Privacy Policy
1. Introduction
OM Events ("we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share your information when you use our mobile application and services.
2. Data We Collect
We collect the following categories of personal data:
- Account Information: Name, email address, phone number, profile photo, and chosen user role.
- Location Data: With your permission, we collect your location to show nearby events and provide location-based alerts.
- Payment Information: Payment details are processed securely by Stripe. We do not store your full card details.
- Organiser Banking (organisers only): If you accept paid bookings, Stripe Connect collects bank account details and identity verification data directly. This information is held by Stripe; we receive only a reference to your connected account.
- Device Information: Device type, operating system, and push notification tokens for delivering notifications.
- Usage Data: App interactions, event preferences, favourites, and search history to improve our service.
- Diagnostics: Crash reports (stack traces, device model, OS version) collected via Firebase Crashlytics to identify and fix bugs. No personal content from the app is included.
3. How We Use Your Data
We use your personal data to:
- Provide and maintain our services
- Process ticket purchases and stall bookings
- Send event notifications, weather alerts, and booking confirmations
- Verify organiser accounts and manage approvals
- Improve the App experience and personalise content
- Comply with legal obligations and prevent fraud
4. Legal Basis for Processing (GDPR)
We process your data under the following legal bases:
- Contract: To fulfil ticket purchases, stall bookings, and account services.
- Consent: For push notifications, location-based alerts, and marketing communications.
- Legitimate Interest: For service improvement, fraud prevention, and security.
- Legal Obligation: To comply with tax, financial, and regulatory requirements.
5. Data Sharing
We may share your data with:
- Stripe: For secure payment processing. If you are an organiser, Stripe Connect handles payouts and identity verification directly between you and Stripe.
- Firebase (Google): For authentication, data storage, cloud functions, crash reporting (Crashlytics), and app integrity checks (App Check). Crashlytics may transmit device model, OS version, and anonymised stack traces.
- Apple / Google Play Integrity: To verify the app is a genuine, untampered build of OM Events. No personal data is sent — only a cryptographic attestation token.
- OneSignal: For push notification delivery.
- SendGrid: For transactional emails (booking confirmations, refund notices, organiser billing).
- Event Organisers: Your name and contact details when you book a stall or purchase tickets, as necessary for event management.
We do not sell your personal data to third parties.
6. Data Retention
We retain your personal data for as long as your account is active or as needed to provide services.
You can delete your account at any time from Profile → Delete Account. On deletion: your profile and credentials are removed; any active subscription is cancelled in Stripe; your tickets and reviews are anonymised (rating value and content kept for organisers' aggregate scores, but your name, email, and user ID are stripped). If you have upcoming events as an organiser, you must cancel them first so ticket holders can be refunded.
After deletion, we may retain certain data for up to 12 months to comply with legal obligations, resolve disputes, or enforce agreements. Payment records are retained by Stripe as required by financial regulations (typically 7 years for UK businesses).
7. Your Rights
Under UK GDPR, you have the right to:
- Access: Request a copy of your personal data.
- Rectification: Correct inaccurate or incomplete data via Profile → Edit, or by contacting us.
- Erasure: Delete your account in-app (Profile → Delete Account) or request erasure by contacting us.
- Restrict Processing: Limit how we use your data.
- Data Portability: Receive your data in a machine-readable format.
- Object: Object to processing based on legitimate interest.
- Withdraw Consent: Withdraw consent at any time for consent-based processing (e.g. notifications, location). Notification preferences are managed in Profile → Notifications; location and other system permissions in your device settings.
For requests we cannot fulfil from within the app, contact us at support@openmarketevents.com.
8. Cookies & Tracking
The App uses Firebase Analytics, Firebase Crashlytics, and similar technologies to understand usage patterns and identify defects. You can manage notification and location permissions through your device settings at any time. The App does not use third-party advertising trackers.
9. Data Security
We implement appropriate technical and organisational measures to protect your data, including: encrypted data transmission (TLS/SSL); secure authentication via Firebase Auth; PCI-compliant payment processing through Stripe; per-user access controls enforced by Firebase Security Rules; and Firebase App Check (Play Integrity on Android, DeviceCheck on iOS) to ensure server requests come from genuine builds of the official OM Events app.
10. Children's Privacy
The App is not intended for children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us to have it removed.
11. International Transfers
Your data may be processed in countries outside the UK where our service providers operate (e.g., Google/Firebase servers). We ensure appropriate safeguards are in place for such transfers in compliance with UK GDPR.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes through the App or via email. Continued use of the App after changes constitutes acceptance.
13. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us:
Email: support@openmarketevents.com Via the Support page in the App