Privacy Policy
Last updated: 30 August 2026
KROME EVENTS LTD trading as Krome Events (“we”, “us”, or “our”) respects your privacy. This policy explains what personal data we collect, why we use it, who we share it with, and your rights when you use krome.events, our ticketing platform at krome.events/tickets, or otherwise interact with us.
We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Ticket purchases are also subject to our Terms and Conditions.
KROME EVENTS LTD
1. Who is responsible for your data?
The data controller is KROME EVENTS LTD (Company number 15187137), registered in England and Wales.
Contact us about privacy or data rights:
- Email: [email protected]
- Website: Contact page
We have not appointed a Data Protection Officer. For general data protection queries, use the contact details above.
2. What data we collect
2.1 Data you provide
- Ticket purchases: name, email address, phone number (if requested), order details, promo codes used, and marketing preferences you select at checkout.
- Customer account: login email, password (stored hashed), profile details, order history, tickets, waitlist entries, refund requests, and ticket transfer activity.
- Payments: billing-related information processed by Stripe (we do not store full card numbers on our servers).
- Newsletter and marketing: name and email where you opt in to hear about new events or offers.
- Contact forms: name, email, phone, and message content.
- Guestlist, VIP, promoter, or society flows: names and contact details where tickets are issued through an authorised partner programme.
- Refund requests: order reference, reason (if provided), and correspondence about your request.
2.2 Data collected automatically
- Technical data: IP address, browser type, device type, operating system, and general location derived from IP.
- Usage data: pages viewed, links clicked, referring URLs, and timestamps (for example via privacy-friendly analytics).
- Attribution data: campaign parameters such as UTM tags or referral codes in links.
- Security logs: login attempts, rate limiting, and fraud-prevention signals.
- Event entry: ticket scan/validation records (time of check-in, ticket identifier) for door management and safety.
2.3 Data from third parties
- Payment providers (Stripe) — payment status and limited billing metadata.
- Authorised promoters or societies — where they issue tickets to you on our platform under our rules.
- External ticket imports — barcode or attendee data imported for door scanning at specific events, where permitted by our agreements.
3. How we use your data and our legal bases
We use personal data only where we have a lawful basis under UK GDPR:
- Contract — to sell and deliver tickets, operate your account, process transfers, manage waitlists, handle refund requests, and provide customer support related to your order.
- Legitimate interests — to secure our Website, prevent fraud, improve our services, analyse aggregated sales performance, run events safely, and defend legal claims (balanced against your rights).
- Consent — for optional marketing emails and similar communications where required. You may withdraw consent at any time.
- Legal obligation — to keep financial records, respond to lawful requests, and meet health, safety, or licensing requirements at venues.
We do not use solely automated decision-making that produces legal or similarly significant effects about you.
4. Marketing communications
We may send you emails about events you have purchased, important service updates, or (with your consent) news about upcoming events and offers.
You can opt out of marketing at any time using the unsubscribe link in emails or by contacting us. Opting out of marketing does not affect service messages about your existing orders.
5. Loyalty (Krome Points) and referrals
If you use Krome Points or referral features, we process purchase history and account identifiers to calculate rewards, prevent abuse, and display your balance in your account. This is normally based on contract and legitimate interests.
6. Who we share data with
We share personal data only as needed to run our business:
- Stripe — payment processing (Stripe Privacy Policy).
- Email and hosting providers — to send transactional emails and host the Website.
- Event venues and security — attendee names, ticket counts, or scan data where required for entry, capacity, or safety.
- Authorised promoters and partner societies — limited data about sales or guestlist tickets they are permitted to manage under our agreements.
- Analytics providers — see section 9 (for example Plausible on our main site).
- Advertising partners — where enabled on ticket pages (for example Meta or TikTok pixels); see section 9.
- Professional advisers and authorities — lawyers, accountants, insurers, or regulators when required by law or to protect our rights.
We do not sell your personal data. Processors must protect your data and use it only on our instructions.
7. International transfers
Some providers (for example Stripe, email, or cloud hosting) may process data outside the UK. Where this happens, we rely on appropriate safeguards such as UK adequacy regulations, the UK International Data Transfer Agreement, or Standard Contractual Clauses, as applicable.
8. How long we keep data
- Order and ticket records: up to 7 years after the transaction for accounting, tax, and legal claims.
- Customer account: while your account is active and for a reasonable period afterwards if you delete it (some order data may be retained as above).
- Marketing preferences: until you unsubscribe or withdraw consent, plus a short suppression record to honour your choice.
- Contact enquiries: typically up to 2 years after we last correspond with you.
- Security and server logs: typically up to 12 months, unless needed for an investigation.
- Check-in / scan logs: for the event season and associated retention for disputes and safety, normally within our order retention period.
- Analytics: aggregated statistics may be kept longer; raw analytics data depends on the tool (see section 9).
We delete or anonymise data when it is no longer needed for the purposes above.
9. Cookies, analytics, and tracking technologies
9.1 Main website (krome.events)
We use Plausible Analytics, a privacy-oriented analytics service, to understand traffic and popular pages. Plausible is designed to minimise personal data collection and does not use third-party advertising cookies on our main marketing site.
Embedded content (for example social media widgets) may set third-party cookies when loaded. You can control cookies through your browser settings.
9.2 Ticketing pages (krome.events/tickets)
- Essential cookies and storage — session login, security (CSRF), language preference, and checkout functionality.
- Stripe — may use cookies or similar technologies during payment; see Stripe’s policy.
- Meta (Facebook) Pixel and TikTok Pixel — we may enable these on ticket and checkout pages to measure advertising performance. They may collect online identifiers and usage data subject to those platforms’ policies.
- Progressive Web App (PWA) — if you install our account or scanner web app, a service worker may cache pages locally on your device to improve loading.
9.3 Abandoned checkout reminders
If enabled, we may email you about an incomplete checkout using the email address you entered. We retain cart data only for a limited operational period.
10. Security
We use technical and organisational measures appropriate to the risk, including HTTPS encryption, access controls, hashed passwords, and secure payment handling via Stripe.
No online system is completely secure. Please use a strong, unique password for your account and keep your ticket emails confidential.
11. Your rights
Under UK GDPR you have the right to:
- Access — request a copy of personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion in certain circumstances (we may retain data we must keep by law).
- Restrict processing — ask us to limit use in specific cases.
- Data portability — receive data you provided in a structured, machine-readable format where applicable.
- Object — object to processing based on legitimate interests, including direct marketing.
- Withdraw consent — where processing is based on consent.
To exercise your rights, email [email protected]. We may need to verify your identity. We aim to respond within one month.
You may complain to the Information Commissioner’s Office (ICO): ico.org.uk.
12. Children
Our ticketing service is intended for adults aged 18 and over. We do not knowingly collect personal data from children under 18 without appropriate parental authority. If you believe a child has provided data to us, contact us and we will take appropriate steps to delete it.
Some events permit younger attendees when accompanied or as stated on the event page; ticket purchase must still be completed by an adult where required by law.
13. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date will change when we do. Significant changes may also be highlighted on the Website or by email where appropriate.
14. Contact
Privacy questions or data rights requests:
- Email: [email protected]
- Website: Contact page
