—Privacy Policy

Privacy Policy

Version 2026-08-17 · AFTR DARK Group Inc., Toronto

What we collect

When you buy a ticket or RSVP: your name, email, optionally your phone number, and your order details. When an organizer uses tracking links: the link you arrived through, stored in cookies (ad_ft for 90 days, ad_lt for 30 days), a hashed IP, and your browser's user agent.

For age-restricted events, we collect each guest’s date of birth to check eligibility on the event date. Birth dates are optional for other events. Optional gender and city responses contribute to the organizer’s aggregate audience charts. They are not verified identity or a replacement for ID checks at the door.

On an aftr.bio page (an organizer's or an artist's link page), we count views and which links are pressed, along with the referring website, a device type of phone, tablet or desktop, and the country, region and city your network resolves to at the edge. No cookie is used for this. Visitors are told apart by a key derived from your IP address and browser, which is re-salted every day and deleted with the data after 400 days, so the same person is counted once a day and cannot be followed between months. When you open an event from one of those pages, a cookie (ad_bio, 30 days) records which page sent you so the organizer or artist can see what their page led to.

If you request an event reminder, we collect your email and require confirmation before sending one reminder. You can cancel using your confirmation link. Saving an event uses a browser identifier cookie (ad_interest, up to one year) and local storage.

When you arrive through a Bandsintown ticket link, we retain its click identifier in a first-party, event-specific cookie for up to 30 days and save it with your order to attribute referrals and purchases. It is not proof of identity or marketing consent.

For organizers: account details, organization details, and — for managed advertising — billing information handled by Stripe. We never see or store full card numbers.

How it's used

Your ticket data exists to get you into the event: passes, door check-in, and communication about the event you booked. The organizer of an event you attend can see your attendance for their own events.

Marketing consent is per organizer. Ticking a consent box for one organizer never signs you up for another's list, and every marketing message records the consent it relies on, as Canadian anti-spam law requires.

Where an organizer runs advertising measurement, we send hashed identifiers (never raw email addresses or phone numbers) to advertising platforms server-side, so the organizer can measure whether their ads led to attendance.

What we don't do

We don't sell personal data. We don't combine attendee lists across organizers for marketing. We don't send raw personal information to advertising platforms.

Your rights

You can ask what we hold about you, ask for a correction, or ask for deletion, subject to records we must keep (like completed transactions). For attendees in the EU or UK, GDPR rights apply and the organizer of your event is the data controller; we process on their behalf.

Write to abdallah@aftrdark.ca and we'll respond within 30 days.

Cookies

We use a session cookie to sign organizers in, and the attribution cookies described above so organizers can tell which link or page brought you. Page view counting on aftr.bio uses no cookie at all. No third-party advertising cookies are set by our pages.