Privacy statement
Which data PartyPPL processes about you, why, who else sees it, how long we keep it and what you can do about it yourself. Written to the GDPR, and as honest as the code allows.
Last updated: 1 October 2026Draft. This statement describes what the platform does today, but it has not been reviewed by a lawyer. Where practice is not yet what it should be, it says so.
1Who is the controller
PartyPPL, a product of NEXG3N, determines the purposes and means of the processing on this page and is therefore the controller under article 4 GDPR.
- Controller
- PartyPPL, a product of NEXG3N
- Chamber of Commerce number
- 97359866
- VAT identification number
- NL005264805B67
- Address and further company details
- Colophon
- Privacy contact
- [email protected].
- Security reports
- Security
We have not appointed a Data Protection Officer (DPO). Any question can go to the address above.
For part of the data the organiser of an event is responsible, for example for what they do with the ticket export. See the article on recipients and the organiser terms.
2What data we process
- Account
- E-mail address, name, username, city, genres, profile photo and banner, bio, links, colour, language and theme, whether your profile is private, your chosen badge, whether you show your reviews, your group chat choice for "I'm going", whether you want tips based on what you do, your notification preferences, quiet hours and whether you want the e-mail digest.
- If you sign in with Apple
- Also the fixed Apple id Apple gives PartyPPL, and the e-mail address Apple passes on (which can be an Apple relay address).
- Age
- Your date of birth, entered once, and the fact that the 18+ check passed. We do not ask for an ID document.
- Logging in
- The six-digit code (valid 10 minutes, 5 attempts), passkeys (the public key, a counter, the kind of device, the name you give it and when you used it), an encrypted TOTP secret and hashed recovery codes if you turn on two-factor authentication.
- Sessions
- Per logged-in device a hash of the session token, when it started, was last used and expires, your IP address, your browser (user agent) and whether you did two-factor authentication. You see that list yourself in your settings.
- Security log
- Logins, failed attempts, codes sent, two-factor authentication, passkeys, logouts and revoked sessions, with your e-mail address, IP address, user agent and time. Never the code itself.
- Social
- "I'm going" and "Interested", your party history ("Was there"), friends and requests, who you follow, blocks, muted and left group chats, invitations, likes, votes, badges and the photos a friend tagged you in. Whether your ticket for a night was scanned OK at the door: that proves you were there, shows as "Was there" under a review or report you write about that night, and makes your own "Your night" page and the notification the day after possible. Who gives respect to a review or report. And the sets you star in a timetable ("My timetable"), with whether you want a nudge before them.
- Finding friends through your contacts
- Only if you choose to at the start: the e-mail addresses from your contacts (at most 200) go to our server to see who is already on PartyPPL. We do not keep that list.
- What you post
- Chat messages, forum topics and replies, reviews of venues and nights, reports, questions and answers, photos, token prices, corrections to pages, site maps, events you submit and your checklist. When you upload a photo we strip its metadata, such as the place it was taken and the device. Profile photo and banner are also re-saved in your browser before they reach us.
- Tickets and orders
- Order, ticket type, amounts, service fee, discount code, ticket code, the name on the ticket, the moment of scanning, resale, transfers and refunds. If you pass a ticket on to an e-mail address that has no account yet, we create an account for that address.
- Tickets from another shop
- If an organiser sold tickets elsewhere and loaded them into PartyPPL, they give us your e-mail address, name, ticket code, type and price. We erase the e-mail address as soon as we have mailed you or the ticket is on your account; after that we keep only an encrypted fingerprint of it to link the ticket to you.
- Pre-Buy
- If you ask us to buy a ticket for you, we keep the names you give per ticket, the kind of ticket, the number, your maximum price, the amounts, the status of the purchase and the code or PDF of the ticket we bought for you. The PDF is kept private: only you and our administrators can open it.
- Payment
- Stripe handles that. We keep only the Stripe references and the amounts, never your card number or IBAN.
- Reports you file
- What you report, the reason, your username and what we did with it.
- Notifications you receive
- In-app notifications, and the addresses your device receives push notifications on: a web push subscription from your browser or a push token from the iPhone app, with the kind of device and the app version.
- The Apple apps
- For widgets a token of which we keep only the hash, for a Live Activity a push token per night, for Apple Wallet which device holds which pass with the address Wallet receives updates on, and for a paired Apple TV the name of the TV, a hash of its key, the IP address at pairing and when it last asked for anything. See the article on the apps.
- Linking Spotify
- Only if you do it: an access key from Spotify, at most 15 minutes, to read which artists you follow there. What you tick becomes an ordinary follow here. We do not keep your Spotify account itself.
- Location
- Only in your browser, when you tap "near me". Your position does not go to our server.
- Organisers
- If you are a team member of an organisation, also your role, the API tokens you create, the scans you make at the door and, if you have the organisation verified, the Chamber of Commerce extract you upload. That extract sits in shielded storage only your team and our administrators can open.
- Statistics
- Counts per day: page views per kind of page, an estimate of unique visitors, how often and how long pages of nights, artists and venues were on screen, and how long visits lasted on which kind of device. No cookie and no id. We count searches per day; a search line that found nothing is kept as text, without an account, IP address or cookie, and lines that look like a name, e-mail address, phone number or address are left out. Clicks on the button to a night's official ticket shop are counted per night per day, without an account, cookie or IP address. See cookies.
- Server log
- Our server writes technical lines for requests. The web server records your IP address, the page, your browser and the time for each request. Our own lines contain your user id and IP address at login, and who did what for administrator actions.
We do not ask for special categories of personal data. What you put in a chat, forum post or photo yourself, we do process. Do not put anything there you would not want out.
3Purposes and legal bases
- Your account and the social features. Basis: contract (art. 6(1)(b) GDPR).
- Logging in, your profile, "I'm going", friends, group chats, forum, in-app notifications and the e-mails that go with them, such as your login code.
- Selling, delivering and handling tickets. Basis: contract.
- Ordering, paying through Stripe, your ticket and the confirmation mail, scanning at the door, resale, passing tickets on, refunds and telling you when an event is moved or cancelled.
- Pre-Buy: buying a ticket in your name. Basis: contract.
- We fill in the names per ticket in the organiser's official ticket shop, because it sells tickets in a name. We use them for nothing else. The ticket, the refund and the messages about them belong to the same contract.
- The apps and their extras. Basis: contract.
- Widgets, Live Activity, Apple Wallet, Apple TV and the Apple Watch do what you switch on. They do not work without this data.
- The 18+ check. Basis: legitimate interest ((f)).
- A platform about going out, alcohol and chats with strangers is not for minors. Our interest is that they do not become socially active or buy tickets here.
- Security, abuse and moderation. Basis: legitimate interest ((f)) and the Digital Services Act ((c)).
- Session management, the security log, rate limits, the automatic check of public text, handling reports and being able to account for our decisions. Our interest: a platform that stays up and where nobody gets scammed.
- Statistics. Basis: legitimate interest ((f)).
- Knowing how many people use the agenda and which pages work, without following individuals.
- Push notifications, the digest and marketing. Basis: consent ((a)).
- You turn push notifications on yourself and off again per kind. Notifications about offers and news are off by default. The digest mails stop in Settings or with the unsubscribe link at the bottom of such a mail.
- Finding friends through your contacts and linking Spotify. Basis: consent ((a)).
- Only when you ask for it, and we keep only the result you choose yourself.
- Filling and sharing the agenda. Basis: legitimate interest ((f)).
- Collecting public event data, having it completed by AI and publishing it, also on our social channels. It holds names of artists and organisers, never data of visitors.
- Verifying organisers. Basis: contract and legitimate interest.
- Checking that an organisation is who it says it is, with the Chamber of Commerce or VAT number and the extract.
- Accounting. Basis: legal obligation ((c)).
- Keeping orders and payments for as long as the tax retention obligation runs, seven years.
No ads, no third-party trackers, no selling of data.
You can object to processing based on legitimate interest. See the article on your rights.
4The apps for iPhone, iPad, Apple Watch, Mac and Apple TV
The apps show the same site as partyppl.nl and use the same account. A few things happen on your device itself or through Apple:
- On your device
- The widget token and your latest widget data (with the ticket code of your next night, so the QR works offline too) sit in the app's shielded storage and go when you log out. Alarms from "Wake me" are set locally by the app with AlarmKit. The Spotlight index of your upcoming nights exists only on your iPhone.
- Apple Intelligence
- Translate and Improve in the chat, and summarising, run on the language model on your iPhone itself. The text does not leave your phone for that and does not come to us.
- Siri and Visual Intelligence
- "What's on tonight" fetches the public list for tonight, without an account. Point the camera at a poster and your iPhone reads the text and sends the largest lines as a search to our public search, without an account. A search that found something is not kept; one that found nothing counts in the statistics above, without an account.
- Push notifications and Live Activity
- Run through Apple's push service (APNs). A Live Activity token belongs to one night you said "I'm going" to and disappears after two days.
- Apple Wallet
- Add a ticket and the pass shows the night, the venue, your name on the ticket and the QR code. Wallet registers with us for updates; on a scan, resale, transfer, postponement or cancellation we send a signal through Apple and Wallet fetches the new pass. Pass the ticket on and your pass becomes void.
- Apple TV
- You pair a TV with a code at /tv/koppel. The TV may then read your personal list and say "I'm going", nothing to do with tickets. Unpair in Settings or on the TV.
- Sign in with Apple
- Apple is responsible for that login step itself. We receive the Apple id and the e-mail address Apple passes on.
5AI and automatic completion of the agenda
We have Claude by Anthropic help to complete the agenda. That is only about public event data: title, date, venue, city, line-up, the organiser's name and website and the source page. With that, Claude searches the web for a poster, a site map, the ticket types, the official shop, offers elsewhere with an indicative price, and for festivals the token price. Claude also writes better descriptions from the same facts and helps pick genres.
- Nothing about you goes to Claude: no account, no chat, no tickets, no visitor data.
- A site map from Claude only goes live after a person has approved it.
- Prices elsewhere and token prices are shown as an indication, with the source and the day they were seen. They are not prices we vouch for.
- Every question to Claude and every answer is kept in a log for six months, so we can trace where something came from. That log holds no visitor data.
On your iPhone, Apple Intelligence runs on the device itself; see the article on the apps.
6Profiling and automated decision-making
There is no automated decision-making with legal or similarly significant effect within the meaning of article 22 GDPR. Technology does decide some things by itself. This is it:
- A check of public text. Chat messages, forum posts, reviews and profile texts get a score on signals of ticket scams, payment requests, contact details, drug dealing, hate, threats, spam and shouting. How new your account is and whether you just posted the same message elsewhere count too. The only outcomes are let through or hold: held text waits until a person looks at it, and you see that it is waiting. Nothing is removed automatically and nobody is suspended automatically.
- The import filters events on date, duplicates and whether it is nightlife. That is about events, not people.
- Rate limits per account or IP address on logging in, uploading, messages, reports, submissions and discount codes.
- Resale automatically gets the price of the ticket type; you cannot set it yourself.
- For you on the home page picks and orders tips. If you are logged in and "Tips based on what I do" is on (the default), it looks at exactly this: the artists, venues and organisers you follow; the nights that are over on which you had "I'm going", and your party history, counted per venue and organiser; your city and your genres; and the nights your friends have "I'm going" on, but only friends with a public profile, and never anyone you blocked or who blocked you. Every tip says in one line why it is there, for example "You follow Amelie Lens", "You were at Shelter 3 times" or "2 friends are going". Nights marked as sensitive count for nothing and are therefore never tipped. The tips are worked out again on every visit and not stored, and nobody else sees them. Featured events, which an organiser paid for, come first and are marked as such.
- Objecting to For you (article 21 GDPR) is one switch: turn off "Tips based on what I do" in your settings under Privacy. For you then only orders by your city and your genres, as for someone who is not logged in, and no longer looks at what you follow, where you went or where your friends go.
- People like you also went on the pages of artists, venues and organisers comes from a count that runs every night: which artists, venues and organisers are visited or followed by the same people. A pair only counts with at least 20 people in common, never from one night on its own, and without nights marked as sensitive. The result holds no people and no numbers: only which pages belong together.
- How busy is it on the page of a night scanned in with PartyPPL says quiet, normal or busy. It comes from the number of scans at the door in a half hour that ended a quarter of an hour ago, next to the number of tickets or "I'm going" for that night, and only appears once 50 people are in. It never shows a number and none of it is about one person.
Moderation decisions are made by people. If an automatic measure hits you unfairly, mail [email protected].
7How long we keep it
Everything we keep has a period. A task that runs every day deletes whatever is past its period. If you ask us to erase something sooner, we do that for whatever is not needed for our records or an open case.
- Account and profile
- As long as your account exists. What happens on deletion is further down.
- Date of birth
- As long as your account exists. Erased on deletion.
- Login code
- 10 minutes.
- Sessions
- At most 30 days, and expired after 14 days without use. Logging out or revoking erases the session at once; expired sessions are deleted every day.
- Passkeys, TOTP secret and recovery codes
- Until you remove them yourself or delete your account.
- Security log
- 12 months.
- A night's group chat
- Twelve months after the night, when we delete the whole chat. If you delete your account before then, your messages stay until then in the name of "Verwijderd".
- Forum and reviews
- As long as the topic or the page exists. If you delete your account, they stay in the name of "Verwijderd".
- Photos
- Until you remove them or we remove them after a report; they are then no longer shown. If you delete your account, we erase your photos and files from storage.
- Social data
- As long as your account exists.
- In-app notifications
- 12 months.
- Push addresses
- Until you turn notifications off, the push service rejects the address, or you delete your account.
- Live Activity
- Two days after it starts.
- Widget token
- 30 days, and never longer than the session it came from.
- Apple Wallet
- Until you remove the pass from Wallet or delete your account.
- Apple TV
- Until you unpair or delete your account.
- Spotify link
- The key at most 15 minutes.
- Invitations
- Your invite link as long as your account exists. The counts of how often it was opened and led to a signup: 400 days.
- Orders, tickets, payouts and Pre-Buy
- Seven years, because of the tax retention obligation. Deleted after that.
- Tickets from another shop
- The e-mail address until you have been mailed or the ticket is linked. The rest 13 months after the night.
- Door scans
- 12 months after the night.
- My timetable
- The starred sets and your choice for a nudge: 30 days after the night.
- Reports and moderation decisions
- 24 months after the decision.
- Questions to support
- Your question, our answers and the attachments: 24 months after the question was closed. A solved question without a reply closes after seven days. If you delete your account, the messages and attachments go at once.
- An organisation's Chamber of Commerce extract
- As long as the organisation has an account; sooner on request.
- AI log
- 6 months. Holds no visitor data.
- Log of our tasks
- 90 days. Which task ran when and what it did; no visitor data.
- Organisers' API usage
- Per key, per day and per part of the API how many requests: 13 months.
- Statistics
- The daily list of shortened hashes expires after 48 hours. Counts per page of a night, artist or venue are deleted after 100 days, search lines that found nothing after 90 days, the number of searches per day and the daily figures for our team after 400 days, the other daily counts after 25 months. Every day, automatically.
- Insights for organisers
- Counts per night and per organisation, without names or ids: sales per day and the audience as a group. Computed again every night; what is no longer computed we delete 25 months after the last time.
- Server log
- By size, not by days: the web server keeps at most five files of 50 MB and erases the oldest when a new one starts, and the system log with our own lines is cleared by size too. We do not copy the lines into our database.
- Backups
- A copy of the database every six hours, on the same server. Every copy is deleted after 15 days. What we erase can therefore remain in a backup for at most that long.
8Recipients and processors
For OVHcloud, Cloudflare, Stripe, Resend and Anthropic the processor terms in their standard agreement apply. We do not have a separately signed data processing agreement. The full list, with per party the purpose, the data, the location and the safeguard, is on Subprocessors.
- OVHcloud (France, server in Germany)
- Our server: hosting, database, file storage, the realtime chat, the backups and the server log. The server is in a data centre in Germany.
- Cloudflare (US, with data centres worldwide)
- DNS, CDN and attack protection. All traffic between you and our server passes through Cloudflare: it decrypts the traffic in its data centre and sends it on encrypted again, and keeps public files such as images and scripts in its cache for a while. Cloudflare also forwards e-mail to addresses on partyppl.nl.
- Stripe (Ireland, parent company in the US)
- Payments, refunds and payouts to organisers through Stripe Connect. Stripe is itself responsible for your payment data.
- Resend (US)
- Sends our e-mail: login codes, tickets, transfers, resale, cancellation and postponement, alerts and the digests.
- The organiser's ticket shop (with Pre-Buy)
- When we buy a ticket for you, that night's official shop gets the names you gave per ticket, because the shop puts them on the ticket. We are the buyer, so the shop gets our e-mail address and our payment, not yours. The shop itself is responsible for what it does with those names.
- Anthropic (US)
- Claude, for completing public event data. No data about visitors; see the article on AI.
- Apple (Ireland and US)
- Push notifications to the iPhone app, Live Activities and Wallet pass updates run through Apple. Sign in with Apple and the App Store are Apple's own services.
- Your browser's push service
- Web push notifications go through your browser's service (for example Apple, Google or Mozilla). It sees the text of the notification.
- Meta (Ireland and US), Bluesky (US), a Mastodon server and a webhook
- Our own account on Facebook, Instagram, Bluesky and Mastodon, and a link to a system of our own. Only public data of new nights and a weekend overview goes there: title, date, venue, city, genres, price, poster and link. Never data of visitors.
- OpenFreeMap
- Map tiles. The map loads them directly in your browser, so OpenFreeMap sees your IP address. No cookies.
- OpenStreetMap (Nominatim)
- Looks up coordinates for venue addresses, from our server. No data of visitors.
- Spotify (Sweden)
- Artist photos and links, from our server. If you link Spotify yourself, you log in at Spotify and we briefly read who you follow there.
- Deezer, MusicBrainz, Wikipedia, Wikidata and iTunes Search
- Public data about artists, fetched from our server. No data of visitors.
- YouTube (Google), SoundCloud and Mixcloud
- Videos and sets only load when you tap play. Note: the still image of a YouTube video already comes from YouTube when the page is shown, so Google sees your IP address then.
- Ticket shops and resale markets
- Ticketmaster, TicketSwap, Tixel and other shops get nothing from us. If you click through, their privacy policy applies. A link to Ticketmaster may carry a partner code of ours.
The organiser of an event receives what they need to let you in:
- at the door: the name on the ticket, the ticket type and whether it has been scanned;
- on the door list, an export for the door for when a scanner fails: the name on the ticket, the ticket type, whether it has been scanned and the buyer's e-mail address. The roles Owner, Administrator and Door can make that list. It is the only place where an organiser sees your e-mail address;
- in the ticket export: per ticket only a number, the type, the price, the status and whether it has been scanned. No name, no e-mail address and no ticket code;
- in overviews: counts, no names.
What an organiser sees about visitors as a group (whether they came before, which province they come from, their age group, which genres they follow, how many followers an artist has in the region) is always a group of at least ten people, and at least twenty-five in a cross table such as age by province. Numbers are rounded to fives, and when a group is too small it says 'fewer than 10'. When exactly one group drops out of an overview, we hide a second one with it, so the missing group cannot be worked out. Your home town comes from your profile and only counts when it is filled in; age comes from your date of birth. The same goes for an artist who manages their profile: they see their fans (who follows them or said they are going to one of their nights) only as numbers per home town and region, in groups of at least ten. A sensitive night counts in none of these overviews.
When a night is cancelled or postponed, we mail you at your account's e-mail address. The organiser does not get your address for that.
The organiser may use that data only to let you in and to inform you about that event; we impose that in the organiser terms. For what they do with it after that, they are responsible themselves. For their guest list, door scans and tickets from their own shop they are the controller and we are their processor; see the data processing agreement.
Other users see what you share. With a public profile everyone sees the nights you have been to ("Was bij"), and only your friends see where you are going ("I'm going"). With a private profile nobody sees where you are going or have been, your friends included; your name, username, colour, city and profile photo stay visible, to friends and in group chats, but you are not in lists like "friends going" and not in search results. Nobody but you sees "Interested". When the organiser or our team marks a night as sensitive, nobody sees that you are going or went there; the number of visitors stays visible. A friend can tag you in a photo; you get a notification and take your name off again with one tap.
Beyond that we only hand over data when the law requires it, for example on a valid order from the police or the public prosecutor, and no more than asked.
9Transfers outside the EEA
Some of the parties above are based in the US or process data there. When personal data goes to a country outside the European Economic Area without an adequate level of protection, the rule is: the EU-US Data Privacy Framework where the supplier is certified, otherwise the European Commission's standard contractual clauses. Which of the two applies per supplier we are still checking; the list is on Subprocessors.
Since 30 September 2026 our database and the stored files are on our server at OVHcloud in Germany, inside the EU. Cloudflare, which sits in front, handles the traffic in the data centre it picks itself; we have not set an EU region there.
10Your rights
You have the right of access, rectification, erasure, restriction, objection and portability.
- Access and portability: in Settings you download your data as a JSON file. That download does not yet hold everything: bio, links, sessions, passkeys, the security log, reviews of nights, reports, badges, questions and answers, checklists, corrections, artist claims, token prices, tickets from other shops, app tokens, Wallet and Apple TV are missing. If you want those too, mail us and we will send them.
- Rectification you mostly do yourself in your profile and settings.
- Erasure: in Settings under Delete account. What does and does not disappear then is in the next article.
For anything else: mail [email protected]. We respond within a month. If it exceptionally takes longer, we tell you within that month, with the reason. We may ask you to show that the account is yours.
Objection to processing based on legitimate interest, such as the statistics or the security log: we stop, unless there are compelling reasons to continue, and we explain those to you.
Consent for push notifications, e-mail, your contacts or Spotify can be withdrawn at any time. What happened before stays lawful.
Exercising your rights is free.
Unhappy with how we handle your data? You can complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), Postbus 93374, 2509 AJ The Hague, autoriteitpersoonsgegevens.nl. If you live in another EU country you can also go to the authority there. Tell us first and we will try to fix it.
11What happens when you delete your account
You confirm with your e-mail address. The deletion happens at once, you can no longer log in afterwards, and this happens:
- Erased
- Your profile (name, username, bio, links, city, genres, date of birth), "I'm going" and your party history, who you follow, friends, blocks, muted and left chats, your resale watchlist, in-app notifications, invitations, votes, your tags on photos by others and your membership of organisations. Also your login means: sessions, passkeys, your TOTP secret and recovery codes, and your Apple id. And what was tied to your devices: push addresses, app and Live Activity tokens, paired Apple TVs and Wallet registrations.
- From storage
- Your profile photo, banner and the photos and files you uploaded. Only a festival map or artist photo you sent in that became part of an event page or artist profile after approval stays there, without your name.
- Anonymised
- Chat messages and forum posts stay, so a conversation stays readable, but the author becomes "Verwijderd". Venue reviews also stand in the name of "Verwijderd". Your ratings and write-ups of nights, questions and answers, token prices and corrections stay under an empty account without a name, e-mail address or photo. Badges and checklists are deleted.
- Kept, without your name
- Orders, tickets, payouts and Pre-Buy orders we must keep for seven years for the tax authorities. We detach those from your name and e-mail address where we can, and they are deleted after those seven years.
The security log, reports and moderation decisions follow their own period from the article above (12 and 24 months), because we must be able to trace misuse. Door scans and tickets from another shop belong to the organiser and follow their period.
Your account remains in the database backups for at most 15 days; after that it is gone from there too.
Still holding tickets for an upcoming event? After deleting you can no longer reach them. Pass them on or put them on resale first.
13How we secure your data
The platform follows the Dutch NCSC security baseline:
- everything over HTTPS, with HSTS and a strict Content Security Policy;
- session tokens are only stored hashed in the database; the token itself sits in an httpOnly cookie;
- passkeys and two-factor authentication for everyone, mandatory for administrators; the TOTP secret is encrypted, recovery codes hashed;
- tokens for widgets, the API and Apple TV are kept only as a hash;
- an origin check on every change and rate limits on logging in, uploading and messages;
- uploads are checked on their real file type, and photos are stripped of their metadata;
- fonts come from our own server;
- administrator actions are logged in the server log.
Found a vulnerability? See Security.
14What we do about a data breach
- We stop the breach: close access, replace keys, revoke sessions.
- We record what happened, which data it affects, for how many people and with what consequences. Including breaches we do not have to report.
- If there is a risk to your rights, we report it to the Dutch Data Protection Authority within 72 hours of discovery.
- If the risk is high, we tell you directly, in plain language, with what you can do yourself.
- We fix the cause and say what we changed.
Spot something that looks like a breach? Report it through Security or [email protected].
15Children
PartyPPL is not for people under 18. At your first login we ask for your date of birth; under 18 you cannot do anything social or buy anything. If an account turns out to belong to a minor, we delete it.
How that works and what you can do as a parent is on Age and safety.
16What we do not have yet
An honest list beats a nicer story:
- No Data Protection Officer.
- No certification and no external audit or penetration test.
- No separately signed data processing agreements. We rely on our suppliers' standard terms.
- No EU region for the traffic through Cloudflare. Our database and files are in the EU.
- No complete export: see the article on your rights.
- No fixed period for organisers' guest lists and an organisation's Chamber of Commerce extract, and no period in days for the server log.
- No legal review of this statement.
If anything changes, it will say so here.
17Changes to this statement
We update this statement as the platform changes. The date at the top is that of the last change; at the bottom is what changed. For a substantive change we let you know in the app or by e-mail.
This statement was written in Dutch. The English version is a translation; where they differ, the Dutch text prevails.
What changed
- Every retention period checked again against the code.
- New: the Apple apps (widgets, Live Activity, Apple Wallet, Apple TV, alarms, Siri, Visual Intelligence, Apple Intelligence on your iPhone).
- New: Claude by Anthropic for completing public event data, and our posts on social media.
- Added: every recipient with where it is based, the automatic check of public text, and what does and does not disappear when you delete your account.
- Corrected: we have not set an EU storage location; the YouTube preview image loads before you click.
- New: a private profile hides where you are going and have been from everyone, friends included; with a public profile friends see your coming nights and everyone sees where you have been; nobody sees "Interested" or sensitive nights; photo tags come with a notification and "Remove me".
- New: Pre-Buy. The names per ticket go to the organiser's ticket shop, only to buy the ticket in a name.
- Retention periods set for everything we keep, from the security log (12 months) to orders (7 years); a daily task clears what is past its period.
- Deleting your account is now complete: what the law lets us keep we detach from your name and e-mail address; the rest we erase or anonymise at once.
- We strip metadata such as location and device from photos when they are uploaded.
- New: Subprocessors with per party the purpose, data, location and safeguard, and the data processing agreement for organisers.
- Since 30 September 2026 our database and files are on a server of our own at OVHcloud in Germany, no longer at Cloudflare. Cloudflare is still in front for DNS, CDN and security. New in the list: the web server log and the backups, with their periods.
- 1 October 2026: the ticket export for organisers no longer has names and e-mail addresses; the buyer's e-mail address is only on the door list.
- 1 October 2026: what organisers see about visitors as a group is always a group of at least ten people, rounded.
- 1 October 2026: new retention periods for the group chat (12 months after the night), API usage (13 months) and insights for organisers (25 months); the daily counts go from 400 days to 25 months.
- 1 October 2026: a new account no longer gets a home town filled in for it; you choose one yourself, or leave it empty. If your account got Amsterdam filled in before and you do not live there, change it in your settings.
- 1 October 2026: "Your night". A scan of your ticket at the door proves you were there; that shows as "Was there" under your review or report of that night, and the day after you get a page only you can see. Giving respect to reviews and reports.
- 1 October 2026: search lines that found nothing are kept as text for 90 days, without an account; clicks to the ticket shop are counted per night. Artists who manage their profile see their fans only as groups of at least ten.