← Back to Panic Booking

Privacy & Cookie Policy

Last updated 25 June 2026

This policy explains how Panic Booking collects, uses, shares, and protects personal data through the panicbooking.com website and platform — including our public site, the booking and roster tools for bands, venues, agents, promoters and labels, and our in-house ticketing. It is written to meet our obligations under the EU General Data Protection Regulation (GDPR) and the UK GDPR.

1. Who is responsible for your data

Panic Booking is the data controller for the personal data described here. For any privacy question or to exercise your rights, contact:

Tom Watson
Data protection contact, Panic Booking
Email: tom@themab.org

2. What we collect, why, and our lawful basis

We collect only what we need to run the service. We do not sell personal data, and we do not run advertising or analytics trackers on this site.

CategoryPurposeLawful basis (GDPR Art. 6)
Account data — email, password (stored only as a secure hash), account type To create and operate your account and sign you in Performance of a contract (b)
Profile data — names, location, contact email/phone, website and social links, band members, venue details, and similar information you add To build your public or private profile and connect bands, venues, agents, and labels Performance of a contract (b)
Booking & inquiry data — messages, requested dates, booking interests and claims To facilitate bookings and represent claims over band/venue profiles Performance of a contract (b); legitimate interests (f)
Ticketing & order data — buyer name and email, order amount, payment references To sell tickets, issue them, and provide receipts and entry Performance of a contract (b); legal obligation (c) for financial records
Contact-form submissions — name, email, phone, event date, message To respond to your inquiry Consent (a) and our legitimate interests in responding (f)
Marketing preference To send product updates and booking tips, only if you opt in Consent (a)
Consent records — your agreement to this policy and its version To demonstrate compliance Legal obligation / accountability (c)
Security data — limited technical data and rate-limiting needed to keep accounts and forms safe To prevent abuse, fraud, and automated attacks Legitimate interests (f)

3. Cookies and local storage

Panic Booking does not use advertising, profiling, or analytics cookies, and loads no third-party trackers. Fonts are served from our own servers, so visiting our pages does not disclose your visit to Google or any font CDN.

  • Strictly necessary — no consent required: a single session cookie (panicbooking_sid) that keeps you signed in, plus a security token (CSRF) that protects form submissions. A small record of your cookie choice (pb_cookie_consent) is also kept so we don’t ask repeatedly.
  • Preferences — consent required: we do not currently store non-essential preference cookies. If we introduce any (for example, remembering an interface setting on your device), they will be stored only if you choose “Accept all” in the cookie banner, and never if you choose “Essential only”.

You can withdraw consent at any time by choosing “Essential only”, or by clearing this site’s data in your browser — which makes the banner reappear on your next visit.

4. Who we share data with

We share personal data only with service providers acting on our behalf under written terms, and only as needed to deliver the service:

  • Stripe and Square — to process ticket payments. Card details are entered directly with these providers; we do not store full card numbers.
  • Email delivery — to send transactional messages such as password resets and responses to contact inquiries.
  • Hosting and infrastructure providers that operate our servers.

Where a provider is located outside the European Economic Area or the UK, any transfer is protected by appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

5. How long we keep it

  • Account and profile data is kept while your account is active.
  • When you delete your account or ask us to erase your data, we remove or anonymise your personal data within 30 days; residual copies in encrypted backups are purged on the normal backup rotation, within 90 days.
  • Ticket orders and other financial records are retained for up to 7 years to meet tax and accounting obligations, but are stripped of identifying buyer details when you are erased.
  • Contact-form submissions are retained for up to 24 months.
  • Password-reset tokens expire shortly after they are issued.

6. Your rights

Under the GDPR you have the right to:

  • Access your data and receive a copy;
  • Rectify inaccurate or incomplete data;
  • Erasure (“the right to be forgotten”);
  • Restrict or object to processing, including processing based on our legitimate interests;
  • Data portability — receive your data in a structured, machine-readable format;
  • Withdraw consent at any time where we rely on it; and
  • Lodge a complaint with a data protection supervisory authority.

If you have an account, you can download all of your data at any time from Settings → Your data & privacy, and delete your account and personal data from the same place. You can also exercise any right by emailing tom@themab.org; we will respond within one month.

7. How we protect your data

Passwords are stored only as salted hashes, never in plain text. Access to personal data is limited to what is necessary to operate the service, form submissions are protected against cross-site request forgery, and sensitive actions are rate-limited to deter abuse.

8. Children

Panic Booking is intended for professional use by bands, venues, and industry partners and is not directed at children under 16. We do not knowingly collect their personal data.

9. Changes to this policy

If we change how we handle personal data we will update this page and the “last updated” date above, and where appropriate notify you through the service.

10. Contact

Questions about this policy or your personal data? Email tom@themab.org.