Unvamp
FeaturesPricingFor OrganisersFor AttendeesAbout
LoginGet Started

Privacy Policy

Version 1.0 · effective September 2026 · Previous versions

This policy explains what personal data Unvamp collects, the legal basis for each use, how long we keep it, who we share it with, and the rights you can exercise. It covers unvamp.com, the attendee and organiser apps, and our emails and notifications.

1. Who is responsible

Unvamp is the data controller for the personal data described here. Where you attend an event, the organiser is a separate controller for the attendee data they receive, and their own privacy notice governs what they do with it. Where Unvamp processes attendee data on an organiser’s instructions, we act as their processor under the terms in our Organiser Agreement.

Privacy contact: privacy@unvamp.com.

2. What we collect, why, and for how long

Purpose, data, lawful basis and retention period
PurposeDataLawful basisRetention
Create and secure your accountName, email, phone, password credential, device and session dataPerformance of a contractLife of the account, then 30 days
Sell and deliver ticketsOrder and ticket records, attendee name, payment referencePerformance of a contract7 years (tax and accounting)
Take payment and pay outPayment method token, transaction records, payout bank detailsPerformance of a contract; legal obligation for records7 years
Verify identity (KYC) and screen for sanctions and PEP statusIdentity document, selfie, date of birth, national ID numbers, screening resultsLegal obligation (AML/CTF); substantial public interest5 years after the relationship ends (FATF R.11)
Prevent fraud and abuseDevice fingerprint, IP address, behavioural signals, enforcement historyLegitimate interests (protecting the platform and its users)2 years from the last signal
Deliver live streams and chatViewing sessions, chat messages, moderation flagsPerformance of a contract; legitimate interests for moderationChat 12 months; moderation records 2 years
Recommend events and rank discoveryAttendance history, bookmarks, follows, linked music-service affinityLegitimate interests; consent where a third-party account is linked24 months from last activity
Send service messagesEmail, phone, push token, notification preferencesPerformance of a contractLife of the account
Send marketingEmail, engagement signalsConsent (opt-in), withdrawable at any timeUntil you withdraw consent
Meet tax obligations and produce invoicesBuyer country, tax identifiers, transaction totalsLegal obligation7 years, or longer where local law requires

Where we rely on legitimate interests, we have weighed those interests against your rights and you may object at any time — see section 6.

3. Identity verification

To sell tickets, receive payouts, or transact above certain limits, you must complete identity verification. This is a legal obligation under anti-money-laundering law, not a commercial choice. Verification is carried out by our providers — Sumsub in all markets, and QoreID for Nigerian government registry lookups. They receive your identity document and a selfie; we receive the verification outcome, your verified date of birth, and screening results. We do not retain copies of your identity documents on our own infrastructure.

We screen against sanctions and politically-exposed-person lists. A screening match never results in an automatic adverse decision — every match is reviewed by a person before any action is taken.

4. Automated decision-making and profiling

Two features involve automated processing, and we want to be precise about what each does:

  • Verified Fan allocation. Where an organiser runs a Verified Fan presale, registrants are scored on a fixed, documented signal set — prior attendance, artist affinity from a music service you chose to link, account age, and absence of prior abuse enforcement. Scoring is deterministic and rule-based; it is not machine learning. Allocation affects access to a presale window only, not your ability to buy at general onsale, so it does not produce a legal or similarly significant effect. You may ask for the reasoning behind your outcome.
  • Event recommendations. We rank events using your attendance and interest history. This affects ordering only; every event remains reachable through search and browse.

We do not use personal data to train general-purpose AI models, and we do not sell personal data.

5. Who we share with

Organisers receive the attendee name, email and ticket type for their own event, so they can admit you and contact you about it. Service providers — payments, identity verification, messaging, hosting, monitoring — process data on our behalf under contract; the current list is at Subprocessors. Authorities receive data where we are legally required to provide it, including suspicious activity reports we are prohibited from telling you about. In a merger or acquisition, data transfers with the business under the same protections.

6. Your rights

Depending on where you live you can: access a copy of your data; correct it; delete it; restrict or object to processing (including profiling and direct marketing); receive it in a portable format; and withdraw consent where consent is the basis. California residents may additionally opt out of sharing for cross-context behavioural advertising and are protected from discrimination for exercising any right; we honour Global Privacy Control signals.

Use the data-export and account-deletion tools in your account settings, or write to privacy@unvamp.com. We respond within 30 days (45 days in California, extendable once where permitted). Deletion has a 14-day grace period during which you can cancel, after which we anonymise your record; we retain what tax and anti-money-laundering law obliges us to keep, and nothing more.

You may complain to your data protection authority — in the UK the Information Commissioner’s Office, and in the EU the supervisory authority where you live or work.

7. International transfers

We host in the EU. Where a provider processes data outside the UK or EEA, we rely on an adequacy decision where one exists, and otherwise on Standard Contractual Clauses with a transfer risk assessment and encryption in transit and at rest.

8. Children

Unvamp is not for under-16s and we do not knowingly collect their data. Some events carry their own minimum age, enforced at purchase and at the door. If you believe a child has given us data, contact us and we will delete it.

9. Security

Encryption in transit and at rest, multi-factor and passkey authentication, least-privilege access with audit logging, and continuous vulnerability scanning. No system is perfectly secure; where a breach is likely to result in a high risk to you, we will tell you without undue delay, and notify the relevant authority within 72 hours as required.

10. Changes

We will tell you before a change that materially affects how we use your data, and where the change requires consent we will ask for it rather than assume it. The revision date at the top reflects the current version.

Unvamp

Your gateway to live events. Stream, discover, buy, sell, and experience entertainment worldwide.

We never share your email. Unsubscribe anytime — every email carries a one-click opt-out.

XIGYTTT
ProductFeaturesPricingFor OrganisersFor Attendees
CompanyAbout UsContactHelp Center
LegalTerms & ConditionsPrivacy PolicyCookie PolicyRefund PolicyPaying in InstalmentsCommunity GuidelinesAccessibilitySubprocessorsReport Infringement

© 2026 Unvamp. All Rights Reserved.

Cookies + privacy

We use essential cookies to run unvamp.com. With your permission we'd also like to set analytics cookies that help us improve the site. Click Accept to allow analytics, or Decline to keep only the essentials.