Legal
Privacy Policy
Last updated: 22 June 2026
This Privacy Policy explains how GRABBYS Events Limited ("we", "us", "our") collects, uses, discloses, and safeguards your information when you use The Grabbys app, websites, and related services (the "Service").
1. Who we are
The data controller is GRABBYS Events Limited. For any privacy-related question, contact us at privacy@grabbys.app.
2. Information we collect
- Account data: name, email, password hash, profile preferences, authentication credentials including passkeys.
- Order data: tickets, packages, room bookings, payment confirmations (we do not store full card numbers).
- Usage data: pages viewed, events saved, schedule selections, device/browser info, IP address, cookies.
- Communications: messages you send us, push-notification tokens you opt in to.
3. How we use information
- To provide the Service, process orders, and deliver event access.
- To authenticate you and secure your account.
- To send transactional emails, reminders and updates about events you registered for.
- To improve the Service, debug, and prevent abuse.
- To comply with legal obligations.
4. Legal bases (EEA/UK)
We rely on: performance of a contract (delivering tickets you bought), legitimate interests (securing the Service, analytics), consent (marketing emails, push notifications, optional cookies), and legal obligation (tax, accounting).
5. Sharing
We share data only with processors who help us run the Service:
- Cloud hosting and database infrastructure.
- Payment processors for ticket and package purchases.
- Email delivery and push-notification providers.
- Analytics and error monitoring (aggregated where possible).
- Authorities when required by law.
6. International transfers
Where data leaves the EEA/UK we rely on Standard Contractual Clauses or equivalent safeguards.
7. Retention
We keep account data while your account is active and for a reasonable period after. Order and tax records are kept for the period required by law (typically 6–10 years).
8. Your rights
You can access, correct, export, restrict or delete your data, and object to processing. See our GDPR page for how to exercise these rights.
9. Security
We use industry-standard safeguards including encryption in transit, hashed passwords, row-level security on our database, and support for passkey (WebAuthn) authentication.
10. Children
The Service is intended for adults 18 years or older. We do not knowingly collect data from minors.
11. Changes
We will post updates to this page and update the "Last updated" date above.