Skip to main content
Ambifest
Home Events Ambi Con Merch
Legal

Privacy Policy

Last updated: 15 July 2026

Health & Safety Website T&Cs Privacy Policy Cookie Policy Code of Conduct

We want this to be simple and honest — here is a plain-language look at how we handle your privacy in this volunteer-written draft.

This policy explains how Ambifest Ltd ("Ambifest", "we", "us") collects, uses and protects your personal data when you use ambifest.com, buy a ticket or merch, join our newsletter, or contact us.

Who we are

Ambifest Ltd, London, UK, is the data controller for the personal data described in this policy. You can reach us at info@ambifest.com.

Ambifest Ltd's registration with the Information Commissioner's Office (ICO) is currently in progress. This page will be updated with our registration number once complete.

What data we collect

  • Ticket details — your name and email, given to Stripe when you buy a ticket. We use these to create your ticket code, email you your QR code, and check you in at the door.
  • Merch order details — your name, email and UK shipping address, given to Stripe when you buy merch, so we can post your order to you.
  • Payment details are collected and processed entirely by Stripe. We never see or store your card details.
  • Your email address, if you sign up to our newsletter or join a waitlist.
  • Basic technical data — your IP address is counted briefly when you use our forms, purely to stop spam and abuse. It's automatically deleted within minutes and isn't used to identify or track you.
  • Correspondence — if you email us directly, we keep that conversation to respond to you.

How we collect it

Ticket and merch purchases go through Stripe Checkout — you enter your details on Stripe's own secure page, and Stripe passes us your name, email and (for merch) your shipping address once payment succeeds.

Your ticket code, name and email are then stored in our Redis database (provided through Vercel) so we can email your QR code and scan you in on the day. Merch orders are recorded in Airtable so we can pack and post them. Confirmation emails are sent through Resend.

Newsletter and waitlist sign-ups come from the forms on this Site and go to Mailchimp.

Why we use it, and our legal basis

  • To give you what you paid for — creating your ticket code, emailing your QR code, checking you in at the door, and posting your merch (performance of a contract). This is the main reason we hold your details, and it applies whether or not you ever want to hear from us again.
  • To send you order and ticket confirmations (performance of a contract).
  • To send you newsletters and updates about future events — only if you've opted in (consent). Buying a ticket does not sign you up. If you buy from us, we'll send you one confirmation email asking whether you'd like to hear from us, and you only join the list if you click the link in it. You can unsubscribe at any time from any newsletter we send.
  • To keep our forms working and stop spam and abuse (legitimate interest).
  • To keep basic order records for accounting purposes (legal obligation).

We do not use your data for anything else, and we don't profile you or make automated decisions about you.

Who we share it with

We use a small number of trusted service providers ("processors") to run the Site, each of whom only receives the data they need to do their specific job:

  • Stripe — payment processing for tickets and merch. Stripe handles your card details; we never see them.
  • Vercel — hosting for this Site, and the Redis database (provided through Vercel) that stores your ticket code, name and email so we can issue your QR code and check you in.
  • Resend — sending your order and ticket confirmation emails.
  • Mailchimp — newsletter and waitlist sign-ups, and sending those emails.
  • Airtable — internal order and stock tracking for merch only. Ticket purchases are never recorded here.

Each processor only receives the data it needs for its specific job. We do not sell your personal data to anyone, and we don't share it for anyone else's marketing.

International transfers

Some of the processors above are based outside the UK/EEA (for example, in the US). Where that's the case, they provide appropriate safeguards — such as Standard Contractual Clauses — as required under UK GDPR.

Cookies

See our Cookie Policy for full detail. In short: this Site doesn't currently set any analytics or tracking cookies itself.

How long we keep your data

  • Ticket records (your name, email and ticket code) — kept until shortly after the event has taken place, since we need them to let you in on the day and to answer any follow-up questions. After that we delete them.
  • Merch order records — kept until your order is delivered and any returns window has passed.
  • Payment and transaction records — held by Stripe for as long as required for UK tax and accounting purposes (currently 6 years). This is a legal obligation and applies even if you ask us to delete everything else.
  • Newsletter data — kept until you unsubscribe.
  • Technical data (the IP counting described above) — automatically deleted within minutes.
  • Correspondence — kept only as long as we need it to deal with your query.

You can ask us to delete your data at any time — see Your rights below.

Your rights

Under UK GDPR, you have the right to access, correct, delete, restrict or object to our use of your data, and to request your data in a portable format. Where we rely on your consent — that's the newsletter — you can withdraw it at any time, either by clicking unsubscribe in any email we send, or by emailing us.

To exercise any of these rights, email info@ambifest.com and we'll action it. We're a small volunteer team, so please bear with us — but we'll always respond within one month, as the law requires. You also have the right to complain to the Information Commissioner's Office (ICO).

Children's data

Our general Ambifest socials are for adults. Ambi Con welcomes under-18s, but a Child ticket must be bought alongside an Adult ticket for the accompanying adult, in the same order — that adult provides any necessary contact details on the child's behalf, and stays with them for the whole visit.

Security

We take reasonable technical and organisational steps to protect your data — for example, API keys and secrets used by this Site are kept server-side and are never exposed in the site's code. No method of transmission over the internet is completely secure.

Changes to this policy

We may update this policy from time to time. The "last updated" date at the top of this page reflects the latest version.

Contact

Questions about this policy or your data? Email info@ambifest.com.

Ambifest

Connecting young creatives across London through events led by volunteers and built on ambition, wellness and connection.

Explore

AboutEventsMerchAmbi Con ↗

Legal

Health & SafetyWebsite T&CsPrivacy PolicyCookie PolicyCode of Conduct
© 2024 to 2026 Ambifest Ltd. London, UK.Built by volunteers