Evie Software Ltd
Privacy Policy
Effective 21 July 2026
This Privacy Policy explains how Evie Software Ltd (“EvieBooking”, “we”, “us”) collects, uses and protects personal data, and the rights you have. We are registered with the UK Information Commissioner’s Office (ICO) under reference [ICO REGISTRATION NUMBER].
1. Our two roles
We handle personal data in two different capacities:
- As a controller — for the personal data of the Businesses that use EvieBooking (their account holders and team members) and of visitors to our own websites. This policy governs that data.
- As a processor — for the personal data of Attendees who book with a Business, which we process on that Business’s instructions. In that case the Business is the controller; our obligations are set out in our Data Processing Agreement, and you should also read the Business’s own privacy notice.
2. Personal data we collect
| Category | Examples |
|---|---|
| Account data | Name, email, phone, business details, team members, password (hashed), and any two-factor authentication details. |
| Booking data | Bookings, attendees, custom form answers, notes, attendance/check-in records. |
| Payment data | We do not store card numbers. Payments are handled by Stripe; we hold transaction references, amounts, fee amounts and payout status. |
| Communications | Emails, support messages and marketing preferences (including the date consent was given). |
| Technical data | IP address, device/browser information, log data and cookies (see our Cookie Policy). |
3. How and why we use personal data
| Purpose | Lawful basis |
|---|---|
| Providing and operating the Service; managing accounts and bookings | Performance of a contract |
| Taking payments and handling fees and payouts | Performance of a contract; legal obligation |
| Sending service emails (confirmations, reminders, changes) | Performance of a contract; legitimate interests |
| Marketing emails to those who have opted in | Consent (you can withdraw at any time) |
| Security, fraud prevention and improving the Service | Legitimate interests |
| Complying with legal, accounting and tax obligations | Legal obligation |
4. Marketing
We only send marketing emails where you have opted in, and every marketing email includes a one-click unsubscribe. Businesses that use the Service to email their own Attendees are responsible for having a lawful basis to do so; we provide the unsubscribe mechanism on their behalf.
5. Who we share data with
We share personal data with service providers who help us run the Service, under contract and only as needed:
- Stripe — payment processing.
- Email delivery provider — sending transactional and marketing emails.
- Hosting and infrastructure providers — hosting the Service and protecting it from abuse.
- Professional advisers and authorities — where required by law.
We do not sell personal data. A current list of our sub-processors is available on request and is covered by our Data Processing Agreement.
6. International transfers
We aim to keep personal data in the UK/EU. Where a provider processes data outside the UK/EU, we rely on appropriate safeguards such as UK adequacy regulations or the International Data Transfer Agreement / Standard Contractual Clauses.
7. How long we keep data
We keep personal data for as long as needed to provide the Service and to meet legal, accounting and tax requirements, then delete or anonymise it. Attendee data processed for a Business is retained according to that Business’s instructions; on request we support export and erasure.
8. Your rights
Subject to conditions in data protection law, you have the right to:
- access a copy of your personal data;
- have inaccurate data corrected;
- have your data erased;
- restrict or object to processing;
- data portability; and
- withdraw consent at any time (without affecting prior processing).
To exercise these rights, contact [email protected]. If your data is processed by a Business (as an Attendee), please contact that Business first. You also have the right to complain to the ICO at ico.org.uk.
9. Security
We use appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls and hashing of credentials. No system is completely secure; we will notify you and the ICO of a personal data breach where required by law.
10. Children
The Service is not directed at children. Where a Business collects data about children (for example a child’s name for a class), the Business is responsible for obtaining any necessary consent.
11. Changes
We may update this policy from time to time and will post the updated version here with a new effective date.
12. Contact
Evie Software Ltd, [REGISTERED OFFICE ADDRESS]. Data protection enquiries: [email protected].