Privacy Policy for Allowed In


ALLOWED IN GROUP

Privacy Policy

How Allowed In Group uses personal information across its ticketing platform

Status: Draft for legal and operational review
Last updated: 4 August 2026
Contact: info@allowedin.com

1. Introduction

1.1 This Privacy Policy explains how Allowed In Group collects and uses personal information when you browse our Platform, create an account, purchase or receive a Ticket, contact us, request accessibility support, subscribe to marketing or otherwise interact with us.

1.2 This policy does not govern how an independent Event Organiser, venue or other third party uses personal information for its own purposes. Please read any privacy notice that they provide.

2. Who we are and how to contact us

2.1 The controller responsible for the Platform and our ticketing operations is [INSERT FULL REGISTERED COMPANY NAME], company number [INSERT COMPANY NUMBER], trading as Allowed In Group. Our registered office is Studio I1c Witan Studios, Witan Gate, Milton Keynes, Buckinghamshire, England, MK9 1EF.

2.2 For privacy questions or to exercise a data-protection right, email info@allowedin.com or write to the registered office and mark the correspondence 'Data Protection'.

2.3 For information we share with an Event Organiser so it can stage and administer an Event, the Event Organiser will normally be a separate controller. Its identity should be shown on the Event page or booking confirmation.

3. Personal information we collect

3.1 Depending on how you use the Platform, we may collect the following categories of information:

  • Identity information, such as your name, title, date of birth or age-verification information where needed for an Event.
  • Contact information, such as your email address, telephone number, billing address and delivery address.
  • Account and profile information, such as login credentials, preferences, saved details, purchase history and marketing choices.
  • Order and transaction information, such as the Event, Ticket type, quantity, price, Booking Fee, payment status, refunds, transfers and customer-service history.
  • Payment-related information. Our payment service provider processes payment-card details. We may receive a payment token, card type, last four digits, billing checks and transaction result. We do not retain the card security code.
  • Technical and usage information, such as IP address, device identifiers, browser, operating system, approximate location, login records, page views, clicks, referring pages and Platform interactions.
  • Communications, reviews, survey responses, competition entries and information you provide when contacting us or an Event Organiser through the Platform.
  • Accessibility information, which may include health or disability information and supporting evidence where necessary to administer an accessibility request.
  • Fraud, security and compliance information, such as risk indicators, chargeback information, ticket-limit checks and records of suspected misuse.

3.2 Please do not send us more personal information than we request, particularly medical documents, identity documents or complete payment-card details.

4. How we obtain information

4.1 We collect information directly from you when you browse, create an account, buy a Ticket, contact us, make a request or set your preferences. We also collect technical information automatically through server logs, cookies and similar technologies.

4.2 We may receive information from the person who bought a Ticket for you, the Event Organiser or venue, payment and fraud-prevention providers, customer-support and delivery providers, analytics services, social platforms where you choose to connect them, and public authorities where permitted by law.

5. Why we use personal information and our lawful bases

The table summarises our principal processing activities. More than one lawful basis may apply to the same information depending on the context.

Purpose

Information typically used

Lawful basis

Create and manage accounts

Identity, contact, profile and technical information

Contract; legitimate interests in operating accounts securely

Process Orders, payments, Tickets, transfers and refunds

Identity, contact, order, transaction, payment-related and technical information

Contract; legal obligations; legitimate interests in accurate fulfilment

Share booking details with the Event Organiser and venue

Identity, contact, Ticket, order and accessibility information where applicable

Contract; legal obligations; legitimate interests in safe and effective Event administration

Provide customer service and manage complaints

Identity, contact, order and communications

Contract; legal obligations; legitimate interests in resolving issues

Prevent fraud, misuse and security incidents

Identity, payment-related, technical, usage, fraud and compliance information

Legitimate interests in security and fraud prevention; legal obligations

Administer accessibility requests

Identity, contact, Ticket and relevant accessibility information

Contract and legal obligations; explicit consent or another applicable condition for health information

Send service and Event communications

Identity, contact, Ticket and order information

Contract; legitimate interests in keeping customers informed

Send marketing and measure campaigns

Identity, contact, preferences, technical and usage information

Consent where required; otherwise legitimate interests where permitted by law

Improve the Platform and understand usage

Technical, usage, account and aggregated information

Consent for non-essential cookies; legitimate interests for security and service improvement where permitted

Meet legal, tax, accounting and regulatory duties and handle claims

Relevant identity, contact, transaction, communications and compliance information

Legal obligations; legitimate interests in establishing, exercising or defending legal claims

6. Orders placed for other people

6.1 If you provide another Ticket holder's personal information, you must be authorised to do so and should show them this policy. We will use their information to administer the Ticket and Event and for related safety, security and legal purposes.

7. Event Organisers and venues

7.1 We share the information reasonably needed for the Event Organiser and venue to validate Tickets, communicate operational information, manage entry, provide accessibility arrangements, respond to incidents and comply with legal duties.

7.2 The Event Organiser normally decides independently how it uses information for staging the Event and is responsible for its own privacy notice and legal compliance. We do not permit an Event Organiser to receive your details for unrelated direct marketing merely because you bought a Ticket. Any marketing choice for an Event Organiser should be presented separately and name that organiser.

8. Who else receives personal information

8.1 We may disclose relevant information to:

  • payment processors, acquiring banks, card schemes and chargeback services;
  • cloud hosting, software, email, messaging, customer-support, ticket-delivery, scanning and database providers;
  • identity, age-verification, fraud-prevention, security and analytics providers;
  • accessibility-support, refund-protection and other optional-service providers you choose to use;
  • professional advisers, auditors, insurers, lenders and potential purchasers in a genuine business transaction; and
  • courts, regulators, law-enforcement bodies, tax authorities and other persons where disclosure is required or permitted by law.

8.2 Service providers acting for us may use personal information only for the agreed service and must protect it as required by law and contract. Other recipients, including Event Organisers and payment providers, may act as separate controllers for some processing.

9. Marketing

9.1 We may send marketing by email, text or similar electronic channels where you have consented or where the law otherwise permits. You can opt out at any time using the unsubscribe method in a message, changing your account preferences or contacting us.

9.2 Opting out of marketing does not stop service messages about an Order, Ticket, account, security issue or Event. We may keep a minimal suppression record so that we honour your opt-out.

9.3 We will obtain the choice required by law before sharing information with another organisation for that organisation's own direct marketing.

10. Cookies and similar technologies

10.1 The Platform uses strictly necessary technologies for functions such as checkout, account security, fraud prevention and remembering privacy choices. Where we use non-essential analytics, personalisation or advertising cookies, we will ask for consent before setting them.

10.2 You can change your choices through the cookie settings made available on the Platform. Blocking some technologies may affect Platform functions. Details of each cookie or provider, its purpose and duration must be kept in our separate Cookie Notice at [INSERT COOKIE NOTICE URL].

11. Automated checks and profiling

11.1 We may use automated signals to identify suspected fraud, duplicate purchases, ticket-limit breaches and security risks, or to measure and personalise marketing where you have consented. These signals may cause an Order to be held for review.

11.2 We do not intend to make a decision based solely on automated processing that produces legal or similarly significant effects unless the law permits it and appropriate safeguards apply. Contact us if you want us to review a materially adverse automated decision.

12. International transfers

12.1 Some providers may store or access information outside the United Kingdom. Where a restricted transfer occurs, we use a safeguard recognised by UK data-protection law, such as UK adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum to approved standard contractual clauses, together with supplementary measures where appropriate.

12.2 Contact us if you want further information about the safeguard used for a particular transfer.

13. Data retention

13.1 We keep personal information only for as long as needed for the purpose collected, including to meet tax, accounting, consumer, fraud-prevention and legal-claims requirements. We take account of the amount, sensitivity and risk of the information and whether the purpose can be achieved in another way.

13.2 Our intended core retention periods are:

  • Order, payment, refund and accounting records: generally six years after the end of the relevant financial year or longer where a dispute or legal duty requires.
  • Account information: while the account remains active and generally for up to six years after the last transaction, unless earlier deletion is appropriate.
  • Customer-support and complaint records: generally two years after closure, or up to six years where needed for a claim or transaction record.
  • Accessibility evidence: only for the shortest period needed to decide and administer the request, normally deleted within 90 days after the Event unless a dispute or law requires longer retention.
  • Marketing records: until you opt out or the information is no longer useful, with a minimal suppression record retained to respect the opt-out.
  • Cookie and analytics information: for the period stated in the current Cookie Notice.

13.3 We may anonymise information so it can no longer identify you and use the anonymous information for statistical or business purposes without a fixed retention period.

14. Security

14.1 We use proportionate technical and organisational measures designed to prevent unauthorised access, alteration, disclosure, loss or destruction. Access is restricted to people and providers who need the information and are subject to confidentiality duties.

14.2 No internet service is completely secure. Keep your credentials and Tickets confidential and contact us promptly if you suspect unauthorised account or Ticket use.

15. Your data-protection rights

15.1 Depending on the circumstances and lawful basis, you may have rights to:

  • ask for access to your personal information and a copy of it;
  • ask us to correct inaccurate or incomplete information;
  • ask us to erase information in certain circumstances;
  • ask us to restrict processing in certain circumstances;
  • object to processing based on legitimate interests and object at any time to direct marketing;
  • receive certain information in a portable format or have it sent to another controller;
  • withdraw consent at any time, without affecting earlier lawful processing; and
  • ask for human intervention where a significant decision is made solely by automated means.

15.2 To exercise a right, contact info@allowedin.com. We may ask for information needed to verify your identity and locate the relevant records. Rights are not absolute, and we will explain if an exemption applies. We normally respond within one month, subject to lawful extensions for complex requests.

16. Children

16.1 The Platform is not intended for a child under 16 to create an account or make a purchase without the involvement of a parent or guardian. Events may have different age rules, which are shown in the Event information. If you believe a child has provided information contrary to this section, contact us.

17. Third-party links

17.1 The Platform may link to an Event Organiser, venue, payment provider, social platform or other website. We do not control their privacy practices. Read their privacy information before providing personal information.

18. Changes to this policy

18.1 We may update this policy to reflect changes in our services, providers, law or regulatory guidance. We will update the date above and provide an appropriate notice of a significant change.

19. Complaints

19.1 Please contact us first at info@allowedin.com so we can try to resolve your concern.

19.2 You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority. Current contact information is available at ico.org.uk/make-a-complaint. You may also contact another competent supervisory authority where applicable.

20. Contact summary

20.1 Controller: Allowed InĀ , company number xxxxxxx , trading as Allowed In Group. Registered office: Studio I1c Witan Studios, Witan Gate, Milton Keynes, Buckinghamshire, England, MK9 1EF. Privacy email: info@allowedin.com. Website: https://allowedin.com.