Privacy & GDPR
Last updated: 8 July 2026
Who we are
fyb.events (“fyb”) is a ticketing, membership and governance platform for burn events. It is independently operated in the United Kingdom by its owner as an individual (a sole trader, not a company). For anything in this policy, contact hello@fyb.events.
Two hats. For your fyb account and profile, fyb is the data controller. When you buy a ticket to an event, apply for membership of a burn, or take part in its AGM, the organisation running that burn is the controller and fyb processes your data on its behalf. Each event and membership page names the organisation responsible. You can send any request to us and we will handle it or route it to the right organisation.
What we collect
- Account & profile: your email and login, plus whatever you choose to add — legal name, display/playa name, phone, date of birth, photo, pronouns. Your public burner profile is off by default.
- Optional welfare details: emergency contact, medical information, dietary requirements and accessibility needs. These are special-category data: we ask for them only so event teams can keep you safe, we process them with your explicit consent, and you can remove them from your profile at any time.
- Tickets & checkout: tickets bought, prices paid, your answers to any questions the event asks at checkout, your media-consent choice, and check-in status. If you add a child to your ticket we store their name, date of birth and relationship to you (see “Children” below).
- Applications: what you write in accessibility, carer or low-income applications, and ID-verification photos where an event requires them — ID images are deleted automatically 90 days after the event.
- Membership & governance: if you join a burn as a legal member, its statutory register of members holds your legal name, postal address, email and membership dates (see “The membership register” below). Standing for a board additionally requires the details Companies House needs from directors.
- Voting: secret ballots are engineered so your vote cannot be linked back to you — by anyone, including administrators: who voted and what was voted are stored separately with no link between them. Show-of-hands votes and community art-grant votes are attributable by design, and that is stated wherever you cast one.
- Payments: card details go directly from your browser to Stripe — they never touch our servers. Each burn processes payments through its own Stripe account and is the merchant of record; we keep payment references and amounts as financial records.
- Technical: login session cookies (see the Cookie Policy), server logs which may include your IP address and browser details (including automatic error reports if a page crashes), and a record of when you accept terms, kept as proof of acceptance.
What we don’t do: no analytics trackers, no advertising, no profiling, no selling of data, no third-party marketing.
Why we can use it
- Running your account, tickets, transfers and check-in — contract.
- The membership register, AGM notices, statutory filings and financial records — legal obligation.
- Welfare, medical, dietary and accessibility data — your explicit consent, withdrawable at any time.
- Photos of you at events — consent, per your per-ticket media choice.
- Platform security and error logs — legitimate interests.
- Public profile, burn history, member badge — consent; all opt-in.
Who we share it with
A small set of service providers: Supabase (database, login, file storage), Stripe (payments), Postmark (email delivery), Vercel (hosting), and Companies House (statutory director filings only). The organisation whose event you interact with sees the data it needs to run that event, with role-restricted access. We never share your data with anyone else unless the law requires it. Some providers are in the United States; transfers are covered by international data-transfer agreements with each provider.
Where your data lives
Your data is stored in the United Kingdom (Supabase, London region). A few providers named above process some data in the United States under the data-transfer safeguards described in that section.
How long we keep it
- Your profile: until you delete your account.
- Welfare details: until you remove them or delete your account.
- Financial records (payments, ticket records): 6 years, as required by UK tax law — kept after account deletion, detached from your identity.
- ID-verification images: 90 days after the event, automatic.
- Sent-email content: purged after 90 days.
- Membership register: the statutory core is kept as long as the law requires; everything voluntary is purged one year after membership ends.
Your rights
- See everything: download a complete copy of your data at Account → Privacy (JSON export).
- Delete your account: also under Account → Privacy. There is a 30-day cooling-off window (log back in to cancel), after which your profile is irreversibly anonymised: name, contact details, photo, welfare data and application answers are erased. Financial records the law requires us to keep are detached from your identity.
- You also have the rights to rectification (edit your profile, or ask us), restriction, objection and portability, and to withdraw any consent.
- Anything you can’t do self-service: hello@fyb.events. We respond within one month.
- You can complain to the Information Commissioner’s Office (ico.org.uk, 0303 123 1113). We’d appreciate the chance to fix it first.
The membership register — what deletion cannot delete
If you become a legal member of a burn, its register of members (legal name, address, email, membership dates) is a statutory record the organisation must keep by law, and members’ liability rules keep a ceased member’s entry legally relevant for one further year. Deleting your fyb account therefore does not remove you from a register you joined. Instead: your entry drops off the member-visible register immediately when you cease; all voluntary data (phone, date of birth, accessibility notes, guardian details) is purged one year after you cease; and the minimal statutory core is retained as the legal record. Register access is itself logged and rate-limited to prevent misuse.
Children
Events set their own age rules. If you add a child to your ticket, you confirm you are their parent or legal guardian and consent to their details being processed for entry and safety; a child’s details are deleted when you delete your account. Burns that admit under-18 members operate a guardian-consent and safeguarding review.
Changes
We’ll post changes here with a new “last updated” date, and email you about material changes.