Docs
Explore

Security and compliance

The laws and standards that apply, what we do for each, how data, payments and the door are protected, and who processes data for us.

This page sets out the laws and standards DEPARTMNT works to, and how data, payments and the door are protected. It is for brands, venues and their legal and security teams. How personal data is handled day to day, in plain words, is on Data and privacy.

Company and baseline

DEPARTMNT is the trading name of DEPARTMNT LABS UK LTD, company number 16465558, registered in England and Wales. The registered office is 71 to 75 Shelton Street, London WC2H 9JQ.

UK GDPR is the baseline. Compliance is never tiered: every client gets the same position, whatever they buy.

Laws and standards

Law or standardWhat it coversWhat we do
UK GDPRPersonal data, and the rights people hold over it.The client is the controller and DEPARTMNT is the processor. A data processing agreement comes with every account. See Data and privacy.
PECRConsent for marketing by push, email and SMS.Consent is given per purpose and recorded with the consent text version, the method and the time. Push is its own channel, separate from email. Marketing is a separate tick. Turning off is as easy as turning on.
DMCC ActShowing the full price up front, with no hidden fees added later.The full price is displayed.
Consumer Contracts RegulationsInformation, cancellation and refunds when people buy online.A refund policy is in place.
Martyn's LawPreparedness for public venues and events.Readiness for Martyn's Law, and a retention policy for door records.
Gambling Act 2005Lotteries and prize competitions. A draw that people pay to enter can be an unlicensed lottery.Free draws are structured as free prize draws under the Gambling Act. See Raffle and competition.
PCI DSSHandling card data.Stripe handles payment. No card data is stored or logged by DEPARTMNT.
ICO children's codeProtecting children online.Marketing is hidden unless a person has told us they are 18 or over, and the server refuses it too.

Security measures

Data

  • Row level security in the database
  • Fail closed defaults
  • Database changes are applied by a person
  • Exports are watermarked, with small cell suppression
  • Analytics use small cell suppression
  • Comment content never becomes a client metric

Notifications

  • Each device's push address and keys are encrypted at rest and looked up by a one way hash
  • Only signed in people can turn notifications on
  • Sends go through one audited action, and every send leaves an audit row
  • Analytics hold counts and purposes only, never a device address, key or message text
  • A notification only opens pages on the brand's own Portal

Payments and tags

No card data is stored or logged, Stripe handles payment, and payments use three layers of idempotency. Both tag tiers authenticate the tag. Tag tiers, authentication and Product Passports (DPP-ready) are on Tags and authentication.

The door

Door validation works offline, using a rotating signed credential. Offline, each device flags a ticket it has already scanned and shows the hold message, and a person decides. A repeat on a second device is detected when the devices sync, not prevented at the door, and one scan per ticket is enforced at the database once scans reach it.

Door logs record the device, the credential and the operator, not fan identity. Forged tickets and tickets from another organisation are rejected alike.

At the door, a human decides:

  • We never refuse entry automatically
  • The paper book stays the official record until a venue opts in
  • No photographs
  • No facial recognition
  • No automated purchase bans

When a scan needs attention, door staff see "Refer to a supervisor. Hold, do not admit." The screen never shows the reason.

Subprocessors

These are the third parties that process data on DEPARTMNT's behalf. Each is covered by an Article 28 data processing agreement.

SubprocessorPurpose
SupabaseDatabase and authentication
CloudflareNetwork and security
ResendEmail
StripePayments
UpstashCaching and rate limiting
VercelHosting
AppleApple Wallet passes

Our honest position

There has been no third party penetration test yet, and DEPARTMNT holds no certifications yet.

We would rather say so than imply otherwise. The measures above are what is built today. When a test or a certification is done, this page will say when and by whom.

Signed clients can find the security pack on Client downloads.