1. Who we are
Glee (“Glee”, “we”, “us”, “our”) operates the Glee mobile application and the website at gleefolder.com (together, the “Service”).
For the purposes of the Kenya Data Protection Act, 2019 (the “DPA”) and, where it applies, the EU General Data Protection Regulation (“GDPR”), Glee is the data controller of the personal data described in this policy.
- Registered name: [INSERT REGISTERED COMPANY NAME]
- Registration number: [INSERT CR12 / COMPANY NUMBER]
- Registered address: [INSERT PHYSICAL ADDRESS], Nairobi, Kenya
- Contact: support@glee.com
We are not currently required to appoint a Data Protection Officer under section 24 of the DPA. Privacy enquiries are handled by our support team at the address above.
2. Scope of this policy
This policy covers personal data we process when you use the Service — whether you browse events, buy a ticket as a guest, create an account, book a table, or subscribe to our newsletter.
It does not cover the separate processing carried out by event organisers, venues and payment providers acting as their own controllers. Where an organiser or venue uses your data for their own purposes, their privacy notice applies to that use. See section 6.
3. Data we collect
We keep data collection deliberately minimal. We collect:
- Identity and contact data — your full name, email address and mobile phone number. This is the information you enter at checkout or when booking a table.
- Transaction data — records of the tickets, tables and memberships you have bought, the event and venue concerned, quantity, amount paid in Kenya Shillings, order and ticket reference numbers, and the payment reference returned by our payment processor.
- Account data — if you create an account, your login credentials in hashed form and your booking history.
- Communications data — messages you send us, support tickets, and your newsletter subscription status.
- Technical data — generated automatically by our servers when you use the Service: IP address, device and browser type, operating system, app version, timestamps and error logs. We use this for security, fraud prevention and debugging.
We do not collect your precise location, your contacts, your photos or camera, biometric data, or health data. We do not run third-party advertising or behavioural tracking SDKs in the Glee app.
We never see or store your card or M-Pesa details. Payments are processed by Paystack. Card numbers, CVVs, PINs and mobile-money credentials are entered on Paystack’s systems and are never transmitted to or stored by Glee. We receive only a confirmation of payment and a reference.
We do not knowingly collect sensitive personal data as defined in section 2 of the DPA (such as data revealing health, race, ethnicity, religious beliefs, sex life or political affiliation). Please do not send us such data.
4. How we collect it
- Directly from you — when you fill in a checkout, booking or newsletter form, create an account, or contact support.
- Automatically — technical data recorded in server logs when your device connects to our systems.
- From our payment processor — Paystack confirms to us whether a payment succeeded or failed, and returns a transaction reference and the masked payment method.
- From partners — where an event organiser or venue passes us a booking you made through them so we can issue your ticket.
5. Why we use it & lawful basis
Under section 30 of the DPA and Article 6 of the GDPR we must have a lawful basis for each processing purpose. Ours are:
- To sell and deliver your ticket or booking — issue the ticket, email or SMS it to you, register you on the guest list, and let the venue validate it at the door. Basis: performance of a contract with you.
- To process payments and issue receipts — via Paystack. Basis: performance of a contract; legal obligation.
- To provide customer support — answer your questions, resolve failed payments, process refunds. Basis: performance of a contract; legitimate interests.
- To keep the Service secure — detect and prevent fraud, duplicate tickets, ticket touting and abuse. Basis: legitimate interests in protecting our users, our partners and our business.
- To send you marketing — our weekly newsletter and event announcements. Basis: your consent. You can withdraw it at any time using the unsubscribe link in every email, without affecting anything else.
- To meet legal and tax obligations — keep accounting records and respond to lawful requests from regulators, the Kenya Revenue Authority or the courts. Basis: compliance with a legal obligation.
- To improve the Service — understand which events and features are used, in aggregate. Basis: legitimate interests.
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may object at any time — see section 9.
7. International transfers
Some of our service providers store or process data outside Kenya. Under sections 48 and 49 of the DPA, we transfer personal data out of Kenya only where we have confirmed that the recipient country or organisation provides appropriate safeguards, or where the transfer is necessary to perform our contract with you.
Where the GDPR applies to a transfer out of the European Economic Area, we rely on the European Commission’s Standard Contractual Clauses or an adequacy decision. You can request a copy of the safeguards we use by writing to us.
8. How long we keep it
We keep personal data only as long as we need it for the purpose we collected it for, or as long as the law requires:
- Account data — for as long as your account is open, then deleted within 30 days of your deletion request.
- Ticket and booking records — 12 months after the event, so we can handle disputes, chargebacks and refunds.
- Transaction and accounting records — seven (7) years, as required by the Tax Procedures Act, 2015 and the Companies Act, 2015. These records are retained even if you delete your account.
- Marketing consent records — until you unsubscribe, plus 2 years to evidence that consent was given and withdrawn.
- Support correspondence — 24 months.
- Server and security logs — 90 days.
When a retention period ends, we delete the data or irreversibly anonymise it so it can no longer be linked to you.
9. Your rights
Section 26 of the DPA — and, where applicable, Chapter III of the GDPR — gives you the following rights over your personal data:
- To be informed of how your data is being used — which is what this policy is for.
- Access — to obtain a copy of the personal data we hold about you.
- Rectification — to have inaccurate or incomplete data corrected.
- Erasure — to have your data deleted where we no longer have a lawful reason to keep it.
- Objection — to object to processing based on legitimate interests, and to object to direct marketing at any time.
- Restriction — to ask us to pause processing while a dispute about accuracy or lawfulness is resolved.
- Portability — to receive your data in a structured, commonly used, machine-readable format, or have it transmitted to another controller where technically feasible.
- Withdraw consent — at any time, where processing is based on consent. This does not affect processing carried out before you withdrew it.
How to exercise them: email support@glee.com from the address on your account, telling us which right you wish to exercise. We may ask for proof of identity before we act, to make sure we do not disclose your data to someone else.
We will respond within 30 days. If your request is complex we may extend this by a further period and will tell you why. Exercising your rights is free; we may charge a reasonable fee only if a request is manifestly unfounded or excessive.
10. Deleting your account
You can delete your Glee account and the personal data associated with it at any time:
- In the app — go to Profile → Settings → Delete account and confirm.
- On the web — use our account deletion page.
We delete your account data within 30 days of a verified request. We must retain transaction and accounting records for seven years as described in section 8, and we may retain limited records where necessary for fraud prevention, security, or to establish or defend a legal claim. Retained records are kept restricted and are not used for any other purpose.
Deleting your account does not cancel tickets you have already bought, and does not entitle you to a refund. See our Terms & Conditions.
11. Security
We take appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, loss or destruction, as required by section 41 of the DPA. These include encryption of data in transit using TLS, hashed password storage, access controls limiting staff access to what their role requires, and delegation of all card and mobile-money handling to a PCI-DSS compliant payment processor.
No system is completely secure. If a personal data breach occurs that poses a real risk to your rights and freedoms, we will notify the Office of the Data Protection Commissioner within 72 hours of becoming aware of it, and will notify you without undue delay, as required by section 43 of the DPA.
12. Children
Glee is an 18+ service. Many of the events and venues we list are licensed nightlife premises restricted to adults. The Service is not directed at children, and we do not knowingly collect personal data from anyone under 18.
Under section 33 of the DPA, a “child” is a person under the age of 18, and processing a child’s data requires parental consent and a means of verifying age. If you believe a person under 18 has provided us with personal data, contact support@glee.com and we will delete it and cancel any associated account.
14. Automated decision-making
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing, and we do not carry out profiling within the meaning of section 35 of the DPA. Automated fraud checks may flag a transaction for review, but a person reviews any decision to decline or reverse a purchase.
15. Changes to this policy
We may update this policy as the Service or the law changes. The “last updated” date at the top always reflects the current version. If we make a material change — for example, if we start collecting a new category of data or sharing it for a new purpose — we will notify you by email or through the app before the change takes effect, and where the law requires it, we will ask for your consent.
16. Contact & complaints
Questions, requests or concerns about this policy or how we handle your data:
- Email: support@glee.com
- Post: [INSERT PHYSICAL ADDRESS], Nairobi, Kenya
We would like the chance to resolve any complaint ourselves. But you always have the right to complain directly to a supervisory authority.
In Kenya, you may lodge a complaint with the Office of the Data Protection Commissioner (ODPC) under section 56 of the DPA — Britam Tower, Hospital Road, Upper Hill, Nairobi; email info@odpc.go.ke; or online at odpc.go.ke.
In the EEA or UK, you may complain to your local data protection supervisory authority.