BackV1 · 15 September 2026

Privacy Policy

Curated Technologies Limited (trading as SwipeOnDeck)

Effective date: 15 September 2026

1. Who we are

Curated Technologies Limited (“Deck”, “we”, “us”) is the data controller for the personal data described in this policy.

Company number16236839 (England and Wales)
Registered office92 Seager Drive, Cardiff, CF11 7EX, United Kingdom
Trading asSwipeOnDeck / Deck
ICO registrationZB972953
Contacthello@swipeondeck.com

We have not appointed a statutory Data Protection Officer. We have assessed the criteria in Article 37 and none of them applies to us at our current scale and activity. We will keep this under review as the platform grows. Privacy questions go to hello@swipeondeck.com.

2. Who this policy is for

Deck is a platform for in-person community organisers. This policy covers three groups, and what we do differs for each:

  • Visitors: anyone browsing our website
  • Organisers: people and organisations who run a community on Deck. Organisers are our customers.
  • Members: people who join a community or buy a ticket to an event run by an Organiser

Where something applies to only one group, we say so.

This policy covers Deck for Communities, our website and platform for organisers and their members. It does not cover our earlier consumer app, which is being retired.

If you used that app, we still hold the account data you gave us. We are keeping it only while we wind the app down, and we will delete it by 31 July 2027 at the latest. Ticket and transaction records from the consumer app are kept for 6 years for tax and accounting purposes, the same as in §8. You can ask us to delete your consumer app data sooner at any time, see §9.

3. What we collect

3.1 Visitors (website)

  • Early access enquiries: your email address (required), the community you run (optional), and whether you would like a demo
  • Technical data: IP address, browser type, device type, and pages viewed, to the extent our hosting provider logs them

3.2 Organisers

  • Account: name, email address, phone number if you sign in with one, and the community you run. We do not hold passwords: you sign in with a one-time code or link, or through Google.
  • Business and payout details: trading name, and the bank and identity details you provide to Stripe in order to be paid. See §5, we do not hold your bank details ourselves.
  • Content you publish: community name, description, images, event listings
  • Subscription: Deck Pro status and billing history (card details are held by Stripe, not by us)
  • Usage: how you use the platform, for support and to improve the product
  • Correspondence: messages you send us

3.3 Members

  • Account: name, email address, and phone number if you sign in with one. We do not hold passwords.
  • Ticket purchases: the events and tickets you have bought, and the amount paid. Card details go directly to Stripe and are never held by us.
  • Community activity: the communities you have joined and events you have attended
  • Correspondence: messages you send us

3.4 Special category data

We do not ask for special category data (health, religion, ethnicity, political views, biometrics) and we ask you not to provide it in free-text fields.

Some communities are organised around a shared characteristic, and joining one can in itself reveal information that data protection law treats as a special category. A faith group, a recovery meeting, or a community organised around ethnicity or sexual orientation are all examples.

Where an Organiser has told us their community is of that kind, we ask for your explicit consent before you join or buy a ticket, and we keep a record of what you agreed to and when. Our lawful basis is your explicit consent under Article 9(2)(a). You can withdraw it at any time, see §9. If you withdraw it we will stop using those records and delete them, other than transaction records we are legally required to keep under §8.

We only apply this to communities an Organiser has identified. It is limited to your membership of that community and the events you attended with them.

4. Why we use it, and our lawful basis

What we doWhose dataLawful basis
Respond to early-access enquiriesVisitorsLegitimate interests: responding to someone who asked to hear from us
Create and run accountsOrganisers, MembersContract: we cannot provide the service without it
Process ticket sales and payoutsOrganisers, MembersContract
Bill Deck Pro subscriptionsOrganisersContract
Send service messages (tickets, receipts, reminders, event changes, refunds)Organisers, MembersContract
Send marketing emailsVisitors, OrganisersConsent: opt in, and you can withdraw any time. We also rely on the soft opt-in in regulation 22 of PECR to email existing Organiser customers about similar services, and every message carries an unsubscribe link.
Community insights for Organisers (§4.1)MembersLegitimate interests: helping Organisers keep their communities together
Process special category data where a community reveals it (§3.4)MembersExplicit consent: Article 9(2)(a). You can withdraw at any time.
Prevent fraud and keep the platform safeAllLegitimate interests: protecting users, Organisers and ourselves
Improve the product and understand usageAllLegitimate interests: we use cookieless analytics that does not identify you
Keep financial and tax recordsOrganisers, MembersLegal obligation
Handle disputes and legal claimsAllLegitimate interests

Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights. You can object, see §9.

We do not send marketing emails to Members. Messages you receive about a community come from the Organiser who runs it, in their name. You can stop those at any time using the unsubscribe link on them, and doing so will not affect tickets, receipts or reminders for anything you have booked.

4.1 Community insights for Organisers

Organisers can see information about the members of their own community: which of their events you have attended, tickets you have bought, and how recently you have been.

We also calculate a small number of derived signals from that history, for example whether you are a regular, or whether it has been a while since you last came, so the Organiser can look after their community. These are automated calculations. A person always decides what to do with them. We do not make automated decisions that have a legal or similarly significant effect on you.

This is limited to the Organiser’s own community. Organisers never see your activity in anyone else’s community. Our lawful basis is legitimate interests, running a community platform that helps Organisers keep their communities together. You can object at any time, see §9.

5. Who we share it with

We do not sell personal data. We share it with service providers who process it on our instructions:

ProviderWhat forWhere
SupabaseOur database and backend: account data, events, ticketsLondon, United Kingdom (AWS eu-west-2)
StripePayment processing and Organiser payouts. Stripe is a separate controller for payment data and holds card and bank details: we never see full card numbers.EU / US
VercelWebsite and application hostingUnited States, with a global edge network
Vercel AnalyticsCookieless website analytics. Does not use cookies, does not track you across sites, and does not identify you individually.United States, with a global edge network
Twilio SendGridService and marketing email, including sign-in links and codesUS / EU
Meta PlatformsAdvertising measurement and retargeting through the Meta Pixel on our website. Meta is a separate controller for the data the Pixel collects. See §10 and our Cookie Policy.US / EU

We also share data where we are legally required to, or to establish or defend legal claims.

6. Organisers and Members: who controls what

This section matters because Deck sits between two parties.

  • We act as agent for Organisers when tickets are sold. The contract for an event is between the Member and the Organiser.
  • We are a controller for data we use for our own purposes: running the platform, fraud prevention, and our own relationship with you.
  • Organisers are separate controllers for the member data they use to run their own community: their mailing lists, their attendance records, their own communications.
  • Where we handle member data purely on an Organiser’s instructions, we act as their processor, under the data processing terms set out in our Organiser Terms of Service.

What this means for Members: when you join a community or buy a ticket, the Organiser receives your name, email, and booking details so they can run the event. The Organiser is responsible for how they then use that data, including their own marketing. Their privacy notice governs that, ask them for it. We require Organisers to handle your data lawfully and not to sell it, but we do not control them.

6.1 When an Organiser imports existing members

Organisers can bring their existing community into Deck, for example records from a previous ticketing platform or a contact list.

Where an Organiser imports data about you, the Organiser is the controller and is responsible for having a lawful basis for doing so. We require them to confirm this at the point of import, and we record that confirmation. We act as their processor for the imported records.

If you are contacted by a community you do not recognise, or you want to know how your details reached them, contact us at hello@swipeondeck.com and we will tell you which Organiser imported them and when.

7. International transfers

Your account, community and ticket data is stored in the United Kingdom. Our database is hosted by Supabase in London (AWS eu-west-2).

Some of the providers in §5 operate outside the UK, including Stripe, Twilio SendGrid and Vercel. Where personal data reaches them, we rely on UK GDPR transfer mechanisms: an adequacy decision where one applies, or the UK International Data Transfer Agreement or Addendum, together with appropriate safeguards.

8. How long we keep it

DataRetention
Early-access enquiries that do not convert12 months
Organiser and Member accountsWhile active, then 12 months after closure
Ticket and transaction records6 years: HMRC record-keeping
Engagement and activity events13 months, then deleted
Derived member insights (§4.1)Recalculated from activity data. Deleted when the underlying activity data is deleted, or when you close your account.
Marketing consents and opt-outsUntil withdrawn; opt-outs kept indefinitely so we do not re-contact you
Support correspondence24 months
Fraud and safety recordsAs long as necessary for the investigation, and up to 6 years where needed to defend a legal claim

Closing your account does not delete your ticket and transaction records. We are required to keep those for 6 years for tax and accounting purposes. They contain what was bought, when, for how much, and from which Organiser. They are not used for anything else once your account is closed.

After these periods we delete or anonymise the data.

9. Your rights

Under UK data protection law you can ask us to:

  • Access a copy of your data
  • Correct anything inaccurate
  • Delete it, where we do not need to keep it
  • Restrict or object to processing, including direct marketing and the insights described in §4.1. An objection to marketing is always honoured.
  • Port your data to another service
  • Withdraw consent at any time, where we relied on it

Email hello@swipeondeck.com. We respond within one month. There is no charge unless a request is manifestly unfounded or excessive.

If you are unhappy with how we have handled your data, you can complain to the Information Commissioner’s Office:

ico.org.uk/make-a-complaint · 0303 123 1113 · Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

10. Cookies and electronic marketing

Cookies and electronic marketing are governed by the Privacy and Electronic Communications Regulations (PECR) as well as UK GDPR.

Cookies are small files stored on your device. We use strictly necessary cookies, the ones the service cannot work without:

  • Sign-in and session management: keeping you logged in
  • Security: protecting your account and preventing abuse
  • Payments: Stripe’s fraud prevention cookies (__stripe_mid, __stripe_sid) when you buy a ticket

These do not require your consent, because the service cannot function without them.

Advertising. We also use the Meta Pixel on our website. It sets cookies so that Meta can measure how our advertising performs and show Deck adverts to people who have visited our site. Our Cookie Policy describes it in more detail. We do not share your browsing behaviour with any other advertising network.

Analytics. We use Vercel Analytics to understand how our website is used: how many people visit, which pages they read, and where they came from. It is cookieless. It stores nothing on your device, does not follow you across other websites, and does not identify you individually. Because it does not store or access information on your device, it does not require consent.

Your choices. You can block or delete cookies in your browser settings. Doing so may stop you staying signed in. You can also turn off activity-based ad targeting in Meta’s ad preferences, which applies across every site that uses the Meta Pixel, not just this one.

11. Children

Deck is for adults. You must be 18 or over to use Deck, whether as an Organiser or as a Member.

We do not knowingly collect personal data from anyone under 18. If you believe a child has given us their data, contact hello@swipeondeck.com and we will delete it.

12. Security

We protect data with encryption in transit and at rest, access controls that limit staff access to what is needed for support and operations, and hosting on providers who maintain recognised security standards. Where we can work with pseudonymised or aggregated data instead of identifiable data, we do.

No system is completely secure. If a personal data breach occurs and it is likely to result in a risk to your rights and freedoms, we will report it to the ICO within 72 hours of becoming aware of it, and we will tell you directly where the risk to you is high.

13. Changes

We may update this policy. Material changes will be notified by email or in-app before they take effect. The version and date are at the top of this page.

14. Contact

Curated Technologies Limited (trading as SwipeOnDeck / Deck)

92 Seager Drive, Cardiff, CF11 7EX, United Kingdom

Company number 16236839 · ICO registration ZB972953

hello@swipeondeck.com

Effective date: 15 September 2026

Version: v1.