Privacy policy
Last updated August 2026
house lights is an arts events tracker for Amsterdam and beyond. This policy explains what data we collect, why we collect it, how long we keep it, and what rights you have over it. It is written in plain English.
Who is responsible for your data
The data controller is Claire Baxter, operating house lights as a personal project based in the Netherlands.
Contact: support@claireheaded.com
What we collect and why
Account data
- — Your email address — to sign in and to contact you if needed
- — A password (hashed by Supabase using bcrypt, never stored or seen in plain text)
- — A username and optional display name — to identify you to other users
- — An optional profile photo — shown on your public profile
Legal basis: contract (Article 6(1)(b) GDPR) — these are necessary to provide the service you've signed up for.
Usage data
- — Your watchlist: shows you've bookmarked, ticket status, notes
- — Your city and venue preferences — which cities and venues appear in your feed
- — Who you follow — visible only to you and the people you follow
- — Your privacy settings — e.g. whether to show friends when you've bought tickets
Legal basis: contract (Article 6(1)(b) GDPR) — this is the core functionality of the service.
Anonymous activity data
- — Ticket link click-throughs (which show was clicked, your user ID if signed in or null if not)
Legal basis: legitimate interest (Article 6(1)(f) GDPR) — used to improve the service and evaluate whether venue partnerships are worthwhile. Collected server-side with no advertising or analytics trackers. If you delete your account, your user ID is removed from this data; anonymous aggregate records are retained for up to 24 months. You can object to this processing at any time by emailing us.
Security and infrastructure data
- — IP addresses and request metadata — processed by Cloudflare to detect and block malicious bots, DDoS attempts, and credential-stuffing attacks
- — Browser and connection characteristics — used by Cloudflare's Bot Fight Mode to classify traffic
Legal basis: legitimate interest (Article 6(1)(f) GDPR) — necessary to protect the security and availability of the service. This data is processed transiently by Cloudflare and is not stored by us. See Cloudflare's privacy policy for details of their own retention practices.
Cookies and local storage
Session cookie
We set one session cookie when you sign in. It contains an authentication token, not personal data. It expires when you sign out or after your session times out.
Cloudflare security cookies
Cloudflare may set short-lived cookies (such as __cf_bm) to support its bot-detection features. These are strictly functional and contain no personally identifying information. They are not used for advertising or tracking.
Guest watchlist (local storage)
If you bookmark shows before creating an account, those bookmarks are stored in your browser's local storage — they never leave your device. When you sign up or log in, they are transferred to your account and the local copy is deleted. You can clear them at any time by clearing your browser's site data for house-lights.nl.
We do not use advertising, tracking, or analytics cookies.
Profile visibility
By default, your profile (username, display name, and watchlist) is public — anyone can see what you're watching. You can make your profile private in Settings, which hides it from other users. Your email address is never visible to other users.
How long we keep your data
- — Account and watchlist data: kept until you delete your account
- — Unverified sign-up attempts (email never confirmed): 30 days, then automatically deleted by Supabase
- — Anonymous activity data (clicks, searches): 24 months, then deleted
- — Cloudflare security logs: retained by Cloudflare per their own policy (typically 24–72 hours for transient data)
When you delete your account, all personal data — profile, watchlist, preferences, avatar — is permanently deleted within 24 hours. Anonymised aggregate records (e.g. total click counts with no user ID) may be retained.
Where your data is stored and transferred
Personal data is stored on Supabase in Frankfurt, Germany (AWS eu-central-1) — within the European Economic Area. Supabase handles password hashing (bcrypt), encryption at rest (AES-256), encryption in transit (TLS), and row-level security (each user can only access their own data).
The site is served by Vercel, which may route requests through edge nodes outside the EEA. Vercel processes request metadata (IP, headers) transiently for routing purposes but does not store your personal data.
Traffic passes through Cloudflare's global network, including nodes that may be outside the EEA. Cloudflare processes IP addresses and request metadata solely for security purposes under Standard Contractual Clauses (SCCs) as the lawful transfer mechanism for any non-EEA processing.
Sub-processors
- — Supabase (AWS Frankfurt) — database, authentication, file storage. GDPR-compliant DPA in place.
- — Vercel — hosting and edge delivery. GDPR-compliant DPA in place.
- — Cloudflare — DDoS protection, bot mitigation, security. GDPR-compliant DPA in place.
No data is shared with any other third party. We do not sell data, run advertising, or use analytics services.
Minimum age
house lights is not directed at children. You must be at least 16 years old to create an account, in line with the Dutch implementation of GDPR (UAVG Article 8). If we become aware that a user is under 16, we will delete their account.
Your rights under GDPR
As a data subject under GDPR, you have the right to:
- — Access — request a copy of the data we hold about you (Article 15)
- — Rectification — correct inaccurate data such as your username or display name (Article 16)
- — Erasure — delete your account and all associated personal data (Article 17)
- — Portability — receive your data in a structured, machine-readable format (Article 20)
- — Object — object to processing based on legitimate interest (Article 21) — e.g. the anonymous activity data
- — Restriction — ask us to pause processing while a dispute is being resolved (Article 18)
- — Withdraw consent — where processing is based on consent, you can withdraw it at any time without affecting prior processing
You can exercise most of these rights directly from Settings — download your data or delete your account with one click. For any other request, email support@claireheaded.com. We will respond within 30 days.
You also have the right to lodge a complaint with the Dutch supervisory authority:
Autoriteit Persoonsgegevens — autoriteitpersoonsgegevens.nl
Automated access and AI crawlers
house lights blocks known AI training crawlers (such as GPTBot, CCBot, and similar) from accessing its pages via Cloudflare's managed bot rules and a robots.txt Content Signals Policy. The scraped event data displayed on the site originates from publicly accessible venue websites; we do not grant permission for it to be used to train machine learning models.
Security
We take reasonable technical and organisational measures to protect your data: all data is encrypted at rest and in transit; passwords are hashed and never readable by us; row-level security policies ensure users can only access their own data; Cloudflare's security layer protects against common network-level attacks. No system is perfectly secure — if you believe your account has been compromised, contact us immediately.
Changes to this policy
If we make material changes to how we process personal data, we will update this page and change the "last updated" date above. For significant changes, we will notify users by email where we are able to. Continued use of house lights after a policy update constitutes acceptance of the revised policy.
Contact
For any privacy-related question or request: