This policy explains what personal data Capacity collects, why we collect it, and what rights you have. It covers our website and our platform.
Capacity Digital Ltd, company number 14487697, registered at 167-169 Great Portland Street, London W1W 5PF, is the controller of the personal data described in section 3.
We handle personal data in two distinct roles, and it matters which applies:
If you bought a ticket, made a booking, or received a marketing message from a venue that uses Capacity, contact that venue about your data. It is the controller and its privacy notice applies.
Where the venue cannot be identified or does not respond, write to legal@getcapacity.co and we will identify it and pass the request on.
Where we rely on legitimate interests, we have assessed that our interest does not override your rights. You can ask us for that assessment.
We use strictly necessary cookies, and, with your consent, analytics and advertising cookies including retargeting pixels operated by Google, Meta, TikTok and Snapchat. Those parties act as controllers of the data they collect.
Consent is requested before any non-essential cookie is set, refusing is as straightforward as accepting, and consent may be withdrawn at any time using the Cookie settings link in the footer. Our Cookie Policy lists each cookie, its purpose and its lifetime.
We share personal data with service providers who help us run Capacity, each under a contract that requires them to protect it:
Third parties processing customer data on our behalf are named, with purpose and data location, on our sub-processor page. Customers receive at least 30 days' notice before one is added or replaced, and may object.
We do not sell personal data, and we do not use customer data to train models.
Some providers are outside the UK. Where personal data is transferred, we rely on UK adequacy regulations, or on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment.
Under the UK GDPR you have the right to be informed, to access your data, to have it corrected or erased, to restrict or object to processing, to data portability, and to withdraw consent where we rely on it. You also have the right not to be subject to a solely automated decision with legal or similarly significant effects.
To exercise a right, contact us using the details in section 12. We will respond within one month. We do not charge unless a request is manifestly unfounded or excessive.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner’s Office at ico.org.uk, or on 0303 123 1113. We ask that you raise the matter with us first.
We use technical and organisational measures appropriate to the risk, including encryption in transit, access control on a least-privilege basis, logging, and regular backups. No system is completely secure, and we cannot guarantee absolute security.
Where a personal data breach is likely to result in a risk to people’s rights, we will notify the ICO within 72 hours of becoming aware, and affected individuals where the risk is high. Where we are a processor, we will notify the customer without undue delay.
Our security page sets out these measures, where data is stored, and how to report a vulnerability. Capacity holds no security certification.
Capacity is a business service and is not directed at children. We do not knowingly collect data from anyone under 18 through our own website. Where our customers sell age-restricted tickets, age verification is their responsibility.
Write to legal@getcapacity.co, or to Capacity Digital Ltd, 167-169 Great Portland Street, London W1W 5PF.
We may update this policy. The date at the top shows when it last changed. Where a change is significant we will tell you directly.