Privacy notice · v4.1 · effective 2026-10-08
What we do with your data
Who we are
Late Reveal is a trading name of LATE REVEAL LTD, registered in England and Wales, company no. 17490427. Registered office: 71-75 Shelton Street, Covent Garden, London WC2H 9JQ. We are the data controller for the information described here - reach us at hello@latereveal.com, or by post at that address. We have not appointed a data protection officer; we're not required to.
What we collect
Only what we need to sell you a ticket, get you to the right place and look after you when you are there:
- Your account: your email address, which is also how you sign in - a code is emailed to you each time. There is no password.
- What you tell us when you first book: your name, the country you are from if you choose to say, a phone number, and anything you can't eat or drink. The phone number is so we can reach you on the day if something changes; we do not use it for marketing and it is not verified.
- Earlier answers: if you joined before October 2026 you may have answered a longer set of questions about yourself. We still hold those answers and no longer ask for them; ask and we will delete them.
- Your bookings: which events you booked, what you paid, and anything you told us afterwards.
- Payments: we do not see or store card numbers. Stripe takes the payment and tells us only whether it worked.
- Where you found us: if you arrive by a link we have tagged (a listing somewhere else, a profile, one of our own emails), the name of that link, kept with your account and with a booking you go on to make.
- Technical: standard server logs, an essential session cookie that keeps you signed in, and the cookie described under Cookies below.
Special category data
Some answers - how you describe your gender, or dietary needs that point to a religion, for instance - can reveal things UK GDPR treats as sensitive. You choose whether to answer, every one of those questions has a 'rather not say' or 'nothing' option, and we use the answers only to feed people properly and, for events that have groups, to build balanced ones. Where a question does touch special category data we rely on your explicit consent under Article 9(2)(a), which you can withdraw at any time by emailing us.
Why we use it, and our lawful basis
Each use has one basis under UK GDPR Article 6:
- Running your account, taking your booking and getting you the details of your event - performance of our contract with you.
- Taking event payments and keeping accounting records - contract, and legal obligation for tax records.
- Keeping events safe and preventing abuse - our legitimate interests in running a working service.
- Counting which of the places we post brings people to us - our legitimate interests in knowing what works. You can object to that; see Cookies.
- Emailing you to sign you in, about events that are coming up, and about bookings you've made - contract. Every email about upcoming events has an unsubscribe link.
What other people see
The host of an event you have booked sees your name, your phone number, the country you gave and anything you said you can't eat or drink, so they can look after you on the night. Where an event is run with a venue, we may pass the venue what people can't eat or drink, without names where we can. Other guests are told nothing about you by us. There is no directory, and nothing about you is published on the public site.
Who we share it with
We do not sell your data. We share it with the suppliers who run the service for us:
- Stripe - payments.
- Resend - the emails we send you, including the sign-in code.
- MongoDB Atlas - the database.
- Our hosting provider - running the site.
Where it goes
Some of those suppliers process data outside the UK. Where they do, the transfer relies on UK adequacy regulations or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.
How long we keep it
Your account and answers for as long as you have an account, and for 2 years after your last registration if you go quiet - then we delete them. Registration and payment records are kept for 6 years, which is what HMRC's record-keeping rules and the limitation period for contract claims require. Server logs are kept for up to 12 months.
Your rights
You can ask for a copy of your data, ask us to correct or delete it, ask us to restrict or stop a particular use, or ask for it in a portable format. Where we rely on legitimate interests you can object; where we rely on consent you can withdraw it. Email hello@latereveal.com and we'll respond within one month. If you're not happy with how we've handled it you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.
Cookies
Two, both our own. The first is strictly necessary: the session cookie that keeps you signed in. It lasts 400 days and renews each time you visit, so signing in once is meant to be the last time; sign out and it's gone. The second is only set if you arrive by a link we have tagged, and it remembers the name of that link ("meetup", say) for 30 days, so we can count which of the places we post brings people to us. It holds that one word, nothing that identifies you, and nobody else can read it. It is not set if your browser sends a Global Privacy Control signal, you can delete it in your browser at any time, and you can email hello@latereveal.com to have the name taken off your account. We run no advertising cookies and nobody else's analytics.
Changes to this notice
If we change this notice we'll update the version and date at the top, and email you about anything significant.