Privacy policy

Last updated: 19 July 2026

Who we are: Buntico ("the Platform", "we", "us") is operated by Stuart Hooper, a sole trader trading as Buntico, of 4 Furlong Row, Clanfield, Bampton, Oxfordshire, OX18 2RW. We are the data controller for the personal data described in this policy. Contact for privacy matters: hms1270@pm.me.

1. The Platform and Organisers — who is responsible for what

The Platform hosts events run by independent Organisers. We are the controller for your Platform account and the data described below. When you book a stall at, or buy a ticket to, a specific event, the relevant Organiser also receives your booking or ticket data and uses it to run their event as a controller in their own right — for example, an Organiser sees the compliance documents of Stall Holders who apply to their events, and the attendee details needed at their gate. Organisers may not use that data for anything beyond running their events and meeting their legal obligations.

2. What we collect

Everyone: name, email, password (stored hashed), phone number if provided, your marketing/SMS preferences, and technical data (IP address, device/browser information, security logs).

Stall Holders additionally: business name and profile (description, photos, logo — public only if you opt in), compliance documents you upload (e.g. insurance certificates, food hygiene certificates, gas or alcohol certification) and their expiry dates, booking history, and pitch requirements (size, power, water, vehicle access).

Customers additionally: ticket orders, tickets and check-in status.

Everyone who pays or is paid: payment is processed by Stripe — we receive transaction records (amount, status, last card digits) but never see or store full card numbers.

Reviews: if you leave a review we store it with your chosen display name (full name, first name, or anonymous).

3. Why we use it and our lawful bases (UK GDPR)

  • To provide the service — accounts, profiles, document storage and review, bookings, tickets, payments, receipts: performance of a contract.
  • Service communications — booking confirmations, document approval outcomes, expiry reminders, event changes and cancellations, by email and (only if you opted in) SMS: performance of a contract / legitimate interests. These are not marketing; they are how the service works. SMS can be switched off in your settings at any time.
  • Safety and integrity — verifying documents, moderating reviews, preventing fraud and abuse, securing accounts, audit trails of approvals and refunds: legitimate interests / legal obligation.
  • Legal compliance — retaining financial and transaction records: legal obligation.
  • Marketing, if we ever send it, will be consent-based and separately opt-in; we do not sell personal data and the Platform carries no advertising.

4. Who we share it with

  • The relevant Organiser — as described in section 1: your documents (Stall Holders who apply to their events), booking and pitch details, attendee/ticket details.
  • Service providers (processors) acting on our instructions: Stripe (payments), Supabase (hosting and database), Resend (email delivery), ClickSend (SMS delivery), Cloudflare (security/anti-bot), Backblaze (encrypted backups). Each is bound by contract to protect your data.
  • Authorities where the law requires it.
  • We never sell personal data.

5. International transfers

Some providers process data outside the UK (including the United States). Where they do, transfers are protected by UK-approved safeguards — adequacy regulations or the International Data Transfer Agreement / Standard Contractual Clauses with the UK addendum. Details available on request.

6. How long we keep it

  • Account and profile data: while your account is active.
  • Compliance documents: deleted automatically 12 months after your last event on the Platform, or sooner on request where no live booking depends on them.
  • Financial and transaction records: 6 years, as UK tax law requires, even after account closure.
  • Reviews: retained after account deletion in anonymised form (your name removed); pending reviews are deleted.
  • Notification and audit logs: 24 months.
  • Account deletion: request it in your settings — your profile is anonymised, documents deleted, and only what the law obliges us to keep is retained.

7. Your rights

You can ask us to: access the data we hold on you (a self-service export is available in your account); correct it; delete it; restrict or object to certain processing; and provide it in a portable format. Contact hms1270@pm.me and we will respond within one month. You can withdraw SMS consent in settings at any time. If you are unhappy with our handling of your data you may complain to the Information Commissioner's Office (ico.org.uk), though we would welcome the chance to resolve it first.

8. How we protect it

Data is encrypted in transit and at rest. Access is isolated per organisation at the database level. Compliance documents live in private storage and are only ever accessible through short-lived, expiring links to the people entitled to see them. Administrator accounts require two-factor authentication. Every document approval, refund and administrative action is recorded in an audit trail. Backups are held with a separate provider.

9. Cookies

We use essential cookies required for login, security and checkout, and — only with your consent via the cookie banner — analytics cookies to understand how the Platform is used. We do not use advertising cookies. A full list is available at /cookies.

10. Children

The Platform is for adults: you must be 18 or over to hold an account or make a purchase. We do not knowingly collect children's data; if you believe we hold any, contact us and we will delete it.

11. Changes to this policy

We will notify account holders of material changes by email with reasonable notice. The current version always lives at /privacy.

Contact: hms1270@pm.me · 4 Furlong Row, Clanfield, Bampton, Oxfordshire, OX18 2RW · Data protection queries: hms1270@pm.me