Privacy Policy
Last updated: April 2026
1. Who We Are
Festival Scanner (“we”, “us”, “our”) is an independent music festival discovery platform operated at festivalscanner.com. We are the data controller for personal data processed through this website.
Contact: contact@festivalscanner.com
2. What Data We Collect
2.1 Automatically Collected Data
When you visit our website, our hosting provider (Vercel) automatically logs standard server data including your IP address, browser type, operating system, referring URL, and timestamp. This data is used for security and performance monitoring and is not stored by us directly.
2.2 Affiliate Click Tracking
When you click an affiliate link on our site (e.g. for tickets, hotels, or flights), we log the following data in our database:
- Timestamp of the click
- Page URL where the click occurred
- A one-way hashed IP address (HMAC-SHA256 — cannot be reversed to your original IP)
- UTM parameters if present in the URL
- The affiliate partner and link type (e.g. ticket, hotel)
No full IP addresses are stored. The hashed IP is used solely for fraud prevention and commission reconciliation. Legal basis: Art. 6 (1)(f) GDPR — legitimate interest in measuring affiliate performance.
2.3 Analytics (Consent-Based)
We use PostHog for website analytics. PostHog is only loaded after you accept optional cookies via our cookie consent banner. If you decline, no analytics data is collected. Legal basis: Art. 6 (1)(a) GDPR — consent.
2.4 Error Tracking (Consent-Based)
We use Sentry for error tracking and performance monitoring. Sentry is only loaded after you accept optional cookies. Legal basis: Art. 6 (1)(a) GDPR — consent.
2.5 Email Communications
If you contact us by email, we store your email address and message content solely to respond to your enquiry. We do not add you to any mailing list without your explicit consent.
3. Cookies
We use two categories of cookies:
- Essential cookies — Required for the site to function (e.g. cookie consent preference stored in localStorage). Always active.
- Optional cookies — Analytics (PostHog) and error tracking (Sentry). Only set with your explicit consent via our cookie banner.
You can change your cookie preference at any time by clearing your browser's localStorage for festivalscanner.com.
4. Affiliate Links & Third Parties
Festival Scanner contains affiliate links to third-party services including Ticketmaster, Booking.com, Skyscanner, GetYourGuide, StubHub, and others. When you click these links and make a purchase, we may earn a commission at no additional cost to you.
These third parties have their own privacy policies. Once you leave our site via an affiliate link, their privacy practices apply. We are not responsible for third-party data practices.
5. Data Storage & Infrastructure
Our website is hosted on Vercel (San Francisco, USA). Our database is hosted on Supabase (EU region — Frankfurt, Germany). Data transfers to the USA are covered by Standard Contractual Clauses (SCCs). All data is encrypted in transit (TLS) and at rest.
6. Data Retention
Affiliate click logs are retained for 24 months for commission auditing purposes and then deleted. Email correspondence is retained for 12 months unless a longer period is legally required. Analytics data is governed by PostHog's retention policy (configurable; we use the default 12-month retention).
7. Your Rights (GDPR)
Under GDPR, you have the following rights regarding your personal data:
- Right of access — Request a copy of personal data we hold about you (Art. 15)
- Right to rectification — Correct inaccurate data (Art. 16)
- Right to erasure — Request deletion of your data (Art. 17)
- Right to restriction — Limit how we process your data (Art. 18)
- Right to portability — Receive your data in a machine-readable format (Art. 20)
- Right to object — Object to processing based on legitimate interest (Art. 21)
- Right to withdraw consent — Withdraw cookie consent at any time without affecting prior processing
To exercise any of these rights, email us at contact@festivalscanner.com with “Privacy Request” in the subject line. We will respond within 30 days.
You also have the right to lodge a complaint with your national data protection authority (e.g. the ICO in the UK, or the relevant EU supervisory authority in your country).
8. Children's Privacy
Festival Scanner is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated date. For significant changes, we will update the “Last updated” date prominently.