Privacy Policy
This privacy policy covers both the marketing website ravevent.com and the Ravevent web application at app.ravevent.com. Part 1 describes the processing of data in the application; Part 2 describes the — much smaller — processing that happens when you simply visit this marketing website.
Last updated: September 2026
Part 1 — For Ravevent Users (app.ravevent.com)
This part applies if you have a Ravevent account and use the application.
1. Data Controller
2. Data We Collect
We collect the following categories of personal data:
Account Data
- Email address (required for registration and communication)
- Username (required for identification)
- Password (stored as a bcrypt hash, never in plain text)
- Full name and display name (optional)
Usage Data
- IP address (stored per login session for security purposes)
- Browser user-agent (stored per session for device recognition)
- Session timestamps (login time, last activity)
Content Data
- Events you create or participate in (name, description, dates, location)
- Artist profiles you create (name, bio, genre, links)
- Timetable slots and scheduling data
3. Legal Basis for Processing
Performance of Contract (Art. 6(1)(b) GDPR): The processing of your account data and the content you create is necessary to provide the event-planning service you registered for.
Legitimate Interest (Art. 6(1)(f) GDPR): Session tracking (IP address, user-agent) and security alerts are based on our legitimate interest in securing user accounts.
Consent (Art. 6(1)(a) GDPR): Where processing is genuinely optional, we rely on your consent.
4. Purpose of Data Processing
- Providing and maintaining your user account
- Enabling event planning, team collaboration, and timetable management
- Protecting your account through session monitoring and security alerts
- Sending transactional emails (verification, password reset, invitations)
5. Data Retention
We retain your data for the following periods:
- Account data: Retained as long as your account is active.
- Session data (IP, user-agent): Retained for 90 days after the session ends.
- Security tokens: Automatically expire and are cleaned up periodically.
- Database backups: Retained for 14 days, then automatically deleted.
6. Third-Party Services
We use the following third-party services as processors, each governed by a data-processing agreement (Art. 28 GDPR):
- Email delivery: Transactional emails are sent via SMTP. No marketing emails are sent.
- Hosting: The application is hosted on servers operated by the data controller.
- Payments: Paid subscriptions are processed by Stripe Payments Europe, Ltd. (Ireland).
Analytics (Umami)
We use Umami for reach measurement. Umami is self-hosted on our own infrastructure and is operated by the data controller himself.
Beyond the self-hosted analytics described above we use no third-party analytics, advertising or tracking services.
8. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of Access (Art. 15): You can export all your data at any time via Profile > Export Data.
- Right to Rectification (Art. 16): You can update your profile information at any time.
- Right to Erasure (Art. 17): You can delete your account at any time via Profile > Delete Account.
- Right to Data Portability (Art. 20): You can download your data in a machine-readable JSON format.
- Right to Object (Art. 21): You can object to the processing of your data by contacting us.
- Right to Withdraw Consent (Art. 7(3)): You can withdraw your consent at any time.
- Right to Lodge a Complaint (Art. 77): You have the right to lodge a complaint with a supervisory authority.
9. Data Security
We implement the following technical measures to protect your data:
- All data in transit is encrypted using TLS/HTTPS.
- Passwords are hashed using bcrypt with individual salts.
- Optional two-factor authentication (TOTP) for enhanced account security.
- Role-based access control ensures users can only access authorized data.
- Rate limiting protects against brute-force attacks.
10. Changes to This Policy
We may update this privacy policy from time to time.
11. Contact
Part 2 — For Visitors of ravevent.com
This part applies if you only visit this marketing website without using the Ravevent application.
The data controller is the same as in Part 1.
This marketing website has no registration, no login and no user accounts.
Server logs: When you open a page, our server processes the usual technical connection data.
Reach measurement: This marketing website uses the same self-hosted Umami instance described in section 6.
Contact by email: If you write to us using the contact link on this website, we process your message solely in order to answer you.
Your rights: The rights listed in section 8 apply to this processing in exactly the same way.