Privacy Policy
Last updated: June 2026
1. About this policy
1.1 This privacy policy explains how Entry Technologies Ltd (we, us or our) collects, uses, shares and protects personal data in connection with the Entry platform, including the website at entry-os.com, the application at app.entry-os.com, any associated subdomains, custom domains operated by Event Providers through our infrastructure, and any related services (together, the Platform).
1.2 We are the controller of personal data we process for our own purposes (such as operating the Platform, account management, fraud prevention, analytics and compliance). In some circumstances, event organisers, venues and artists (Event Providers) are independent controllers of personal data they receive through the Platform for their own purposes. We explain this in section 11.
1.3 We are subject to the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1.4 Please read this policy carefully. It explains your rights and how to contact us or the Information Commissioner's Office if you have a concern.
2. Who this policy applies to
2.1 This policy applies to:
- (a) visitors to the Platform;
- (b) attendees and ticket buyers (including guest checkout users);
- (c) promoters participating in the Promoter Programme;
- (d) referrers participating in the Referrer Programme;
- (e) Event Providers (organisers, venues, artists) and their staff using professional tools on the Platform; and
- (f) anyone who contacts us or submits information through the Platform.
2.2 Where the Platform links to third-party websites or services (including Stripe for payment processing and Apple for digital wallet passes), those third parties process your data under their own privacy policies.
3. Age restriction
3.1 The Platform is intended for users aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe someone under 18 has provided us with personal data, please contact us so we can delete it.
4. Personal data we collect
The personal data we collect depends on how you use the Platform.
Attendees and ticket buyers
4.1 When you create an account, purchase tickets, join a guestlist, apply for a membership or use guest checkout, we may collect:
- (a) name (first and last), email address, telephone number (where provided);
- (b) gender, date of birth, Instagram handle, and profile photo (where you provide these or where an Event Provider requires them as a condition of entry or purchase);
- (c) authentication data (such as one-time passcode verification);
- (d) ticket purchase details, order history, discount codes applied, and guestlist requests and responses;
- (e) membership applications, tier, billing status and cancellation history;
- (f) digital ticket and membership data, including QR code identifiers;
- (g) check-in data when your ticket is scanned at an event (your name, email, ticket status and timestamp);
- (h) communications with us, including support queries;
- (i) technical and usage data (see section 5); and
- (j) marketing-consent decision records, including an IP address and browser user-agent string, captured when you set or change your marketing preferences, to demonstrate the choice you made.
Promoters
4.2 If you participate in the Promoter Programme, we additionally collect:
- (a) referral codes and links associated with your account;
- (b) referral click data (anonymised technical identifiers and timestamp; we do not store full IP addresses for referral tracking);
- (c) commission data (amounts earned, payout status and payment references); and
- (d) Stripe Connect account details required for payout processing (collected by Stripe during onboarding, see section 4.6).
Referrers
4.3 If you participate in the Referrer Programme, we additionally collect:
- (a) brand assignment details (which Event Provider brands you are assigned to, date range, tier);
- (b) commission data (amounts earned, payout status and payment references); and
- (c) monthly summary data (aggregated earnings by brand).
4.4 Promoters and referrers do not see the personal details of individuals who purchase through referral links. They see only aggregated statistics and commission amounts.
Event Providers and their staff
4.5 When you use the Platform as an Event Provider, we may collect:
- (a) account and business contact details;
- (b) VAT registration details, business name and business address (where applicable);
- (c) audience lists you upload or collect through your events, campaigns and guestlists (see section 11 on controller relationships); and
- (d) venue address and location data entered when setting up venues and events.
Stripe data
4.6 When you make a payment or onboard for payouts, you are redirected to Stripe's hosted pages. Stripe collects your payment card details and, where required, identity verification data directly. We do not see or store your full payment card details. We receive transaction details and account status information from Stripe. Stripe processes this data under its own privacy policy.
5. Technical and usage data
5.1 When you use the Platform, we automatically collect:
- (a) device type (mobile, tablet, desktop);
- (b) referring URL;
- (c) pages viewed (with personal identifiers removed from page paths);
- (d) actions taken on the Platform (such as event views, purchases, guestlist requests and searches); and
- (e) your user ID (if you are logged in) associated with the above.
5.2 This data is collected by our own first-party analytics system, which does not use third-party analytics tools for our own purposes. We also load Google Tag Manager, a tag management service provided by Google, on the Platform. Event Providers use Google Tag Manager to configure their own analytics and advertising tags (such as Meta Pixel) on their event pages (see section 8), and Google may process data as a result. This first-party analytics data is used for platform operations, reporting and service improvement.
6. How we collect personal data
6.1 We collect personal data:
- (a) directly from you when you create an account, purchase tickets, use guest checkout, apply for membership, join a guestlist, contact support or complete forms;
- (b) from Event Providers when they use our tools (for example, uploading an audience list, adding you to a guestlist, or sending communications through the Platform);
- (c) from Stripe when processing payments and managing connected accounts; and
- (d) automatically through cookies, similar technologies and our first-party analytics when you browse and use the Platform.
7. How and why we use your personal data
7.1 We only use personal data when we have a lawful basis under UK GDPR. The sections below set out our processing purposes and the lawful basis for each.
Contract performance (Article 6(1)(b))
7.2 Where processing is necessary to perform our contract with you (the Attendee Terms of Use or Business Terms of Use, as applicable):
- (a) creating and managing your account, including authentication via one-time passcode;
- (b) processing ticket purchases, free orders, guestlist requests and membership applications;
- (c) delivering digital tickets and QR codes, and generating Apple Wallet passes;
- (d) processing refunds and handling chargebacks;
- (e) calculating, tracking and paying promoter and referrer commissions;
- (f) facilitating Stripe Connect onboarding for promoters, referrers and Event Providers;
- (g) providing Event Provider tools (event creation, attendee management, campaign sending, guestlist management);
- (h) sending transactional communications (sign-in codes, order confirmations, ticket delivery, guestlist notifications and membership updates).
Legitimate interests (Article 6(1)(f))
7.3 Where processing is necessary for our legitimate interests, provided those interests are not overridden by your rights:
- (a) platform operations, service improvement and first-party analytics (our interest: understanding how the Platform is used to improve it);
- (b) fraud prevention, platform security and abuse monitoring, including monitoring referral and commission activity for fraud (our interest: protecting the Platform and its users);
- (c) recording check-in data when tickets are scanned at events (our interest: verifying ticket validity and preventing duplicate entry);
- (d) attributing orders to campaigns for performance reporting (our interest: enabling Event Providers to measure campaign effectiveness);
- (e) personalising and improving your experience based on your activity on the Platform, such as event recommendations (our interest: improving relevance for users);
- (f) email deliverability management, including processing bounce, complaint and engagement data from our email delivery provider (our interest: maintaining sender reputation and service quality); and
- (g) defending legal claims and enforcing our rights.
Legal obligation (Article 6(1)(c))
7.4 Where processing is necessary to comply with a legal obligation:
- (a) financial record-keeping, tax and accounting requirements; and
- (b) responding to lawful requests from authorities.
Consent (Article 6(1)(a))
7.5 Where we rely on your consent:
- (a) cookies and similar technologies where consent is required (see our Cookie Policy); and
- (b) certain types of direct marketing where consent is required under PECR (see section 9).
Special category data
7.6 We do not intentionally collect special category data (such as health information, racial or ethnic origin, or religious beliefs). However, Event Providers may ask additional questions as part of membership applications or entry requirements using free-text fields on the Platform. Where special category data is collected in this way, the Event Provider is responsible for ensuring they have a lawful basis for processing it, including an appropriate condition under Article 9 UK GDPR. We process such data as a processor on the Event Provider's instructions.
Profiling
7.7 We use your activity on the Platform to personalise your experience, including event recommendations. This constitutes profiling under Article 4(4) UK GDPR. This profiling is based on our legitimate interests (see section 7.3(e)) and does not produce legal effects or similarly significantly affect you. You have the right to object to this profiling (see section 15).
8. Third-party services on the Platform
Stripe
8.1 Stripe processes payments and manages saved payment methods. When you pay or manage payment methods, you are redirected to Stripe's hosted pages. Stripe is an independent controller of the personal data it collects. See Stripe's privacy policy at https://stripe.com/privacy.
Apple Wallet
8.2 Where you add a ticket or membership pass to Apple Wallet, the pass is generated on our servers and downloaded to your device. Once installed, Apple handles storage and synchronisation under its own terms and privacy policy.
Meta (Pixel and Conversions API)
8.3 Event Providers may choose to enable Meta tracking (Meta Pixel and/or Meta Conversions API) on their event pages on the Platform. Where an Event Provider enables this:
- (a) browser-based tracking (Meta Pixel), loaded through the Event Provider's tags in Google Tag Manager, may collect page view and purchase event data, along with Meta's own cookies;
- (b) server-side tracking (Conversions API) may send event data to Meta, including technical identifiers, IP address, and a hashed (non-reversible) version of your email address on purchase events only. Your email is never sent to Meta in readable form; and
- (c) no other personal data (such as your name or phone number) is sent to Meta.
8.4 Meta tracking is configured and controlled by the Event Provider through their own tags in Google Tag Manager (see section 5.2). The Event Provider is the controller of the personal data collected through their Meta tracking. We provide the tag management layer and emit event signals to it; the Event Provider's tag configuration determines what is loaded and fired, and we operate this layer on their behalf as their processor. We do not operate any Meta tracking for our own purposes.
9. Marketing
Marketing from us
9.1 We may send you marketing communications about the Platform where we have a lawful basis to do so. For attendees, we rely on the soft opt-in exception under PECR (where you have purchased a ticket or completed a similar transaction through the Platform, we may contact you about similar services, provided you are given the opportunity to opt out). For Event Providers, we may send marketing about the Platform and related services based on our legitimate interests in promoting our services to business contacts. You can opt out at any time using the unsubscribe link in our emails or by contacting us.
Marketing from Event Providers
9.2 Event Providers may use tools on the Platform to send you communications, including event announcements and marketing campaigns. Where an Event Provider sends you marketing, the Event Provider is acting as controller and is responsible for ensuring they have a lawful basis to do so (including under PECR). You can unsubscribe from Event Provider marketing using the unsubscribe link in those communications.
9.3 Where you create an account or set your marketing preferences in your profile, you can choose whether to receive marketing. We record the choice you make, together with an IP address and your browser user-agent, so that we can demonstrate your choice. Event Providers are responsible for the lawful basis of any marketing they send to you, including any opt-in or opt-out requirements under PECR. You can opt out of Event Provider marketing at any time using the unsubscribe link in those communications.
9.4 Where you opt in to marketing from an Event Provider (for example at checkout, on a guestlist or presale sign-up, or in your profile), your personal data — including your email address in a hashed (non-reversible) form and, where provided, your name — may be shared with advertising platforms such as Meta so that the Event Provider can reach you, and people similar to you, with relevant ads for their events. The Event Provider is the controller for this activity and directs it; we act as their processor and pass the data on their instructions. This sharing only happens for contacts who have opted in, and you can withdraw your consent at any time using the unsubscribe link in the Event Provider's communications or by asking the Event Provider directly.
10. Who we share personal data with
Event Providers
10.1 When you buy a ticket, join a guestlist or apply for a membership, we share relevant information with the Event Provider so they can administer the event and manage their audience. This typically includes your name, email address, profile photo and, where provided, phone number, Instagram handle, gender and date of birth. Event Providers can see this information in their attendee management and audience tools.
10.2 Event Providers are generally independent controllers of the attendee data they receive through the Platform for their own purposes (see section 11).
Promoters and referrers
10.3 We do not share attendee personal data with promoters or referrers. They see only aggregated statistics and commission amounts relating to their own activity.
Service providers (processors)
10.4 We use service providers to operate the Platform, including:
- (a) cloud hosting and database providers;
- (b) email delivery providers (for transactional and campaign emails);
- (c) payment processing (Stripe, see section 8.1); and
- (d) content delivery and security providers.
10.5 Our service providers process personal data only on our instructions and are bound by contractual data processing terms. A current list of our sub-processors is available on request by contacting us at [email protected].
Professional advisers and authorities
10.6 We may share personal data with auditors, lawyers and other professional advisers, and with law enforcement, courts and regulators where required by law or to protect our rights.
11. Controller relationships
11.1 Entry as controller. We are a controller for personal data we process for our own purposes, including operating the Platform, managing accounts, processing transactions, first-party analytics, fraud prevention, service communications and compliance.
11.2 Event Providers as controllers. Event Providers are generally independent controllers of the attendee personal data they receive through the Platform for their own purposes, including event administration, customer service, their own marketing and meeting their legal obligations. They are responsible for providing you with their own privacy information where required.
11.3 Entry as processor for Event Providers. Where Event Providers use certain Platform tools, we act as their processor. This includes:
- (a) sending event communications and marketing campaigns on the Event Provider's behalf;
- (b) managing guestlists and membership applications; and
- (c) operating the tag management layer (Google Tag Manager) through which the Event Provider's Meta tracking is configured (see section 8.3).
11.4 Where we act as processor, we process data only on the Event Provider's instructions and subject to data processing terms in place with them.
11.5 When an Event Provider sends a campaign through the Platform, we also use email delivery data (such as bounces and complaints) for our own purposes, including deliverability management and platform reporting. For those purposes, we act as controller.
12. How long we keep personal data
12.1 We keep personal data only for as long as needed for the purposes described in this policy, including to meet legal, accounting and reporting requirements.
12.2 Our general retention approach is:
- (a) Account data: retained for as long as your account is active, and for a reasonable period after account deletion to resolve any outstanding matters, after which it is deleted or anonymised;
- (b) Transaction records (tickets, orders, commissions): retained for up to 7 years after the transaction to meet financial record-keeping and tax obligations;
- (c) Check-in logs: retained for up to 12 months after the event;
- (d) Analytics data: retained in aggregated or pseudonymised form; raw event-level data retained for up to 24 months;
- (e) Email engagement data: retained for up to 24 months, after which it is aggregated or deleted;
- (f) Support communications: retained for up to 3 years after resolution;
- (g) Security and fraud logs: retained for up to 24 months; and
- (h) Marketing-consent audit records: retained for up to 7 years to evidence the marketing choice you made.
12.3 Where data is no longer needed, we will delete or anonymise it. Specific retention periods may vary where a longer period is required by law.
13. International data transfers
13.1 Some of our service providers are located outside the UK, including in the United States. Where we transfer personal data outside the UK, we do so using appropriate safeguards, including:
- (a) transfers to countries covered by UK adequacy regulations; and/or
- (b) UK-approved contractual safeguards (such as the UK Addendum to the EU Standard Contractual Clauses).
13.2 You can request more information about international transfers and the safeguards in place by contacting us (see section 18).
14. Cookies
14.1 We use cookies and similar technologies to operate the Platform, remember preferences and measure usage. Where required, we will ask for your consent via our cookie tool.
14.2 Event Providers may enable third-party cookies on their event pages through tags they configure in Google Tag Manager (such as Meta Pixel and Google services, see section 8.3). These cookies are placed by those third parties (such as Meta and Google), not by us.
14.3 Please see our Cookie Policy for full details of the cookies used on the Platform.
15. Your rights
15.1 Under UK GDPR, you generally have the following rights, which you can usually exercise free of charge:
- (a) Access — the right to receive a copy of your personal data;
- (b) Correction — the right to require us to correct any inaccuracies in your personal data;
- (c) Erasure — the right to require us to delete your personal data in certain circumstances;
- (d) Restriction — the right to require us to restrict processing of your personal data in certain circumstances;
- (e) Data portability — the right to receive the personal data you provided to us in a structured, commonly used and machine-readable format, and to transmit it to another controller in certain circumstances;
- (f) Objection — the right to object to processing based on legitimate interests (including profiling) and the right to object at any time to your personal data being used for direct marketing;
- (g) Automated decision-making — the right not to be subject to a decision based solely on automated processing (including profiling) that produces legal effects concerning you or similarly significantly affects you; and
- (h) Withdrawal of consent — where we rely on your consent, the right to withdraw it at any time (without affecting the lawfulness of processing before withdrawal).
15.2 Automated decision-making. The Platform uses automated rules to determine access to certain features (for example, membership-gated ticket availability and promoter eligibility modes set by Event Providers). These rules restrict or enable access to purchasing options but do not produce legal effects or similarly significantly affect you within the meaning of Article 22 UK GDPR. We do not make solely automated decisions that produce legal effects concerning you.
15.3 To exercise any of your rights, please contact us at [email protected]. When contacting us, please provide enough information to identify yourself and let us know which right(s) you wish to exercise.
15.4 Requests relating to Event Provider data. If your request relates to how an Event Provider uses your data (including their marketing), please contact the Event Provider directly. If you contact us by mistake, we will direct you to the relevant Event Provider or, where appropriate, forward your request.
16. Keeping your personal data secure
16.1 We have appropriate security measures in place to prevent personal data from being accidentally lost, or used or accessed unlawfully. We limit access to your personal data to those who have a genuine need to access it.
16.2 We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.
17. How to complain
17.1 Please contact us if you have any queries or concerns about our use of your personal data (see section 18). We hope we will be able to resolve any issues you may have.
17.2 You also have the right to lodge a complaint with the Information Commissioner's Office (ICO). They may be contacted at https://ico.org.uk/make-a-complaint or by telephone: 0303 123 1113.
18. How to contact us
18.1 If you have any questions about this privacy policy or the information we hold about you, wish to exercise a right under data protection law, or wish to make a complaint, you can contact us:
- By post: Entry Technologies Ltd, 1 Water Lane, London, England, NW1 8NZ
- By email: [email protected]
19. Changes to this policy
19.1 We may change this privacy policy from time to time. Where we make significant changes, we will take steps to inform you (for example, by email or by a notice on the Platform).
19.2 The "Last updated" date at the top of this policy will be revised accordingly.
20. Accessibility
20.1 If you would like this policy in another format (for example, audio, large print or braille), please contact us using the details above.