Privacy Policy

Effective Date: 11 May 2026
Last Updated: 21 August 2026

This Privacy Policy describes how Deuce Creative Limited(“we”, “us”, “our”), trading as Grofomo, collects, uses, and shares information across the Grofomo platform.

1. Who We Are

Deuce Creative Limited, a company registered in England and Wales, company number 07991249. VAT number GB935707211.

Registered office: Unit 8 Great Bramshot Farm Barns, Bramshot Lane, Fleet, Hampshire, GU51 2SF, United Kingdom.

For any privacy question or request, contact privacy@grofomo.com.

1.1 What this policy covers

This policy applies to:

Organisers and artists each have a separate agreement covering their use of the platform: the Organiser Terms and the Artist Terms. Organisers are additionally covered by our Data Processing Addendum.

2. Information We Collect

2.1 Information you provide

2.2 Information collected automatically

2.3 Camera

The app requests camera access solely to scan QR codes that link to events, artists, or friend invites. Camera images are processed on-device in real time and never stored, uploaded, or transmitted.

2.4 What we do not collect

3. How We Use Information

We use the information above to:

  1. Provide the core app experience: showing events, lineups, favourites, friends, and reminders.
  2. Sell you tickets, deliver them, and support you if something goes wrong.
  3. Authenticate your device and your account with our Service.
  4. Deliver transactional messages that are part of the service you asked for: ticket confirmations, receipts, event change notices, payment plan reminders, event reminders you have scheduled, and friend-invite notifications.
  5. Deliver marketing communications (push notifications, and for users who have submitted a Grofomo web form or bought a ticket: email, SMS, or WhatsApp) onlyon the basis described in §3.1 and §3.2.
  6. Keep the platform secure and prevent fraud and abuse, including bot protection on public forms and rate limiting.
  7. Investigate crashes or other issues using diagnostic information that you choose to share with us when reporting a problem (for example, by emailing support). Grofomo does not collect or transmit crash or telemetry data automatically.
  8. Meet our legal obligations, including keeping accounting and tax records of sales.

We do not sell your information, share it with advertisers for their own purposes, or use it for behavioural advertising. We do not use your personal data to train machine learning models.

3.1 Marketing in the app

Separately from transactional notifications, Grofomo may send you marketing communications about future events, ticket releases, lineup announcements, and related offers. Marketing is never required to use the app or to buy a ticket. In the app, marketing is opt-in onlyand is captured in two stages, so that you only ever receive what you have specifically agreed to. Marketing choices shown at ticket checkout are described separately in §3.2.

Stage 1 – Marketing push notifications. An in-app banner may invite you to enable marketing push notifications. Push notifications of any kind can only reach you if you have granted Grofomo push permission via your device system dialog: that operating-system permission is the underlying consent. The in-app Marketing notifications toggle then sits on top as a granular preference that controls whether your device is included when we send a marketing push (about future ticket releases and related news).

At this stage your preference is tied only to your device identifier: we do not yet hold your name, email, or phone number for marketing purposes. You can opt out at any time by:

Stage 2 – Web form opt-in.A marketing push notification (from Stage 1), or a link from elsewhere, may invite you to submit a web form that Grofomo operates on an event organiser behalf, for example a pre-sale (“prelaunch”) registration form. These forms collect your first name, email address, and optionally a mobile number. The organiser named on the form is the controller for the marketing you sign up to, just as with marketing at ticket checkout (see §3.2); Grofomo runs the form and keeps the records on their behalf. Where the form says so plainly at the point of submission, submitting the form itself signs you up for the organiser email updates about the event named on the form (such as on-sale alerts, presales, and related news). Any SMS, WhatsApp, or postal marketing is separate and strictly opt-in, sent only if you actively tick that box. At the point of submission we record:

You can withdraw consent for email, SMS, or WhatsApp marketing at any time by:

Withdrawing marketing consent stops the relevant communications. You will continue to receive transactional push notifications (e.g. reminders you have scheduled, friend-invite notifications) unless you disable those separately.

3.2 Marketing at ticket checkout

When you buy a ticket through a Grofomo-powered checkout, up to three separate marketing choices are shown, each as its own clearly-labelled box:

In every case we record which boxes were shown and their exact wording, your choice, a timestamp, your IP address and browser, and the form version, so we can demonstrate the basis for any message we send and honour any withdrawal or objection.

4. Who is responsible for your data

Grofomo is a platform that event organisers use to run their events, so for some data we decide what happens to it and for other data the organiser does. Under data protection law the party who decides is the “controller”, and it is the party you exercise your rights against. This matters in practice, so here it is plainly.

4.1 The event organiser is the controller

When you buy a ticket, register for a pre-sale, fill in an organiser form, message an organiser on WhatsApp, or volunteer for an event, the organiser decides what to collect and what to do with it. Grofomo processes it on their instructions. That covers:

The organiser name is shown on the event page, on the checkout, and on your receipt. For requests about that data you can contact them directly, or contact us and we will help.

4.2 Grofomo is the controller

We decide what happens to, and are responsible for:

4.3 Both, separately

At checkout you may agree to hear from the organiser and, separately, from Grofomo. Those are two different relationships with two different controllers. Unsubscribing from one does not unsubscribe you from the other, and each of us is responsible only for our own messages.

5. Cookies

We use cookies to keep you signed in, to remember your preferences, and to credit the right referrer for a ticket sale. These are necessary for the service to work.

The only non-essential technology is an event organiser own advertising pixel, where they have added one to their ticket page. That does not run unless you accept it, and declining changes nothing about your ability to buy a ticket.

Full detail, including every cookie name and how to change your choice, is in our cookie policy.

6. How We Share Information

Service providers. We use third-party providers to run the platform: to host it, store data, take payments, send email, deliver push notifications, and protect forms from abuse. They act on our instructions, may use the data only to provide their service to us, and are bound by written data protection terms.

We publish the complete, current list, including what each one can access, where it processes, and the safeguard we rely on, at https://events.grofomo.com/subprocessors. That page is kept up to date as the authoritative record rather than as a summary.

The event organiser.When you buy a ticket or interact with an event, the organiser of that event receives the details they need to sell to you and admit you, as described in §4.1.

Services an organiser has connected. An organiser can connect their own advertising, messaging, or notification tools. Where they have, data may flow to those tools on their instructions. These are identified separately on the subprocessors page.

Legal disclosures. We may disclose information if required by a valid legal process, or to protect our rights, safety, or property.

Business transfers. If Deuce Creative Limited is acquired or merges with another entity, your information may transfer as part of that transaction, subject to this policy.

7. Where your data is processed

Our database is in the United Kingdom. Everything the platform stores about you, including your account, orders, tickets, consent records, and uploaded media, is held in London.

Some processing happens elsewhere. Our hosting provider currently runs server code in the United States, holding data only in memory for the moment it takes to serve a request before writing it back to the United Kingdom. Payments, email delivery, push notifications, and some other services also involve providers outside the United Kingdom. The subprocessors page states, for each provider, exactly where it processes.

Where data leaves the United Kingdom we rely on one of: the UK International Data Transfer Agreement; the EU Standard Contractual Clauses together with the UK Addendum; or the UK Extension to the EU-US Data Privacy Framework where the provider is certified under it. We assess these transfers and can provide our assessments on request.

8. Data Retention

We keep information only as long as we need it, and delete or anonymise it on a schedule:

Two things deliberately survive an erasure request. The financial record of a sale, stripped of your details, is kept because we are legally required to keep accounting records. Consent records are kept because they are the only evidence that a message we sent you was lawful, and destroying them would remove your own ability to challenge it. Neither is ever used to contact you again.

Backups are overwritten on a rolling cycle and are fully replaced within 60 days.

9. Your Rights

You have the right to:

To exercise any of these rights, email privacy@grofomo.com. We acknowledge within 3 business days and respond within 30 days. Exercising a right is free, and we will never make you give a reason.

Where the request concerns data an event organiser controls (see §4.1), we will either pass it to them or help you reach them, and tell you which we have done.

You have the right to complain to the Information Commissioner’s Office at ico.org.uk. We would rather you came to us first, but you do not have to.

10. Data Deletion

You can delete your Grofomo account from Settings → Sign out and delete account in the app, or by emailing privacy@grofomo.com from the address you registered with. Deleting your account signs you out and removes the personal data linked to it: your device record, nickname and avatar, your magic-link email and auth record, your favourites and reminders, and friends entries naming you.

If you have bought tickets, deleting your account also anonymises your personal details (name, email, phone) on those past purchases, so the organiser keeps only a de-identified record of the sale for their own accounting and legal obligations. The exception is tickets for events that have not yet taken place: the organiser retains the details needed to admit you until after the event, after which your details are removed by routine cleanup. Deleting your account does not cancel or refund tickets you have already bought.

If you have submitted a Grofomo web form (e.g. a marketing opt-in or pre-sale registration), you can have the data captured there deleted by emailing privacy@grofomo.com from the address you registered with.

Full detail is on our data deletion page.

11. Information we hold that you did not give us

Grofomo maintains a public directory of artists and events, so that organisers can build lineups and audiences can find gigs. Some entries are compiled from publicly available sources rather than provided by the person concerned. That can include a performing name, a real name where it is publicly associated with the act, a biography, a location, publicly listed booking or press contact details, links to public social profiles, and publicly posted images.

Where it comes from. Public event listings and venue websites, public music and event databases including Resident Advisor, MusicBrainz, Wikidata and Spotify, and publicly accessible social media profiles.

Why we do it. Our legitimate interest, and that of the organisers who use the platform, in maintaining a usable directory of who performs where. We balance that against the interests of the people listed, which is why entries hold professional information only and never anything private.

Counting click-throughs. When someone follows a ticket link from a directory listing, we count that click so we can tell a venue how much traffic the directory sends it. We record the listing, which seller was clicked, the time, the website you came from, a broad device type and a two-letter country. We do not record your IP address, your full browser details or anything that identifies you, and we do not store anything on your device to do it.

What you can do. If you are listed, you can claim your profile and take control of it, correct it, ask us to restrict how it is used, or object to the listing entirely and ask us to remove it. Email privacy@grofomo.com and we will action it. We do not require you to justify the request.

12. Children

Grofomo is not directed at children under 13, and you must be 18 or over to buy a ticket. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with information, contact privacy@grofomo.com and we will delete it.

Data about a child can still reach the platform: a parent naming a child on a ticket they bought, or an organiser recording an under-18 volunteer. Where that happens the organiser is the controller and is responsible for handling it appropriately.

13. Security

All traffic between your device and the Service is encrypted with TLS, and data is encrypted at rest. Every table in our database enforces row-level access control, so a request can only ever return data the requester is entitled to. Device authentication uses signed tokens, and third-party access tokens are separately encrypted before storage. Provider credentials are held in environment-scoped secrets and never in our source code. Access by our staff follows least privilege and is removed when a role ends.

A fuller description of our technical and organisational measures is published as Annex 2 of our Data Processing Addendum. No system is perfectly secure, but we follow industry-standard practices, and if a breach ever affects your data we will tell you where the law requires it.

14. Changes to This Policy

We may update this policy. Material changes will be announced via in-app notification, push notification, or email at least 14 days before they take effect. The “Last Updated” date at the top of this page always reflects the most recent revision.

15. Contact

Deuce Creative Limited
Unit 8 Great Bramshot Farm Barns
Bramshot Lane
Fleet
Hampshire
GU51 2SF
United Kingdom

Privacy enquiries: privacy@grofomo.com


By using Grofomo, you acknowledge that you have read and understood this Privacy Policy.