Privacy Notice
Last updated: 29 August 2026 · Version 4
Who we are
FYB Limited (company number 17427970, registered office 21 Linden Road, Leatherhead, KT22 7JB, United Kingdom) operates this platform. Contact: hello@fyb.events.
The one thing to understand: two kinds of data
- Your FYB account (we are the controller). When you sign up, your account belongs to the platform, not to any one burn. Your registration and profile details, login credentials, security logs and platform-wide preferences are held by FYB Limited as an independent controller, because you can use one account with any organisation on the platform. This notice governs that data.
- Your data inside a burn (the burn is the controller). When you join an organisation as a member, buy a ticket, sign up as a lead, link or volunteer, take part in a meeting, ballot or election, or upload content for a burn, that data lives inside that organisation’s space on the platform. The organisation — a third-party burn organisation, a legal entity separate from FYB Limited — is the controller of that data and decides why it is collected and how long it is kept; FYB processes it only on the organisation’s instructions under a written data processing agreement. Requests about that data (access, correction, deletion) are decided by the organisation — we will pass your request on, or you can contact the organisation directly.
One practical consequence: leaving an organisation, or an organisation leaving the platform, does not delete your FYB account; and deleting your FYB account does not by itself delete records an organisation is legally required to keep (for example a company’s statutory register of members).
What we collect for your account and why
| Data | Why | Lawful basis |
|---|---|---|
| Registration and profile data | To provide the account | Contract |
| Authentication and security logs | To keep the platform secure and prevent abuse | Legitimate interests |
| Platform preferences and notification settings | To run the service | Contract |
| Marketing email — only if you opt in | To send you news you asked for | Consent — withdraw any time in one click |
In practice your account holds: your email and login, legal name, display/playa name, date of birth (required so we can verify eligibility for age-restricted events, camps and board elections, and for safeguarding), and optionally phone, photo and pronouns. Your public burner profile is off by default. Optional welfare details (emergency contact, medical information, dietary requirements, accessibility needs) are special-category data: we ask for them only so event teams can keep you safe, we process them with your explicit consent, and you can remove them at any time. Technically, we also keep login session cookies (see the Cookie Policy), server logs which may include your IP address and browser details (including automatic error reports if a page crashes), and a record of when you accept terms, kept as proof of acceptance.
What we don’t do: no analytics trackers, no advertising, no profiling, no selling of data, no third-party marketing.
Inside a burn’s space: what that covers
The data controlled by the organisation whose burn you interact with includes:
- Tickets & checkout: tickets bought, prices paid, your answers to any questions the event asks at checkout, your media-consent choice, and check-in status. If you add a child to your ticket the organisation holds their name, date of birth and relationship to you (see “Children” below).
- Applications: what you write in accessibility, carer or low-income applications, and ID-verification photos where an event requires them — ID images are deleted automatically 90 days after the event.
- Membership & governance: if you join a burn as a legal member, its statutory register of members holds your legal name, postal address, email and membership dates (see “The membership register” below). Standing for a board additionally requires the details Companies House needs from directors.
- Voting: secret ballots are engineered so your vote cannot be linked back to you — by anyone, including administrators: who voted and what was voted are stored separately with no link between them. Show-of-hands votes and community art-grant votes are attributable by design, and that is stated wherever you cast one.
- Payments: card details go directly from your browser to Stripe — they never touch our servers. Each burn processes payments through its own Stripe account and is the merchant of record; payment references and amounts are kept as financial records.
Who we share account data with (sub-processors)
- Supabase, Inc. — database, authentication and file storage, hosted in AWS eu-west-2, London.
- Vercel, Inc. — application hosting and content delivery.
- Stripe — payment processing.
- Postmark / ActiveCampaign, LLC — transactional email.
Some of these providers are US companies; where data leaves the UK it is protected by UK-approved safeguards (the UK Addendum to the EU Standard Contractual Clauses or the UK Extension to the EU–US Data Privacy Framework). We also send Companies House statutory director filings when someone stands for a board — nothing else. The organisation whose event you interact with sees the data it needs to run that event, with role-restricted access. We never share your data with anyone else unless the law requires it.
If the operation of fyb is transferred to another company in our corporate group, or to a successor operator of the platform, your personal data will transfer with it under the same protections and for the same purposes described here. We will tell you before that happens.
How long we keep account data
For the life of your account plus 30 days after deletion, except where law requires longer (e.g. financial records) — and records held by organisations follow that organisation’s retention rules, not ours. In detail:
- Your profile: until you delete your account, plus the 30-day cooling-off window below.
- Welfare details: until you remove them or delete your account.
- Financial records (payments, ticket records): 6 years, as required by UK tax law — kept after account deletion, detached from your identity.
- ID-verification images: 90 days after the event, automatic.
- Sent-email content: purged after 90 days.
- Membership register: the statutory core is kept as long as the law requires; everything voluntary is purged one year after membership ends.
Your rights
Access, rectification, erasure, restriction, objection, portability, and the right to withdraw consent where processing is based on consent.
- See everything: download a complete copy of your data at Account → Privacy (JSON export).
- Delete your account: also under Account → Privacy. There is a 30-day cooling-off window (log back in to cancel), after which your profile is irreversibly anonymised: name, contact details, photo, welfare data and application answers are erased. Financial records the law requires us to keep are detached from your identity.
- Anything you can’t do self-service: hello@fyb.events. We respond within one month. Requests about data inside a burn’s space are decided by that organisation — we will pass your request on.
- You can complain to the Information Commissioner’s Office (ico.org.uk, 0303 123 1113). We’d appreciate the chance to fix it first.
The membership register — what deletion cannot delete
If you become a legal member of a burn, its register of members (legal name, address, email, membership dates) is a statutory record the organisation must keep by law, and members’ liability rules keep a ceased member’s entry legally relevant for one further year. Deleting your fyb account therefore does not remove you from a register you joined. Instead: your entry drops off the member-visible register immediately when you cease; all voluntary data (phone, date of birth, accessibility notes, guardian details) is purged one year after you cease; and the minimal statutory core is retained as the legal record. Register access is itself logged and rate-limited to prevent misuse.
Children
Events set their own age rules. If you add a child to your ticket, you confirm you are their parent or legal guardian and consent to their details being processed for entry and safety; a child’s details are deleted when you delete your account. Burns that admit under-18 members operate a guardian-consent and safeguarding review.
Where your data lives
Your data is stored in the United Kingdom (Supabase, London region). A few providers named above process some data in the United States under the data-transfer safeguards described in that section.
Changes
We’ll post changes here with a new “last updated” date and version, and email you about material changes.