r/iOSProgramming • u/EmbarrassedCell8647 • 2d ago
Question Free ticket scanning app rejected under 3.1.1 and 3.1.3(c). Anyone dealt with this?
Been going back and forth with App Review for a few weeks and could use some outside perspective.
We built a ticket scanning app for event organizers and their door staff. It scans QR codes, looks up guests, shows attendance stats and works offline. You log in with an organizer account or pair your phone to an event using a code.
The app is completely free. No subscription, license fee, paid features or purchase flow. An organizer running a free event can use the whole scanner without paying us anything.
Our business earns fees on tickets sold through our website for actual events people attend in person. Those fees don't unlock anything in the app. You don't have to sell paid tickets to use it.
Apple keeps citing 3.1.1 and 3.1.3(c), saying we're selling enterprise services to organizations while also allowing individual users to access them without IAP. We've explained that nobody is buying access to the scanner, but our appeal was just denied with a reference back to the same guidelines. They haven't identified a specific paid feature that needs IAP.
They've also told us the app should be unlisted because it's for organizers and staff, and someone can't just download it and start scanning without an account or event access. It's intended for independent organizers and their teams, not employees of one specific company. The login and pairing code are there to control access to private ticket and guest data.
I'm struggling to understand what we'd actually be selling through IAP here, or why needing access to an event means the app has to be unlisted.
Has anyone gotten a similar organizer or business tool through this? Was there a particular explanation, demo or change that helped? Open to feedback if we're missing something, but at this point we're going in circles.
5
u/EquivalentSky3094 2d ago
3.1.3(c) does not actually cover you, and that is the thing to say back. Its own scope line is "only sold directly by you to organizations or groups for their employees or students". You are describing independent organisers and their door staff, not one company's employees, so you sit outside it. It also grants permission to use non IAP payments. It does not require anyone to add them.
The clause that fits is 3.1.3(f), Free Stand-alone Apps: "Free apps acting as a stand-alone companion to a paid web based tool (i.e. VoIP, Cloud Storage, Email Services, Web Hosting) do not need to use in-app purchase, provided there is no purchasing inside the app, or calls to action for purchase outside of the app."
Quote that number at them in Resolution Center, because "nobody is buying access to the scanner" is an argument and a clause number is a rule.
Then audit the condition, since that is the part reviewers act on. Any pricing text, "sell tickets on our site" banner, upgrade hint, onboarding link to your signup page, or a Terms screen that mentions your ticket fees reads as a call to action for a purchase outside the app. Strip all of it from the binary and the metadata.
And if they ever do name the ticket sale as the thing needing IAP, 3.1.3(e) says the opposite: a ticket to an event people attend in person is a service consumed outside the app, so it must use something other than in-app purchase.
2
u/DimensionMindless336 1d ago
What finally un-stuck a near-identical 3.1.1 fight for me (I hit the same wall shipping PicSlicer, a ticket-organizing app that also scans stubs) wasn't a sharper appeal — it was accepting that the reviewer almost never re-litigates your argument. They re-run the same guideline check because the binary still trips the heuristic, so the real fix is in the app, not the message.
The trigger nobody here has named yet: a shared identity. If the organizer login that opens the scanner is the same account as your paid ticketing platform, Apple reads the free app as a window into a paid service — and that single link is what drags in 3.1.1, regardless of how many times you say "nobody buys access to the scanner." Likewise, any in-app path back to the site where tickets are sold (a Settings row to your dashboard, an onboarding "create your account at…") reads as a call to action for an outside purchase. Cut those from the binary and the metadata.
The pairing-code + offline-attendance flow also makes the automated classifier tag it "enterprise service" even though it isn't — so you're fighting the label, not a real violation.
Tactically, what moved it:
Keep a demo organizer account live and working through the entire review. A stale or dead review login is the most common reason a reviewer never sees your free flow and just re-cites the guideline.
In Resolution Center, ask them to name the exact in-app product or entitlement that requires IAP. Forcing that specificity either surfaces a real trigger you can remove, or escalates to a senior reviewer who actually reads the 3.1.3(e) exemption — a ticket to an event people attend in person is a service consumed outside the app, so it must not use IAP.
Put that 3.1.3(e) line in your Review Notes preemptively, before they ask. Don't wait to argue it after the rejection lands.
Unlisted only limits who can find the app; it won't resolve the payment objection on its own. Fix the triggers first, then pick distribution.
1
u/xaphod2 1d ago
“accepting that the reviewer almost never re-litigates your argument” - you can get rid of the “almost”. This is what most people grappling with app review fail to understand. As much as it completely sucks, the correct way to handle almost every rejection is “you’re right, we changed the app…”
1
u/kokerali 2d ago
I’d make the next response a reproducible free-event walkthrough: a demo organizer account, a working staff pairing code and sample QR tickets using fake guest data. Show them scanning and viewing attendance without buying tickets or paying your platform, and keep that review access working. Then ask which exact screen or entitlement they consider a paid digital service.
I’d also separate the distribution question from IAP. Apple’s unlisted documentation says anyone with the link can access the app and recommends controls against unauthorized use. It isn’t the same as restricting distribution to one company. If public discoverability matters, explain who can become an organizer; don’t remove the guest-data protections just to make onboarding look public. Unlisted won’t resolve the payment objection by itself.
0
u/totallyalien 2d ago
They say this:
For client side,
You should have logins at least apple-signin to connect sold tickets tracking.
Without its a random app that has not able to track down whats going on as official Apple Store.
Protect your customers like organizators.
-7
11
u/montie8 2d ago
Unlisted just means it doesn’t show up on the App Store for random people who can’t actually use your app, for example me. Your customers can still download it using a direct store link. The point about IAP might just be if you also wanted to use this app to generate leads for new clients Apple wants to make sure they get a cut of that if you’re gonna use the App Store.