Legal document
Privacy Policy
How BookItEase collects, uses, shares, retains and protects personal data.
Who we are
BookItEase is an event ticketing and box office platform for organisers, attendees, customers and invited team members. In this policy, "BookItEase", "we", "us" and "our" mean the operator of this website and platform.
For platform account data and our own website analytics, we normally act as a data controller. For attendee data that an organiser collects through their box office, we may act as a processor on behalf of that organiser.
Data we collect
- Customer and attendee identity data, including name, email address, phone number and date of birth or age only where an event lawfully requires it.
- Account data, including a one-way password hash, role, saved preferences, authentication and security events. We do not store readable account passwords.
- Order and attendance data, including ticket selections, attendee answers, allocated seats, QR or barcode identifiers, order references, check-in time, refund history and communication preferences.
- Billing and transaction data, including billing address, Stripe customer/payment identifiers, currency, transaction amounts, platform fees, payout and dispute status. We do not store full card numbers, card security codes or online-banking credentials.
- Organiser data, including legal or trading name, contact details, organisation role, box-office settings, events, team permissions, Stripe Connect status, invoices, payouts, subscriptions, uploaded verification material and customer-support conversations.
- Marketing and consent evidence, including channel choices, policy versions accepted, timestamps, source, IP address and user agent. Optional email, WhatsApp and partner marketing permissions are recorded separately.
- Technical and security data, including IP address, browser and device information, approximate country, pages viewed, cookie choices, fraud signals, audit records and usage events.
How we collect data
We collect data directly when you create an account, create a box office, publish an event, buy a ticket, contact support, upload content or change settings.
We also collect technical data automatically through security logs, cookies and similar technologies. Some data may be received from service providers such as Stripe, email providers, analytics tools and authentication providers.
Legal basis for processing
- Contract: to create accounts, process orders, deliver tickets, operate organiser tools, provide support and manage paid services.
- Legitimate interests: to secure the platform, prevent fraud, improve product reliability, understand usage and communicate important service information.
- Consent: for optional marketing messages and non-essential cookies where consent is required.
- Legal obligation: to keep accounting records, respond to lawful requests, comply with tax, fraud prevention and regulatory obligations.
How we use data
- To provide event discovery, ticketing, checkout, order management, refunds, scanning and organiser dashboards.
- To send transactional emails such as order confirmations, ticket delivery, event updates and account security notices.
- To operate payments, fraud prevention, dispute handling, tax records, platform fee reporting and Stripe Connect onboarding.
- To improve performance, accessibility, product design, customer support and platform reliability.
- To enforce our terms, acceptable use rules and legal rights.
Data retention
We keep personal data only for as long as needed for the purposes described in this policy. Account data is kept while the account is active and for a reasonable period after closure. Order, payment, invoice and tax records may be retained for longer where required for accounting, legal or fraud prevention purposes.
Expired login and marketplace sessions are removed after a limited operational period. Search and event-interaction history is normally removed after 24 months. Payment, invoice, payout, refund, tax and related audit records are normally retained for up to seven years after the relevant accounting period, unless a longer period is required for a dispute, fraud investigation or legal claim.
When an approved customer erasure request is completed, direct account, order, attendee and marketplace identifiers are deleted or anonymised where lawful. We may keep minimal suppression, transaction, audit or security records where needed to protect the platform, preserve purchased-ticket records and honour legal obligations.
Data sharing and third parties
We share only the data needed for a documented service purpose. Organisers receive attendee, order and check-in data for events they manage and may be independent controllers for how they use that information. Attendees should review the organiser’s privacy information.
We do not sell personal data. We do not allow service providers to use BookItEase personal data for their own advertising except where you separately choose to interact with that provider.
- Stripe: checkout, card and wallet processing, fraud prevention, tax calculation, refunds, disputes, subscriptions and organiser payouts. Stripe receives transaction, contact, billing, device and payment-method data directly; BookItEase retains identifiers and financial records, not full card details.
- Google reCAPTCHA: bot and abuse prevention on protected forms. Google may receive device, browser, IP and interaction signals under its own terms.
- Google account login: optional authentication. We receive the account identifier, name, email and profile information authorised during sign-in.
- Microsoft 365 and Microsoft Graph: transactional and permitted marketing email delivery. Recipient addresses, message content and delivery metadata are processed to deliver and diagnose email.
- Meta/Facebook and Instagram: optional organiser social-feed connections, campaign links or social content. Account identifiers, authorised content and engagement metadata are processed only for enabled integrations.
- TikTok: optional organiser social-feed content. Account identifiers, authorised content and post metadata are processed only after the organiser connects the service.
- Infrastructure, security and support providers: hosting, storage, monitoring, malware scanning and customer support, subject to access controls and contractual safeguards.
Marketing choices and service messages
At checkout, the required Booking and Privacy Policy acknowledgement is separate from one optional email-marketing choice. Email marketing is off by default and is never required to create an account or complete a purchase. Other optional channels, where offered, require their own affirmative choice in the relevant preference screen.
The checkout acknowledgement records the applicable Terms, Privacy Policy and organiser policy versions as one clear customer action while retaining separate evidence of each document in our compliance records.
Withdrawal takes effect immediately for future campaign selection. We retain minimal suppression and consent evidence so that we can honour the choice. Transactional messages needed to deliver tickets, receipts, refunds, security alerts, event changes or requested support are not marketing and may still be sent.
International transfers
Some providers may process data outside the United Kingdom. Where this happens, we use appropriate safeguards such as adequacy regulations, approved contractual terms, transfer risk assessments or equivalent protections required by data protection law.
Your rights
Depending on the context, you may have rights to access, correct, delete, restrict or object to processing of your personal data. You may also have a right to data portability and a right to withdraw consent where processing is based on consent.
Signed-in users can create a secure ZIP export, manage marketing choices, or submit and track a request in the Privacy Centre at /account/privacy. Export links expire after seven days. You can also contact us using the details in the Legal Requests section. We normally respond without undue delay and within one month, subject to lawful extensions for complex or multiple requests.
We may ask for information needed to verify identity. If your request relates to an organiser-controlled event, we may refer the request to the organiser or assist them in responding. A deletion request does not require us to erase records that must be retained for tax, accounting, fraud prevention, legal claims or another lawful reason.
Security measures
We use technical and organisational measures designed to protect personal data, including access controls, encrypted transport, password hashing, role-based permissions, audit logging, secure infrastructure practices and limited internal access.
No online service can be guaranteed completely secure. If you believe your account or data has been affected by a security issue, contact us immediately.
Complaints
We would like the chance to resolve privacy concerns first. You also have the right to complain to the UK Information Commissioner’s Office at ico.org.uk if you are unhappy with how your personal data has been handled.
Legal document
Terms and Conditions
The rules for using BookItEase websites, accounts, organiser tools and checkout services.
Using BookItEase
By using BookItEase, creating an account, listing an event or buying a ticket, you agree to these terms. If you use BookItEase for an organisation, you confirm that you are authorised to bind that organisation.
These terms apply alongside any event-specific terms set by the organiser and any payment provider terms that apply to the transaction.
Account responsibilities
- Provide accurate information and keep it up to date.
- Keep login credentials secure and do not share accounts without permission.
- Use appropriate roles and permissions for team members.
- Tell us promptly if you suspect unauthorised access.
Website usage rules
You must not misuse the platform, interfere with service operation, scrape data without permission, bypass access controls, upload harmful code, impersonate others, or use BookItEase for unlawful, misleading or abusive activity.
Organiser obligations
- Organisers are responsible for event accuracy, lawful ticket sales, venue arrangements, accessibility information, cancellation terms, attendee support and legal compliance for their events.
- Organisers must honour valid tickets, handle attendee enquiries fairly, and make refund/cancellation terms clear before purchase.
- Organisers must not list events that infringe rights, breach laws, create unacceptable safety risks, or mislead customers.
Payments, fees and subscriptions
BookItEase may charge platform fees, booking fees, subscription fees or other charges shown during setup or checkout. Payment processing is handled by Stripe or another supported provider.
Where a customer pays a booking fee, it should be shown transparently at checkout. Where an organiser absorbs fees, the customer total should not include hidden additions.
Intellectual property
BookItEase owns or licenses the platform, design, software, trademarks and brand assets. You retain ownership of content you upload, but grant us the rights needed to host, display, process and distribute that content to operate the service.
Liability limits
BookItEase is provided with reasonable care and skill. We do not promise that the platform will be uninterrupted or error free. To the fullest extent permitted by law, we are not liable for indirect loss, loss of profit, loss of goodwill, or losses caused by organiser-controlled event decisions.
Nothing in these terms excludes liability that cannot legally be excluded, including liability for death or personal injury caused by negligence, fraud, or statutory consumer rights that apply by law.
Suspension and termination
We may suspend or terminate access where we reasonably believe there is a breach of these terms, unacceptable risk, fraud, unlawful activity, non-payment or harm to users or the platform.
Governing law
These terms are governed by the laws of England and Wales, unless mandatory consumer law in another UK jurisdiction gives you additional rights.
Legal document
GDPR and Data Protection
Our approach to UK GDPR roles, organiser data ownership, processor duties and deletion requests.
Controller and processor roles
For organiser account management, platform security, billing, product analytics and our direct communications, BookItEase normally acts as a controller.
For attendee data collected by an organiser through an event checkout, the organiser is usually the controller and BookItEase acts as a processor or service provider. The organiser decides why the data is collected and how it is used for their event.
Customer data ownership
Organisers own and control their event, attendee and order data, subject to our legal obligations and platform terms. We do not sell attendee lists. We use organiser-controlled data to provide the platform, support orders, deliver tickets, prevent fraud and meet legal obligations.
Data handling principles
- Lawfulness, fairness and transparency: we explain how data is used and rely on an appropriate lawful basis.
- Purpose limitation: we use data for defined platform, payment, support, security and legal purposes.
- Data minimisation: we aim to collect only what is needed for account, event, checkout and compliance workflows.
- Storage limitation: we keep data only as long as required for operational, legal and accounting reasons.
- Security: we protect data using access controls, secure infrastructure, encryption in transit and operational safeguards.
- Accountability: we maintain policies, records and vendor controls appropriate for our role.
Security and hosting
BookItEase uses managed infrastructure, encrypted connections, role-based access controls, authentication protections, secure development practices and monitoring. Access to production data is limited to people and systems that need it.
Third-party processors
We use providers for hosting, payments, email delivery, analytics, authentication, storage and support. These providers are expected to process data only under appropriate contractual safeguards and only for authorised service purposes.
Deletion and access requests
Users can request access, correction or deletion of their personal data. Where BookItEase is a processor for organiser-controlled event data, we may need to coordinate with the organiser before completing the request.
Some data may need to be retained for accounting, security, fraud prevention, dispute handling or legal compliance.
Data Processing Agreement
Where required, organiser customers may request a Data Processing Agreement covering processor terms, confidentiality, security, subprocessors, assistance with rights requests, deletion/return of data and audit support.
Legal document
Acceptable Use Policy
Rules designed to keep events, accounts, attendees and the wider platform safe.
Purpose
This policy protects attendees, organisers, partners and BookItEase. It applies to accounts, events, listings, uploads, messages, checkout forms, emails, APIs and any other use of the platform.
Prohibited content and activity
- Illegal events, goods, services or fundraising.
- Fraud, misleading pricing, fake events, impersonation or deceptive ticketing.
- Harassment, hate, threats, exploitation, abuse or discriminatory activity.
- Malware, phishing, spam, credential harvesting or unauthorised scraping.
- Content that infringes intellectual property, privacy, publicity or contractual rights.
- Events that create unreasonable safety, financial, regulatory or reputational risk.
Enforcement
We may remove content, pause payouts, suspend sales, require verification, cancel listings, notify affected users, or terminate accounts where we reasonably believe this policy has been breached.
Legal document
Refund and Cancellation Policy
How refunds, cancellations and consumer rights work for ticket purchases.
Organiser refund terms
Each organiser is responsible for setting clear refund and cancellation terms for their event. Those terms should be visible before purchase and must comply with applicable consumer law.
Cancelled or materially changed events
If an event is cancelled or materially changed, the organiser is normally responsible for offering an appropriate remedy, which may include a refund, exchange or alternative arrangement depending on the circumstances and applicable law.
Consumer rights
UK consumer law may give customers rights where services are not provided with reasonable care and skill, are not as described, or are not delivered as agreed. Nothing in this policy removes mandatory consumer rights.
Fees and refund processing
Where a refund is approved, the refundable amount may depend on the organiser’s policy, payment provider rules, taxes, chargebacks and whether booking or platform fees are refundable in the circumstances.
Legal document
Security Policy
Security measures, responsible disclosure and account protection guidance.
Security measures
- TLS for data in transit.
- Password hashing and authentication safeguards.
- Role-based permissions for organiser teams.
- Limited internal access to production systems.
- Security monitoring, logging and operational review.
- Vendor review for critical providers such as hosting, payment and email services.
What users should do
- Use a strong unique password.
- Do not share login credentials.
- Review team access regularly.
- Contact us quickly if you suspect unauthorised access.
Responsible disclosure
If you believe you have found a security issue, contact us with enough detail to reproduce and assess the issue. Do not access, alter, delete or exfiltrate data that is not yours. We will review good faith reports and respond as quickly as practical.
Legal document
Third Party Services
Types of vendors and integrations used to run BookItEase.
Provider categories
- Payments and payouts, such as Stripe.
- Hosting, database, storage and infrastructure providers.
- Email delivery and notification services.
- Analytics, monitoring, logging and performance tools.
- Authentication providers, including optional social login.
- Customer support, communication and operational tools.
How we manage providers
We choose providers based on security, reliability, legal suitability and operational need. We aim to share only the data needed for the provider to perform its service and require appropriate contractual protections where personal data is processed.
Legal document
Contact and Legal Requests
How to contact BookItEase for privacy, legal, security and rights requests.
Contact details
For privacy, data protection, security or legal requests, contact: legal@bookitease.com.
For attendee requests about a specific event, include the event name, order reference and email address used at checkout so we can identify the relevant organiser or record.
How we respond
We may need to verify your identity before acting on a request. We aim to respond within applicable legal timeframes. If your request is complex or involves organiser-controlled data, we may explain the next steps and whether the organiser needs to assist.
Important note
These legal pages are provided for transparency and platform governance. They are not legal advice. You should obtain independent legal advice for your own organisation, event terms, refund policy and data protection obligations.