Privacy policy
Draft updated 20 September 2026
These policies are being completed. Retention periods, business-disclosure requirements and commercial terms still require confirmation. This draft does not reduce any rights you have under applicable law.
Who is responsible
This notice describes the Nightfair website’s current data flows. The data controller is Janhavi Oturkar, an individual trading as Nightfair, based in London, UK. Contact support@savethenight.uk or +44 7393 080444 for privacy enquiries.
Information we process
Organiser information includes business or organisation name, verified organisation email, event information, artwork, ticket inventory and admission/check-in records. We record age declarations and terms acceptance; a declaration is not independent proof of age. Account information includes your email, profile name, optional photo, preferences, password hash where applicable, verification records and sign-in sessions. If you choose Google sign-in, we receive the provider identifier and verified account information needed to sign you in or link your account.
Marketplace information includes events and ticket descriptions you submit, uploaded ticket files, file and QR fingerprints used for duplicate checks, prices, orders, payment references, delivery records and payout status. Support messages, audit records and technical service logs may also contain personal information. If you use login-based ticket delivery, submitted credentials are sensitive delivery data stored in encrypted form; never submit unrelated account credentials.
Support messages and maps
When you use our contact form, we store your email address and message in a private administrator inbox and send a notification to our support operator using Resend. The email address is used to answer your enquiry. Do not include passwords, payment-card details or usable ticket codes. Event pages also load Google Maps, which receives technical information from your browser to display the location.
Why we use it
- To provide accounts, listings, purchases, delivery and requested support: performance of our contract or steps you ask us to take before a contract.
- To secure accounts, detect duplicate tickets, investigate misuse and maintain service reliability: legitimate interests, subject to a balancing assessment.
- To meet applicable accounting, regulatory and lawful disclosure requirements: legal obligation.
- For optional marketing or non-essential tracking where consent is required: your consent, which you may withdraw.
Required fields are needed to provide the relevant service. Optional profile information can be left blank. A notification preference alone does not mean that a marketing programme or tracking service is active.
Security and email records
We use short-lived hashed request counters to limit abusive requests. Scheduled cleanup removes expired counters. Booking-email records include recipient details, message content, retry state and provider delivery information. Verified bounce or complaint reports can suppress future booking emails. We record changes to optional marketing preferences, including the time, source and notice version. Marketing remains optional and is separate from essential account and booking messages.
What other people can see
Event and listing information is displayed to visitors using the marketplace. For directly issued tickets, the event organiser can see the purchaser’s email, order reference, ticket type, quantity, amount paid including the booking fee, booking/refund status and check-in status to fulfil the booking and manage entry. Organisers are responsible for the uses of booking information they determine. They must protect this information and use it for booking purposes, not unsolicited marketing. We do not collect individual attendee names for direct bookings. Ticket files and delivery details are intended for authorised parties to the transaction and staff who need access to support it. Ticket documents may contain the original purchaser’s name; check what you upload. Do not include unrelated personal information in public event descriptions.
Service providers and disclosures
The application uses Vercel for hosting, Cloudflare R2 for file storage, Resend for transactional email, Stripe for payment and payout services, and Google when you choose their sign-in services. A configured PostgreSQL database stores account and transaction records. The database provider and processing locations must be confirmed. Providers process information according to their roles and applicable agreements; some also act as independent controllers for their own services.
Relevant information may be disclosed to professional advisers or competent authorities where necessary and lawful. We do not describe publicly displayed catalogue information as private.
International processing and retention
Service providers may process information outside the UK. The actual hosting regions, recipients and applicable transfer safeguards must be recorded and confirmed before this notice is finalised; no particular transfer safeguard is claimed by this draft.
Account data is needed while your account is active. Transaction and dispute records may need to be retained after closure for legal obligations and claims. Closing an account currently disables access; it does not automatically erase every database record or uploaded file. Category-specific retention periods and deletion processes remain to be finalised. Contact support about erasure rather than assuming account closure deletes everything.
Your choices and rights
Depending on the circumstances, you may request access, correction, erasure, restriction or portability of your personal data, or object to processing. You may withdraw consent without affecting processing that was lawful before withdrawal. We may need proportionate identity verification before responding. Some information may be retained where a lawful exception applies.
Automated file and duplicate checks can prevent a ticket being uploaded. Contact support if you believe a check is wrong. We do not claim that passing those checks proves a ticket is genuine.
You may complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint. You can contact us first, but you do not have to do so to exercise that right.
Children and changes
Accounts are for people aged 16 or older. Event organisers must be 18 or older. Individual events may require attendees to be 18 or older or meet other age restrictions. If you believe an underage person has an account, contact us so we can investigate. We will update this notice when our data practices change.
Nightfair is operated by Janhavi Oturkar, an individual trading as Nightfair, based in London, UK. Nightfair is not a registered company.
Contact: support@savethenight.uk · +44 7393 080444. You can also visit Help & Support.
