Data and privacy
Your data in plain words: who controls it, what a tap records, how consent and push work, your rights, and what happens when a plan ends.
This page explains, in plain words, what happens to personal data when someone taps a tag, signs up to a Portal or turns on notifications. It is for brands planning a project and for anyone who has tapped a tag and wants to know what was recorded. The legal baseline and the laws we follow are on Security and compliance.
Your data in one minute
- A tap is not a person. A tap records which tag, when, and the category of device. Nothing about a tap identifies you on its own.
- Core does not follow anybody. Every tap is a person choosing to take part. Nothing follows you between taps.
- Signing up is your choice. A record of you starts only when you create an account or give an email address.
- The brand owns its data. The brand you tapped is the controller. DEPARTMNT processes the data for it, under contract.
- You choose what you hear about. Notifications and marketing are separate choices, each recorded, and you can withdraw any of them.
- You can see it, fix it or delete it. Ask for a copy, a correction or deletion at any time, or delete your account yourself.
Who controls the data
- YouThe person who taps and signs up
- Choose to sign up
- Choose each consent
- Exercise your rights
- The brandController
- Decides why data is collected
- Owns its audience
- Answers your requests
- DEPARTMNTProcessor
- Runs the Portal and Core
- Acts only on the brand's instructions
- Passes your requests to the brand
- SubprocessorsServices we use
- Hosting, database, email, payments
- Each under a data processing agreement
Today, the client is the controller and DEPARTMNT is the processor. When a brand runs an activation on our platform, it controls the records it collects and owns its data, and we process them under contract on its behalf. A data processing agreement comes with every account, and the terms are in Agreements and terms.
Fan identity stays in the Portal. Core has a Fans view, with a record per fan, for the brand that holds the relationship. Analytics in Core are consent filtered aggregates with small cell suppression, and exports are consent filtered and watermarked.
Requests from people about their data go to the brand as controller; if one reaches DEPARTMNT, we pass it on and support it. The subprocessors are listed on Security and compliance.
What a tap records
A tap records which tag was tapped, when, and the category of device. It is a record of presence, not of a person, until someone chooses to sign up. A tag itself stores a UXID and a link, never personal data.
Core records a tap, where it happened and when, and whatever someone chose to share after it. Because every tap is a person choosing to take part, the count is worth trusting.
If you create an account or give an email address, that is a deliberate act. The record becomes yours as well as the brand's, and you can ask for it or ask for it to be deleted. Consented device trust is how a returning device is recognised against an existing DEPT ID.
Consent
Every consent is recorded with its purpose, wording version and time, and withdrawal is honoured. Consent is versioned per named partner, and each record holds the wording version, the time, the method and the scope. Consent capture is part of Core Connect.
Giving an address is never a scoring input.
Push notifications
Push notifications are available, as web push with no app; see Push notifications. Push is its own channel, separate from email, and these consent rules apply:
- The brand asks first. The brand's own card asks before the phone does, at a moment when notifications are clearly useful, such as just after an RSVP or a claim. "Not now" carries equal weight.
- The phone's prompt comes second. It appears only to people who have already said yes on the card. On iPhone and iPad, the Portal is added to the Home Screen first.
- Consent is per purpose. For example event updates, drops and marketing. Each is recorded with the consent text version, the method and the time.
- Nothing is preticked. Marketing is its own optional tick, never bundled into the main yes.
- Marketing is 18+ only. It is hidden unless the person has told us they are 18 or over, and the server refuses it too.
- No nagging. The card asks at most three times per device, at least 14 days apart.
- Turning off is as easy as turning on. Settings, then Turn off, within two taps. Changes apply on all of a person's devices.
- A claim never depends on it. Saying no to notifications never blocks a claim or the page.
Your rights
| Right | What it means | How to use it |
|---|---|---|
| Access | A copy of what is held about you. | Ask the brand. If you ask us, we pass it on. |
| Correction | Fix anything that is wrong. | Edit your profile in the Portal, or ask the brand. |
| Erasure | Have your record deleted. | Delete your account from the account drawer, at any time, or ask the brand. |
| Objection | Ask for your data not to be used for a purpose. | Ask the brand. If you ask us, we pass it on. |
| Withdrawing consent | Change your mind about something you agreed to. | Untick the purpose in Settings. Turning notifications off takes two taps. |
Retention and erasure
People can delete their own account from the account drawer, at any time. This is part of Core Identity.
| Data | How long it is kept |
|---|---|
| Ticket buyer email | Kept while a ticket is live, then anonymised after the event plus a grace period |
| Push device records | Removed when the account is deleted |
| Consent records | Kept as proof of consent, under their own retention rule |
| Audit logs | Kept |
| Everything else | To be confirmed |
End of a campaign
When a campaign ends, tags stay live and can be repointed without reprinting. Tags in the field stay encoded against their host and cannot move to another host.
When a plan ends, this is what persists:
| State | What |
|---|---|
| Still works | Tap function, user profiles, memberships |
| Limited | Portal hosting, support |
| Export only | Analytics |
| Off | Portal builder, tag deployment, ticketing, notifications |
| Suspended | Gamification, integrations and API |
For people who have tapped a tag, Your profile and data explains the same things in the Help section.