Privacy Policy

Last updated: 6 July 2026

1. Who we are

Sommly is operated by Sommly Ltd, a company registered in England and Wales (Company No. 17121707). Our registered address is 45 Church Road, Tiptree, Colchester, Essex, England, CO5 0SU.

If you have any questions about this policy or how we handle your data, contact us at [email protected].

2. What data we collect

We collect the following personal data depending on how you use Sommly:

Account registration

When you create an account we collect your name, email address, and password (stored securely hashed, never in plain text).

Ticket purchases

When you buy tickets we collect your name and email address for order confirmation and ticket delivery. Payment is processed entirely by our payment provider, Mollie (see section 5). We do not store your card details or bank information.

Newsletter subscription

If you subscribe to our weekly newsletter we collect your email address and postcode. Your postcode is used to find events near you. We derive approximate latitude and longitude from your postcode using the postcodes.io API so we can personalise event recommendations by distance.

Business accounts

If you register as an event organiser, we additionally collect your business name, description, and venue details (including addresses). If you connect a Mollie account for payments, Mollie provides us with your Mollie organisation ID and access tokens, which we store encrypted.

Connected platforms (event organisers only)

If you connect Sommly to an external platform where you already publish events (for example Eventbrite, Ticket Tailor, Bookwhen, Humanitix, TryBooking, Shopify, Google Calendar, or any iCalendar (.ics) feed), Sommly receives event data from that platform on your behalf. The data we receive is limited to event details: titles, descriptions, dates, venue addresses, ticket prices, cover image URLs, and the public link back to the original event.

We do not receive, request, or store order data, attendee data, payment information, or any other customer-facing information from those platforms. For OAuth-based connections we receive access and refresh tokens, which are stored encrypted and used solely to fetch event data on your behalf. See section 6 for full details, including our compliance with the Google API Services User Data Policy.

3. How we use your data

We use your personal data to:

  • Provide and operate the Sommly platform
  • Process ticket orders and deliver tickets via email
  • Send you our weekly newsletter (only if you have subscribed)
  • Personalise event recommendations based on your location
  • Enable event organisers to manage their events, venues, and ticket sales
  • Process payments via Mollie on behalf of event organisers
  • Analyse how the platform is used so we can improve it (see section 4)
  • Prevent fraud and ensure platform security

Our legal basis for processing your data is contract performance (to provide the services you have requested), legitimate interest (to improve and secure the platform, including the cookieless analytics described in section 4), and consent (for newsletter subscriptions).

4. Analytics and cookies

We use PostHog for product analytics to understand how people use Sommly and to improve the experience. PostHog Inc. acts as our data processor and hosts this data in the European Union (PostHog Cloud EU). You can read their privacy policy at posthog.com/privacy.

Our analytics is cookieless: it sets no cookies and stores nothing on your device. As a visitor you are not tracked across visits, which is why we do not show a cookie consent banner for analytics.

PostHog may collect:

  • Pages you visit and actions you take on the site
  • Browser type, device type, and screen size
  • Referring website
  • Approximate location derived from your IP address

If you are logged in, we link analytics events to your account (user ID, email, and name) so we can understand usage patterns across sessions.

We also use essential cookies for session management and authentication. These are strictly necessary and cannot be disabled.

5. Payment processing

All payments on Sommly are processed by Mollie B.V., a payment service provider regulated by De Nederlandsche Bank. When you purchase tickets, you are redirected to Mollie's secure checkout to complete payment. We do not have access to your full card details or bank information.

Mollie processes your payment data in accordance with their own privacy policy, which you can read at mollie.com/privacy.

We receive from Mollie a payment ID and payment status, which we store to track your order. Event organisers who use Mollie Connect receive funds directly into their own Mollie accounts.

6. Third-party integrations

Event organisers can connect Sommly to platforms where they already publish their events, so those events appear on Sommly automatically. Sommly currently supports connections to Eventbrite, Ticket Tailor, Bookwhen, Humanitix, TryBooking, Shopify, Google Calendar, and any iCalendar (.ics) feed.

What we access

  • Event titles, descriptions, dates, venue, ticket prices, cover image URLs.
  • For Shopify, the product listings you choose to sync (title, description, price, images), which we turn into event listings.
  • The public link back to the original event page on the partner platform.
  • Where the partner offers them, webhooks notifying us when an event is created, updated, or removed.

What we never access

  • Order data, attendee names or emails, or any data about your customers. This includes Shopify: we never read or store your Shopify customers' data.
  • Payment information, refund history, or financial reports.
  • Anything other than event metadata.

Credentials and security

For OAuth integrations (Eventbrite, Shopify, Google Calendar) Sommly requests only the minimum scopes required to read event data, and stores the resulting access tokens and refresh tokens encrypted at rest. For API-key integrations (Ticket Tailor, Bookwhen, Humanitix) the merchant pastes a key generated from the partner's dashboard, which Sommly stores encrypted. For feed-URL integrations (iCalendar, TryBooking) Sommly stores the public feed URL only.

Disconnecting

You can disconnect any integration at any time from your dashboard. Disconnecting wipes the credentials we stored, unsubscribes Sommly from any webhook delivery, and stops future events from syncing. Your existing event listings stay live on Sommly because they were published with your authorisation. To delete those listings as well, email [email protected].

Google API Services and Limited Use

Sommly's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, when you connect Google Calendar to Sommly:

  • We request only the https://www.googleapis.com/auth/calendar.events.readonly scope, which permits read-only access to events on calendars you explicitly authorise.
  • We use the data we receive from Google APIs solely to display your wine events on the Sommly discovery surface.
  • We do not transfer the data to third parties, except as necessary to provide or improve the Sommly product, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to you.
  • We do not use the data for advertising purposes.
  • We do not allow humans to read the data unless we have your affirmative agreement for specific items, the access is necessary for security purposes (such as investigating abuse), the access is required to comply with applicable law, or the data is aggregated and used for internal operations in a way that prevents the identification of any individual user.
  • We do not use the data to develop, improve, or train generalised artificial intelligence or machine-learning models.
  • You can revoke Sommly's access to your Google Calendar at any time from your Sommly Connections page, or by removing Sommly from your Google Account at myaccount.google.com/permissions.

7. Data sharing

We do not sell your personal data. We share data only in these circumstances:

  • Event organisers: When you buy tickets, the organiser receives your name and email address so they can manage attendance and communicate about the event.
  • Mollie: Payment data is shared with Mollie to process transactions (see section 5).
  • Resend: We send all email (newsletters, ticket confirmations, login links) via Resend, our email delivery provider. Your name and email address pass through their systems. Resend is a US company; transfers are safeguarded under the EU-US Data Privacy Framework and standard contractual clauses.
  • PostHog: Analytics data is processed on our behalf by PostHog in the EU (see section 4).
  • postcodes.io: Your postcode is sent to the postcodes.io API to derive coordinates for location-based features. postcodes.io is a free, open-source UK postcode lookup service.
  • Connected platforms: When an event organiser connects an integration (see section 6) Sommly fetches event data from the partner's API, but does not send your personal data to those platforms. The flow is from them to us, not the other way around.
  • Legal requirements: We may disclose data if required by law or to protect our legal rights.

8. Data retention

We retain your account data for as long as your account is active. Order and ticket data is retained for 7 years to comply with UK tax and accounting obligations. If you subscribed to the newsletter without creating an account, your subscriber record (email, postcode, and derived location) is deleted immediately when you unsubscribe. If you have a Sommly account, unsubscribing stops all marketing email immediately and your account data is retained as described above. Analytics data is retained for 12 months. Event metadata received from connected platforms (see section 6) is deleted from Sommly within 90 days of the event finishing, unless you are still connected and the partner platform continues to surface it. Integration credentials are deleted immediately when you disconnect.

9. Your rights

Under UK data protection law (UK GDPR), you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request deletion of your data
  • Object to or restrict processing of your data
  • Data portability (receive your data in a structured format)
  • Withdraw consent at any time (for example by unsubscribing from the newsletter)

To exercise any of these rights, email us at [email protected]. We will respond within 30 days.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

10. Security

We take appropriate technical and organisational measures to protect your data. Passwords are hashed using bcrypt. Mollie access tokens, integration access tokens, refresh tokens, API keys, and webhook signing secrets are all stored encrypted at rest. All data is transmitted over HTTPS.

11. Changes to this policy

We may update this policy from time to time. Material changes will be communicated via the platform. The "last updated" date at the top of this page indicates when the policy was last revised.