Privacy Policy
Version 2026-10-07.1 · AFTR DARK Group Inc., Toronto
What we collect
When you buy a ticket or RSVP: your name, email, optionally your phone number, and your order details. When an organizer uses tracking links: the link you arrived through, stored in cookies (ad_ft for 90 days, ad_lt for 30 days), a hashed IP, and your browser's user agent. A third cookie (ad_path, 90 days) keeps up to ten recent steps that brought you to an event page: the tracking link's code, the campaign tags in the address, whether you clicked through from Facebook or Instagram, or the name of the referring website, each with a time. It holds nothing about who you are, and it is saved with your order so the organizer can see which steps led to ticket sales.
For age-restricted events, we ask you to confirm at checkout that every guest meets the minimum age on the event date. After your order is confirmed you can optionally add your birthday. Optional birthday, gender and city responses contribute to the organizer’s aggregate audience charts. They are not verified identity or a replacement for ID checks at the door.
On an aftr.bio page (an organizer's or an artist's link page), we count views and which links are pressed, along with the referring website, a device type of phone, tablet or desktop, and the country, region and city your network resolves to at the edge. No cookie is used for this. Visitors are told apart by a key derived from your IP address and browser, which is re-salted every day and deleted with the data after 400 days, so the same person is counted once a day and cannot be followed between months. When you open an event from one of those pages, a cookie (ad_bio, 30 days) records which page sent you so the organizer or artist can see what their page led to.
If you request an event reminder, we collect your email and require confirmation before sending one reminder. You can cancel using your confirmation link. Saving an event uses a browser identifier cookie (ad_interest, up to one year) and local storage.
When you arrive through a Bandsintown ticket link, we retain its click identifier in a first-party, event-specific cookie for up to 30 days and save it with your order to attribute referrals and purchases. It is not proof of identity or marketing consent.
For organizers: account details, organization details, and — for managed advertising — billing information handled by Stripe. We never see or store full card numbers.
How it's used
Your ticket data exists to get you into the event: passes, door check-in, and communication about the event you booked. The organizer of an event you attend can see your attendance for their own events.
Marketing consent is per organizer. Ticking a consent box for one organizer never signs you up for another's list, and every marketing message records the consent it relies on, as Canadian anti-spam law requires.
Where an organizer runs advertising measurement, we send hashed identifiers (never raw email addresses or phone numbers) to advertising platforms server-side, so the organizer can measure whether their ads led to attendance.
What we don't do
We don't sell personal data. We don't combine attendee lists across organizers for marketing. We don't send raw personal information to advertising platforms.
DUSK AI and human support
DUSK is an optional AI assistant powered by Anthropic. Before you use AI chat, we ask for explicit permission to send your messages and the chat history included with your request to Anthropic to generate answers. This may include personal information you type. For event questions, DUSK can use relevant event details. For signed-in organizers, it can use organization name and event information available to that role, including event titles, status, dates, capacity and ticket sales counts. These tool results may be sent to Anthropic as part of answering your question.
Attached pictures are stored in private Supabase storage for authorized support staff. We do not send the image files to Anthropic; the model only receives a notice that images were attached. Chat messages and support requests are recorded in our support system. When you request human help, your question, contact details and chat transcript may be shared with the AFTR DARK team or the relevant organizer according to the support request. If you use Report on a DUSK reply, we store that reply, the reason you chose and any note you add so the AFTR DARK team can review it; organizers do not see reports.
You can choose Not now and continue using the app or contact the team without AI. Use Withdraw AI permission in the chat panel to stop future AI sharing. Withdrawal does not recall information already sent. Organizer permission applies to your user and organization; fan permission is separate for the browser conversation and event. We store the permission version, wording, choice and decision time. A private session cookie links fan choices to this browser. Material changes to the provider, information shared or purpose require a new choice.
Your rights
You can ask what we hold about you, ask for a correction, or ask for deletion, subject to records we must keep (like completed transactions). For attendees in the EU or UK, GDPR rights apply and the organizer of your event is the data controller; we process on their behalf.
You can initiate deletion of your Backroom login in Security → Delete my account. The page explains what is removed, what remains with your organization, and shows completion. For other privacy requests, including attendee data, write to hello@aftrdark.ca and we'll respond within 30 days.
Cookies
We use a session cookie to sign organizers in, and the attribution cookies described above so organizers can tell which link or page brought you. Page view counting on aftr.bio uses no cookie at all. No third-party advertising cookies are set by our pages.