Security and compliance
The laws and standards that apply, what we do for each, how data, payments and the door are protected, and who processes data for us.
This page sets out the laws and standards DEPARTMNT works to, and how data, payments and the door are protected. It is for brands, venues and their legal and security teams. How personal data is handled day to day, in plain words, is on Data and privacy.
Company and baseline
DEPARTMNT is the trading name of DEPARTMNT LABS UK LTD, company number 16465558, registered in England and Wales. The registered office is 71 to 75 Shelton Street, London WC2H 9JQ.
UK GDPR is the baseline. Compliance is never tiered: every client gets the same position, whatever they buy.
Laws and standards
| Law or standard | What it covers | What we do |
|---|---|---|
| UK GDPR | Personal data, and the rights people hold over it. | The client is the controller and DEPARTMNT is the processor. A data processing agreement comes with every account. See Data and privacy. |
| PECR | Consent for marketing by push, email and SMS. | Consent is given per purpose and recorded with the consent text version, the method and the time. Push is its own channel, separate from email. Marketing is a separate tick. Turning off is as easy as turning on. |
| DMCC Act | Showing the full price up front, with no hidden fees added later. | The full price is displayed. |
| Consumer Contracts Regulations | Information, cancellation and refunds when people buy online. | A refund policy is in place. |
| Martyn's Law | Preparedness for public venues and events. | Readiness for Martyn's Law, and a retention policy for door records. |
| Gambling Act 2005 | Lotteries and prize competitions. A draw that people pay to enter can be an unlicensed lottery. | Free draws are structured as free prize draws under the Gambling Act. See Raffle and competition. |
| PCI DSS | Handling card data. | Stripe handles payment. No card data is stored or logged by DEPARTMNT. |
| ICO children's code | Protecting children online. | Marketing is hidden unless a person has told us they are 18 or over, and the server refuses it too. |
Security measures
Data
- Row level security in the database
- Fail closed defaults
- Database changes are applied by a person
- Exports are watermarked, with small cell suppression
- Analytics use small cell suppression
- Comment content never becomes a client metric
Notifications
- Each device's push address and keys are encrypted at rest and looked up by a one way hash
- Only signed in people can turn notifications on
- Sends go through one audited action, and every send leaves an audit row
- Analytics hold counts and purposes only, never a device address, key or message text
- A notification only opens pages on the brand's own Portal
Payments and tags
No card data is stored or logged, Stripe handles payment, and payments use three layers of idempotency. Both tag tiers authenticate the tag. Tag tiers, authentication and Product Passports (DPP-ready) are on Tags and authentication.
The door
Door validation works offline, using a rotating signed credential. Offline, each device flags a ticket it has already scanned and shows the hold message, and a person decides. A repeat on a second device is detected when the devices sync, not prevented at the door, and one scan per ticket is enforced at the database once scans reach it.
Door logs record the device, the credential and the operator, not fan identity. Forged tickets and tickets from another organisation are rejected alike.
At the door, a human decides:
- We never refuse entry automatically
- The paper book stays the official record until a venue opts in
- No photographs
- No facial recognition
- No automated purchase bans
When a scan needs attention, door staff see "Refer to a supervisor. Hold, do not admit." The screen never shows the reason.
Subprocessors
These are the third parties that process data on DEPARTMNT's behalf. Each is covered by an Article 28 data processing agreement.
| Subprocessor | Purpose |
|---|---|
| Supabase | Database and authentication |
| Cloudflare | Network and security |
| Resend | |
| Stripe | Payments |
| Upstash | Caching and rate limiting |
| Vercel | Hosting |
| Apple | Apple Wallet passes |
Our honest position
There has been no third party penetration test yet, and DEPARTMNT holds no certifications yet.
We would rather say so than imply otherwise. The measures above are what is built today. When a test or a certification is done, this page will say when and by whom.
Signed clients can find the security pack on Client downloads.