Privacy Policy
Last updated: 6 June 2026
1. About this policy
This Privacy Policy explains how Fidget collects, uses, shares, and protects personal data when people use the website and related services.
Fidget is an events discovery and ticket-comparison platform with features including search, favourites, personalised "For You" recommendations, optional music-service connections, and location-based discovery.
2. Controller details
The controller of personal data processed through Fidget is:
- Legal name: Fidget
- Contact email: [email protected]
Processors and sub-processors
Fidget uses service providers to operate the platform, including providers for cloud hosting and databases, authentication (including Google Sign-In where enabled), transactional email (Bird), error monitoring (Sentry), and product analytics (PostHog, when enabled). These providers process personal data on Fidget's instructions and under appropriate contractual safeguards.
Client-side analytics and diagnostics (PostHog, Sentry in the browser) run only after you choose to allow them in the cookie consent tool. Server-side operational telemetry for auth and email flows (for example sign-up, verification, and password reset) may be logged using opaque user identifiers to monitor service reliability; this is separate from optional browser analytics and is not controlled by the cookie banner's analytics toggle.
Marketing vs cookie consent
Email marketing: If you opt in when creating an account or in account settings, Fidget may send you news and updates by email. That preference is stored on your account (marketingOptIn), not in advertising cookies.
Advertising / tracking cookies: Fidget does not currently use advertising or cross-site marketing cookies. If introduced later, they would require appropriate consent via the cookie tool and this policy would be updated.
3. Personal data collected
Depending on how the service is used, Fidget may collect:
- Account data, such as name, email address, encrypted credentials, and account settings.
- Preference data, such as favourite artists, venues, events, followed genres, hidden content, and recommendation settings.
- Search and usage data, such as searches, filters used, viewed events, clicks, saved items, and outbound ticket-link interactions.
- Integration data from connected music services, limited to the data and permissions the user authorises and that are necessary to power relevant features.
- Device and technical data, such as IP address, browser type, device identifiers, operating system, language settings, crash logs, and security logs.
- Location data, including approximate location inferred from IP address and, where permitted, more precise device location used for nearby discovery or localisation.
- Communication data, such as support messages, survey responses, and feedback.
- Marketing and consent data, such as alert preferences, newsletter status, consent signals, and suppression records.
Email marketing opt-in is collected at registration or in account settings and stored on your account. Optional browser cookies for analytics, diagnostics, and (future) advertising are managed separately via the Cookies Policy and cookie consent tool.
4. How data is collected
Personal data may be collected:
- Directly from users when they create an account, save favourites, connect services, subscribe to alerts, contact support, or otherwise use the platform.
- Automatically through cookies, logs, analytics tools, and similar technologies.
- From third-party providers, such as authentication providers, connected music services, event data suppliers, or ticketing partners, where relevant to the feature used.
5. Purposes and legal bases
Under UK GDPR and, where applicable, EU GDPR, Fidget may process personal data for the following purposes:
| Purpose | Examples | Legal basis |
|---|---|---|
| Provide the service | Search, compare, save favourites, manage accounts, maintain session state | Contract or steps prior to contract |
| Personalise content | Recommend events, highlight favourite artists, rank results, localise discovery | Legitimate interests; consent where required |
| Run optional integrations | Connect music services and use authorised data for discovery features | Contract; consent; legitimate interests depending on the feature |
| Operate and secure the platform | Monitoring, debugging, fraud prevention, rate limiting, abuse detection | Legitimate interests; legal obligation where applicable |
| Communicate with users | Service emails, alerts, transactional notices, support replies | Contract; legitimate interests |
| Send marketing | Newsletters and promotional communications | Consent where required; legitimate interests where lawfully permitted |
| Comply with law | Record keeping, legal claims, regulatory requests, tax or compliance obligations | Legal obligation; legitimate interests |
Where legitimate interests are relied on, those interests generally include operating, securing, improving, and growing the service while applying safeguards proportionate to users' rights and expectations.
6. Personalisation and profiling
Fidget may use favourites, search history, filter behaviour, saved items, location signals, and interaction history to personalise rankings, recommendations, and "For You" content.
If a user connects a music service, Fidget may use authorised data from that service to improve relevance. Personalisation is intended to improve discovery and does not normally involve automated decisions with legal or similarly significant effects.
7. Sharing personal data
Personal data may be shared with:
- Hosting, infrastructure, database, analytics, email, authentication, customer-support, and security providers.
- Music-service providers where a user chooses to connect an account.
- Ticketing partners, event data suppliers, venues, organisers, and promoters where needed to support referral journeys, attribution, fraud prevention, or operational reporting.
- Professional advisers, auditors, insurers, courts, regulators, and law enforcement where necessary.
- Buyers, investors, lenders, or group companies in connection with a merger, acquisition, financing, or reorganisation.
Fidget does not sell personal data in the ordinary meaning of that term. If advertising or cross-context behavioural advertising is later introduced, this policy should be updated accordingly.
8. International transfers
Some suppliers or partners may process personal data outside the UK or EEA. Where that happens, Fidget should use a lawful transfer mechanism, such as adequacy regulations, standard contractual clauses, or the UK international data transfer addendum, as applicable.
9. Retention
Personal data is kept only for as long as reasonably necessary for the purposes described in this policy, including to provide services, keep appropriate records, resolve disputes, enforce agreements, and comply with legal obligations.
Retention periods should be documented internally for categories such as account data, logs, support messages, consent records, and marketing suppression lists.
10. User rights
Depending on applicable law, users may have the right to:
- Access personal data.
- Correct inaccurate or incomplete personal data.
- Request deletion of personal data.
- Restrict processing.
- Object to processing based on legitimate interests.
- Request portability of data provided by the user.
- Withdraw consent at any time where processing relies on consent.
- Lodge a complaint with the Information Commissioner's Office or another competent regulator.
Requests may be sent to [email protected]. Fidget may request information necessary to verify identity before acting on a request.
11. Children's data
Fidget is not directed at children. The minimum permitted user age is 18 years, or the age of legal majority in the user's jurisdiction if higher, as stated in the Terms and Conditions.
Account creation requires acceptance of the Terms and Privacy Policy, which include this age requirement. Fidget does not operate a separate age-verification or parental-consent workflow because accounts are not offered to users below the minimum age. If Fidget learns that an account was created by someone below the minimum age, that account may be suspended or deleted.
12. Security
Fidget should use appropriate technical and organisational measures to protect personal data, including least-privilege access controls, encryption where appropriate, logging, vulnerability management, and incident-response processes. No online service can guarantee absolute security.
13. Third-party services
Fidget may link to or integrate with third-party ticket sellers, organisers, venues, music platforms, maps, and authentication providers. Those third parties process data under their own terms and privacy notices.
14. Changes to this policy
This Privacy Policy may be updated from time to time to reflect service changes, legal developments, or operational requirements. The latest version should be published on the website with the revised effective date.
15. Contact
Privacy questions and rights requests should be sent to:
- Email: [email protected]