.

Please review our separate Cookie Policy and use the Cookie Settings link available on our website to manage or withdraw your preferences.


17. Direct Marketing Preferences

Where you choose to receive marketing, we may use your name, email address, telephone number and relevant preferences to send information about Marathon Sports Travel tickets, events, promotions and related services.

We will not make consent to unrelated marketing a condition of purchasing tickets.

Marketing consent must be:

Every electronic marketing message will contain an appropriate method of unsubscribing.

An unsubscribe from marketing will not prevent us from sending essential service messages concerning:


18. Children’s Personal Data

Our website and ticket-purchasing services are intended to be used by adults or by persons who have the legal capacity and authority to make the relevant purchase.

Children should not create an account, make a booking or provide personal data without the involvement of a parent or legal guardian where required.

A parent, guardian or adult lead booker may need to provide a child’s name, age or other limited information where necessary for:

We will only collect information about children that is reasonably necessary for the booking or legal requirement. We do not knowingly use children’s personal data for behavioural advertising or profiling.

Under the Irish Data Protection Act 2018, specific rules apply to children and information-society services. 

If you believe a child has provided information to us improperly, please contact us so that the matter can be investigated.


19. Automated Processing and Fraud Screening

Our website, payment provider or ticket supplier may use automated tools to identify:

In most cases, these tools support human review rather than making a final decision by themselves.

If Marathon Sports Travel uses solely automated decision-making that produces legal or similarly significant effects, we will provide any additional information and safeguards required under GDPR.


20. Links to Third-Party Websites

Our website may contain links to:

We are not responsible for the content, security or privacy practices of independent third-party websites. Customers should review the privacy policy of each third party before providing personal data.


21. Social Media

If you interact with Marathon Sports Travel through social media, the relevant platform may process personal data under its own privacy policy.

We may receive:

We will use this information to respond to you, administer promotions, moderate content and manage our business presence on the platform.

The social media provider may act as an independent controller for its own processing activities.


22. Competitions and Promotions

Where we operate a competition or promotion, we may process:

The applicable competition rules will provide additional information where necessary.

Personal data collected to administer a competition will not automatically be used for unrelated marketing unless an appropriate and separate legal basis exists.


23. Changes to This Privacy Policy

We may update this Privacy Policy to reflect:

The updated version will be published on our website with a revised “last updated” date.

Where a change materially affects how we use personal data, we will provide additional notice where reasonably necessary.

The Data Protection Commission recommends that privacy policies be regularly reviewed and updated so that they continue to reflect an organisation’s actual data-processing activities.  


24. Contact Us

Questions regarding this Privacy Policy or Marathon Sports Travel’s handling of personal data should be directed to:

Marathon Sports Travel
Suite 40, Block 5
Northwood Court
Northwood Industrial Estate
Santry, Dublin 9
D09 T266
Ireland

Privacy email: sports@marathonsportstravel.ie
Customer-service email: sports@marathonsportstravel.ie
Telephone: 01 475 5010

When contacting us about an existing booking, please include the booking reference but do not send full payment-card details, passwords or unnecessary identity documentation by ordinary email.