Privacy Policy
This policy describes what data the platform processes, why, and your rights. For ticket buyers’ data, each church is the data controller; the platform acts as processor (see the DPA).
1. What we process
Ticket buyers: name, e-mail, phone (optional), guest names, and the purchase record. Card data is handled exclusively by the payment processor (SumUp or Stripe) — it never touches our servers.
Church teams: name, e-mail and role (admin, entrance, kitchen).
Customer churches: contact and subscription billing details (via Stripe).
2. Why
To issue tickets and QR codes, send confirmation e-mails, run check-in and product redemption, produce reports for the church itself, and invoice the platform subscription.
We do not sell data. We do not advertise using buyers’ data.
3. Sub-processors
Supabase (database and authentication), Vercel (hosting), Resend (e-mail delivery), Stripe (platform billing), SumUp (church payments). Each processes data only as needed for the service.
4. Retention
Purchase records are kept while the church remains a customer, as they are the church’s financial records. On termination they are exported on request and deleted after confirmation, unless a legal retention duty applies.
5. Your rights
Access, rectification, erasure and portability under UK GDPR. Buyers should direct requests to the church they bought from (the controller); we assist the church in fulfilling them.
Data breaches are notified to the affected church without undue delay and, where required, to the ICO within the statutory 72 hours.