Last updated 25 June 2026
This policy explains how Panic Booking collects, uses, shares, and protects personal data through the panicbooking.com website and platform — including our public site, the booking and roster tools for bands, venues, agents, promoters and labels, and our in-house ticketing. It is written to meet our obligations under the EU General Data Protection Regulation (GDPR) and the UK GDPR.
Panic Booking is the data controller for the personal data described here. For any privacy question or to exercise your rights, contact:
We collect only what we need to run the service. We do not sell personal data, and we do not run advertising or analytics trackers on this site.
| Category | Purpose | Lawful basis (GDPR Art. 6) |
|---|---|---|
| Account data — email, password (stored only as a secure hash), account type | To create and operate your account and sign you in | Performance of a contract (b) |
| Profile data — names, location, contact email/phone, website and social links, band members, venue details, and similar information you add | To build your public or private profile and connect bands, venues, agents, and labels | Performance of a contract (b) |
| Booking & inquiry data — messages, requested dates, booking interests and claims | To facilitate bookings and represent claims over band/venue profiles | Performance of a contract (b); legitimate interests (f) |
| Ticketing & order data — buyer name and email, order amount, payment references | To sell tickets, issue them, and provide receipts and entry | Performance of a contract (b); legal obligation (c) for financial records |
| Contact-form submissions — name, email, phone, event date, message | To respond to your inquiry | Consent (a) and our legitimate interests in responding (f) |
| Marketing preference | To send product updates and booking tips, only if you opt in | Consent (a) |
| Consent records — your agreement to this policy and its version | To demonstrate compliance | Legal obligation / accountability (c) |
| Security data — limited technical data and rate-limiting needed to keep accounts and forms safe | To prevent abuse, fraud, and automated attacks | Legitimate interests (f) |
Panic Booking does not use advertising, profiling, or analytics cookies, and loads no third-party trackers. Fonts are served from our own servers, so visiting our pages does not disclose your visit to Google or any font CDN.
panicbooking_sid) that keeps you signed in, plus a security token (CSRF) that protects
form submissions. A small record of your cookie choice (pb_cookie_consent) is also kept
so we don’t ask repeatedly.You can withdraw consent at any time by choosing “Essential only”, or by clearing this site’s data in your browser — which makes the banner reappear on your next visit.
We share personal data only with service providers acting on our behalf under written terms, and only as needed to deliver the service:
Where a provider is located outside the European Economic Area or the UK, any transfer is protected by appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
Under the GDPR you have the right to:
If you have an account, you can download all of your data at any time from Settings → Your data & privacy, and delete your account and personal data from the same place. You can also exercise any right by emailing tom@themab.org; we will respond within one month.
Passwords are stored only as salted hashes, never in plain text. Access to personal data is limited to what is necessary to operate the service, form submissions are protected against cross-site request forgery, and sensitive actions are rate-limited to deter abuse.
Panic Booking is intended for professional use by bands, venues, and industry partners and is not directed at children under 16. We do not knowingly collect their personal data.
If we change how we handle personal data we will update this page and the “last updated” date above, and where appropriate notify you through the service.
Questions about this policy or your personal data? Email tom@themab.org.