Keeping NitePass safe
Reselling tickets through random Snapchat and WhatsApp messages is easy to get scammed on. Here's how NitePass is built to be safer.
University email confirmation
An opt-in flow emailed a one-hour token to a .ac.uk address and marked the account confirmed. It was built and worked, but signing up never required it.
Listing review queue
New listings were held pending approval rather than auto-published, with a moderation queue built to work through them. No listing was ever submitted.
Reporting
Any listing could be flagged. Reports went into the same moderation queue, which supported removing listings and suspending accounts.
Seller profiles
Each seller had a public profile showing their confirmation status and listing history.
Duplicate-image detection
Uploaded ticket images were read with OCR and fingerprinted with a perceptual hash, so the same ticket listed twice could be caught automatically.
Row-level database security
Every table had row-level security policies so a signed-in user could only read and write their own records.
Prohibited listings
To keep NitePass safe and legal, some listings are never allowed. Breaking these rules will get a listing removed and may get an account banned.
No football tickets
Reselling football match tickets without the organiser's authority is a criminal offence in the UK. Football tickets must never be listed or sold on NitePass — no exceptions.
- No fake tickets
- No duplicate listings
- No bulk or speculative resale
- No misleading prices
- No selling tickets you don't own
- No restricted or non-transferable tickets unless clearly disclosed
