Privacy & GDPR

Last updated: 8 July 2026

Who we are

fyb.events (“fyb”) is a ticketing, membership and governance platform for burn events. It is independently operated in the United Kingdom by its owner as an individual (a sole trader, not a company). For anything in this policy, contact hello@fyb.events.

Two hats. For your fyb account and profile, fyb is the data controller. When you buy a ticket to an event, apply for membership of a burn, or take part in its AGM, the organisation running that burn is the controller and fyb processes your data on its behalf. Each event and membership page names the organisation responsible. You can send any request to us and we will handle it or route it to the right organisation.

What we collect

What we don’t do: no analytics trackers, no advertising, no profiling, no selling of data, no third-party marketing.

Why we can use it

Who we share it with

A small set of service providers: Supabase (database, login, file storage), Stripe (payments), Postmark (email delivery), Vercel (hosting), and Companies House (statutory director filings only). The organisation whose event you interact with sees the data it needs to run that event, with role-restricted access. We never share your data with anyone else unless the law requires it. Some providers are in the United States; transfers are covered by international data-transfer agreements with each provider.

Where your data lives

Your data is stored in the United Kingdom (Supabase, London region). A few providers named above process some data in the United States under the data-transfer safeguards described in that section.

How long we keep it

Your rights

The membership register — what deletion cannot delete

If you become a legal member of a burn, its register of members (legal name, address, email, membership dates) is a statutory record the organisation must keep by law, and members’ liability rules keep a ceased member’s entry legally relevant for one further year. Deleting your fyb account therefore does not remove you from a register you joined. Instead: your entry drops off the member-visible register immediately when you cease; all voluntary data (phone, date of birth, accessibility notes, guardian details) is purged one year after you cease; and the minimal statutory core is retained as the legal record. Register access is itself logged and rate-limited to prevent misuse.

Children

Events set their own age rules. If you add a child to your ticket, you confirm you are their parent or legal guardian and consent to their details being processed for entry and safety; a child’s details are deleted when you delete your account. Burns that admit under-18 members operate a guardian-consent and safeguarding review.

Changes

We’ll post changes here with a new “last updated” date, and email you about material changes.