Privacy policy

What TENdays collects, why, who sees it, where it is held, how long we keep it, and what you can do about it. Written to be read, not skimmed past.

Version 1.4, 11 September 2026. Applies to the TENdays app on iPhone and Android, the web version of the app, and this website.

Who we are

TENdays is the planning tool for community events run by Will Laithwaite. For anything in this policy, email hello@tendays.app. We are the data controller for the personal data described here: we decide why and how it is used.

What we collect

Your accountYour name, your email address (which is also your sign-in), and a phone number if you add one. Whether you hold a personal licence, if you tell us in Settings. The date and version of the terms you accepted in the app.
Your eventsThe event's name, type, dates and times, postcode, expected attendance, activities, venue type and licence status, whether it is ticketed and for-profit. The committee you invite (their email addresses until they join, then their accounts), and the roles and areas of responsibility you give them.
PlanningTasks, who they are assigned to, when they were completed and by whom. Risk-assessment answers, confirmed controls, and sign-offs, each recorded against the person who made them. Temporary Event Notice details you enter, including the name, phone number and email address of the person named as the premises user. Documents and photos you upload. Costs, ticket types, sales and other income you record. Debrief answers and incident notes from the day. Names of day-of volunteers a lead adds to the briefing.
MessagesMessages, photos and files you send in an event's chat, polls you create and vote in, and which messages you have read. If you report a message, we keep the report (the message, its author, your reason) and show it to the event's leads and to us; the person reported is not told who reported them. If you block someone, only you can see that you have.
PreferencesYour notification settings per event, and whether you have opted in to hear from us (see Only with your consent below). We keep a dated record of each consent choice, including the wording you saw.
TechnicalA sign-in session held on your device. When you sign in, a bot check run by Cloudflare sees your connection details, and a record of each sign-in (date and connection address) is kept in our database. Our hosting provider keeps short-lived request logs to run and secure the service. The app fetches the public bank-holiday calendar from GOV.UK and looks up event postcodes at Postcodes.io, so those services see your device's connection address. If you allow notifications, we hold a notification token for each phone you allow them on, so reminders can reach you when the app is closed. You can stop them at any time in Settings inside the app, or in your phone's own settings; signing out removes that phone's token. If the app stops working unexpectedly, we receive a crash report: what failed and where in our own code, the app version, the type of device and operating system, and a random identifier for that installation of the app so repeat crashes from one phone can be grouped — not your account. It does not carry your name, your messages or your event details, and we have switched off the settings that would send your connection address or record your screen. On this website, GitHub (our host) and Google Fonts receive your IP address when pages and fonts load. This website sets no cookies and runs no analytics.

We do not take payments and hold no payment details. We do not collect your location: the postcode you enter is the event's, and it is used only to find the licensing authority and map position for the event.

Information about other people

Committees enter details about people other than themselves: an email address to invite someone (we email that address an invitation naming the inviter and the event), a volunteer's name for the briefing, the person named on a Temporary Event Notice, or an incident note. We hold that information so the event can run. Our legal basis is our legitimate interest in running the planning tool the committee has asked for, and the committee's own legitimate interest in organising its event; we hold no more than the event needs, and never use these details for marketing. The committee is responsible for having a proper reason to share them and for telling the person. If you find yourself named in TENdays and want to know why, or want it removed, email us.

Why we use it, and our legal basis

We make no decisions about you by automated means that have legal or similarly significant effects. The guidance the app gives about licensing and safety is planning help for your committee, not a decision about you.

Who sees it

We do not sell personal data and we do not share it for advertising. Where a partner offer is ever included in an email you have opted in to, we send it; the partner never receives your details.

Where it is held

Your data is stored in the United Kingdom. Some providers above process data outside the UK, for example when an email is delivered. Where that happens we rely on the UK International Data Transfer Agreement or Addendum, the UK Extension to the EU-US Data Privacy Framework for providers certified under it, or a UK adequacy decision.

How long we keep it

Your rights

Under UK data protection law you can ask us for a copy of your personal data, ask us to correct or delete it, restrict or object to how we use it, ask for it in a portable form, and withdraw consent at any time. Email hello@tendays.app from the address on your account and we will respond within one month. If we need to check it is you, we will reply to the address on your account first.

If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would rather you told us first.

Security

Data travels between the app and our servers encrypted. Access rules in the database mean an event's data can only be read by that event's members, according to their role. Sign-in uses one-time codes sent to your email, so there is no password to lose. Access to the systems behind TENdays is limited to the people who run it.

Children

TENdays is for adults organising events and is not intended for anyone under 18. Where a committee records details about young volunteers, the committee is responsible for handling them lawfully.

Changes

When this policy changes we will update the version and date at the top of this page. If a change affects how we use your data in a way you would not expect, we will tell you in the app before it takes effect.

Questions about this policy: hello@tendays.app