Fetygasy Privacy Policy

Effective date: 8 August 2026
Last updated: 9 August 2026

This policy explains how Fetygasy handles personal data across its websites, applications, social and event features, QR-ticket and finance tools, moderation, email, and messaging services (the Services).

The Services are operated by Fetygasy Studio, trading as Fetygasy. Contact us at [email protected].

1. Information we collect

We may collect:

  • Account data: name, username, email, hashed password, phone and WhatsApp numbers, profile picture, preferences, verification status, roles, permissions, connected Google, Facebook, or Clerk identities, and sessions;
  • Content and event data: posts and media, comments, reactions, saved posts, artist and venue profiles, events, reports, moderation and support messages, and uploaded files;
  • Event-operation data: attendee names, ticket details and prices, VIP status, tags, notes, delivery destinations, QR tickets, check-ins, team roles, and finance entries; and
  • Communication and technical data: message or ticket content, recipients, delivery results, email opens and clicks, provider references, IP address, device and browser information, cookies, logs, errors, and security data. If an organiser connects WhatsApp, we also store the credentials and status needed for that connection.

We receive data from you, organisers and event teams, identity and communication providers, other users, and public artist or venue sources.

2. How we use personal data

We use data to create and secure accounts, publish social and event content, manage attendees and teams, create and deliver QR tickets, record check-ins and event finances, send notifications, moderate content, provide support, prevent abuse, improve the Services, and comply with law.

Where required, we rely on a contract, our legitimate interests in operating and protecting the Services, legal obligations, or consent.

3. Organisers, visibility, and sharing

Fetygasy controls account, profile, social, security, communication, moderation, and administration data. An organiser controls why its attendee, ticket, check-in, team, and finance data is used. Organisers must have a lawful reason to submit another person's data, give required notices, and restrict access to authorised team members.

Profiles, posts, comments, reactions, artist and venue pages, and events may be public. Organisers and their teams can see the event records they manage. Public information may be copied or reshared outside our control.

We share only necessary data with other users, organisers, authorised personnel, authorities where required, and providers such as Google, Meta/Facebook, Clerk, Resend, Brevo, Sent.dm, WhatsApp/Meta, Cloudflare, and Directus where deployed. We do not sell personal data for money or use it for third-party targeted advertising.

4. Cookies and international transfers

We use cookies and similar storage for sign-in, security, abuse prevention, language, and theme choices. Blocking necessary cookies may stop core features from working. Optional cookies require consent where applicable.

Some providers or users may be in other countries. Where required, we use an applicable legal exception or safeguard for international transfers. Contact us for information about a transfer affecting your data.

5. Data retention

We keep data only as long as needed for the Services or for legal, accounting, security, fraud-prevention, and dispute purposes. Accounts are kept while active and during the 30-day deletion period. Sessions and verification records expire or are revoked. Public content is kept until deleted or no longer needed, although published event posts may remain as detached event history with a previously public author name. Organiser-controlled records may remain for event and legal needs. Logs, communications, moderation records, and backups are kept for operational or legal needs, with backups removed through normal rotation.

6. Your rights and account deletion

Depending on applicable law, you may request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or transfer information. You may also object to direct marketing and complain to the competent authority.

Send requests to [email protected]. We may verify your identity. For organiser-controlled data, we may refer the request to the organiser or help it respond.

You may request account deletion from your profile where available. Your account is deactivated immediately and scheduled for permanent deletion after 30 days. Account data is then deleted or de-identified. Detached event posts, organiser records, legal or security records, other users' data, and rotating backups may remain where necessary.

7. Security, content checks, and children

We use TLS, hashed passwords and tokens, encryption for selected credentials, access controls, session expiry, rate limits, backups, and restricted administration. No service can guarantee absolute security, so keep passwords, verification codes, connected accounts, and QR tickets secure.

We may compare submitted text with safety rules and send content for human review. These checks do not make solely automated decisions with legal or similarly significant effects.

The Services are not directed to children under 16. A person under 16 must not create an account.

8. Changes and contact

We may update this policy and will change the date above and provide additional notice when required. For questions, requests, or complaints, contact Fetygasy Studio at [email protected].