Privacy Policy
Version 1.0 · effective · Previous versions
This policy explains what personal data Unvamp collects, the legal basis for each use, how long we keep it, who we share it with, and the rights you can exercise. It covers unvamp.com, the attendee and organiser apps, and our emails and notifications.
1. Who is responsible
Unvamp is the data controller for the personal data described here. Where you attend an event, the organiser is a separate controller for the attendee data they receive, and their own privacy notice governs what they do with it. Where Unvamp processes attendee data on an organiser’s instructions, we act as their processor under the terms in our Organiser Agreement.
Privacy contact: privacy@unvamp.com.
2. What we collect, why, and for how long
| Purpose | Data | Lawful basis | Retention |
|---|---|---|---|
| Create and secure your account | Name, email, phone, password credential, device and session data | Performance of a contract | Life of the account, then 30 days |
| Sell and deliver tickets | Order and ticket records, attendee name, payment reference | Performance of a contract | 7 years (tax and accounting) |
| Take payment and pay out | Payment method token, transaction records, payout bank details | Performance of a contract; legal obligation for records | 7 years |
| Verify identity (KYC) and screen for sanctions and PEP status | Identity document, selfie, date of birth, national ID numbers, screening results | Legal obligation (AML/CTF); substantial public interest | 5 years after the relationship ends (FATF R.11) |
| Prevent fraud and abuse | Device fingerprint, IP address, behavioural signals, enforcement history | Legitimate interests (protecting the platform and its users) | 2 years from the last signal |
| Deliver live streams and chat | Viewing sessions, chat messages, moderation flags | Performance of a contract; legitimate interests for moderation | Chat 12 months; moderation records 2 years |
| Recommend events and rank discovery | Attendance history, bookmarks, follows, linked music-service affinity | Legitimate interests; consent where a third-party account is linked | 24 months from last activity |
| Send service messages | Email, phone, push token, notification preferences | Performance of a contract | Life of the account |
| Send marketing | Email, engagement signals | Consent (opt-in), withdrawable at any time | Until you withdraw consent |
| Meet tax obligations and produce invoices | Buyer country, tax identifiers, transaction totals | Legal obligation | 7 years, or longer where local law requires |
Where we rely on legitimate interests, we have weighed those interests against your rights and you may object at any time — see section 6.
3. Identity verification
To sell tickets, receive payouts, or transact above certain limits, you must complete identity verification. This is a legal obligation under anti-money-laundering law, not a commercial choice. Verification is carried out by our providers — Sumsub in all markets, and QoreID for Nigerian government registry lookups. They receive your identity document and a selfie; we receive the verification outcome, your verified date of birth, and screening results. We do not retain copies of your identity documents on our own infrastructure.
We screen against sanctions and politically-exposed-person lists. A screening match never results in an automatic adverse decision — every match is reviewed by a person before any action is taken.
4. Automated decision-making and profiling
Two features involve automated processing, and we want to be precise about what each does:
- Verified Fan allocation. Where an organiser runs a Verified Fan presale, registrants are scored on a fixed, documented signal set — prior attendance, artist affinity from a music service you chose to link, account age, and absence of prior abuse enforcement. Scoring is deterministic and rule-based; it is not machine learning. Allocation affects access to a presale window only, not your ability to buy at general onsale, so it does not produce a legal or similarly significant effect. You may ask for the reasoning behind your outcome.
- Event recommendations. We rank events using your attendance and interest history. This affects ordering only; every event remains reachable through search and browse.
We do not use personal data to train general-purpose AI models, and we do not sell personal data.
5. Who we share with
Organisers receive the attendee name, email and ticket type for their own event, so they can admit you and contact you about it. Service providers — payments, identity verification, messaging, hosting, monitoring — process data on our behalf under contract; the current list is at Subprocessors. Authorities receive data where we are legally required to provide it, including suspicious activity reports we are prohibited from telling you about. In a merger or acquisition, data transfers with the business under the same protections.
6. Your rights
Depending on where you live you can: access a copy of your data; correct it; delete it; restrict or object to processing (including profiling and direct marketing); receive it in a portable format; and withdraw consent where consent is the basis. California residents may additionally opt out of sharing for cross-context behavioural advertising and are protected from discrimination for exercising any right; we honour Global Privacy Control signals.
Use the data-export and account-deletion tools in your account settings, or write to privacy@unvamp.com. We respond within 30 days (45 days in California, extendable once where permitted). Deletion has a 14-day grace period during which you can cancel, after which we anonymise your record; we retain what tax and anti-money-laundering law obliges us to keep, and nothing more.
You may complain to your data protection authority — in the UK the Information Commissioner’s Office, and in the EU the supervisory authority where you live or work.
7. International transfers
We host in the EU. Where a provider processes data outside the UK or EEA, we rely on an adequacy decision where one exists, and otherwise on Standard Contractual Clauses with a transfer risk assessment and encryption in transit and at rest.
8. Children
Unvamp is not for under-16s and we do not knowingly collect their data. Some events carry their own minimum age, enforced at purchase and at the door. If you believe a child has given us data, contact us and we will delete it.
9. Security
Encryption in transit and at rest, multi-factor and passkey authentication, least-privilege access with audit logging, and continuous vulnerability scanning. No system is perfectly secure; where a breach is likely to result in a high risk to you, we will tell you without undue delay, and notify the relevant authority within 72 hours as required.
10. Changes
We will tell you before a change that materially affects how we use your data, and where the change requires consent we will ask for it rather than assume it. The revision date at the top reflects the current version.