Privacy Policy
Effective Date: 11 May 2026
Last Updated: 21 August 2026
This Privacy Policy describes how Deuce Creative Limited(“we”, “us”, “our”), trading as Grofomo, collects, uses, and shares information across the Grofomo platform.
1. Who We Are
Deuce Creative Limited, a company registered in England and Wales, company number 07991249. VAT number GB935707211.
Registered office: Unit 8 Great Bramshot Farm Barns, Bramshot Lane, Fleet, Hampshire, GU51 2SF, United Kingdom.
For any privacy question or request, contact privacy@grofomo.com.
1.1 What this policy covers
This policy applies to:
- the Grofomo mobile app;
- events.grofomo.com, the console event organisers use;
- artists.grofomo.com, the portal artists use;
- grfm.to and m.grfm.to, where tickets are sold and managed;
- api.grofomo.com, the service behind the app;
- grofomo.com, developers.grofomo.com, and docs.grofomo.com;
- event websites we host on an organiser behalf.
Organisers and artists each have a separate agreement covering their use of the platform: the Organiser Terms and the Artist Terms. Organisers are additionally covered by our Data Processing Addendum.
2. Information We Collect
2.1 Information you provide
- Account and sign-in email: an account is created only when you sign in, using a magic link sent to your email address, or by signing in with Google or Apple. We then store that email and an account record so you can sign in across devices, see your tickets, and manage or delete your data. Buying a ticket does not create an account on its own: your purchase is recorded against the email you used, and is linked to your account if and when you sign in with that email. Much of the app works with only a device identifier (see §2.2). You can delete your account at any time (see §10).
- Nickname and avatar choice (if you set one). Used to identify you to friends within the app.
- Ticket purchase details: your name, email address, and where the organiser asks for it a phone number, together with the details of what you bought. Where you buy merchandise we also collect a delivery address. Card details go directly to our payment provider and never reach us.
- Answers to questions the organiser asksat checkout or on their forms. The organiser decides what to ask; see §4.
- Email address (if you submit a Grofomo web form, for example a marketing opt-in form, a pre-sale registration, or a similar interest form). Used, with your separate opt-in at the form, to send marketing email about events, ticket releases, and related news.
- Phone number (only if you submit a Grofomo web form and choose SMS or WhatsApp as a contact channel). Used only to send the communications you opted in to.
- WhatsApp messages you send to an organiser, where they use WhatsApp through Grofomo. The message content and your WhatsApp display name are stored so the organiser can reply.
- Friend invite tokens (when you accept an invite from another user).
- Marketing notification preference (device-level): whether you have toggled marketing push notifications on for this device. This is a per-device preference, like any other notification setting, and is stored against your device identifier only. You can flip it at any time from Settings → Notifications in the app or from your device system Settings.
- Marketing consent records (named): if you submit a Grofomo web form that captures marketing choices (e.g. a pre-sale registration, marketing opt-in form, or ticket checkout), we record, at the point of submission, which channels you agreed to (email, SMS, WhatsApp), the exact wording of each choice as it was shown to you (including, for a clearly-labelled pre-ticked box, that you did not opt out), a timestamp, and the form and version you submitted through, so we can demonstrate the basis for any message we send and honour any later withdrawal or objection.
2.2 Information collected automatically
- Device identifier: a randomly-generated identifier created when you first open the app. Used to associate your local data (favourites, reminders, nickname) with your device.
- Push notification token: an Expo Push Token issued by our push-delivery processor, Expo. The token is derived from the underlying Apple (APNs) or Google (FCM) token but is scoped to our Expo project; we never see the raw APNs or FCM token. Used to deliver event reminders, friend-invite notifications, and any marketing pushes you have opted into.
- App and device metadata: platform (iOS or Android), app version, device locale, and approximate last-seen timestamp. Used for compatibility checks and to identify inactive sessions.
- IP address and browser: recorded at specific moments where we need to be able to evidence what happened. Those moments are: placing an order, recording a marketing consent choice, requesting a ticket-recovery code, granting media consent, and being checked in at an event. It is also processed transiently for security, rate limiting, and bot protection. We do not keep a general log of your browsing.
- Referral source: where you followed a tagged or affiliate link to a ticket page, we record which campaign or referrer sent you, so the right person is credited for the sale. This is stored against the link, and in a cookie against the event, not against you.
- Clipboard (read on launch): when you open the app, we briefly inspect the system clipboard to detect a pasted friend-invite link. We act only on values matching our invite-link format; we do not retain, transmit, or otherwise process clipboard contents. (iOS may display a system banner when this read occurs.)
2.3 Camera
The app requests camera access solely to scan QR codes that link to events, artists, or friend invites. Camera images are processed on-device in real time and never stored, uploaded, or transmitted.
2.4 What we do not collect
- We do not collect your precise or approximate location. There is no GPS in the app, and our own analytics resolve no finer than country.
- We do not access your contacts, photo library, or microphone.
- We do not access the iOS advertising identifier (IDFA) or the Android advertising ID, and Grofomo does not request App Tracking Transparency consent.
- Grofomo does not track you across other apps or websites, and we do not sell your information or share it with advertisers. One qualification: an event organiser can add their own Meta advertising pixel to their ticket page, which is third-party tracking by that organiser. It only runs if you accept analytics cookies, and it is described in our cookie policy.
- We do not collect financial, biometric, or government-issued identifier information, and we do not ask for health information. Note that an organiser can add their own questions to a checkout or form, so what an organiser asks you for is their decision, not ours. See §4.
3. How We Use Information
We use the information above to:
- Provide the core app experience: showing events, lineups, favourites, friends, and reminders.
- Sell you tickets, deliver them, and support you if something goes wrong.
- Authenticate your device and your account with our Service.
- Deliver transactional messages that are part of the service you asked for: ticket confirmations, receipts, event change notices, payment plan reminders, event reminders you have scheduled, and friend-invite notifications.
- Deliver marketing communications (push notifications, and for users who have submitted a Grofomo web form or bought a ticket: email, SMS, or WhatsApp) onlyon the basis described in §3.1 and §3.2.
- Keep the platform secure and prevent fraud and abuse, including bot protection on public forms and rate limiting.
- Investigate crashes or other issues using diagnostic information that you choose to share with us when reporting a problem (for example, by emailing support). Grofomo does not collect or transmit crash or telemetry data automatically.
- Meet our legal obligations, including keeping accounting and tax records of sales.
We do not sell your information, share it with advertisers for their own purposes, or use it for behavioural advertising. We do not use your personal data to train machine learning models.
3.1 Marketing in the app
Separately from transactional notifications, Grofomo may send you marketing communications about future events, ticket releases, lineup announcements, and related offers. Marketing is never required to use the app or to buy a ticket. In the app, marketing is opt-in onlyand is captured in two stages, so that you only ever receive what you have specifically agreed to. Marketing choices shown at ticket checkout are described separately in §3.2.
Stage 1 – Marketing push notifications. An in-app banner may invite you to enable marketing push notifications. Push notifications of any kind can only reach you if you have granted Grofomo push permission via your device system dialog: that operating-system permission is the underlying consent. The in-app Marketing notifications toggle then sits on top as a granular preference that controls whether your device is included when we send a marketing push (about future ticket releases and related news).
At this stage your preference is tied only to your device identifier: we do not yet hold your name, email, or phone number for marketing purposes. You can opt out at any time by:
- Toggling Marketing notifications off in Settings → Notifications within the app, or
- Revoking Grofomo push permission entirely in your device system Settings (this also stops transactional notifications).
Stage 2 – Web form opt-in.A marketing push notification (from Stage 1), or a link from elsewhere, may invite you to submit a web form that Grofomo operates on an event organiser behalf, for example a pre-sale (“prelaunch”) registration form. These forms collect your first name, email address, and optionally a mobile number. The organiser named on the form is the controller for the marketing you sign up to, just as with marketing at ticket checkout (see §3.2); Grofomo runs the form and keeps the records on their behalf. Where the form says so plainly at the point of submission, submitting the form itself signs you up for the organiser email updates about the event named on the form (such as on-sale alerts, presales, and related news). Any SMS, WhatsApp, or postal marketing is separate and strictly opt-in, sent only if you actively tick that box. At the point of submission we record:
- the channels you signed up to and the exact wording you were shown for each,
- the timestamp, your IP address and browser,
- the form and version you submitted through, and
- where you arrived from a marketing push, the link between your submitted personal data and the device identifier that opened the form, so we can recognise you across the app and our mailing lists.
You can withdraw consent for email, SMS, or WhatsApp marketing at any time by:
- using the unsubscribe link included in every marketing email,
- replying STOP to any marketing SMS,
- using the WhatsApp “stop messages” option, or
- emailing privacy@grofomo.com to withdraw across all channels at once.
Withdrawing marketing consent stops the relevant communications. You will continue to receive transactional push notifications (e.g. reminders you have scheduled, friend-invite notifications) unless you disable those separately.
3.2 Marketing at ticket checkout
When you buy a ticket through a Grofomo-powered checkout, up to three separate marketing choices are shown, each as its own clearly-labelled box:
- The event organiser emails (soft opt-in). The organiser you are buying from is the data controller for their own marketing. Because you provide your details in the course of buying a ticket from them, they may email you about their own similar events, presales and announcements on the basis of their legitimate interests, under the UK “soft opt-in” rule (PECR Regulation 22(3)). The checkout shows this as a clearly-worded, pre-ticked box that you can untick at the point of purchase, and every such email contains an unsubscribe link. You have the right to object at any time: untick the box at checkout, use the unsubscribe link in any email, or email privacy@grofomo.com.
- The organiser SMS and WhatsApp messages are strictly opt-in: they are sent only if you actively tick the messaging box, and you can opt out at any time by replying STOPto any SMS or using the WhatsApp “stop messages” option.
- Grofomo own emails. Grofomo runs the checkout and delivers your tickets, and acts as an independent controller for its own marketing about similar events available on Grofomo. Depending on the checkout version shown, this choice is captured either as an unticked opt-in box (consent), or (where we rely on legitimate interests under the same soft opt-in rule) as a clearly-worded pre-ticked box you can untick at the point of purchase. Every Grofomo marketing email contains an unsubscribe link, and you can object at any time via that link or privacy@grofomo.com.
In every case we record which boxes were shown and their exact wording, your choice, a timestamp, your IP address and browser, and the form version, so we can demonstrate the basis for any message we send and honour any withdrawal or objection.
4. Who is responsible for your data
Grofomo is a platform that event organisers use to run their events, so for some data we decide what happens to it and for other data the organiser does. Under data protection law the party who decides is the “controller”, and it is the party you exercise your rights against. This matters in practice, so here it is plainly.
4.1 The event organiser is the controller
When you buy a ticket, register for a pre-sale, fill in an organiser form, message an organiser on WhatsApp, or volunteer for an event, the organiser decides what to collect and what to do with it. Grofomo processes it on their instructions. That covers:
- your order and ticket records for their event;
- any custom questions they choose to ask you;
- their marketing to you, and the consent you gave them;
- your messages with them;
- volunteer, guest list, and supplier records.
The organiser name is shown on the event page, on the checkout, and on your receipt. For requests about that data you can contact them directly, or contact us and we will help.
4.2 Grofomo is the controller
We decide what happens to, and are responsible for:
- your Grofomo account and how you sign in;
- the Grofomo mobile app: your device record, nickname, favourites, reminders, and friend connections;
- marketing that Grofomo sends about Grofomo, where you agreed to it separately (see §3.2);
- the public artist and event directory, including entries compiled from public sources (see §11);
- keeping the platform secure, and our own accounting and tax records.
4.3 Both, separately
At checkout you may agree to hear from the organiser and, separately, from Grofomo. Those are two different relationships with two different controllers. Unsubscribing from one does not unsubscribe you from the other, and each of us is responsible only for our own messages.
5. Cookies
We use cookies to keep you signed in, to remember your preferences, and to credit the right referrer for a ticket sale. These are necessary for the service to work.
The only non-essential technology is an event organiser own advertising pixel, where they have added one to their ticket page. That does not run unless you accept it, and declining changes nothing about your ability to buy a ticket.
Full detail, including every cookie name and how to change your choice, is in our cookie policy.
6. How We Share Information
Service providers. We use third-party providers to run the platform: to host it, store data, take payments, send email, deliver push notifications, and protect forms from abuse. They act on our instructions, may use the data only to provide their service to us, and are bound by written data protection terms.
We publish the complete, current list, including what each one can access, where it processes, and the safeguard we rely on, at https://events.grofomo.com/subprocessors. That page is kept up to date as the authoritative record rather than as a summary.
The event organiser.When you buy a ticket or interact with an event, the organiser of that event receives the details they need to sell to you and admit you, as described in §4.1.
Services an organiser has connected. An organiser can connect their own advertising, messaging, or notification tools. Where they have, data may flow to those tools on their instructions. These are identified separately on the subprocessors page.
Legal disclosures. We may disclose information if required by a valid legal process, or to protect our rights, safety, or property.
Business transfers. If Deuce Creative Limited is acquired or merges with another entity, your information may transfer as part of that transaction, subject to this policy.
7. Where your data is processed
Our database is in the United Kingdom. Everything the platform stores about you, including your account, orders, tickets, consent records, and uploaded media, is held in London.
Some processing happens elsewhere. Our hosting provider currently runs server code in the United States, holding data only in memory for the moment it takes to serve a request before writing it back to the United Kingdom. Payments, email delivery, push notifications, and some other services also involve providers outside the United Kingdom. The subprocessors page states, for each provider, exactly where it processes.
Where data leaves the United Kingdom we rely on one of: the UK International Data Transfer Agreement; the EU Standard Contractual Clauses together with the UK Addendum; or the UK Extension to the EU-US Data Privacy Framework where the provider is certified under it. We assess these transfers and can provide our assessments on request.
8. Data Retention
We keep information only as long as we need it, and delete or anonymise it on a schedule:
- Your app device record persists for as long as the device is active. If the app has not contacted the Service for 12 months, the associated record is deleted.
- Push notification tokens are invalidated and removed from active use once APNs or FCM (via Expo) signals that they are no longer valid, for example after you uninstall the app or revoke push permission. Tokens are deleted together with the associated device record.
- Ticket purchases are kept for the retention period the organiser sets, which defaults to 7 years to match tax record-keeping requirements. At the end of that period your personal details are removed and only an anonymous record of the sale remains.
- Abandoned checkouts, where you entered details but never purchased, are anonymised after 180 days.
- Pre-sale registrations are deleted after the period set for that event, which defaults to 2 years.
- WhatsApp message content is redacted after the organiser retention window, which defaults to 24 months.
- Link click records are deleted after 400 days, and checkout analytics 180 days after the event ends.
- Ticket recovery codes are deleted after 24 hours.
- Data from a Grofomo web form (name, email, optional phone, channel consents) persists until you withdraw consent across all channels or request deletion, at which point it is removed from active marketing use and deleted from our records within 30 days.
Two things deliberately survive an erasure request. The financial record of a sale, stripped of your details, is kept because we are legally required to keep accounting records. Consent records are kept because they are the only evidence that a message we sent you was lawful, and destroying them would remove your own ability to challenge it. Neither is ever used to contact you again.
Backups are overwritten on a rolling cycle and are fully replaced within 60 days.
9. Your Rights
You have the right to:
- Access the personal data we hold about you, and receive a copy.
- Correct inaccurate data.
- Deleteyour data (“right to erasure”).
- Object to or restrict processing of your data.
- Port your data to another service, in a structured, commonly used, machine-readable format.
- Withdraw consentto marketing communications (per channel, see §3.1), objectto marketing sent under legitimate interests (see §3.2), withdraw from all push notifications (via your device system notification settings), or from the use of the app entirely (by uninstalling).
To exercise any of these rights, email privacy@grofomo.com. We acknowledge within 3 business days and respond within 30 days. Exercising a right is free, and we will never make you give a reason.
Where the request concerns data an event organiser controls (see §4.1), we will either pass it to them or help you reach them, and tell you which we have done.
You have the right to complain to the Information Commissioner’s Office at ico.org.uk. We would rather you came to us first, but you do not have to.
10. Data Deletion
You can delete your Grofomo account from Settings → Sign out and delete account in the app, or by emailing privacy@grofomo.com from the address you registered with. Deleting your account signs you out and removes the personal data linked to it: your device record, nickname and avatar, your magic-link email and auth record, your favourites and reminders, and friends entries naming you.
If you have bought tickets, deleting your account also anonymises your personal details (name, email, phone) on those past purchases, so the organiser keeps only a de-identified record of the sale for their own accounting and legal obligations. The exception is tickets for events that have not yet taken place: the organiser retains the details needed to admit you until after the event, after which your details are removed by routine cleanup. Deleting your account does not cancel or refund tickets you have already bought.
If you have submitted a Grofomo web form (e.g. a marketing opt-in or pre-sale registration), you can have the data captured there deleted by emailing privacy@grofomo.com from the address you registered with.
Full detail is on our data deletion page.
11. Information we hold that you did not give us
Grofomo maintains a public directory of artists and events, so that organisers can build lineups and audiences can find gigs. Some entries are compiled from publicly available sources rather than provided by the person concerned. That can include a performing name, a real name where it is publicly associated with the act, a biography, a location, publicly listed booking or press contact details, links to public social profiles, and publicly posted images.
Where it comes from. Public event listings and venue websites, public music and event databases including Resident Advisor, MusicBrainz, Wikidata and Spotify, and publicly accessible social media profiles.
Why we do it. Our legitimate interest, and that of the organisers who use the platform, in maintaining a usable directory of who performs where. We balance that against the interests of the people listed, which is why entries hold professional information only and never anything private.
Counting click-throughs. When someone follows a ticket link from a directory listing, we count that click so we can tell a venue how much traffic the directory sends it. We record the listing, which seller was clicked, the time, the website you came from, a broad device type and a two-letter country. We do not record your IP address, your full browser details or anything that identifies you, and we do not store anything on your device to do it.
What you can do. If you are listed, you can claim your profile and take control of it, correct it, ask us to restrict how it is used, or object to the listing entirely and ask us to remove it. Email privacy@grofomo.com and we will action it. We do not require you to justify the request.
12. Children
Grofomo is not directed at children under 13, and you must be 18 or over to buy a ticket. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with information, contact privacy@grofomo.com and we will delete it.
Data about a child can still reach the platform: a parent naming a child on a ticket they bought, or an organiser recording an under-18 volunteer. Where that happens the organiser is the controller and is responsible for handling it appropriately.
13. Security
All traffic between your device and the Service is encrypted with TLS, and data is encrypted at rest. Every table in our database enforces row-level access control, so a request can only ever return data the requester is entitled to. Device authentication uses signed tokens, and third-party access tokens are separately encrypted before storage. Provider credentials are held in environment-scoped secrets and never in our source code. Access by our staff follows least privilege and is removed when a role ends.
A fuller description of our technical and organisational measures is published as Annex 2 of our Data Processing Addendum. No system is perfectly secure, but we follow industry-standard practices, and if a breach ever affects your data we will tell you where the law requires it.
14. Changes to This Policy
We may update this policy. Material changes will be announced via in-app notification, push notification, or email at least 14 days before they take effect. The “Last Updated” date at the top of this page always reflects the most recent revision.
15. Contact
Deuce Creative Limited
Unit 8 Great Bramshot Farm Barns
Bramshot Lane
Fleet
Hampshire
GU51 2SF
United Kingdom
Privacy enquiries: privacy@grofomo.com
By using Grofomo, you acknowledge that you have read and understood this Privacy Policy.