Last updated: 11 June 2026

PRIVACY POLICY

RIDR ("we", "us" or "our") is a backstage operating system for live-event production. We are the data controller for personal data processed through the platform.

Registered address and contact details are available on request via the email at the end of this policy.

We collect and process the following categories of personal data:

  • Account data — name, email address, and authentication credentials when you create a manager account.
  • Rider content — artist names, contact details, dietary requirements, hospitality preferences, medical or accessibility notes, and any other personal information contained in the riders you upload.
  • Crew data — names, roles, and share-link activity so that crew members can access role-specific summaries.
  • Usage data — IP address, browser type, device information, and interaction logs for security and service improvement.

We process personal data on the following legal bases under the UK / EU GDPR:

  • Performance of a contract — to provide the RIDR platform and crew-link distribution.
  • Legitimate interests — fraud prevention, service security, and product development.
  • Consent — where required for specific communications or cookies.
  • Legal obligation — compliance with applicable laws and regulatory requirements.

We use personal data to:

  • Extract, structure, and display rider information for event organisers.
  • Generate and distribute read-only crew links with role-appropriate views.
  • Communicate service updates, security alerts, and support responses.
  • Maintain platform security, prevent abuse, and debug technical issues.
  • Anonymise and aggregate data for analytics and product improvement.

We do not sell personal data. We share data only with trusted sub-processors necessary to deliver the service:

  • Supabase — cloud hosting, database storage, and authentication infrastructure.
  • AI gateway — large-language-model processing for rider extraction (temporary, non-training use).
  • Email provider — transactional emails such as password resets and share-link invitations.

All sub-processors are bound by data-processing agreements that meet UK / EU adequacy standards.

We retain personal data for as long as your account is active or as needed to provide the service. After account closure, we anonymise or securely delete rider content and usage logs within 90 days, unless longer retention is required by law.

Under the GDPR you have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate or incomplete data.
  • Request erasure (the "right to be forgotten").
  • Restrict or object to certain processing activities.
  • Request data portability in a machine-readable format.
  • Withdraw consent at any time (where processing is based on consent).

To exercise any of these rights, contact us using the details below. We respond within one calendar month.

Our sub-processors may store data in the European Economic Area, the United Kingdom, and the United States. Where data is transferred outside the UK / EEA, we rely on UK / EU Standard Contractual Clauses and additional technical safeguards.

We use essential cookies to maintain authentication and session state. Optional analytics cookies help us understand platform usage. You can manage preferences through your browser settings.

If you have questions about this policy or wish to exercise your rights, please contact us at privacy@ridrpro.com.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) or your local supervisory authority if you believe we have not handled your data properly.