1. Who We Are
This Privacy Policy explains how Ventir Ltd (“Ventir”, “we”, “us” or “our”) collects, uses, shares and protects personal information when you visit ventir.app, communicate with us, or use any current or future Ventir services.
Company name: Ventir Ltd. Company number: 13423472. Registered office: 3rd Floor, 86-90 Paul Street, London EC2A 4NE, United Kingdom. Contact email: contact@ventir.app. ICO registration number: ZC134905.
Ventir Ltd is the data controller responsible for your personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, unless we explain otherwise. We are not currently required to appoint a Data Protection Officer. If this changes, we will update this policy.
2. Scope and Launch Status
Ventir is launching in stages. The Service currently collects information for venue listings and discovery, user accounts, Enquiries, Host and Venue verification and messaging between Guests and Hosts — all of which are live today. Payments, confirmed bookings and reviews are not yet available to the public; when they go live they may involve additional personal data and this Privacy Policy will be updated to reflect that before they do.
We will update this policy before collecting materially different categories of personal data or using personal data for materially different purposes.
3. Personal Data We Collect
Information you give Ventir may include your email address, name, account details, business or Venue details, support requests, complaints, feedback, marketing preferences and consent records.
Your date of birth, when you create an account. Ventir asks for your date of birth once, on the sign-up form, and stores it against your account. We ask for it to establish that the account holder is 18 or over, which our Terms of Service require. It replaces the tick box that previously asked you to confirm your age: a date you enter is a stronger and more honest record of the same single fact than a box you tick, and asking for both would be collecting more than we need.
Our lawful basis is legitimate interests — ours and every other user’s, in a marketplace where the people entering booking contracts are adults who can enter them. We do not rely on consent for this, and we want to be plain about why: you cannot create an account without giving it, so a “consent” you could not decline would not be freely given, and calling it one would misdescribe what is happening.
What your date of birth is never used for. It is not sent to Stripe or any other payment processor. It is not used for marketing, segmentation, profiling, advertising or age-targeted content. It is not used to work out your age for any purpose other than the 18-or-over check above. And it is never displayed to anyone— not to Hosts, not to Guests, and not to Ventir staff on any internal screen. It is kept for as long as your account exists and is deleted with it; there is no separate timer.
This is a different thing from the date of birth Stripe asks a Host for when setting up a payout account (section 3, “Payout accounts for Hosts”). That one is collected by Stripe for its own legal obligations as a regulated payments business, on Stripe’s pages, and Ventir never receives it.
When you send an Enquiry, Ventir collects the Venue you are enquiring about, your event type, event date and time, expected guest numbers, and any message or other information you include.
When you list a Venue and submit it for verification, Ventir collects your full name, your role at the Venue, the business name, the Venue address, a contact email address, a contact telephone number, and any website or social media link you choose to provide. We use this to check that a real business exists and that you have permission to list the Venue.
If you message a Host or a Guest through the Service, Ventir stores the content of those messages so both sides can read the conversation and so we can investigate reports, disputes and misuse.
Booking terms agreement records. Before you pay for a booking, you are shown the Host’s booking terms — the security deposit, the cancellation rule and any house rules — and asked to confirm that you agree to them. When you confirm, Ventir records a copy of those exact terms as they appeared to you, the date and time you agreed, your account identifier, and the IP address your device was using at that moment.
We record the IP address as evidence of who agreed to what and when. If a Guest and a Host later disagree about the terms of a booking — for example about how much of a payment is refundable after a cancellation — that record is what allows either side to show what was actually shown and accepted. Our lawful basis is legitimate interests: we, the Host and the Guest all have a genuine interest in a booking agreement that can be evidenced, and a single IP address recorded at one moment is a narrow, proportionate way to do that. It is not used to track you around the Service, to build a profile, to infer your location, or for marketing.
These records cannot be edited after they are created — including by us — because an agreement record that could be changed afterwards would be worthless as evidence to either side. They are kept for as long as the booking they belong to; see section 14 for how long that is and how deletion works.
What a venue’s listing said when you enquired. When you send an enquiry we keep a copy of the host’s own wording as it read at that moment — the description, amenities, address text, any hourly-rate note, and the cancellation notes and house rules. We record that alongside your account, the venue, the host and the time.
This is the host’s text, not yours, and we keep no part of your message. We keep it because a listing can be edited afterwards, and if there is later a disagreement about what was promised, both you and the host should be able to see what was actually on the page — rather than what it says today. Our lawful basis is our legitimate interest in being able to resolve a dispute fairly. It is kept for as long as the enquiry it belongs to, and is deleted with it.
Host Terms acceptance records. If you list a venue, you are shown our Host Terms and asked to confirm that you accept them before your listing is submitted for review. When you confirm, Ventir records your account identifier, which version of the Host Terms you accepted, the date and time, and the IP address your device was using at that moment.
The purpose is the same as for booking agreements, and so is the reasoning. If a Host and Ventir later disagree about which version of the Host Terms applied — for example about a deposit-return obligation or an insurance requirement that changed between versions — that record is what allows either side to show what was actually shown and accepted. Our lawful basis is legitimate interests: Ventir and the Host both have a genuine interest in an acceptance that can be evidenced, and a single IP address recorded at one moment is a narrow, proportionate way to do it. It is not used to track you around the Service, to build a profile, to infer your location, or for marketing.
These records cannot be edited or deleted after they are created, including by us, for the same reason as booking agreements. A Host who accepts a later version of the Host Terms produces a new record rather than replacing the old one, so the history of what was accepted and when stays intact. They are kept for as long as you have a listing with us and then in line with section 14; there is no separate timer.
Payout accounts for Hosts (Stripe Connect). Ventir cannot pay a Host without a payout account. To set one up you are sent to Stripe, who run the whole process on their own pages. Stripe asks you for the things a regulated payments business must collect before it can send you money — typically your name, date of birth, address, bank account details and one or more identity documents.
Ventir never receives any of that. It is submitted to Stripe directly and we are not shown it. What comes back to us, and all we store, is a Stripe account identifier and two yes/no indicators: whether you have finished the form, and whether Stripe will let us send you money yet. We use those to show you the right thing on your dashboard and to stop us attempting a payout that would fail.
Stripe is not acting as our processor for this. When Stripe verifies who you are, it does so for its own legal obligations as a regulated payments business, and it decides for itself what to collect and how long to keep it. In data protection terms Stripe is an independent controller for that verification, and Ventir is a controller only for the account identifier and the two indicators described above. What Stripe does with the information you give them is governed by Stripe’s own privacy policy, which you should read before you start.
Our lawful basis for storing the identifier and the indicators is performance of a contract: the Host Terms oblige us to pay you the hire fee, and we cannot do that without knowing where to send it. Stripe’s basis for the identity checks is its own legal obligation, not ours. None of this is used for marketing, profiling or advertising, and no decision about you is made automatically on the strength of it — see section 16. We keep the identifier for as long as you have a listing or an unpaid booking with us, and then in line with section 14.
When Marketplace Features launch, we may collect account registration details, authentication information, Guest booking details, event details, attendee numbers, Venue preferences, booking history, Host details, business names, Venue listing data, availability, pricing, payout details, verification data, messages, reviews, ratings, complaints, support requests, dispute evidence and moderation records.
Payment-related information may include payment status, transaction IDs, refunds, chargebacks and Stripe customer or connected-account identifiers. Card details should be handled by our payment provider and not stored directly by Ventir unless expressly stated.
Identity, business, right-to-list, fraud prevention, sanctions or safety verification data may be collected where required for trust, safety, legal or payment compliance.
4. Data Collected Automatically
When you visit ventir.app or use the Service, we and our providers may process technical information including IP address, device and browser type, operating system, pages visited, timestamps, referring website, approximate location inferred from IP address, and security, error and diagnostic logs.
We use this information for security, abuse prevention, troubleshooting, service operation and, where enabled with appropriate controls, analytics and product improvement.
5. Information From Third Parties
When Marketplace Features launch, we may receive information from payment processors, identity verification providers, fraud prevention providers, hosting providers, email delivery services, analytics providers, maps providers, business verification services, professional advisers, law enforcement or regulators where legally permitted.
6. Special Category Data and Children
We do not intentionally collect special category data such as health, race, religion, biometric data, political opinions or trade union membership.
When you send a message to a Host, that message is passed to the Host so they can respond. If you choose to include sensitive personal information in it — for example accessibility requirements or dietary needs — that information is passed on with the rest of your message and is used only to deliver your enquiry and handle any related support or dispute. We do not use it for any other purpose.
Please include sensitive personal information only where it is necessary for your enquiry. If you would rather not put it in writing, contact us at contact@ventir.app and we will help you raise it with the Host another way.
Ventir is intended for users aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided personal data, contact us and we will take appropriate steps to delete it.
7. Why We Use Personal Data
We use personal data to send launch updates and product updates where permitted; respond to enquiries; create and manage accounts; enable listings, enquiries, bookings, payments, refunds, payouts, reviews and messaging; verify users, Hosts, businesses, Venues, payment activity and booking activity; prevent, detect and investigate fraud, misuse, security incidents, unlawful activity, disputes and breaches; comply with legal obligations; and improve, secure, test and develop the Service.
8. Lawful Bases for Processing
Under UK GDPR, we rely on the following lawful bases. More than one lawful basis may apply depending on context.
| Lawful basis | When we use it | Examples |
|---|---|---|
| Consent | Where you have given clear permission. | Waitlist emails, launch updates, optional marketing and non-essential cookies where used. |
| Contract | Where needed to provide services you request or take steps before entering a contract. | Account creation, booking management, Host listings, support and marketplace transactions. |
| Legitimate interests | Where we have a legitimate business reason and your rights do not override it. | Security logs, fraud prevention, service improvement, platform integrity, basic analytics where lawful, recording the IP address used when a Guest agrees to a Host’s booking terms, as evidence of that agreement (see section 3), and your date of birth, collected once at account creation to establish that the account holder is 18 or over (see section 3). We do not treat that one as consent, because an account cannot be created without it and a permission you cannot decline is not freely given. |
| Legal obligation | Where we must comply with the law. | Tax/accounting records, regulator requests, legal claims and data rights responses. |
| Legal claims / substantial public interest where applicable | Where necessary and permitted by law. | Disputes, fraud investigations, safety incidents and enforcement of terms. |
9. Email Marketing and Waitlist Communications
We will only send marketing emails, launch updates or product updates where you have consented or where we are otherwise permitted by law. We will not disguise our identity in marketing emails and will provide a valid contact method or unsubscribe mechanism.
You can opt out at any time by using the unsubscribe link in our emails or by contacting contact@ventir.app. If you opt out, we will stop using your information for the direct marketing covered by that opt-out. We may still send non-marketing service or administrative messages where necessary, such as security notices, account notices, booking confirmations or legal updates.
10. Cookies and Similar Technologies
We do not currently use non-essential cookies for advertising or third-party tracking on the Service. The Service may use essential cookies or similar technologies where strictly necessary for website delivery, security, preferences, authentication, load balancing or similar core functionality.
If we introduce analytics, advertising, personalisation, heatmap, social media pixel or other non-essential cookies or similar technologies, we will update this policy and our Cookie Policy and, where required, request consent before placing those technologies on your device. Users must be able to reject non-essential cookies as easily as accepting them and must be able to change preferences.
11. Who We Share Personal Data With
We do not sell personal information. We share personal data only where needed to operate, secure, improve or provide the Service, comply with law, enforce our terms or protect rights and safety.
Service providers may include Supabase or other database providers; Vercel or other hosting providers; GoDaddy, Cloudflare or other domain/DNS providers; Stripe or other payment providers; email delivery and customer communication providers; identity, business, fraud, sanctions or safety verification providers; analytics, monitoring, error logging and security providers; and professional advisers including lawyers, accountants, insurers and auditors.
One of those relationships is not a processor relationship. Where a Host sets up a payout account, Stripe verifies that Host’s identity for Stripe’s own regulatory obligations and acts as an independent controller for that, rather than on our instructions. Ventir does not receive the identity documents, date of birth or bank details involved. See payout accounts for Hosts in section 3.
Our current core providers are: Supabase (database, authentication and file storage); Vercel (hosting); Upstash (rate limiting); Resend (transactional email); Sentry, EU region (error monitoring); UptimeRobot (availability monitoring); Cloudflare (Turnstile bot protection and domain services); and OpenStreetMap (map tiles, which load from OpenStreetMap servers when you view venue maps).
When you send an Enquiry, the Host of that Venue receives the details necessary to respond, including your name, the event details you provide, and your message.
When Marketplace Features launch, certain information may be shared between Hosts and Guests where necessary for bookings, Venue access, cancellations, refunds, disputes, reviews and support. For example, a Host may receive booking details and a Guest may receive Host contact, Venue and access information.
We may disclose personal data where necessary to comply with law, respond to lawful requests, enforce terms, prevent fraud, protect users or third parties, obtain advice, defend claims or support a merger, acquisition, restructuring, financing or sale of business assets.
12. Processor Register and Launch Confirmation
Before publication and launch, Ventir maintains an internal processor register confirming each provider, purpose, data categories, location, role, data processing terms, security measures, sub-processors and transfer mechanism. This policy will be updated if public-facing provider details materially change.
13. International Transfers
Our primary database and authentication data are hosted in London, United Kingdom (Supabase, AWS eu-west-2). Other processors may process personal data outside the UK.
Where personal data is transferred outside the UK to a country not recognised as providing adequate protection, we use appropriate safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
We keep a record of the processors we use, covering the personal data each one processes, its terms, its security measures, its sub-processors and its transfer mechanism.
14. How Long We Keep Personal Data
We keep personal data only for as long as reasonably necessary for the purposes described in this policy, including to provide the Service, comply with law, resolve disputes, enforce agreements, prevent fraud and maintain business records.
| Data type | Indicative retention period |
|---|---|
| Waitlist email and consent record | Until you unsubscribe, request deletion, or 12 months after launch if you do not become an active user, unless longer retention is needed for legal or dispute reasons. |
| Marketing suppression records | As long as necessary to respect your opt-out. |
| Server, security and diagnostic logs | Usually up to 30 days, unless needed longer for security, fraud, legal or investigation purposes. |
| Account and booking records | For the life of the account and then for a reasonable period needed for legal, tax, accounting, fraud prevention and dispute purposes. |
| Date of birth given at account creation | For the life of the account, and deleted with it. There is no separate timer, and it is not retained after account closure for any of the purposes in the row above — the 18-or-over check it exists for has no meaning once the account is gone. See section 3. |
| Enquiry records | For the life of your account and then normally up to 6 years after the last Enquiry or account closure where needed for legal, dispute, safety, fraud-prevention or record-keeping purposes, unless a shorter or longer period is required or justified. Ventir may delete or anonymise records earlier where they are no longer needed. |
| Booking terms agreement records, including the IP address recorded at the moment of agreement | Kept for as long as the booking record they belong to, and deleted automatically when that booking record is deleted. There is no separate timer on the IP address and no routine that removes it earlier — if you delete your account, your bookings are deleted and these records go with them. See section 15 for how to request deletion. |
| Venue verification records (name, role, business, address, email, phone) | For as long as the Venue is listed, and then for a reasonable period needed for trust, safety, legal and dispute purposes. |
| Messages between Guests and Hosts | For the life of the accounts involved and then as needed for disputes, safety and record-keeping. Both sides can see the conversation, so a message is not removed from the other person’s view by one side alone. |
| Payment, refund, payout and invoice records | Usually up to 7 years where required for tax, accounting or legal purposes. |
| Support, complaints and dispute records | For as long as needed to resolve the matter and protect legal rights. |
| Verification and fraud prevention records | For as long as needed to protect platform integrity, meet legal/payment requirements, resolve disputes and prevent repeat misuse. |
15. Your Rights Under UK GDPR
Depending on the circumstances, you may have the right to be informed, access your data, rectify inaccurate data, erase data, restrict processing, data portability, object to processing including direct marketing, withdraw consent, and not be subject to certain solely automated decisions with legal or similarly significant effects.
To exercise rights, contact contact@ventir.app. We may need to verify your identity before responding. We will usually respond within one month unless the law allows longer for complex requests.
You also have the right to complain to the UK Information Commissioner’s Office (ICO): ico.org.uk, 0303 123 1113, Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom.
16. Automated Decision-Making and Profiling
We do not currently make decisions based solely on automated processing that produce legal or similarly significant effects for waitlist users.
When Marketplace Features launch, we may use automated or semi-automated tools to help detect fraud, suspicious bookings, payment risk, sanctions risk, abusive behaviour or security threats. Where such processing has a significant effect and the law requires it, we will provide appropriate information and rights of review.
17. How We Protect Personal Data
We use reasonable technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure. These may include HTTPS encryption in transit, access controls, role-based restrictions, database security controls such as row-level security where configured, restricted service credentials, password hashing or encryption where used, logging, monitoring, abuse prevention and periodic review of security practices.
No system is completely secure. If a personal data breach occurs and it is likely to result in a risk to individuals’ rights and freedoms, we will notify the ICO where required within 72 hours of becoming aware of it and will inform affected individuals where required without undue delay.
18. Your Responsibilities
You are responsible for providing accurate information, keeping account credentials secure, using the Service lawfully and not submitting unnecessary sensitive personal data. If you provide personal data about another person, you must have a lawful basis or proper permission to do so.
19. Third-Party Websites and Services
The Service may contain links to third-party websites, payment pages, maps, social platforms or tools. We are not responsible for their privacy practices. You should review third-party privacy notices before providing personal data to them.
20. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last updated” date will show when it was last changed. Significant changes may be notified by email, website notice, in-app notice or another reasonable method. You should review this policy periodically, especially before using new Marketplace Features.
21. Contact Us
- Email: contact@ventir.app
- Postal address: Ventir Ltd, 3rd Floor, 86-90 Paul Street, London EC2A 4NE, United Kingdom
- Company number: 13423472
- ICO registration number: ZC134905