Privacy policy
Last updated: 4 August 2026
This policy explains what personal data Festa processes, why, and what rights you have under the EU General Data Protection Regulation (GDPR). The short version: we process what is needed to run accounts, tickets, tips and payouts — nothing more. Festa shows no ads, sells no data, and uses no tracking or analytics cookies.
1. Controller
oyfora AB, Anders Reimers väg 17, 117 50 Stockholm, Sweden
Email: hi@oyfora.io
2. What we process, and why
a) Account data
Email address, name and a securely hashed password (or your Google/Apple sign-in identifier) when you create an account; profile data you add as an organizer or artist. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
b) Ticket purchases
Buyer name and email address, the order and its tickets, an optional message to the organizer, and a shortened (hashed) form of your IP address used to prevent abuse. Your name and ticket status are visible to the organizer's door staff at check-in. When you open an event through a shared referral link, we count the click with a hashed IP (no profile, no tracking across sites). Legal basis: performance of a contract (Art. 6(1)(b)); fraud prevention and referral counting as legitimate interests (Art. 6(1)(f)).
c) Tips and contributions
The amount, the recipient, an optional message and — only if you choose to provide it — your email address. Tips can be sent without an account. Legal basis: performance of a contract (Art. 6(1)(b)).
d) Payment data
All payments are processed by Stripe. Your card or bank details are entered directly with Stripe and never reach our servers; we receive only payment status and reference identifiers. Organizer and artist payouts run through their own Stripe accounts (Stripe Connect).
e) Emails
We send transactional email — order confirmations, tickets, transfer and payout notifications — and log delivery status. Legal basis: performance of a contract (Art. 6(1)(b)). In addition, after an event you bought a ticket for, we may send you one email for that event inviting you to support the people behind it. Legal basis: our legitimate interest in promoting similar services to existing customers (Art. 6(1)(f) GDPR, § 7 (3) UWG). Every such email contains a one-click opt-out link, and we honour opt-outs permanently. If you tick the newsletter box at checkout we store that consent (Art. 6(1)(a)); you can withdraw it anytime — we currently send no newsletter.
f) Access applications
If you request access during our invite-only phase, we process the name, email address and message you submit, to review the application and reply. Legal basis: steps prior to entering a contract (Art. 6(1)(b)).
g) Server logs
Technical request logs (URL, timestamp, status, user agent) kept briefly for security and operations. Legal basis: legitimate interest (Art. 6(1)(f)).
3. Cookies and local storage
We use no advertising or analytics cookies. Your browser stores only what is technically required to keep you signed in (authentication session). Because this storage is strictly necessary, no consent banner is required.
4. Who receives data
- The organizer or artist you buy from or tip: when you buy a ticket, the organizer receives your name, email address and order details as the party responsible for running the event; if you tip with a message, the recipient sees the message and amount.
- Stripe (Stripe Payments Europe Ltd., Ireland) — payment processing and payouts. Stripe may transfer data to the USA under EU standard contractual clauses / the EU-US Data Privacy Framework.
- Supabase — database and authentication hosting, located in Frankfurt, Germany (EU).
- Google Cloud — application hosting in the EU (europe-west1, Belgium).
- Resend — transactional email delivery (USA, safeguarded by EU standard contractual clauses).
- Google Wallet — only if you choose "Add to Google Wallet" on a ticket: the pass (your name, event, ticket type and QR code) is sent to Google LLC at your request; Google's own privacy policy applies, and a transfer to the USA may occur.
These providers act as our processors under Art. 28 GDPR (except Stripe and the organizer, who are independently responsible for their own processing). We never sell personal data.
5. How long we keep data
- Account data: until you delete your account.
- Orders, payments and payout records: for the duration of statutory bookkeeping and tax retention periods (up to 10 years).
- Email delivery logs and referral-click logs: up to 12 months, then purged automatically. Server request logs: short technical retention.
6. Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21). Where processing is based on consent, you may withdraw it at any time with future effect. You can delete your account yourself in the app under Settings.
You also have the right to lodge a complaint with a supervisory authority — in Sweden the Integritetsskyddsmyndigheten (IMY), or the data protection authority of your own country of residence.
7. No automated decision-making
We make no automated decisions with legal effect and build no profiles.
8. Changes
We update this policy when the service changes. The current version is always published on this page.