Legal

Privacy Policy

Last updated 24 September 2026

This policy explains what personal information we collect, why we collect it, who we share it with, how long we keep it, and your rights. It covers swifteepay.com and the emails we send.

1. Who we are

SwifteePay runs this website.

Email: info@swifteepay.com

We are responsible for your personal information under UK data protection law (the UK GDPR and the Data Protection Act 2018). This makes us the “controller” of it.

2. What we collect

When you buy tickets: your name, email address and phone number, the tickets you bought, the price, any discount code, and when you paid.

Payment: Stripe handles your payment. We receive a payment reference and the details Stripe returns about the payment, such as whether it succeeded. We never see or store your full card number.

At the event: when your ticket was scanned, which staff account scanned it, and a note if entry was refused.

Your account: your email address, when you last signed in, and your password if you set one. Passwords are stored in scrambled (hashed) form, so nobody can read them, including us.

Emails about new events: if you tick the box at checkout, we record that you agreed, the exact words you agreed to, when, and which order it came from.

Messages to us: if you use our contact form, your name, email address, subject and message.

“Tell me when you’re back” requests: if the site is offline and you ask us to email you when it returns, your email address. We delete it once that email is sent.

How the site is used: we count page views and visitors per day. To count visitors without cookies, we make a code from your IP address and browser type that changes every day. We only keep the daily totals. We do not store your IP address and cannot identify you from these numbers.

Security: when you sign in, request a sign-in link, or check out, we keep a scrambled code made from your IP address for a short time so we can stop repeated attempts.

If you work for us or an organiser: your name, email address, role, the event you work on, and the check-ins you make.

3. Why we use it

The law requires a reason for each use of your information. Here is what we do and the reason for each.

  • To sell you tickets, send them, and let you into the event. Reason: we need to, to carry out our contract with you.
  • To email you about your bookings, such as your tickets, sign-in links, and updates about events you have tickets for. Reason: our contract with you, and our legitimate interest in making sure you can use your tickets.
  • To run your account. Reason: our contract with you.
  • To keep sales records for tax and accounting. Reason: the law requires it.
  • To handle refunds, disputes and chargebacks. Reason: our contract with you, and our legitimate interest in resolving them.
  • To keep the site secure and stop fraud and abuse. Reason: our legitimate interest in protecting you, us and the site.
  • To count how many people use the site. Reason: our legitimate interest in running and improving it.
  • To reply to your messages. Reason: our legitimate interest in answering you.
  • To email you about new events. Reason: your consent. We only do this if you tick the box at checkout, and you can withdraw at any time.

We do not sell your personal information. We do not use it to make automated decisions about you.

4. Who we share it with

The event organiser and door staff. Door staff see your name and ticket details so they can check you in. Each door staff account can only see the one event it works on. The organiser of an event you booked may also receive your name, email address and phone number to run the event and contact you about it.

Companies that provide services to us. They can only use your information to provide their service to us:

  • Stripe: takes payments and handles refunds
  • Brevo: sends our emails
  • Vercel: hosts the website
  • Upstash: runs our database
  • EmailJS: delivers contact form messages to us

When the law requires it. For example to the police, the courts or HMRC, or to protect someone’s safety.

If the business changes hands. If SwifteePay is sold or restructured, your information may pass to the new owner, who must keep using it in line with this policy.

5. Storing information outside the UK

Some of these companies store or process information outside the UK, including in the European Union and the United States. When they do, the transfer is protected by safeguards recognised under UK law, such as the UK and US data bridge or approved contract clauses.

6. How long we keep it

  • Sales records (orders and payment references): at least 6 years, because UK tax law requires it.
  • Tickets and check-in records: as long as needed to run the event and handle any refunds or disputes afterwards.
  • Your account: until you ask us to close it. Sales records are then kept as above.
  • Your agreement to emails about new events: until you unsubscribe or ask us to delete it. If you unsubscribe, we keep a note of it so we do not email you again.
  • Contact form messages: as long as needed to deal with your message.
  • Sign-in links and codes: 15 minutes, and each works only once.
  • Security codes made from your IP address: up to one hour.
  • Daily visitor totals: about 13 months.

7. How we protect it

  • The whole site uses an encrypted connection (HTTPS).
  • Passwords are hashed, so they cannot be read.
  • Sign-in links and codes expire after 15 minutes and work only once.
  • Only staff who need your information can see it. Door staff can only see the event they work on.
  • Payments are handled by Stripe, which is certified to the PCI DSS standard for card security.

8. Your rights

You have the right to:

  • get a copy of the personal information we hold about you
  • have it corrected if it is wrong
  • have it deleted
  • limit how we use it, or object to how we use it
  • receive it in a format you can take elsewhere
  • withdraw your consent at any time, where we rely on consent

To use any of these rights, email info@swifteepay.com. It is free. We will reply within one month. We may ask you to confirm who you are first.

Some information cannot be deleted straight away. For example, we must keep sales records for tax purposes.

9. Cookies

We only use cookies the site needs to work. We do not use advertising or tracking cookies, so we do not ask for your consent to cookies.

  • _swiftee_account

    Keeps you signed in to your account.

    Lasts: 30 days

  • _swiftee_order_[order ID]

    Remembers that you confirmed your email for an order, so you can open those tickets again.

    Lasts: 30 days

  • _swiftee_admin

    Keeps our staff and organisers' door staff signed in. Only set for staff.

    Lasts: Up to 8 hours

When you pay, you go to Stripe’s checkout page. Stripe sets its own cookies there for security and to prevent fraud. See Stripe’s cookie policy.

You can delete or block cookies in your browser settings. If you block the cookies above, you will not be able to stay signed in.

10. Emails about new events

We only send these if you tick “Email me about new SwifteePay events” at checkout. The box is never ticked for you.

To stop them, click unsubscribe in any of those emails, or email info@swifteepay.com. You will still get emails about tickets you have bought.

11. Children

The site is not for children under 13. Events often have their own age limits, which are shown on the event page and checked at the door.

12. Changes to this policy

We may update this policy. The date at the top shows when it last changed. If we make an important change, we will tell you by email or on the site.

13. Complaints

If you are unhappy with how we use your information, email info@swifteepay.com and we will try to put it right.

You can also complain to the Information Commissioner’s Office (ICO), the UK data protection regulator, at ico.org.uk or on 0303 123 1113.

Questions about this page? Email info@swifteepay.com.