Effective 10 August 2026. Version 2026-08-10.
The short version
VenueFlow is software venues use to run their bookings — their calendar, the performers they work with, and their record of who was paid what. It is operated as an independent business in the United States. Venues using it also agree to our terms of service, which set out what they are responsible for and what they have asked us to do with their data; reach us at getvenueflow@gmail.com about anything on this page.
This distinction matters more than anything else on the page: the venue decides, and we hold. A venue chooses who to keep records on, what to write, and how long to keep it. We store and process that on their instruction. In data protection terms the venue is the controller and we are the processor.
In practice that does not mean we send you away. If you ask us to remove your information, we act on it — see section 8. It means a venue can also act on your request directly, often faster, because it is their record.
One exception, and it’s about our own customers. For the accounts venue staff sign up with — their email, name and role — we are the controller, because those are our records and we decide what to do with them. So: our data about our customers,their data about the performers they book.
Venue staff accounts.We need your email and name to give you an account and to send you the notifications you’ve asked for. Without them there is no service to provide. (In GDPR terms: performance of a contract.)
Performers and booking requests.A venue keeps this to run its business — to book acts, to remember who played, and to pay them. That is the venue’s legitimate interest in operating, and it’s the basis they rely on when they enter your details. If you’d rather they didn’t, section 8 is how to stop it.
Deletion requests.We keep these to handle your request properly and to be able to show later that we did — both our own legitimate interest and, where privacy law applies, our obligation under it.
Booking and payment records are kept because a business has to be able to account for what it paid and to whom.
We don’t rely on consent for any of this, which means there is no consent for you to withdraw — the routes that matter to you are deletion and objection, in sections 7 and 8.
Your information is most likely here because a venue typed it in, because you sent them a booking request through a form on their website, or because they uploaded an old contact list and had the names pulled out of it.
What a venue can hold about you: your name or stage name, a contact name, email, phone, website and social links, payment handles (Venmo, Cash App, PayPal, Zelle), a bio, genre, location, technical requirements, a photo, and the bookings you’ve played with the amounts agreed and whether they’ve been paid.
A venue can also keep private notes and its own assessments about you, in free-text fields. Those are deleted along with everything else if you ask.
Two ways to get it removed: ask the venue directly, or use our deletion request form. The form works even if you don’t know which venue holds your details.
Venue staff (people with accounts). Email, name, and role. Sign-in is handled by Clerk, our authentication provider — passwords, sessions and any two-factor setup stay with them. We also keep which venues you can access, which emails you’ve switched off, and a per-day count of AI-assisted imports.
Performers and people who send booking requests. The fields listed in section 3. If you submitted through a venue’s booking form, that is information you gave us directly. If a venue typed it in or imported it, we received it from them.
People who ask us to delete data. The name, email and optional phone number you put on the request form, the signed declaration confirming the request is genuine, and a record of what we decided and why.
What we don’t collect: we take no payment details from anyone — we don’t process payments, so venues pay performers directly, outside VenueFlow. We run no advertising or analytics trackers, and we build no profiles for marketing.
We use a small number of service providers. Each has its own privacy policy, which we link rather than summarise — describing someone else’s terms means owning a claim that can go out of date without us noticing.
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in California law.
Where it is held. VenueFlow is operated from the United States, and the providers above store and process data in the United States and other countries where they operate. If you are outside the US, using VenueFlow or being listed by a venue that uses it means your information is handled there.
On AI, and what it does not do. The only place we use AI is the import described above: pulling names and contact details out of a document a venue uploaded, so they don’t have to retype them. A person reviews the result and chooses what to save. Nothing decides anything about you automatically — we don’t score, rank, or profile performers, and the rating and notes a venue may keep are written by them, not generated by us.
This applies to venues that connect Google Calendar. It is optional, the rest of VenueFlow works without it, and it can be switched off later.
What we ask Google for, and why. When a venue connects their account, Google asks them to grant three things:
We work on the events we made. A venue can point us at a calendar they already use. If they do, the events we add, change and remove there are the ones VenueFlow put there for their bookings. Other entries in that calendar are left as they are.
What we keep. The permission Google gives us, encrypted before it is stored and with the key held outside the database; which calendar was chosen; and a reference to each event we created, so we can update the right one later. The contents of a venue’s calendar are not copied into our database.
What it is used for. Putting a venue’s bookings into the calendar they chose. It is not used for advertising, not sold, and not used to train AI models.
VenueFlow’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Turning it off. Disconnect under Settings → Google Calendar and the stored permission is deleted. It can also be withdrawn from the Google side at your Google account’s third-party access page. Events already written to the calendar stay where they are — they are in the venue’s own Google account, not ours, and are theirs to keep or delete.
Photos are served from long, randomly generated web addresses without a login, because venues embed their upcoming shows on their own websites. Treat a photo link as shareable: anyone who has it can open it. If a photo is deleted, the link stops working once the deletion becomes permanent — see below.
Anyone can ask, whether or not they have an account, using the deletion request form. We’ll email you a link to confirm the request really came from you — that click is the only identity check available for someone with no account, so nothing happens without it.
You’ll get an answer within 30 days, usually far sooner. Where we can confirm a record is yours, it is removed immediately. Where we find a record that might be yours but can’t confirm it is, we ask the venue holding that record, since they know who they’ve booked; if they don’t respond in time we act anyway rather than let the request go unanswered.
Removal happens in two stages. The record is taken out of use immediately — not shown, not searchable, not usable to contact you. It is then permanently erased 30 days later. That gap exists so a mistake can be undone: a deletion made in good faith on the wrong record is recoverable during it, and unrecoverable after.
What is erased: everything that identifies you or lets anyone reach you, and anything not needed for the venue’s books — contact name, email, phone, website, social links, payment handles, bio, photo, and all notes and assessments.
What the venue keeps: the booking itself. The date, the amount agreed, whether it was paid, and the name of who was paid. That is the venue’s accounting record, and both European and Californian law specifically allow keeping what is needed for tax and accounting or to resolve a payment dispute. A deletion request is meant to stop you being contacted and marketed to, not to force a business to falsify its own books. What stays is the transaction record, not a way to reach you.
We don’t delete records on a schedule. A venue keeps its records for as long as it wants to; we don’t sweep them on a timer, because deleting a venue’s working records on our own initiative would be its own kind of harm. That is why the deletion request route above exists, and why it doesn’t depend on the venue acting.
Some things do have fixed lifetimes:
Two honest limits. First, this describes our own systems — the service providers above have their own retention periods for things like delivery logs and error reports, set by their policies rather than ours. Second, if a venue has connected Google Calendar, events already created there carry the show title, and those live in the venue’s own Google account, which we can’t reach into.
Depending on where you live, you may also have the right to ask what we hold about you, to get a copy of it, to have it corrected, to restrict how it’s used, and to object to that use. There is no self-serve button for these — email us and a person will handle it. You can also ask the venue directly; it’s their record and they can act on it without us.
We won’t charge you, and we won’t treat you differently for asking. If we can’t act on a request, we’ll write and explain why rather than going quiet, and if you’re not satisfied with how we’ve handled it you can raise it with your local data protection authority.
One thing worth knowing, because it protects you from anyone impersonating us: we will never ask you to email a copy of your ID.
Access is enforced at the database level, so an account reaches only its own venue’s records. Credentials for a venue’s Google Calendar connection are encrypted before they are stored, using a key held outside the database. Traffic is encrypted in transit.
Accounts are for venue staff and are not intended for children. We don’t knowingly collect information directly from anyone under 13.
Venues do sometimes book performers under 18 — all-ages shows are normal. If a venue holds details for a performer who is a minor, the performer or their parent or guardian can use the deletion request form exactly like anyone else, or contact us and we’ll help.
If we change this policy in a way that matters, we’ll update the version and effective date above, and tell account holders. Continuing to use VenueFlow after a change means accepting the updated policy.
Questions, requests, or complaints: getvenueflow@gmail.com. For deletion specifically, the request form is faster — it verifies you automatically.