RUNDOWN

Cayman's Events Platform

Privacy Policy

How Rundown collects, uses, shares, and protects your personal data. Applicable to all visitors, account holders, ticket purchasers, and event organizers using the Platform.

This Privacy Policy (the “Policy”) explains how Rundown Events, a registered partnership in the Cayman Islands trading as “Rundown”, with operational offices at 18 Apple Blossom Gardens, P.O. Box 66, Grand Cayman KY1-1401, Cayman Islands (“Rundown”, “we”, “us”, or “our”), collects, uses, shares, and protects personal data in connection with the Rundown mobile application and the website at rundownevents.com (together, the “Platform”).

Technical operation of the Platform is overseen by Invovibe Tech Ltd, a Cayman Islands company engaged by Rundown Events as its technology service provider. Invovibe Tech Ltd processes personal data solely on behalf of, and under the instructions of, Rundown Events in its capacity as a data processor.

This Policy applies to all visitors to the Platform, registered account holders, ticket purchasers, ticket recipients, event organizers, and members of the public whose personal data is processed by us in connection with the Platform. For the purposes of the Cayman Islands Data Protection Act, 2017 (the “DPA”), Rundown is the data controller in respect of the personal data described in this Policy, except where this Policy states otherwise (for example, in respect of Attendee Data after it is made available to an event organizer through the Organizer Dashboard, where the organizer becomes the controller).

By accessing the Platform, creating a Rundown account, purchasing a ticket, accepting a transfer, listing an event, or otherwise interacting with us, you confirm that you have read and understood this Policy. This Policy works alongside the Rundown Terms of Use, the Rundown Purchase Policy, the Rundown Terms and Conditions (Ticket), the Rundown Ticket Exchange Policy, and (for event organizers) the Rundown Merchant Agreement. Capitalised terms used but not defined in this Policy have the meaning given to them in the Rundown Terms of Use.

1.1 This Policy describes the personal data we collect when you use the Platform; the purposes for which we use that data; the parties with whom we share it; the choices and rights you have in respect of it; and how we protect, retain, and transfer it.

1.2 This Policy does not apply to: (a) the privacy practices of event organizers in respect of personal data they collect or process outside the Platform; (b) third-party websites or services that may be linked from the Platform; or (c) information that does not identify you and is not capable of being used to identify you (“anonymised data”). Anonymised data is not personal data and is not regulated by this Policy.

We collect personal data in three broad ways: directly from you when you provide it; automatically when you use the Platform; and from third-party sources. The specific categories we collect depend on how you use the Platform.

2.1 Data You Provide Directly

When you create or update a Rundown account, place an order, accept a ticket transfer, list an event, communicate with us, or otherwise interact with us, you may provide:

2.2 Data Collected Automatically

When you use the Platform we automatically collect certain data about your device and how you interact with the Platform:

2.3 Cookies and Similar Technologies

The web Platform uses cookies and similar technologies (such as web beacons, pixels, and local-storage objects) to operate the site, remember your preferences, measure performance, and (where you consent) support analytics and marketing. A short description of each cookie category, and how you can manage your preferences, is provided in our Cookie Notice (which forms part of this Policy and is presented in the cookie banner the first time you visit the web Platform). The mobile App uses analogous device-storage mechanisms, including secure key-value storage and local databases, to support similar functions.

2.4 Data from Third Parties

We may receive personal data about you from third parties, including:

2.5 Children

The Platform is intended for users aged 16 and over. Users aged 16–17 should use the Platform with the consent of a parent or legal guardian. We do not knowingly collect personal data from children under 16. If you believe a child under 16 has provided personal data to us, please contact us at the address in section 14 and we will take reasonable steps to delete it.

We use personal data for the purposes set out below. For each purpose we identify, in brackets, the lawful basis on which we rely under the DPA: “contract” (necessary to perform a contract with you or to take steps at your request to enter into one), “legitimate interests” (necessary for our or a third party’s legitimate interests, which we have balanced against your rights), “consent” (where you have given consent), or “legal obligation” (necessary to comply with a legal obligation).

3.1 To create and operate your Rundown account — including authenticating sign-in, securing your account, displaying your profile, syncing your data across devices, and providing customer support (contract; legitimate interests).

3.2 To process orders and deliver tickets — including taking payment through our payment processor, issuing your digital ticket and confirmation, generating the QR code used for entry, recording transfers and resales, and providing post-purchase customer service (contract).

3.3 To operate event listings and the Ticket Exchange — including publishing event information submitted by organizers, ranking and surfacing listings, running search and discovery functions, and matching buyers and sellers on the Ticket Exchange (contract; legitimate interests).

3.4 To send you transactional and service communications — including order confirmations, ticket-transfer receipts, event reminders, event-change notifications, password resets, security alerts, and notices about changes to our policies. You cannot unsubscribe from these messages while you maintain a Rundown account, because they form part of the service (contract; legal obligation).

3.5 To send you marketing communications — including push notifications, email, and in-app messages about events you may like, organizers you follow, new features, and promotions. Where required by law we send marketing only where you have opted in, and you may opt out at any time using the unsubscribe link in any email, the in-app notification settings, or your device-level notification settings (consent; legitimate interests).

3.6 To personalise your experience — including ranking recommendations, surfacing categories you have shown interest in, remembering your location preference, and applying language and currency settings (legitimate interests; consent where required).

3.7 To measure and improve the Platform — including analytics on usage patterns, conversion funnels, performance, and crash diagnostics; A/B testing of new features; and product research (legitimate interests; consent where required for non-essential analytics).

3.8 To detect, prevent, and respond to fraud, abuse, and security incidents — including monitoring for bot activity, scalping, payment fraud, account takeover, chargeback fraud, and breaches of our Terms of Use and Other Policies (legitimate interests; legal obligation).

3.9 To comply with legal, regulatory, and risk-management obligations — including anti-money-laundering, counter-terrorist-financing, counter-proliferation-financing, sanctions-screening, tax-record-keeping, and other obligations applicable to us or our payment processor; responding to lawful requests from regulators, courts, or law-enforcement officers; and protecting our legal rights (legal obligation; legitimate interests).

3.10 To support corporate transactions — including in connection with a merger, acquisition, financing, corporate reorganisation, sale of business or assets, or insolvency, where personal data may be transferred or disclosed to the parties involved and their advisers (legitimate interests).

We share personal data with the categories of recipient described below. We do not sell your personal data.

4.1 Event organizers. When you purchase, transfer, or attempt entry to an event, we share with the relevant organizer the personal data they need to operate the event and provide customer service in connection with it — typically your name, email address, ticket tier, order reference, and any accessibility information you have chosen to provide. Once the organizer receives this data through the Organizer Dashboard, the organizer becomes a separate data controller in respect of it and its handling of that data is governed by the organizer’s own privacy policy and by the Rundown Merchant Agreement.

4.2 Payment processors. We use Stripe (and any other processor we may engage from time to time) to process payments, run fraud-prevention checks, manage payouts to organizers, and handle chargebacks. Stripe operates under its own privacy policy and may collect data directly from you through its secure card-input interface.

4.3 Identity-verification and compliance providers. We use specialist providers to verify identity, age, business credentials, beneficial ownership, source of funds, and sanctions status, particularly in connection with organizer onboarding, higher-tier purchases, and AML compliance.

4.4 Communications providers. We use providers for transactional email, SMS, and push notifications, including Apple Push Notification Service, Firebase Cloud Messaging, and email-delivery services. These providers process data on our behalf strictly to deliver the relevant communication.

4.5 Infrastructure and hosting providers. The Platform is built on Google Firebase services (Firestore, Authentication, Cloud Functions, Cloud Storage, Cloud Messaging, Analytics for Firebase, Crashlytics) and Google Cloud, which host and process data on our behalf in data centres operated by Google. We may use other cloud-infrastructure providers from time to time.

4.6 Analytics and product-research providers. We use analytics tools to understand how the Platform is used, identify defects, and measure the performance of features. Where required by law these are activated only with your consent.

4.7 Insurance providers. Where you purchase Missed Event Insurance or a similar protection product, we share the limited personal data necessary to bind and administer that policy with the insurance provider. The insurance contract is between you and the provider; the provider operates under its own privacy policy.

4.8 Professional advisers. We share personal data with our legal, accounting, audit, tax, banking, and insurance advisers where necessary in connection with their advice or services to us.

4.9 Regulators, law-enforcement officers, and other authorities. We share personal data with regulators, courts, law-enforcement officers, the Cayman Islands Financial Reporting Authority, the Cayman Islands Monetary Authority, the Office of the Ombudsman, and analogous authorities where we are required to do so by law, by court order, by regulator request, or by payment-processor direction, or where we reasonably believe disclosure is necessary to prevent harm, fraud, or unlawful activity.

4.10 Acquirers and prospective acquirers. Where we are involved in a merger, acquisition, financing, corporate reorganisation, sale of business or assets, or insolvency, we may share personal data with the parties involved and their professional advisers, subject to appropriate confidentiality and data-protection commitments.

4.11 With your direction. We share personal data with other parties where you direct us to do so — for example, when you transfer a ticket to a named recipient, when you list a ticket on the Ticket Exchange, or when you choose to share an event listing through a third-party app.

Our cloud-infrastructure providers (including Google Firebase, Google Cloud, and Stripe) operate global networks. As a result, your personal data may be transferred to, stored in, or processed in jurisdictions outside the Cayman Islands, including the United States, the United Kingdom, the European Union, and other regions. Where we transfer personal data outside the Cayman Islands we rely on the safeguards permitted under the DPA, including transfers to jurisdictions recognised as providing an adequate level of protection, transfers subject to contractual safeguards equivalent to the standard contractual clauses approved in the United Kingdom or European Union, transfers necessary for the performance of a contract with you, and transfers with your explicit consent. You can request further information about the safeguards we use by contacting us at the address in section 14.

6.1 We send marketing communications by push notification, email, and in-app message about events, organizers, features, and promotions we think you may be interested in.

6.2 You can opt out of marketing at any time by: (a) tapping the unsubscribe link in any marketing email; (b) updating your in-app notification preferences in your Account → Notifications settings; or (c) disabling Rundown notifications at the operating-system level on your device. Opting out of marketing does not stop transactional and service communications described in section 3.4, because these form part of the service.

6.3 We do not engage in sale of personal data and do not engage in cross-context behavioural advertising for monetary or other valuable consideration as those terms are used in certain jurisdictions.

7.1 We keep personal data only for as long as we need it for the purposes for which it was collected. The actual retention period depends on the category of data and the purpose. The principles we apply are:

7.2 When the retention period ends, we delete personal data or anonymise it so that it can no longer be associated with you. Where deletion is not technically feasible (for example, where personal data is held in routine backup archives), we isolate it from further processing until deletion becomes feasible.

Under the DPA you have a number of rights in respect of your personal data. We will respond to a valid request within the period required by law. We may need to verify your identity before responding, and we may charge a reasonable fee or refuse to respond where the law allows (for example, where the request is manifestly unfounded or excessive).

8.1 Right of access. You have the right to ask whether we hold personal data about you and, if so, to receive a copy of it, together with information about how we use it.

8.2 Right to rectification. You have the right to ask us to correct personal data that is inaccurate or incomplete. Many of these corrections can be made directly from your Account → Profile screen.

8.3 Right to stop or restrict processing. You have the right to ask us to stop or restrict our processing of your personal data in certain circumstances — for example, where you object to direct marketing, where you contest the accuracy of the data, or where the processing is unlawful but you do not want the data deleted.

8.4 Right to erasure. You have the right to ask us to delete personal data we hold about you in certain circumstances. You can initiate account deletion from your Account → Privacy & Data settings, which removes your profile data and disassociates your future activity from your identity. Some categories of data must be retained for the periods described in section 7 and cannot be deleted on request — for example, transaction records we are required to retain for tax, accounting, or AML purposes.

8.5 Right to data portability. Where we process your personal data by automated means under a contract with you or with your consent, you have the right to ask for a copy in a structured, commonly used, machine-readable format.

8.6 Right to object. You have the right to object to processing carried out on the basis of legitimate interests, including direct marketing. Where you object to direct marketing we will stop processing your personal data for that purpose.

8.7 Right not to be subject to automated decision-making. Some of our fraud-prevention, security, and risk-screening checks involve automated decisions (for example, automated rejection of an order flagged as high risk). You have the right to ask for human review of any such decision that has a significant effect on you.

8.8 Right to complain. If you believe we have not handled your personal data in accordance with the DPA, you have the right to complain to the Office of the Ombudsman (Cayman Islands), the supervisory authority for data protection. We would, however, appreciate the chance to deal with your concerns directly first — please contact us at the address in section 14.

8.9 How to exercise your rights. You can exercise your rights by contacting us using the details in section 14. Please describe your request clearly and provide enough information for us to verify your identity.

9.1 We use technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, and unauthorised access. These include encryption in transit, encryption at rest for sensitive data categories, access controls, security monitoring, mandatory authentication for our staff, and (for organizer payouts) banking-grade controls through our payment processor.

9.2 No security measure is perfect. We cannot guarantee the security of personal data transmitted to or stored by us, and we accept no liability for unauthorised access to personal data that occurs despite our reasonable measures, except to the extent imposed on us by applicable law.

9.3 You play an important role in keeping your account secure. Please choose a strong password, do not share your password or sign-in tokens, sign out of devices you no longer use, and notify us promptly if you suspect any unauthorised activity on your account.

10.1 The Platform may contain links to third-party websites and may display content from third-party services (including payment processors, mapping providers, identity-verification providers, insurance providers, and social-media platforms). When you follow a link to a third-party site or interact with third-party content, you leave the Platform and the third party’s privacy practices apply. We are not responsible for the content of, or the privacy practices of, any third-party site or service.

10.2 Event organizers operate independently of Rundown and have their own privacy practices. Once we share Attendee Data with an organizer in accordance with the Merchant Agreement, the organizer becomes a separate data controller in respect of that data and its handling is governed by the organizer’s own privacy policy.

We do not require you to provide sensitive personal data (such as data about your health, religion, political opinions, or sexual orientation). Where you choose to share sensitive personal data with us — for example, an accessibility request that reveals a health condition — we will use it solely for the purpose for which you shared it. Where we are required by law to obtain explicit consent, we will request it before processing.

For the web Platform, we maintain a separate Cookie Notice describing each cookie category, the purpose it serves, its retention, and how you can manage your preferences. You will see the Cookie Notice in the cookie banner the first time you visit the web Platform, and you can change your preferences at any time through the “Cookie Preferences” link in the footer. The mobile App uses analogous device-storage mechanisms, configured to follow the operating-system-level tracking and analytics settings on your device.

13.1 We may update this Policy from time to time. The most recent version will be available on rundownevents.com and in the Rundown app, and we will indicate the date of the last update at the top of this Policy.

13.2 Where the change is material we will give you reasonable advance notice through the App, by email, or both before the change takes effect. Continued use of the Platform after the change takes effect constitutes acceptance of the updated Policy. If you do not agree with a change, you may stop using the Platform and close your account.

14.1 Questions about this Policy, requests to exercise your data-protection rights, and other privacy-related enquiries can be sent to the privacy support email address published on rundownevents.com, or raised via our support page at https://rundownevents.com/support.

14.2 You may also contact us by post at Rundown Events t/a Rundown, 18 Apple Blossom Gardens, P.O. Box 66, Grand Cayman KY1-1401, Cayman Islands.

14.3 If you are not satisfied with our response, you have the right to complain to the Office of the Ombudsman (Cayman Islands).

— End of Privacy Policy —

← Back to Rundown