Data protection
Who is responsible for your audience data, and how to handle a request about it.
Your ticket buyers, subscribers, volunteers and suppliers are all real people with rights over the information you hold about them. This page covers who is responsible for what, what to do when someone asks, and the two places where the answer depends on you rather than on us.
Who is responsible
You are. For your audience data, you are the data controller: you decide what to collect and what to do with it. That covers your orders and tickets, your contacts and subscribers, your marketing, your WhatsApp conversations, and your volunteer, supplier and guest list records.
We are the processor. We hold and handle that data on your instructions, and we do not use it for our own purposes. What we commit to is set out in our Data Processing Addendum, which applies automatically and which we will sign a copy of if your venue or funder asks for one.
A few things are ours rather than yours: Grofomo accounts and sign-in, the Grofomo app, the public artist directory, and any marketing Grofomo sends about Grofomo where someone agreed to that separately. Those are covered by our Privacy Policy.
If someone asks to see or delete their data
Anyone can ask you for a copy of what you hold, or ask you to delete it, and you have one month to respond. Email privacy@grofomo.com with the person's email address or phone number and what they asked for, and we will action it against your account. A phone number is enough on its own for someone who only ever gave you a number.
Deletion removes their name, email, phone and address, scrubs the answers they gave you, and withdraws their marketing permissions across every channel. Two things stay: the anonymous financial record of the sale, which you need for your accounts, and the record that they once gave and then withdrew consent, which is the evidence that any message you sent them was lawful. Neither can be used to contact them again.
You can also choose whether the deletion covers just your relationship with them or their whole Grofomo record. Tell us which.
How long we keep things
Most of it clears itself down. You control the two windows that matter, in your organisation settings:
- Ticket buyer records default to seven years, matching how long you need to keep accounting records. Shorten it if you want to.
- WhatsApp inbox history defaults to 24 months, after which message contents are removed.
Pre-sale registrations clear after two years per event, abandoned checkouts after 180 days, and click data after 400 days. You do not have to do anything for any of that.
The bit that is genuinely on you
Custom questions. You can ask your buyers anything you like at checkout or on a form. That freedom means we cannot know in advance what you are collecting, so if you ask about health conditions, access requirements, dietary needs or anything about children, you need a lawful reason to collect it and you need to tell people why you are asking. Collect it only if you actually need it, and mark the question as containing personal details so deletion reaches it.
Volunteers. The volunteer records hold dates of birth, emergency contacts, dietary requirements and qualifications including DBS checks. That is some of the most sensitive information on the platform, it often concerns under-18s, and it includes details of people who never dealt with you directly. Tell your volunteers what you are recording, tell emergency contacts they have been listed, and keep it only while you need it.
Imported lists. When you import contacts you either bring their consent in a column of the file or confirm, channel by channel, that they agreed to hear from you by email, SMS or WhatsApp. We keep that confirmation with the import. Someone on the list with only a phone number can never be emailed, whatever the file says. Buying or scraping a list and uploading it is the fastest way to a complaint, and it will be your complaint, not ours.
Who else touches your data
Everything runs on a handful of providers: hosting, database, payments, email, push notifications. We publish the full list, what each one can access, and where it processes, at grofomo.com subprocessors. We tell you before we add one.
Your database is in the United Kingdom.
That page also lists services you switch on, such as your own advertising pixel, your WhatsApp Business account, your social accounts and any webhook you point at us. Those go to companies you have the relationship with, so they are your call and your responsibility.
Of those, the Meta Pixel is the one that touches your ticket buyers directly, which is why your ticket page asks each visitor's permission before it loads and remembers what they chose. An event with no pixel set asks nothing, because there is nothing to consent to.