1. Who We Are
Stubmatic is operated by FiveW Technology Ltd, a company registered in England and Wales. Our registered office is at Wesley Clover Innovation Centre, Chepstow Road, Newport, NP18 2YB, United Kingdom.
FiveW Technology Ltd is the data controller for personal data processed through the Stubmatic platform. If you have any questions about how we handle your data, please contact us at hello@stubmatic.io.
2. What Data We Collect
We collect and process the following categories of personal data:
Account holders (Organisers):
- Name, email address, and password
- Business name and website URL
- Country, time zone, and currency preferences
- Billing information (processed by Stripe — we do not store card details)
- Event and sales data generated through use of the platform
Ticket Buyers:
- Name and email address
- Attendee names (if collected by the Organiser)
- Payment information (processed securely by Stripe or PayPal — we do not store card details)
- Any additional information requested by the Organiser (e.g. dietary requirements)
All visitors:
- IP address and browser information for security and analytics purposes
- Cookies — see Section 9 below
3. How We Use Your Data
We use personal data for the following purposes:
- To provide and operate the Stubmatic platform
- To process ticket purchases and send booking confirmations
- To manage your account and subscription
- To communicate with you about your account, events, or support requests
- To comply with legal obligations
- To detect and prevent fraud and abuse
- To improve the platform through anonymised analytics
4. Legal Basis for Processing
We process personal data on the following legal bases under UK GDPR:
- Contract: Processing necessary to provide the Service to Organisers and to fulfil ticket orders for Ticket Buyers
- Legitimate interests: Fraud prevention, platform security, and service improvement
- Legal obligation: Compliance with applicable laws and regulations
- Consent: Where you have opted in to marketing communications
5. Data Sharing
We do not sell your personal data. We share data only in the following circumstances:
- With Organisers: Ticket Buyer data (name, email, booking details) is made available to the Organiser of the relevant event. Organisers are independent data controllers and are responsible for handling this data in accordance with applicable data protection law.
- Payment processors: Stripe and PayPal process payment data in accordance with their own privacy policies and PCI-DSS compliance standards.
- Email delivery: We use SendGrid to deliver transactional emails. Email content and recipient addresses are shared with SendGrid solely for delivery purposes.
- Cloud infrastructure: We use Amazon Web Services (AWS) for file storage and DigitalOcean for hosting. Data is stored in the United Kingdom and European Economic Area.
- Legal requirements: We may disclose data if required to do so by law, court order, or governmental authority.
6. International Transfers
Some of our third-party service providers (including Stripe, PayPal, and SendGrid) may process data outside the UK and EEA. Where this occurs, we ensure appropriate safeguards are in place, such as the UK's International Data Transfer Agreement (IDTA) or equivalent mechanisms.
7. Data Retention
We retain personal data for as long as necessary to provide the Service and comply with legal obligations. Specifically:
- Account data is retained for the duration of your account plus up to 7 years for legal and financial compliance purposes
- Ticket Buyer data is retained for up to 7 years to comply with financial record-keeping requirements
- You may request deletion of your data at any time, subject to our legal obligations to retain certain records
8. Your Rights
Under UK GDPR, you have the following rights regarding your personal data:
- Right of access: Request a copy of the personal data we hold about you
- Right to rectification: Request correction of inaccurate data
- Right to erasure: Request deletion of your data in certain circumstances
- Right to restrict processing: Request that we limit how we use your data
- Right to data portability: Receive your data in a structured, machine-readable format
- Right to object: Object to processing based on legitimate interests
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time
To exercise any of these rights, please contact us at hello@stubmatic.io. We will respond within 30 days.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
9. Cookies
We use cookies and similar technologies to operate the platform. These include:
- Essential cookies: Required for the platform to function, including session management and security. These cannot be disabled.
- Analytics cookies: Used to understand how the platform is used, helping us improve the Service. These are anonymised and do not identify individuals.
We do not use advertising or tracking cookies, and we do not share cookie data with advertisers.
10. Security
We take security seriously. All data is transmitted over encrypted HTTPS connections. Passwords are hashed and never stored in plain text. Payment data is handled exclusively by PCI-DSS compliant processors. We regularly review our security practices.
For more detail, see our Security Statement.
11. Children's Privacy
Stubmatic is not directed at children under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by displaying a notice in your account. The date at the top of this page indicates when it was last updated.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, please contact us at:
FiveW Technology Ltd
Wesley Clover Innovation Centre
Chepstow Road, Newport
NP18 2YB, United Kingdom
hello@stubmatic.io