Capacity
Platform How it works
TicketingSell under your own name For nightclubsBuilt around how the week runs
Integrations Book a demo
Sign in Book a demo

Privacy Policy

Last updated 24 August 2026

This policy explains what personal data Capacity collects, why we collect it, and what rights you have. It covers our website and our platform.

1. Who we are

Capacity Digital Ltd, company number 14487697, registered at 167-169 Great Portland Street, London W1W 5PF, is the controller of the personal data described in section 3.

2. Two different roles

We handle personal data in two distinct roles, and it matters which applies:

  • As a controller. For our own website visitors, prospects, and the staff at our customers who use the platform. We decide why and how that data is used, and this policy governs it.
  • As a processor. For the customer data our customers put into the platform, including their ticket buyers, bookers, enquirers and marketing contacts. This includes the contact lists venues use to send email, SMS and WhatsApp marketing through Capacity. Our customer is the controller of that data and their own privacy notice governs it, not this one. We process it only on their documented instructions, under our Data Processing Agreement.

If you bought a ticket, made a booking, or received a marketing message from a venue that uses Capacity, contact that venue about your data. It is the controller and its privacy notice applies.

Where the venue cannot be identified or does not respond, write to legal@getcapacity.co and we will identify it and pass the request on.

3. What we collect as a controller

  • Account and contact data: name, work email, phone number, job title, business name and address.
  • Enquiry data: what you tell us when you request a demo or get in touch.
  • Billing data: billing contact, address and VAT details. Card details are handled by our payment provider, not by us.
  • Usage data: pages visited, features used, approximate location from IP, device and browser type, and log data.
  • Communications: emails and messages between us, and notes from calls.

4. Why we use it, and our lawful basis

  • To provide the service and administer your account. Basis: performance of a contract.
  • To take payment and keep accounts. Basis: contract, and legal obligation for tax records.
  • To support you and respond to enquiries. Basis: contract, or legitimate interests in answering people who contact us.
  • To improve and secure the platform, including troubleshooting and preventing abuse. Basis: legitimate interests in running a reliable, secure service.
  • To market to businesses, where we think our service is relevant. Basis: legitimate interests, or consent where required. You can opt out at any time.
  • To meet legal obligations, including responding to lawful requests. Basis: legal obligation.

Where we rely on legitimate interests, we have assessed that our interest does not override your rights. You can ask us for that assessment.

5. Cookies and similar technologies

We use strictly necessary cookies, and, with your consent, analytics and advertising cookies including retargeting pixels operated by Google, Meta, TikTok and Snapchat. Those parties act as controllers of the data they collect.

Consent is requested before any non-essential cookie is set, refusing is as straightforward as accepting, and consent may be withdrawn at any time using the Cookie settings link in the footer. Our Cookie Policy lists each cookie, its purpose and its lifetime.

6. Who we share it with

We share personal data with service providers who help us run Capacity, each under a contract that requires them to protect it:

  • cloud hosting and database providers;
  • payment processing;
  • email and SMS delivery;
  • analytics and product telemetry;
  • customer support and CRM tools;
  • professional advisers, and authorities where the law requires it.

Third parties processing customer data on our behalf are named, with purpose and data location, on our sub-processor page. Customers receive at least 30 days' notice before one is added or replaced, and may object.

We do not sell personal data, and we do not use customer data to train models.

7. International transfers

Some providers are outside the UK. Where personal data is transferred, we rely on UK adequacy regulations, or on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment.

8. How long we keep it

  • Account data: for the life of the account and six years after it closes, to cover the limitation period.
  • Billing records: six years, as tax law requires.
  • Enquiry data from prospects who do not become customers: 24 months.
  • Usage and log data:
  • Customer Data processed for our customers: for the term of their subscription and 30 days after it ends, unless they ask us to delete it sooner.

9. Your rights

Under the UK GDPR you have the right to be informed, to access your data, to have it corrected or erased, to restrict or object to processing, to data portability, and to withdraw consent where we rely on it. You also have the right not to be subject to a solely automated decision with legal or similarly significant effects.

To exercise a right, contact us using the details in section 12. We will respond within one month. We do not charge unless a request is manifestly unfounded or excessive.

If you are unhappy with how we have handled your data you can complain to the Information Commissioner’s Office at ico.org.uk, or on 0303 123 1113. We ask that you raise the matter with us first.

10. Security

We use technical and organisational measures appropriate to the risk, including encryption in transit, access control on a least-privilege basis, logging, and regular backups. No system is completely secure, and we cannot guarantee absolute security.

Where a personal data breach is likely to result in a risk to people’s rights, we will notify the ICO within 72 hours of becoming aware, and affected individuals where the risk is high. Where we are a processor, we will notify the customer without undue delay.

Our security page sets out these measures, where data is stored, and how to report a vulnerability. Capacity holds no security certification.

11. Children

Capacity is a business service and is not directed at children. We do not knowingly collect data from anyone under 18 through our own website. Where our customers sell age-restricted tickets, age verification is their responsibility.

12. Contact and changes

Write to legal@getcapacity.co, or to Capacity Digital Ltd, 167-169 Great Portland Street, London W1W 5PF.

We may update this policy. The date at the top shows when it last changed. Where a change is significant we will tell you directly.

Capacity

Ticketing, bookings and marketing for venues. Sell under your own brand, own the customer, and bring them back.

Product

Platform Integrations How it works

Company

Agency Security Careers Contact FAQ

Get started

Book a demo Sign in

Legal

Terms Privacy DPA Acceptable use Cookies
© Capacity Digital Ltd 2026 · Company No. 14487697 Cookie settings 167-169 Great Portland Street, London W1W 5PF