Privacy Policy
EntryRate is operated by Showday Tickets LTD, a UK-registered company. We're the data controller for your promoter account; we're a joint controller with you for buyer data on events you list. This policy explains what we collect, why, and what you can do about it.
1 · What we collect
| Category | What & why |
|---|---|
| Promoter account | Your name, business name, email, phone, billing address. Required to operate your account. |
| Stripe Connect | Stripe collects your bank/identity directly — we see only what Stripe returns (account ID, payout status). Stripe's privacy policy applies separately. |
| Buyer PII | Buyer email and name on tickets they bought through your events. You see it as the promoter; we hold it as the platform. |
| Audit log | Every admin action (event edit, refund, payout, role change) timestamped with the actor's email. Retained for 24 months. |
| Server logs | IP, user-agent, request path. Retained for 30 days for security & debugging. No advertising use. |
2 · What we don't collect
- No third-party advertising trackers (no Google Analytics, no Facebook Pixel, no behavioural ad networks).
- No session-replay tools (FullStory, Hotjar, etc.).
- No biometric data, no precise location, no device fingerprinting.
- We do not share your buyer list with marketing platforms or sell it to third parties — ever.
2.1 Disclosed third-party connections on this marketing site
The EntryRate marketing site (this site) makes two third-party connections, both light-touch:
- Google Fonts — three typefaces (Geist, Geist Mono, Instrument Serif) load from
fonts.googleapis.comandfonts.gstatic.com. Google logs the requesting IP for those font requests. We are working to self-host and remove the dependency. - Plausible Analytics — page-view counts only. Plausible is GDPR-aligned by design: no cookies, no cross-site tracking, no personal identifiers, no fingerprinting. The aggregate dashboard tells us "how many people read pricing.html today"; nothing identifies who you are. Plausible's data policy.
The promoter dashboard at dashboard.showday.co.uk loads no third-party assets and runs no analytics.
3 · Lawful basis (UK GDPR Art. 6)
- Contract (Art. 6(1)(b)) — your promoter account, ticket fulfilment, payouts.
- Legitimate interests (Art. 6(1)(f)) — fraud prevention, audit log, security alerts.
- Legal obligation (Art. 6(1)(c)) — tax records, AML/KYC where Stripe requires.
- Consent (Art. 6(1)(a)) — marketing emails (you opt in; you can opt out any time).
4 · Where data lives
Primary database: MongoDB Atlas, EU region (eu-west-1, Ireland). Application servers: Hetzner, Falkenstein, Germany. Email delivery: Brevo (EU). Card processing: Stripe (US, with EU data-processing agreements in place). Cloudinary handles event imagery (EU region). All transit is TLS 1.2+.
5 · Your rights
Under UK GDPR you can ask us to:
- Access a copy of all data we hold on you (we'll respond within 30 days).
- Correct anything inaccurate (most fields are editable in the dashboard directly).
- Delete your account and PII (the in-app "delete account" flow handles this; some financial records are retained for 7 years per HMRC).
- Export your event, order and customer database as CSV at any time.
- Object to processing on legitimate-interest grounds, or withdraw consent for marketing.
- Complain to the ICO (ico.org.uk) if you believe we're not handling your data lawfully.
6 · Cookies
We use one functional cookie (your auth token, sd_token) and one preference cookie (your theme & collapsed-state UI choices). No analytics cookies, no advertising cookies, no third-party cookies. There is no cookie banner because there is nothing to consent to under PECR for these categories.
7 · Children
EntryRate is a B2B platform; we do not knowingly collect data from anyone under 18. Showday (the consumer side) requires buyers to be 16 or older.
8 · Changes
If we materially change this policy we'll email every active promoter account at least 14 days before the change takes effect. Minor clarifications (typos, structural cleanup) are pushed without notice.
Data protection enquiries: privacy@showday.co.uk. Postal: Showday Tickets LTD, Bristol, England.