Privacy.
how we handle your data.
This policy explains what data Nightwires collects, why, and what your rights are under the EU General Data Protection Regulation (GDPR). We've tried to keep it short and plain — if anything is unclear, email us at management@nightwires.com.
Who we are
The data controller is Christian Alcides Tavares Canuto, operating as Sole trader (entreprise individuelle), based at 4, rue Gaston Thorn, L-4543 Differdange, Luxembourg. You can reach us about anything in this policy at management@nightwires.com.
What we collect
When you use the site anonymously
Browsing the feed, reading event pages, or saving events to your local list requires no account. We don't track you across the web. Saves are stored in your browser's local storage, not on our servers.
When you sign in (magic-link authentication)
We collect and store:
- Your email address
- Sign-in timestamps (for session management)
- Which artists you follow, and which event notifications we've already sent you (so we don't email you about the same show twice)
That's it. No name, no phone number, no payment details (we don't accept payments from end-users).
Server logs
Our hosting provider (Vercel Inc.) keeps standard request logs — IP address, user agent, requested URL, timestamp — for up to 30 days for security and abuse prevention. This is a legitimate interest under GDPR Article 6(1)(f).
What we don't collect
- No third-party analytics (Google Analytics, Facebook Pixel, etc.)
- No advertising cookies
- No cross-site tracking
- No data about the devices or browsers you use, beyond what's in normal server logs
Why we collect it
- Email: to send you magic-link sign-in codes and, if you follow artists, show announcements. Legal basis: contract (Article 6(1)(b)) — you asked us for this service.
- Follow list: to personalize the feed and decide who to notify. Legal basis: contract.
- Notification log: to avoid sending duplicate emails. Legal basis: legitimate interest (Article 6(1)(f)).
- Server logs: security, debugging, abuse prevention. Legal basis: legitimate interest.
Who we share it with
We don't sell your data. We don't share it with advertisers. Data reaches a small number of processors — each bound by standard EU data processing agreements:
- Vercel Inc. — hosts the website and the database. Servers in the EU region.
- Neon — PostgreSQL database provider. EU region.
- Resend — delivers the magic-link and notification emails. We send your email address and the email contents only.
- Ticketmaster and Dice.fm — we fetch event data from them, we do not send any of your data to them.
How long we keep it
- Account data — until you delete your account. Inactive accounts (no sign-in for 24 months) are auto-deleted.
- Notification log — up to 12 months after an event has passed, then purged.
- Server logs — 30 days maximum.
Your rights
Under GDPR you can, at any time:
- Access — request a copy of all data we hold about you
- Rectify — correct inaccurate data
- Delete — request we erase your account and all associated data ("right to be forgotten")
- Object — withdraw consent for any processing based on consent, or object to processing based on legitimate interest
- Port — receive your data in a machine-readable format (JSON) to take to another service
- Complain — lodge a complaint with the Luxembourg data protection authority (CNPD, cnpd.public.lu)
Email management@nightwires.com to exercise any of these. We respond within 30 days as required by law. We'll never charge a fee.
International transfers
Most of our processors are either in the EU or use the EU Standard Contractual Clauses for any transfers outside. Resend's servers and Vercel Inc.'s US infrastructure may process your data under this mechanism.
Cookies
We use one essential cookie: the session cookie that keeps you signed in. No tracking, analytics, or advertising cookies. Because the cookie is strictly necessary for the service to function, no consent banner is legally required under the e-Privacy Directive.
Children
Nightwires is not directed at children under 16. We don't knowingly collect data from anyone under that age. If you believe a child has created an account, email us and we'll delete it.
Changes
If we change this policy materially, we'll email signed-in users and update the "Last updated" date above. Continued use after changes means you accept the new policy.
management@nightwires.com