Privacy policy

Last updated: 29 July 2026

This privacy policy explains how Biddly (“we”, “us”, “our”) collects, uses, and shares personal data when you use biddly.app, related short links (such as bidd.ly), embeds on organiser websites, our APIs, and the Biddly Scanner app (together, the “Services”).

Biddly provides event ticketing, auctions, ballots, refunds tooling, and door scanning for organisations (“organisers”) and the people who buy tickets or enter draws (“buyers”).

For account registration, authentication, platform operations, support, and product analytics we carry out as the service provider, Biddly is the data controller.

When an organiser runs an event on Biddly, that organiser typically decides the purposes for which event, ticket, attendance, and related buyer details are processed. In those cases the organiser is usually the controller of that event-related data, and Biddly processes it on their behalf as a processor to provide the Services. If you have questions about a specific event’s use of your data (for example refunds or marketing by the organiser), contact the organiser first.

Depending on how you use the Services, we may process:

  • Identity and contact details — name, email address, and similar account profile fields.
  • Account and authentication data — sign-in identifiers, linked sign-in methods (for example email/password or Google), session and security logs.
  • Organisation and team data — organisation name, membership, roles (for example admin, editor, viewer, scanner), and invite details.
  • Event and commerce data — event details you create or attend, ticket purchases, auction bids, ballot entries, refund requests, complimentary claims, and related status history.
  • Payment-related data — amounts, currency, payment status, and Stripe identifiers needed to fulfil orders and reconcile payouts. Card numbers and full payment credentials are handled by Stripe; we do not store full card numbers.
  • Scanning and attendance data — ticket validation and scan-in/scan-out records when door staff use the Scanner app.
  • Technical data — IP address, device/browser type, approximate location derived from IP where used for security or features you request, app version, and diagnostic logs.
  • Communications — messages you send to support, and transactional emails we send (purchase confirmations, invites, auction or ballot notices).
  • You, when you create an account, join an organisation, buy tickets, bid, enter a ballot, or contact support.
  • Organisers and their team members, when they create events, invite users, or process refunds.
  • Payment and identity providers such as Stripe (payments and Connect onboarding) and our authentication provider.
  • Automatically from your device when you use the website, embeds, or Scanner app.

We use personal data to:

  • Provide, operate, and secure the Services (accounts, events, checkout, auctions, ballots, refunds, embeds, and scanning).
  • Process payments and payouts with Stripe, including Connect onboarding for organisers.
  • Send transactional messages (for example purchase confirmations, password reset, organisation invites, auction or ballot results).
  • Provide customer support and investigate abuse, fraud, or security incidents.
  • Improve reliability and product quality using aggregated or diagnostic information.
  • Meet legal obligations and enforce our terms.

Where UK data protection law applies, we rely on one or more of: performance of a contract (providing the Services you request); legitimate interests (securing and improving the platform, preventing abuse — balanced against your rights); legal obligation; and consent where we ask for it (for example certain cookies or optional features). Organisers are responsible for their own lawful bases when they use buyer data for their events.

We share personal data only as needed to run the Services, including with:

  • Organisers and their authorised team members — for events you interact with (for example ticket lists, bidder details the organiser needs to fulfil an auction, scan results).
  • Stripe — payment processing and Connect account onboarding. Stripe’s use of data is described in Stripe’s own privacy notice.
  • Infrastructure and service providers that host or operate parts of the platform (for example cloud hosting, email delivery, error monitoring), under appropriate agreements.
  • Professional advisers or authorities where required by law or to protect rights, safety, and security.

We do not sell your personal data.

We primarily operate infrastructure in the European Economic Area (including AWS regions such as Ireland). Some providers may process data in other countries. Where we transfer personal data internationally, we use appropriate safeguards required by applicable law (such as standard contractual clauses) where needed.

We keep personal data only as long as needed for the purposes above: for example while your account is active, for the life of an event’s operational needs, and thereafter for limited periods required for security, dispute handling, accounting, and legal compliance. We then delete or anonymise data where practicable.

We use technical and organisational measures appropriate to the risk, including encrypted transport (HTTPS), access controls, and monitoring. No method of transmission or storage is completely secure; please use a strong unique password and protect your devices.

Depending on your location, you may have rights to access, correct, delete, or restrict processing of your personal data, to object to certain processing, to data portability, and to withdraw consent where processing is based on consent. You may also complain to the UK Information Commissioner’s Office (ICO) or another supervisory authority.

To exercise rights about platform account data, contact us using the details below. For event-specific requests that the organiser controls, we may need to involve the organiser.

The Services are aimed at organisations and adults. They are not directed at children under 16. If you believe we have collected data from a child inappropriately, contact us and we will take appropriate steps.

We use cookies and similar technologies that are necessary to sign you in, keep sessions secure, remember preferences (such as theme or locale), and operate the site. If we introduce non-essential analytics cookies, we will provide appropriate notices and controls where required.

We may update this privacy policy from time to time. We will post the updated version on this page and revise the “Last updated” date. If changes are material, we may provide additional notice (for example by email or in-product notice).

Privacy questions: email support@biddly.app. Please include enough detail for us to identify your account or request.