Legal
Privacy policy
What we collect, why we have it, who else sees it, and what you can make us do about it. Written to be read rather than to be survived.
Last updated 28 August 2026
This document is not finished
The company details shown in square brackets below have not been filled in yet. Until they are, treat this page as a draft rather than a binding agreement.
1.Who is responsible for your data
[REGISTERED COMPANY NAME] ([CAC REGISTRATION NUMBER]), of [REGISTERED ADDRESS], operates CrowdBuzz and is the data controller for the information described here. We handle personal data under the Nigeria Data Protection Act 2023.
For anything about your data, write to [PRIVACY CONTACT EMAIL].
One thing to be clear about up front: when you buy a ticket, the organiser of that event also holds your details and is responsible for them separately from us. See clause 7.
2.What we collect
If you open an organiser account:
- Your name and email address.
- Your public handle, and anything you choose to add to your profile — a photo, a short description, a location.
- Your bank details, so your ticket money can reach you. See clause 3, because we deliberately store very little of this.
- The events you create, and the orders and tickets that result.
If you buy a ticket:
- Your name, email address and, where you give it, your phone number.
- What you bought, when, and for how much.
- Whether and when your ticket was scanned at the door.
Automatically, from any visit: the pages you looked at, roughly which country you were in, and what browser and device you used. We do not build advertising profiles and we do not sell any of this.
You do not need an account to buy a ticket, and we do not create one for you.
3.Bank details and card numbers
We never see your card number. It goes directly to our payment provider and never touches our systems. And of your bank account number, we store only the last four digits — enough to show you which account is connected, and useless to anybody who obtained it.
The full account number is passed to the payment provider once, so they can verify the account and settle your money into it. They hold it under their own licence and their own security obligations. We do not keep a copy.
4.Why we hold it
- To perform our contract with you — creating your account, taking payment, issuing tickets, letting a door scan them. Without this data the service cannot function.
- Because we have a legitimate interest — keeping the service secure, preventing fraud and duplicate tickets, understanding which pages people use so we can improve them.
- Because the law requires it — transaction records have to be kept for tax and anti-fraud purposes.
- Because you agreed — for anything optional, such as marketing email. You can withdraw that at any time.
5.Who else sees it
We share personal data only with the companies that make the service work, and only with what they need. We do not sell data to anybody.
PaystackPayments
Buyer name, email and card or bank details; the organiser's bank account for settlement.
Processes data in: Nigeria and the United States
SupabaseDatabase, accounts and file storage
Everything you or your buyers enter: account details, events, orders and tickets.
Processes data in: Outside Nigeria, depending on the region the project runs in
VercelHosting and site analytics
Technical request data — pages viewed, approximate country, browser type.
Processes data in: Global content network
ResendEmail delivery
The recipient's email address and the contents of tickets and receipts.
Processes data in: United States
We may also disclose data where we are legally required to, or to establish or defend a legal claim.
6.Where your data goes
Some of the companies above process data outside Nigeria. Where personal data leaves Nigeria we rely on the transfer conditions in the Nigeria Data Protection Act 2023, including contractual protections with each provider requiring them to protect it to a comparable standard.
7.Organisers and their attendees
If you buy a ticket, the organiser of that event receives your name, email address and what you bought. They need it to run the door and to contact you if the event changes.
That organiser is responsible for your data in their own right. What they do with it afterwards — including whether they email you about future events — is their decision and their legal obligation, not ours. If you want them to delete your details, ask them.
Organisers: exporting your attendee list makes you responsible for that copy of it.
8.How long we keep it
- Account details: while your account is open, and for a period afterwards to handle anything outstanding.
- Orders, tickets and transaction records: at least seven years, because tax and financial record-keeping rules require it. This is why closing your account does not erase your sales history.
- Technical and analytics data: a short period, in aggregate.
- Anything you asked us to delete, where no legal duty requires us to keep it: removed.
9.Your rights
Under the Nigeria Data Protection Act 2023 you can ask us to:
- Show you the personal data we hold about you.
- Correct it if it is wrong.
- Delete it, where we have no continuing legal reason to keep it.
- Stop or limit a particular use of it.
- Give you a copy in a portable format, or send it to somebody else.
- Stop sending you marketing, at any time and without a reason.
Write to [PRIVACY CONTACT EMAIL]. We will respond within thirty days. We may need to confirm who you are first, so that we do not hand your data to somebody else.
If you are not satisfied with how we have handled it, you can complain to the Nigeria Data Protection Commission.
10.Keeping it safe
- Everything travels over an encrypted connection.
- Access to data in our database is restricted at the row level, so one organiser cannot read another's events, orders or attendees.
- Card numbers never reach us, and we store only the last four digits of a bank account.
- Access to production systems is limited to those who need it.
No system is perfectly secure. If a breach occurs that is likely to put you at risk, we will notify you and the Commission as the law requires.
11.Children
The service is not for under-18s and we do not knowingly collect their data. An event may admit under-18s — that is the organiser's arrangement with them. If you believe a child has given us personal data, write to us and we will remove it.
12.Cookies
Covered separately, in short, on our cookie policy.
13.Changes
When this policy changes, the date at the top changes with it. If a change materially affects how we use your data, we will tell you before it takes effect.
Questions about anything on this page? Write to [CONTACT EMAIL].