Privacy Policy
RUNDOWN
Cayman's Events Platform
Privacy Policy
How Rundown collects, uses, shares, and protects your personal data. Applicable to all visitors, account holders, ticket purchasers, and event organizers using the Platform.
| DOCUMENT | Privacy Policy — v1.1 |
|---|---|
| OPERATOR | Rundown Events, a registered partnership in the Cayman Islands, t/a Rundown |
| TECHNOLOGY PROVIDER | Invovibe Tech Ltd (technical operation of the Platform) |
| PLATFORM | Rundown app (iOS, Android) and rundownevents.com |
| RELATED POLICIES | Terms of Use, Purchase Policy, Ticket Exchange Policy, Terms and Conditions, Merchant Agreement |
| GOVERNING LAW | Cayman Islands |
| EFFECTIVE | 23 May 2026 |
| LAST UPDATED | 27 July 2026 |
Introduction
This Privacy Policy (the “Policy”) explains how Rundown Events, a registered partnership in the Cayman Islands trading as “Rundown”, with operational offices at 18 Apple Blossom Gardens, P.O. Box 66, Grand Cayman KY1-1401, Cayman Islands (“Rundown”, “we”, “us”, or “our”), collects, uses, shares, and protects personal data in connection with the Rundown mobile application and the website at rundownevents.com (together, the “Platform”).
Technical operation of the Platform is overseen by Invovibe Tech Ltd, a Cayman Islands company engaged by Rundown Events as its technology service provider. Invovibe Tech Ltd processes personal data solely on behalf of, and under the instructions of, Rundown Events in its capacity as a data processor.
This Policy applies to all visitors to the Platform, registered account holders, ticket purchasers, ticket recipients, event organizers, and members of the public whose personal data is processed by us in connection with the Platform. For the purposes of the Cayman Islands Data Protection Act, 2017 (the “DPA”), Rundown is the data controller in respect of the personal data described in this Policy, except where this Policy states otherwise (for example, in respect of Attendee Data after it is made available to an event organizer through the Organizer Dashboard, where the organizer becomes the controller).
By accessing the Platform, creating a Rundown account, purchasing a ticket, accepting a transfer, listing an event, or otherwise interacting with us, you confirm that you have read and understood this Policy. This Policy works alongside the Rundown Terms of Use, the Rundown Purchase Policy, the Rundown Terms and Conditions (Ticket), the Rundown Ticket Exchange Policy, and (for event organizers) the Rundown Merchant Agreement. Capitalised terms used but not defined in this Policy have the meaning given to them in the Rundown Terms of Use.
1. What This Policy Covers
1.1 This Policy describes the personal data we collect when you use the Platform; the purposes for which we use that data; the parties with whom we share it; the choices and rights you have in respect of it; and how we protect, retain, and transfer it.
1.2 This Policy does not apply to: (a) the privacy practices of event organizers in respect of personal data they collect or process outside the Platform; (b) third-party websites or services that may be linked from the Platform; or (c) information that does not identify you and is not capable of being used to identify you (“anonymised data”). Anonymised data is not personal data and is not regulated by this Policy.
2. Personal Data We Collect
We collect personal data in three broad ways: directly from you when you provide it; automatically when you use the Platform; and from third-party sources. The specific categories we collect depend on how you use the Platform.
2.1 Data You Provide Directly
When you create or update a Rundown account, place an order, accept a ticket transfer, list an event, communicate with us, or otherwise interact with us, you may provide:
- identity and contact data, including your full name, email address, mobile phone number, profile photograph, date of birth (where required for age verification), and (for event organizers) trading name and business address;
- authentication data, including the password you choose, the unique identifier returned by a third-party sign-in provider (Apple, Google, or another supported provider), and the device identifiers associated with your sign-in sessions;
- payment data, including (in the case of card purchases) the last four digits of the card, the card brand, the cardholder name, and the billing postcode — the full card number and security code are entered directly into the secure interface of our payment processor and are not received or stored by Rundown;
- event and ticket data, including the events you save, follow, purchase, transfer, or sell; the tickets you redeem; and any preferences (such as accessibility requirements) you provide in connection with attendance;
- organizer onboarding data, including (where you create an Organizer account) information required for identity verification, business verification, banking details for payouts, and beneficial-ownership and source-of-funds information required by anti-money-laundering law;
- communications data, including any messages you send to us through in-app support, email, contact forms, social-media accounts operated by us, or otherwise;
- preferences data, including the categories of events you select, the organizers you follow, your notification preferences, and your language and currency selection.
2.2 Data Collected Automatically
When you use the Platform we automatically collect certain data about your device and how you interact with the Platform:
- device data, including device model, operating system and version, unique device identifier, mobile network operator, time zone, and language settings;
- usage data, including the screens you view, the searches you run, the events you save and follow, the items you add to a cart, the buttons you tap, the time and duration of your sessions, and how you arrived at the Platform (including the referring page or marketing campaign, where applicable);
- location data, where you grant location permission in the operating-system prompt, including coarse or precise location (as you choose) for the purpose of showing nearby events or applying location-based features;
- push-notification tokens, including the unique token issued by Apple Push Notification Service (APNs) or Firebase Cloud Messaging (FCM) for your device, used to deliver push notifications you have opted to receive;
- technical and security data, including the IP address from which you connect, browser type and version (where you use the web Platform), crash and error reports, and security-event data used to detect and prevent fraud, bot activity, and abuse.
2.3 Cookies and Similar Technologies
The web Platform uses cookies and similar technologies (such as web beacons, pixels, and local-storage objects) to operate the site, remember your preferences, measure performance, and (where you consent) support analytics and marketing. A short description of each cookie category, and how you can manage your preferences, is provided in our Cookie Notice (which forms part of this Policy and is presented in the cookie banner the first time you visit the web Platform). The mobile App uses analogous device-storage mechanisms, including secure key-value storage and local databases, to support similar functions.
2.4 Data from Third Parties
We may receive personal data about you from third parties, including:
- sign-in providers (Apple, Google, and any other supported provider) when you choose to create or access your Rundown account using their authentication services — typically your name, email address, and a stable provider-specific identifier;
- event organizers, where the organizer has collected information about you in connection with an event you attended, transferred, or registered for and has shared that information with us in accordance with the Merchant Agreement;
- payment processors and fraud-prevention providers, where they share information with us in connection with the processing or verification of a transaction (for example, the outcome of a card-authorisation request, a chargeback notification, or a fraud-risk score);
- identity-verification providers, where we use them to verify identity, age, or business credentials in connection with organizer onboarding or higher-tier account features;
- publicly available sources, where we use them to maintain or update our records (for example, the Cayman Islands General Registry, the Registrar of Non-Profit Organisations, or sanctions lists for compliance screening);
- social-media platforms, where you choose to share content from the Platform with a connected account, or where we run advertising on those platforms.
2.5 Children
The Platform is intended for users aged 16 and over. Users aged 16–17 should use the Platform with the consent of a parent or legal guardian. We do not knowingly collect personal data from children under 16. If you believe a child under 16 has provided personal data to us, please contact us at the address in section 14 and we will take reasonable steps to delete it.
3. How We Use Personal Data
We use personal data for the purposes set out below. For each purpose we identify, in brackets, the lawful basis on which we rely under the DPA: “contract” (necessary to perform a contract with you or to take steps at your request to enter into one), “legitimate interests” (necessary for our or a third party’s legitimate interests, which we have balanced against your rights), “consent” (where you have given consent), or “legal obligation” (necessary to comply with a legal obligation).
3.1 To create and operate your Rundown account — including authenticating sign-in, securing your account, displaying your profile, syncing your data across devices, and providing customer support (contract; legitimate interests).
3.2 To process orders and deliver tickets — including taking payment through our payment processor, issuing your digital ticket and confirmation, generating the QR code used for entry, recording transfers and resales, and providing post-purchase customer service (contract).
3.3 To operate event listings and the Ticket Exchange — including publishing event information submitted by organizers, ranking and surfacing listings, running search and discovery functions, and matching buyers and sellers on the Ticket Exchange (contract; legitimate interests).
3.4 To send you transactional and service communications — including order confirmations, ticket-transfer receipts, event reminders, event-change notifications, password resets, security alerts, and notices about changes to our policies. You cannot unsubscribe from these messages while you maintain a Rundown account, because they form part of the service (contract; legal obligation).
3.5 To send you marketing communications — including push notifications, email, and in-app messages about events you may like, organizers you follow, new features, and promotions. Where required by law we send marketing only where you have opted in, and you may opt out at any time using the unsubscribe link in any email, the in-app notification settings, or your device-level notification settings (consent; legitimate interests).
3.6 To personalise your experience — including ranking recommendations, surfacing categories you have shown interest in, remembering your location preference, and applying language and currency settings (legitimate interests; consent where required).
3.7 To measure and improve the Platform — including analytics on usage patterns, conversion funnels, performance, and crash diagnostics; A/B testing of new features; and product research (legitimate interests; consent where required for non-essential analytics).
3.8 To detect, prevent, and respond to fraud, abuse, and security incidents — including monitoring for bot activity, scalping, payment fraud, account takeover, chargeback fraud, and breaches of our Terms of Use and Other Policies (legitimate interests; legal obligation).
3.9 To comply with legal, regulatory, and risk-management obligations — including anti-money-laundering, counter-terrorist-financing, counter-proliferation-financing, sanctions-screening, tax-record-keeping, and other obligations applicable to us or our payment processor; responding to lawful requests from regulators, courts, or law-enforcement officers; and protecting our legal rights (legal obligation; legitimate interests).
3.10 To support corporate transactions — including in connection with a merger, acquisition, financing, corporate reorganisation, sale of business or assets, or insolvency, where personal data may be transferred or disclosed to the parties involved and their advisers (legitimate interests).
5. International Transfers
Our cloud-infrastructure providers (including Google Firebase, Google Cloud, and Stripe) operate global networks. As a result, your personal data may be transferred to, stored in, or processed in jurisdictions outside the Cayman Islands, including the United States, the United Kingdom, the European Union, and other regions. Where we transfer personal data outside the Cayman Islands we rely on the safeguards permitted under the DPA, including transfers to jurisdictions recognised as providing an adequate level of protection, transfers subject to contractual safeguards equivalent to the standard contractual clauses approved in the United Kingdom or European Union, transfers necessary for the performance of a contract with you, and transfers with your explicit consent. You can request further information about the safeguards we use by contacting us at the address in section 14.
6. Marketing and Communications
6.1 We send marketing communications by push notification, email, and in-app message about events, organizers, features, and promotions we think you may be interested in.
6.2 You can opt out of marketing at any time by: (a) tapping the unsubscribe link in any marketing email; (b) updating your in-app notification preferences in your Account → Notifications settings; or (c) disabling Rundown notifications at the operating-system level on your device. Opting out of marketing does not stop transactional and service communications described in section 3.4, because these form part of the service.
6.3 We do not engage in sale of personal data and do not engage in cross-context behavioural advertising for monetary or other valuable consideration as those terms are used in certain jurisdictions.
7. Data Retention
7.1 We keep personal data only for as long as we need it for the purposes for which it was collected. The actual retention period depends on the category of data and the purpose. The principles we apply are:
- Account data. Kept while your account is active and for a reasonable period after closure to allow for re-activation, dispute resolution, and chargeback windows.
- Order and ticket data. Kept for the period necessary to honour the order, support post-event customer service, and meet our legal record-keeping obligations (typically at least six years under Cayman Islands tax and accounting law).
- AML, sanctions, and identity-verification data. Kept for at least five years from the end of the business relationship, in accordance with the Anti-Money Laundering Regulations and CIMA guidance.
- Communications data. Kept for the period necessary to operate the support function and to demonstrate the quality of our service.
- Marketing data. Kept while you are subscribed to marketing and for a short period afterwards to suppress further marketing to you.
- Analytics and security data. Kept for limited periods aligned with the purposes for which the data was collected, after which it is deleted or anonymised.
7.2 When the retention period ends, we delete personal data or anonymise it so that it can no longer be associated with you. Where deletion is not technically feasible (for example, where personal data is held in routine backup archives), we isolate it from further processing until deletion becomes feasible.
8. Your Rights
Under the DPA you have a number of rights in respect of your personal data. We will respond to a valid request within the period required by law. We may need to verify your identity before responding, and we may charge a reasonable fee or refuse to respond where the law allows (for example, where the request is manifestly unfounded or excessive).
8.1 Right of access. You have the right to ask whether we hold personal data about you and, if so, to receive a copy of it, together with information about how we use it.
8.2 Right to rectification. You have the right to ask us to correct personal data that is inaccurate or incomplete. Many of these corrections can be made directly from your Account → Profile screen.
8.3 Right to stop or restrict processing. You have the right to ask us to stop or restrict our processing of your personal data in certain circumstances — for example, where you object to direct marketing, where you contest the accuracy of the data, or where the processing is unlawful but you do not want the data deleted.
8.4 Right to erasure. You have the right to ask us to delete personal data we hold about you in certain circumstances. You can initiate account deletion from your Account → Privacy & Data settings, which removes your profile data and disassociates your future activity from your identity. Some categories of data must be retained for the periods described in section 7 and cannot be deleted on request — for example, transaction records we are required to retain for tax, accounting, or AML purposes.
8.5 Right to data portability. Where we process your personal data by automated means under a contract with you or with your consent, you have the right to ask for a copy in a structured, commonly used, machine-readable format.
8.6 Right to object. You have the right to object to processing carried out on the basis of legitimate interests, including direct marketing. Where you object to direct marketing we will stop processing your personal data for that purpose.
8.7 Right not to be subject to automated decision-making. Some of our fraud-prevention, security, and risk-screening checks involve automated decisions (for example, automated rejection of an order flagged as high risk). You have the right to ask for human review of any such decision that has a significant effect on you.
8.8 Right to complain. If you believe we have not handled your personal data in accordance with the DPA, you have the right to complain to the Office of the Ombudsman (Cayman Islands), the supervisory authority for data protection. We would, however, appreciate the chance to deal with your concerns directly first — please contact us at the address in section 14.
8.9 How to exercise your rights. You can exercise your rights by contacting us using the details in section 14. Please describe your request clearly and provide enough information for us to verify your identity.
9. Security
9.1 We use technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, and unauthorised access. These include encryption in transit, encryption at rest for sensitive data categories, access controls, security monitoring, mandatory authentication for our staff, and (for organizer payouts) banking-grade controls through our payment processor.
9.2 No security measure is perfect. We cannot guarantee the security of personal data transmitted to or stored by us, and we accept no liability for unauthorised access to personal data that occurs despite our reasonable measures, except to the extent imposed on us by applicable law.
9.3 You play an important role in keeping your account secure. Please choose a strong password, do not share your password or sign-in tokens, sign out of devices you no longer use, and notify us promptly if you suspect any unauthorised activity on your account.
10. Linked Sites and Third-Party Content
10.1 The Platform may contain links to third-party websites and may display content from third-party services (including payment processors, mapping providers, identity-verification providers, insurance providers, and social-media platforms). When you follow a link to a third-party site or interact with third-party content, you leave the Platform and the third party’s privacy practices apply. We are not responsible for the content of, or the privacy practices of, any third-party site or service.
10.2 Event organizers operate independently of Rundown and have their own privacy practices. Once we share Attendee Data with an organizer in accordance with the Merchant Agreement, the organizer becomes a separate data controller in respect of that data and its handling is governed by the organizer’s own privacy policy.
11. Sensitive Personal Data
We do not require you to provide sensitive personal data (such as data about your health, religion, political opinions, or sexual orientation). Where you choose to share sensitive personal data with us — for example, an accessibility request that reveals a health condition — we will use it solely for the purpose for which you shared it. Where we are required by law to obtain explicit consent, we will request it before processing.
13. Changes to this Policy
13.1 We may update this Policy from time to time. The most recent version will be available on rundownevents.com and in the Rundown app, and we will indicate the date of the last update at the top of this Policy.
13.2 Where the change is material we will give you reasonable advance notice through the App, by email, or both before the change takes effect. Continued use of the Platform after the change takes effect constitutes acceptance of the updated Policy. If you do not agree with a change, you may stop using the Platform and close your account.
14. Contact and Data Protection Enquiries
14.1 Questions about this Policy, requests to exercise your data-protection rights, and other privacy-related enquiries can be sent to the privacy support email address published on rundownevents.com, or raised via our support page at https://rundownevents.com/support.
14.2 You may also contact us by post at Rundown Events t/a Rundown, 18 Apple Blossom Gardens, P.O. Box 66, Grand Cayman KY1-1401, Cayman Islands.
14.3 If you are not satisfied with our response, you have the right to complain to the Office of the Ombudsman (Cayman Islands).
— End of Privacy Policy —