Privacy Policy
Last updated: 27 May 2025
1. Who We Are
DHB Events (“we”, “us”, “our”) operates this event ticketing platform. We are committed to protecting your personal data and respecting your privacy. This policy explains how we collect, use, store, and protect your information when you use our website and services.
If you have any questions about this policy, please contact us at neil@dhbevents.co.uk.
2. Information We Collect
We collect the following categories of personal data:
2.1 Information you provide directly
- Account information: email address and name when you sign in via magic link
- Booking information: first name, last name, postal address, and telephone number when you purchase tickets
- Payment information: processed securely by Stripe — we do not store your card details on our servers
2.2 Information collected automatically
- Usage data: pages visited, browser type, device information, and IP address
- Cookies: a session cookie to keep you signed in (essential functionality only)
3. How We Use Your Information
We use your personal data for the following purposes:
- To process and fulfil your ticket orders
- To send you booking confirmations, QR code tickets, and refund notifications by email
- To manage event check-in and maintain guest lists
- To communicate with you about your bookings or account
- To comply with our legal obligations
- To prevent fraud and ensure the security of our platform
We do not use your personal data for marketing purposes, nor do we sell, rent, or share your data with third parties for their marketing purposes.
4. Legal Basis for Processing
We process your personal data on the following legal grounds under UK GDPR:
- Contract: processing necessary to fulfil your ticket purchase and provide our services
- Legitimate interests: maintaining platform security, fraud prevention, and improving our services
- Legal obligation: compliance with applicable laws, tax requirements, and regulatory obligations
5. Data Sharing
We share your personal data only with the following third parties, solely for the purposes described:
- Stripe: to securely process payments. Stripe's privacy policy is available at stripe.com/gb/privacy
- Vercel: our hosting provider, which processes requests on our behalf
- Neon: our database hosting provider, which stores data securely in the cloud
- Email provider: to send transactional emails (booking confirmations, magic links, refund notices)
We do not transfer your personal data outside the UK/EEA unless adequate safeguards are in place.
6. Data Retention
We retain your personal data for as long as necessary to fulfil the purposes for which it was collected:
- Account data: retained while your account is active, or until you request deletion
- Order and booking data: retained for 7 years after the event date for accounting and legal compliance
- Magic link tokens: automatically expire after 15 minutes and are marked as used
- Session cookies: expire after 7 days
7. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- Encrypted connections (HTTPS/TLS) for all data in transit
- Secure, httpOnly session cookies that cannot be accessed by client-side scripts
- Payment processing handled entirely by PCI-DSS compliant Stripe — we never see or store your card details
- Database access restricted to authorised application processes only
- Regular security reviews and updates
8. Your Rights
Under UK GDPR, you have the following rights regarding your personal data:
- Right of access: request a copy of the personal data we hold about you
- Right to rectification: request correction of inaccurate or incomplete data
- Right to erasure: request deletion of your personal data (subject to legal retention requirements)
- Right to restriction: request that we limit how we process your data
- Right to data portability: request your data in a structured, machine-readable format
- Right to object: object to processing based on legitimate interests
To exercise any of these rights, please email us at neil@dhbevents.co.uk. We will respond within 30 days.
9. Cookies
We use only essential cookies required for the functioning of the platform:
- Session cookie: an httpOnly cookie containing your authentication token, used to keep you signed in. Expires after 7 days. No tracking or analytics cookies are used.
As we use only strictly necessary cookies, no cookie consent banner is required under UK/EU cookie regulations.
10. Children's Privacy
Our services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us and we will promptly delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated “Last updated” date. We encourage you to review this page periodically.
12. Contact & Complaints
If you have any questions, concerns, or complaints about how we handle your personal data, please contact us at:
DHB Events
Email: neil@dhbevents.co.uk
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe your data protection rights have been violated: ico.org.uk/make-a-complaint