Privacy policy
What TENdays collects, why, who sees it, where it is held, how long we keep it, and what you can do about it. Written to be read, not skimmed past.
Version 1.4, 11 September 2026. Applies to the TENdays app on iPhone and Android, the web version of the app, and this website.
Who we are
TENdays is the planning tool for community events run by Will Laithwaite. For anything in this policy, email hello@tendays.app. We are the data controller for the personal data described here: we decide why and how it is used.
What we collect
| Your account | Your name, your email address (which is also your sign-in), and a phone number if you add one. Whether you hold a personal licence, if you tell us in Settings. The date and version of the terms you accepted in the app. |
|---|---|
| Your events | The event's name, type, dates and times, postcode, expected attendance, activities, venue type and licence status, whether it is ticketed and for-profit. The committee you invite (their email addresses until they join, then their accounts), and the roles and areas of responsibility you give them. |
| Planning | Tasks, who they are assigned to, when they were completed and by whom. Risk-assessment answers, confirmed controls, and sign-offs, each recorded against the person who made them. Temporary Event Notice details you enter, including the name, phone number and email address of the person named as the premises user. Documents and photos you upload. Costs, ticket types, sales and other income you record. Debrief answers and incident notes from the day. Names of day-of volunteers a lead adds to the briefing. |
| Messages | Messages, photos and files you send in an event's chat, polls you create and vote in, and which messages you have read. If you report a message, we keep the report (the message, its author, your reason) and show it to the event's leads and to us; the person reported is not told who reported them. If you block someone, only you can see that you have. |
| Preferences | Your notification settings per event, and whether you have opted in to hear from us (see Only with your consent below). We keep a dated record of each consent choice, including the wording you saw. |
| Technical | A sign-in session held on your device. When you sign in, a bot check run by Cloudflare sees your connection details, and a record of each sign-in (date and connection address) is kept in our database. Our hosting provider keeps short-lived request logs to run and secure the service. The app fetches the public bank-holiday calendar from GOV.UK and looks up event postcodes at Postcodes.io, so those services see your device's connection address. If you allow notifications, we hold a notification token for each phone you allow them on, so reminders can reach you when the app is closed. You can stop them at any time in Settings inside the app, or in your phone's own settings; signing out removes that phone's token. If the app stops working unexpectedly, we receive a crash report: what failed and where in our own code, the app version, the type of device and operating system, and a random identifier for that installation of the app so repeat crashes from one phone can be grouped — not your account. It does not carry your name, your messages or your event details, and we have switched off the settings that would send your connection address or record your screen. On this website, GitHub (our host) and Google Fonts receive your IP address when pages and fonts load. This website sets no cookies and runs no analytics. |
We do not take payments and hold no payment details. We do not collect your location: the postcode you enter is the event's, and it is used only to find the licensing authority and map position for the event.
Information about other people
Committees enter details about people other than themselves: an email address to invite someone (we email that address an invitation naming the inviter and the event), a volunteer's name for the briefing, the person named on a Temporary Event Notice, or an incident note. We hold that information so the event can run. Our legal basis is our legitimate interest in running the planning tool the committee has asked for, and the committee's own legitimate interest in organising its event; we hold no more than the event needs, and never use these details for marketing. The committee is responsible for having a proper reason to share them and for telling the person. If you find yourself named in TENdays and want to know why, or want it removed, email us.
Why we use it, and our legal basis
- To provide the service (contract). Building your plan, calculating deadlines, sharing the event with its committee, sending sign-in codes, and sending the reminders your own plan generates: deadline warnings, the Temporary Event Notice countdown, and the notifications you have turned on. Service messages like these are part of running your account and are not marketing.
- To keep the service working and safe (legitimate interests). Bot checks on sign-in, rate limits, request logs, and investigating faults or misuse. We have weighed these against your interests and believe they are what you would expect from a service like this.
- Only with your consent. Occasional emails about TENdays and, separately, asking how your event went. Both are opt-in switches under Keeping in touch in Settings, off by default, and can be turned off there at any time. Turning one off stops those emails; it does not affect the service messages above.
We make no decisions about you by automated means that have legal or similarly significant effects. The guidance the app gives about licensing and safety is planning help for your committee, not a decision about you.
Who sees it
- Us. We can read what is stored, including messages, because the service is run and supported by a person rather than by machines alone. We only do so to fix a fault or to act on a report. Nothing you write in TENdays is encrypted in a way that hides it from us, so please treat it as you would an email to the committee rather than a private conversation.
- The people in your event. Everyone on the committee, lead or member, can see everything in the event: the plan, tasks, documents and uploads, chat, costs and income, the Temporary Event Notice record, the debrief, and the names, email addresses and phone numbers of fellow committee members (an invitee's email address shows on the committee list until they join). Leads can additionally manage the event: invite and remove people, assign work, and delete the event. If you are chosen as the person giving a Temporary Event Notice, your name, phone number and email address appear on the notice guide the app produces for the committee, and a copy is kept with the event once the notice is served. Day-of volunteers see only the briefing, anything they are named for, and one message channel. What you record in Settings about holding a personal licence is visible to your committee, because it affects who can serve a Temporary Event Notice.
- Providers that run TENdays for us, each bound to process data only on our instructions:
- Supabase: database, sign-in and file storage. Held in London (AWS eu-west-2).
- Resend: sends our email: sign-in codes, invitations (naming the inviter and the event), deadline reminders (naming the task they are about) and, if you opt in, news. Resend receives the recipient's address and the text of each email.
- Cloudflare: the bot check when you ask for a sign-in code.
- Postcodes.io: turns an event postcode into a licensing authority and map position. Only the postcode is sent.
- GOV.UK: the app downloads the official bank-holiday calendar to work out working-day deadlines. Nothing about you or your event is sent. GOV.UK is a public data source rather than a provider working under our instructions.
- Expo: builds the app for us, and — if you allow notifications — carries each notification to your phone. Expo receives your phone's notification token and the title and first line of the notification, and passes them to Apple or Google to deliver.
- Apple and Google: deliver the app to your device through their app stores, and deliver notifications you have allowed to your phone.
- Sentry: receives a report when the app crashes, so we can find and fix the fault. Held in Germany. It receives the technical details of the failure, not your account or anything you have written.
- GitHub: hosts this website.
- If the law requires it. We would disclose information to a court, regulator or the police where we are legally obliged to, and only to the extent required.
We do not sell personal data and we do not share it for advertising. Where a partner offer is ever included in an email you have opted in to, we send it; the partner never receives your details.
Where it is held
Your data is stored in the United Kingdom. Some providers above process data outside the UK, for example when an email is delivered. Where that happens we rely on the UK International Data Transfer Agreement or Addendum, the UK Extension to the EU-US Data Privacy Framework for providers certified under it, or a UK adequacy decision.
How long we keep it
- Your account: while it is open. When you delete it in the app your personal details are removed at once; a request made by email is completed within 30 days. Events stay available to the rest of their committee. Tasks you ticked, controls you confirmed, messages you sent and risk-assessment sign-offs stay in the event's record, and we remove the link to your account so they no longer carry your name. One exception: if a Temporary Event Notice was served with you named as the premises user, the frozen record of what was declared to the council (your name and the contact details given) stays with that event, because the committee may need it as evidence of what was served. Ask us if you want that removed too. See Delete your account.
- Events: for as long as they exist in the app. We do not delete events on a timer, because committees come back to them for the debrief and to run the event again next year. Any lead can delete an event at any time; a deleted event is hidden from everyone and kept so it can be recovered if deleted by mistake. Ask us and we will erase it.
- Consent records and sign-in records: deleted with your account.
- Request logs: our hosting provider keeps them for a short period, currently one day.
- Backups: where our hosting provider's backups are enabled, they can hold a copy for up to seven days after deletion.
Your rights
Under UK data protection law you can ask us for a copy of your personal data, ask us to correct or delete it, restrict or object to how we use it, ask for it in a portable form, and withdraw consent at any time. Email hello@tendays.app from the address on your account and we will respond within one month. If we need to check it is you, we will reply to the address on your account first.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would rather you told us first.
Security
Data travels between the app and our servers encrypted. Access rules in the database mean an event's data can only be read by that event's members, according to their role. Sign-in uses one-time codes sent to your email, so there is no password to lose. Access to the systems behind TENdays is limited to the people who run it.
Children
TENdays is for adults organising events and is not intended for anyone under 18. Where a committee records details about young volunteers, the committee is responsible for handling them lawfully.
Changes
When this policy changes we will update the version and date at the top of this page. If a change affects how we use your data in a way you would not expect, we will tell you in the app before it takes effect.
Questions about this policy: hello@tendays.app