Privacy Policy
Last updated: 24 July 2026
This Privacy Policy explains how Festival Jockey ("we", "us") collects, uses, shares and protects personal data when you use our website and booking service (the "Service"). Festival Jockey is the data controller for the personal data described here. If your local law requires it, we will identify a local representative on request via support@festjockey.com.
1. Data we collect
- Account data: email, password hash (via our auth provider), display name, avatar, sign-in provider (e.g. Google).
- Traveler data: full legal name, date of birth, gender, nationality, passport number and expiry, phone. Provided by you and required by ticketing, airline and accommodation providers to issue bookings in your name.
- Booking data: events, tickets, stays and travel selected; totals; provider confirmation references; order status.
- Billing data: billing address and contact details. Card details are collected and processed by Stripe directly — we never receive or store your full card number.
- Technical data: IP address, device / browser information, log data and cookies strictly necessary to operate the Service.
2. Why we use your data (legal bases)
- Performance of a contract (Art. 6(1)(b) GDPR): to create your account, take and fulfil bookings, and share the data needed with providers to issue tickets, rooms and travel.
- Legal obligation (Art. 6(1)(c)): tax, accounting and consumer-protection records.
- Legitimate interests (Art. 6(1)(f)): fraud prevention, service security, and product improvement in an aggregated form.
- Consent (Art. 6(1)(a)): optional analytics cookies and marketing communications, where offered.
3. Who we share it with
Festival Jockey acts as a technology intermediary. To fulfil a booking we share the minimum necessary data with:
- Ticketing providers (e.g. Ticketmaster) — event, ticket tier, lead traveler identity.
- Accommodation providers (e.g. Booking.com, Hotels.com) — guest names, dates, contact.
- Travel providers (e.g. Skyscanner, Amadeus, Kiwi and the operating airline) — passenger name, DOB, gender, nationality, passport details.
- Payment processor — Stripe, for the Festival Jockey service fee only. Providers collect their portion directly.
- Infrastructure — our hosting and database processors, under written data-processing agreements.
Providers become independent controllers of the data you submit to book with them; their own privacy notices apply. We never sell your personal data.
4. International transfers
Some providers are located outside the EEA / UK. Where we transfer personal data internationally we rely on adequacy decisions or the European Commission's Standard Contractual Clauses, with additional measures where necessary.
5. Retention
- Account & profile data: for the life of your account.
- Booking & billing records: up to 7 years to meet tax and consumer-protection obligations.
- Traveler passport / ID data: for the duration of the trip plus the retention period required by the relevant provider.
- Analytics data (if enabled): up to 14 months.
6. Your rights
Under GDPR and equivalent laws you have the right to access, rectify, erase, restrict or object to processing, and to data portability. You may withdraw consent at any time without affecting prior processing. Exercise these rights from your account — which offers one-click data export and account deletion — or by contacting support@festjockey.com. You may also lodge a complaint with your local supervisory authority.
7. Security
We use TLS in transit, encryption at rest, row-level access control, least-privilege service credentials, and audit logging. Card data is handled by Stripe under PCI-DSS. No system is 100% secure — please use a strong, unique password.
8. Changes
We will update this policy from time to time. Material changes will be announced in-product; the "Last updated" date above always reflects the current version.