Privacy policy

Last updated 4 August 2026

Who we are

Pencilled is booking software for session-based pop-up experiences, operated by Pencilled ("we", "us"). [Registered address]. For anything in this policy, contact hello@pencilled.app.

Who controls your data

When you book a session, you book with an independent operator — the business running the event. That operator is the data controller for your booking details and questionnaire answers: they decide why the data is collected and how long they need it. Pencilled is their data processor — we store and handle that data on their behalf, on their instructions.

Pencilled is the data controller for a small amount of data of our own: operator staff accounts, customer sign-in records (the email codes and sessions used for the account area), and the operational logs needed to run the service. We run no analytics or tracking on this site.

What we collect

  • Booking details — your name, email address, optional phone number, and what you booked.
  • Payments — handled entirely by Stripe. Your card details never touch Pencilled's servers; we see only the payment status and amount.
  • Questionnaire responses — where an operator asks attendees to complete a form (for example a health & safety declaration), your answers may include health information. They are stored securely and shared only with that operator to run your session.
  • Cookies — essential session cookies only, used to keep operators and customers signed in. There is no advertising, analytics or cross-site tracking, so you won't see a cookie banner.

Lawful bases

Booking data is processed to perform the contract you make when you book. Sign-in and security records rest on our legitimate interest in running the service safely. Health information within questionnaire responses is collected with your explicit consent, given through the declaration you tick when you complete a form — if you'd rather not answer online, speak to the operator at the venue.

How long we keep things

  • Bookings are kept for the operator's records — order history, refunds and their accounting obligations.
  • Questionnaire responses are intended to be short-lived: operators are given a delete-all action for each event and are asked to remove responses once the event is over and they no longer need them.
  • Sign-in codes expire after ten minutes; sessions expire automatically.

Who else touches the data

We use a short list of subprocessors, each bound by their own agreements:

  • Cloudflare — hosting, storage and email delivery for the platform.
  • Stripe — card payments and payouts to operators.

We don't sell data, and we don't share it with anyone else except where the law requires.

Your rights

You can ask to see, correct or delete personal data held about you. For booking details and questionnaire answers, contact the operator you booked with — they control that data and every event page shows who they are. For platform accounts and anything else, email hello@pencilled.app. If you're unhappy with how a request is handled, you can complain to the Information Commissioner's Office (ico.org.uk).

Changes

If this policy changes in a way that matters, we'll update this page and the date at the top. Significant changes affecting operators are notified to them directly.