Privacy Policy
Curated Technologies Limited (trading as SwipeOnDeck)
Effective date: 15 September 2026
1. Who we are
Curated Technologies Limited (“Deck”, “we”, “us”) is the data controller for the personal data described in this policy.
| Company number | 16236839 (England and Wales) |
|---|---|
| Registered office | 92 Seager Drive, Cardiff, CF11 7EX, United Kingdom |
| Trading as | SwipeOnDeck / Deck |
| ICO registration | ZB972953 |
| Contact | hello@swipeondeck.com |
We have not appointed a statutory Data Protection Officer. We have assessed the criteria in Article 37 and none of them applies to us at our current scale and activity. We will keep this under review as the platform grows. Privacy questions go to hello@swipeondeck.com.
2. Who this policy is for
Deck is a platform for in-person community organisers. This policy covers three groups, and what we do differs for each:
- Visitors: anyone browsing our website
- Organisers: people and organisations who run a community on Deck. Organisers are our customers.
- Members: people who join a community or buy a ticket to an event run by an Organiser
Where something applies to only one group, we say so.
This policy covers Deck for Communities, our website and platform for organisers and their members. It does not cover our earlier consumer app, which is being retired.
If you used that app, we still hold the account data you gave us. We are keeping it only while we wind the app down, and we will delete it by 31 July 2027 at the latest. Ticket and transaction records from the consumer app are kept for 6 years for tax and accounting purposes, the same as in §8. You can ask us to delete your consumer app data sooner at any time, see §9.
3. What we collect
3.1 Visitors (website)
- Early access enquiries: your email address (required), the community you run (optional), and whether you would like a demo
- Technical data: IP address, browser type, device type, and pages viewed, to the extent our hosting provider logs them
3.2 Organisers
- Account: name, email address, phone number if you sign in with one, and the community you run. We do not hold passwords: you sign in with a one-time code or link, or through Google.
- Business and payout details: trading name, and the bank and identity details you provide to Stripe in order to be paid. See §5, we do not hold your bank details ourselves.
- Content you publish: community name, description, images, event listings
- Subscription: Deck Pro status and billing history (card details are held by Stripe, not by us)
- Usage: how you use the platform, for support and to improve the product
- Correspondence: messages you send us
3.3 Members
- Account: name, email address, and phone number if you sign in with one. We do not hold passwords.
- Ticket purchases: the events and tickets you have bought, and the amount paid. Card details go directly to Stripe and are never held by us.
- Community activity: the communities you have joined and events you have attended
- Correspondence: messages you send us
3.4 Special category data
We do not ask for special category data (health, religion, ethnicity, political views, biometrics) and we ask you not to provide it in free-text fields.
Some communities are organised around a shared characteristic, and joining one can in itself reveal information that data protection law treats as a special category. A faith group, a recovery meeting, or a community organised around ethnicity or sexual orientation are all examples.
Where an Organiser has told us their community is of that kind, we ask for your explicit consent before you join or buy a ticket, and we keep a record of what you agreed to and when. Our lawful basis is your explicit consent under Article 9(2)(a). You can withdraw it at any time, see §9. If you withdraw it we will stop using those records and delete them, other than transaction records we are legally required to keep under §8.
We only apply this to communities an Organiser has identified. It is limited to your membership of that community and the events you attended with them.
4. Why we use it, and our lawful basis
| What we do | Whose data | Lawful basis |
|---|---|---|
| Respond to early-access enquiries | Visitors | Legitimate interests: responding to someone who asked to hear from us |
| Create and run accounts | Organisers, Members | Contract: we cannot provide the service without it |
| Process ticket sales and payouts | Organisers, Members | Contract |
| Bill Deck Pro subscriptions | Organisers | Contract |
| Send service messages (tickets, receipts, reminders, event changes, refunds) | Organisers, Members | Contract |
| Send marketing emails | Visitors, Organisers | Consent: opt in, and you can withdraw any time. We also rely on the soft opt-in in regulation 22 of PECR to email existing Organiser customers about similar services, and every message carries an unsubscribe link. |
| Community insights for Organisers (§4.1) | Members | Legitimate interests: helping Organisers keep their communities together |
| Process special category data where a community reveals it (§3.4) | Members | Explicit consent: Article 9(2)(a). You can withdraw at any time. |
| Prevent fraud and keep the platform safe | All | Legitimate interests: protecting users, Organisers and ourselves |
| Improve the product and understand usage | All | Legitimate interests: we use cookieless analytics that does not identify you |
| Keep financial and tax records | Organisers, Members | Legal obligation |
| Handle disputes and legal claims | All | Legitimate interests |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights. You can object, see §9.
We do not send marketing emails to Members. Messages you receive about a community come from the Organiser who runs it, in their name. You can stop those at any time using the unsubscribe link on them, and doing so will not affect tickets, receipts or reminders for anything you have booked.
4.1 Community insights for Organisers
Organisers can see information about the members of their own community: which of their events you have attended, tickets you have bought, and how recently you have been.
We also calculate a small number of derived signals from that history, for example whether you are a regular, or whether it has been a while since you last came, so the Organiser can look after their community. These are automated calculations. A person always decides what to do with them. We do not make automated decisions that have a legal or similarly significant effect on you.
This is limited to the Organiser’s own community. Organisers never see your activity in anyone else’s community. Our lawful basis is legitimate interests, running a community platform that helps Organisers keep their communities together. You can object at any time, see §9.
5. Who we share it with
We do not sell personal data. We share it with service providers who process it on our instructions:
| Provider | What for | Where |
|---|---|---|
| Supabase | Our database and backend: account data, events, tickets | London, United Kingdom (AWS eu-west-2) |
| Stripe | Payment processing and Organiser payouts. Stripe is a separate controller for payment data and holds card and bank details: we never see full card numbers. | EU / US |
| Vercel | Website and application hosting | United States, with a global edge network |
| Vercel Analytics | Cookieless website analytics. Does not use cookies, does not track you across sites, and does not identify you individually. | United States, with a global edge network |
| Twilio SendGrid | Service and marketing email, including sign-in links and codes | US / EU |
| Meta Platforms | Advertising measurement and retargeting through the Meta Pixel on our website. Meta is a separate controller for the data the Pixel collects. See §10 and our Cookie Policy. | US / EU |
We also share data where we are legally required to, or to establish or defend legal claims.
6. Organisers and Members: who controls what
This section matters because Deck sits between two parties.
- We act as agent for Organisers when tickets are sold. The contract for an event is between the Member and the Organiser.
- We are a controller for data we use for our own purposes: running the platform, fraud prevention, and our own relationship with you.
- Organisers are separate controllers for the member data they use to run their own community: their mailing lists, their attendance records, their own communications.
- Where we handle member data purely on an Organiser’s instructions, we act as their processor, under the data processing terms set out in our Organiser Terms of Service.
What this means for Members: when you join a community or buy a ticket, the Organiser receives your name, email, and booking details so they can run the event. The Organiser is responsible for how they then use that data, including their own marketing. Their privacy notice governs that, ask them for it. We require Organisers to handle your data lawfully and not to sell it, but we do not control them.
6.1 When an Organiser imports existing members
Organisers can bring their existing community into Deck, for example records from a previous ticketing platform or a contact list.
Where an Organiser imports data about you, the Organiser is the controller and is responsible for having a lawful basis for doing so. We require them to confirm this at the point of import, and we record that confirmation. We act as their processor for the imported records.
If you are contacted by a community you do not recognise, or you want to know how your details reached them, contact us at hello@swipeondeck.com and we will tell you which Organiser imported them and when.
7. International transfers
Your account, community and ticket data is stored in the United Kingdom. Our database is hosted by Supabase in London (AWS eu-west-2).
Some of the providers in §5 operate outside the UK, including Stripe, Twilio SendGrid and Vercel. Where personal data reaches them, we rely on UK GDPR transfer mechanisms: an adequacy decision where one applies, or the UK International Data Transfer Agreement or Addendum, together with appropriate safeguards.
8. How long we keep it
| Data | Retention |
|---|---|
| Early-access enquiries that do not convert | 12 months |
| Organiser and Member accounts | While active, then 12 months after closure |
| Ticket and transaction records | 6 years: HMRC record-keeping |
| Engagement and activity events | 13 months, then deleted |
| Derived member insights (§4.1) | Recalculated from activity data. Deleted when the underlying activity data is deleted, or when you close your account. |
| Marketing consents and opt-outs | Until withdrawn; opt-outs kept indefinitely so we do not re-contact you |
| Support correspondence | 24 months |
| Fraud and safety records | As long as necessary for the investigation, and up to 6 years where needed to defend a legal claim |
Closing your account does not delete your ticket and transaction records. We are required to keep those for 6 years for tax and accounting purposes. They contain what was bought, when, for how much, and from which Organiser. They are not used for anything else once your account is closed.
After these periods we delete or anonymise the data.
9. Your rights
Under UK data protection law you can ask us to:
- Access a copy of your data
- Correct anything inaccurate
- Delete it, where we do not need to keep it
- Restrict or object to processing, including direct marketing and the insights described in §4.1. An objection to marketing is always honoured.
- Port your data to another service
- Withdraw consent at any time, where we relied on it
Email hello@swipeondeck.com. We respond within one month. There is no charge unless a request is manifestly unfounded or excessive.
If you are unhappy with how we have handled your data, you can complain to the Information Commissioner’s Office:
ico.org.uk/make-a-complaint · 0303 123 1113 · Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
11. Children
Deck is for adults. You must be 18 or over to use Deck, whether as an Organiser or as a Member.
We do not knowingly collect personal data from anyone under 18. If you believe a child has given us their data, contact hello@swipeondeck.com and we will delete it.
12. Security
We protect data with encryption in transit and at rest, access controls that limit staff access to what is needed for support and operations, and hosting on providers who maintain recognised security standards. Where we can work with pseudonymised or aggregated data instead of identifiable data, we do.
No system is completely secure. If a personal data breach occurs and it is likely to result in a risk to your rights and freedoms, we will report it to the ICO within 72 hours of becoming aware of it, and we will tell you directly where the risk to you is high.
13. Changes
We may update this policy. Material changes will be notified by email or in-app before they take effect. The version and date are at the top of this page.
14. Contact
Curated Technologies Limited (trading as SwipeOnDeck / Deck)
92 Seager Drive, Cardiff, CF11 7EX, United Kingdom
Company number 16236839 · ICO registration ZB972953