Privacy policy
What we know
about you
We collect what it takes to sell you a ticket, get you on the boat and split the money between five societies. We do not sell it, we do not send marketing, and we delete it after the event. Card numbers never reach this site at all.
01Who is asking
This site is run by the Night in Lanka committee on behalf of the Sri Lankan societies of UNSW, Western Sydney, Sydney, Macquarie and UTS. Tickets are sold by the Sri Lankan Students Society of the University of New South Wales, which is the organisation responsible for the information described here.
We are a student society, not a company with a privacy department. We have written this to follow the Australian Privacy Principles because that is the right standard to hold ourselves to, and because you are handing your details to people your own age.
02What we collect
When you buy a ticket
- Your name, email address and mobile number
- The full name of each person a ticket is for, and which of the five societies each is with
- Dietary requirements and accessibility needs, if you tell us. Both are optional and free text, so you choose what to write
- How you heard about the event, and a promo code if you used one
- The order itself: which release, how many tickets, the amount, the time, and a reference to the payment held by Stripe
If a card is declined for being overseas
- The country your card was issued in, recorded against the cancelled order so the page can tell you why it did not go through
If you join the waitlist
- Your name, email and how many tickets you would want. One row per address, used to email you if seats come back, and nothing else
Automatically, as with any website
- Your IP address, counted for a few minutes at a time so that one person cannot hammer the checkout and hold seats they never pay for
- Anonymous page analytics, and technical error reports if something breaks. Neither is tied to your name
03Why we collect it
- Your email is where the ticket goes, and how we reach you if the boarding time changes
- Your mobile is how the door team finds you if something goes wrong at the wharf on the night
- Attendee names are on the tickets because entry requires photo ID matching the name, which is what stops tickets being scalped
- The society on each ticket is how five societies work out the split of the proceeds. Without it the split is a guess
- Dietary and accessibility notes are passed to the boat's crew and caterer so the food and the boarding actually work for you
- How you heard about it tells us which channel worked, and goes into the report our sponsors are promised, as a number and never as a name
We do not send marketing emails. There is no mailing list to be added to: the only emails you get are about the ticket you bought.
04What we never see
Your card number never touches this site. The payment box on the checkout page is served by Stripe, and the details go from your browser straight to them. We receive a payment reference and whether it succeeded. Nobody on the committee can see your card, and neither can anyone who broke into our database.
Stripe is a payment processor certified to the card industry's security standard, and their handling of your card is covered by their own privacy policy at stripe.com/au/privacy.
05Who else touches it
We do not sell or rent your information, and we do not hand it to sponsors. It reaches other organisations only where they run part of the machinery:
- Stripe takes the payment and emails your receipt
- Supabase holds the database of orders and tickets, hosted in Sydney
- Vercel hosts this site and runs the code behind the checkout
- Resend sends the ticket and confirmation emails
- Sentry receives an error report if something breaks, so we find out before you have to tell us
- The cruise operator gets the numbers it needs to run the night, including dietary counts and any access needs
- Google Fonts serves the typefaces, which means Google sees your IP address when the page loads
Some of these are based overseas or process data outside Australia, so by using this site you accept that your information may be handled outside the country. We would also disclose information where the law requires it, which for an event like this realistically means a police request about an incident on the night.
07On the night
Your ticket carries a QR code. When the door team scans it we record that it was scanned, when, and by which phone, which is what stops the same ticket being used twice. The door team also carries the list of names for the night as a paper backup.
The QR code proves the ticket is genuine using a signature rather than by holding your details, and a scanner phone can verify it without your information being on the phone.
08How long we keep it
We keep what we need while it is needed and then get rid of it.
- Contact details, attendee names, dietary and access notes: deleted within 90 days after the event, once the door count is reconciled and the proceeds are split
- The waitlist: deleted at the same time, sooner if you ask
- The financial record of the sale (date, amount, order reference) is kept for as long as the society's accounts and tax obligations require. Stripe keeps its own record of the payment independently of us, under their retention rules
- Rate-limiting counts: minutes, then gone
Each year's committee hands over to the next one. What gets handed over is the accounts, not a list of last year's buyers.
09Getting a copy, or getting it deleted
Email info.nightinlanka@gmail.com from the address you booked with and you can ask us to:
- Send you a copy of what we hold about you
- Correct it if it is wrong. You can already change the name on a ticket yourself, using the link on the ticket
- Delete it. If the event has not happened yet, deleting your details means cancelling your ticket, because we cannot board somebody we hold no record of. We will say so before we do anything
We aim to answer within 30 days, and we do not charge for any of it.
10How it is protected
- The whole site is served over HTTPS
- Ticket and order pages are reached through a long random token rather than a guessable number, are told not to be indexed, and are never cached by anything in between
- The committee tools are password protected and locked to a handful of people
- Card details are Stripe's problem, by design, not ours
No system is perfect. If something did go wrong with information we hold, we would tell the people affected and act on it rather than sit on it.
11Complaints, and changes to this policy
If you think we have mishandled your information, email us first and tell us what happened. We would much rather fix it. If you are not satisfied with how we respond, you can take it to the Office of the Australian Information Commissioner at oaic.gov.au.
If this policy changes, the date at the top of the page changes with it, and anything that affects tickets already sold is emailed to the people holding them.
Privacy contact
info.nightinlanka@gmail.com · a member of the committee reads it, and answers within 30 days.