1. Who we are
Venues2U is operated by Mark Evans, a sole trader trading as Venues2U (“Venues2U”, “we”, “us” or “our”). Venues2U helps customers discover and book venues and helps venue operators create, verify and manage listings.
Mark Evans trading as Venues2U is the controller of the personal information described in this policy unless stated otherwise. This policy applies to venues2u.com, partners.venues2u.com, Venues2U mobile applications, the partner portal and related booking services.
Privacy enquiries can be sent to [email protected].
2. Information we collect
Account and contact information
This may include a person’s name, date of birth, email address, telephone number, account identifiers, authentication and verification status, communication preferences, and records relating to password resets, email verification and multi-factor authentication. We do not receive or store a readable copy of a user’s password.
Venue and business information
For venue owners and representatives, this may include venue and business names, addresses, postcodes and geographic coordinates, website and contact details, Companies House information, authority to represent a venue, descriptions, facilities, capacities, opening hours, availability, prices, policies, photographs and verification evidence. Information submitted for a public venue listing may be published.
Identity and business verification
We may process identity-verification status and outcomes, Stripe Identity session references, business-matching results, supporting documents, verification correspondence, reviewer decisions and fraud or security signals. Stripe collects and processes identity documents and biometric verification materials used in Stripe Identity. Venues2U receives the result and session reference but does not intend to store Stripe’s copy of an identity document or selfie. Supporting business documents uploaded directly to Venues2U are held separately in private cloud storage.
Bookings, payments and communications
This may include venue enquiries, event requirements, booking status, customer and venue contact details, prices, fees, refunds, payment status, Stripe transaction references, support requests and other communications. Payment-card details are collected and processed by Stripe. Venues2U does not intend to store full card numbers or card security codes.
Technical information
We may collect IP address, device and browser type, operating system, app version, authentication and security events, API requests, error logs, approximate location derived from an IP address, access times, and diagnostic or performance information.
3. How we obtain information
We obtain personal information:
- directly from users when they register, create a listing, make a booking, upload information or contact us;
- automatically when users access or interact with our services;
- from another booking participant, venue representative or organisation;
- from public sources such as Companies House; and
- from service providers such as Firebase, Stripe and fraud-prevention or security services.
4. How and why we use information
| Purpose | Typical lawful basis |
|---|---|
| Create and administer accounts | Contract or steps requested before entering a contract |
| Authenticate users and maintain secure sessions | Contract and our legitimate interests in operating a secure service |
| Create, verify and publish venue listings | Contract, pre-contractual steps and our legitimate interests in maintaining trustworthy listings |
| Process enquiries, bookings, payments, refunds and fees | Contract and compliance with financial, tax and accounting obligations |
| Verify identity, authority and business information | Our legitimate interests in preventing fraud and protecting customers, venues and the platform; legal obligations where applicable |
| Provide support and service communications | Contract and our legitimate interests in supporting users |
| Detect fraud, abuse and security incidents | Our legitimate interests in protecting the service, users and third parties; legal obligations where applicable |
| Maintain records and resolve disputes | Contract, legal obligations and our legitimate interests in establishing or defending legal claims |
| Diagnose and improve the service | Our legitimate interests where appropriate; consent where required |
| Send optional marketing communications | Consent or legitimate interests where permitted by law |
Where we rely on legitimate interests, we consider whether the processing is necessary and proportionate and balance it against individual rights. Consent can be withdrawn at any time without affecting earlier lawful processing.
5. Public venue information
Venue listings may make business information public, including venue names, descriptions, addresses, contact information, facilities, capacities, photographs, prices and availability. Venue operators must not upload another person’s information unless they have the right to publish it. Search engines and third parties may independently index or copy public listing information.
7. International transfers
Some providers may process information outside the United Kingdom. Where required, we use an appropriate safeguard such as UK adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
8. How long we keep information
We keep personal information only for as long as reasonably necessary for the purposes described in this policy, including legal, accounting, security and dispute-resolution needs. The period depends on the type of record and why it is held.
- Account and venue information is generally kept while an account or listing remains active and for a reasonable period afterwards.
- Booking, payment and contractual records may be kept for up to six years where needed for tax, accounting or legal claims.
- Verification evidence is kept only for the period needed to complete review, handle disputes and prevent fraud.
- Security logs and support correspondence are kept for the period reasonably needed to investigate incidents and resolve the relevant matter.
- Marketing preference records may be retained so that we can respect an opt-out request.
Information that is no longer required is deleted or irreversibly anonymised where appropriate.
9. Automated checks and human review
Venues2U may use automated checks to compare submitted venue and company information with Companies House data or obtain fraud and identity signals from service providers. These checks may produce a recommendation or flag an application for review. We do not intend to make decisions producing legal or similarly significant effects solely through automated processing without appropriate safeguards. Users can request human review or provide additional evidence by contacting us.
10. Your rights
Depending on the circumstances, individuals may have the right to:
- obtain a copy of their personal information;
- correct inaccurate or incomplete information;
- request deletion or restriction;
- object to processing based on legitimate interests or to direct marketing;
- receive certain information in a portable format;
- withdraw consent; and
- request safeguards concerning certain automated decisions.
Rights are not absolute and exemptions may apply. Requests can be sent to [email protected]. We may need to verify the requester’s identity before acting.
11. Security
We use safeguards designed to protect personal information, including authentication controls, restricted administrative access, encrypted network connections, private document storage, managed cloud identities, audit logging and security monitoring. No online service can guarantee absolute security, and users should protect their login details.
12. Children
Venues2U is not intended for anyone under 18 as an account holder or contracting party. If we learn that personal information has been collected contrary to this restriction, we will take appropriate steps.
13. Complaints and contact
Please contact Mark Evans trading as Venues2U at [email protected] if you have a question, rights request or complaint.
You also have the right to complain to the Information Commissioner’s Office. Visit ico.org.uk/make-a-complaintor telephone 0303 123 1113.