Ten at the event
Small enough that one conversation holds the whole night.
London · Small events
One event, ten seats, booked under our name in a bar a short walk from the station. No name badges, no pitch decks—just an easy way to meet good people.
Small enough that one conversation holds the whole night.
We aim for a balanced mix and keep the faces fresh.
Welcoming venues, clear details and a host who has it covered.
We have not been able to confirm a booking for this payment yet. We will keep trying automatically each time you open the site.
If you have been charged and this message keeps appearing, email hello@gatherby.uk quoting payment reference .
Choose an event to see the full details and book your tickets.
Manage your account and view your Gatherby bookings.
Sign in to see your bookings and manage your data.
Logged in as
Choose an event and book your next Gatherby experience.
Venue
📍
Exact venue unlocks 24 hours before the event.
📅
Ticket reference:
Booked on
Tickets
£ total
📍
📅
Booked on
Tickets
£ total
Download my data
A copy of your account, bookings and signups, as a JSON file.
If the download did not start, you can copy your data from here.
Delete my account
Closes your account and removes your name, email and profile details.
Date and time
Location
Ticket price
£ per person
Maximum 10 tickets per purchase
Total amount
£
× £
Legal
How Gatherby collects, uses and protects your personal data.
Last updated 7 August 2026
Gatherby runs small, hosted social events in London and sells tickets to them at www.gatherby.uk. When you use this site, the data controller for your personal data is:
[[LEGAL_ENTITY_NAME]] (trading as Gatherby)
[[REGISTERED_ADDRESS]]
[[COMPANY_NUMBER_OR_SOLE_TRADER]]
ICO registration number [[ICO_REGISTRATION_NUMBER]]
For anything to do with your personal data, including any of the rights described in section 9, contact us at hello@gatherby.uk. We have not appointed a Data Protection Officer, because we are not required to. Requests go to the address above.
This policy covers the www.gatherby.uk website and the events we sell through it. It does not cover any bar or venue we meet at, which runs its own premises and its own privacy practices.
We keep this deliberately short, because we collect little. Everything below is stored in our own database. Nothing else is collected.
Your full name, your email address, and your password. Your password is never stored in a readable form: we store only a PBKDF2-HMAC-SHA256 hash of it, computed with a random salt that is unique to you. We cannot read your password, recover it, or tell you what it is.
Purpose: creating and running your account
Lawful basis: performance of a contract with you (UK GDPR Article 6(1)(b)) - we cannot give you an account or sell you a ticket without it.
This field is optional and you can leave it blank. We use it only to try to keep a reasonable mix of people at each event, which is part of how we put a table together.
Purpose: balancing the guest list
Lawful basis: your consent (Article 6(1)(a)), given by choosing to fill the field in. You can withdraw it at any time by clearing the field or asking us to remove it, and your account and bookings will carry on working exactly as before.
When you log in we create a session so that you stay logged in. We store a SHA-256 hash of your session token, never the token itself, along with when the session was created, when it expires, and whether it has been revoked. See section 4 for the cookie this uses.
Purpose: keeping you signed in, and keeping your account secure
Lawful basis: performance of a contract (Article 6(1)(b)), and our legitimate interests in protecting accounts from unauthorised access (Article 6(1)(f)).
For each ticket you buy we store which event it is for, the event title and meet-up group, how many tickets you bought, the unit price, the subtotal, the VAT, the total, the currency, the reference of the Stripe checkout session, the payment status Stripe reports back to us, your ticket reference, and the dates the booking was made and confirmed. We also store a signup record with your name, email and the event, so we know who is coming.
We never see or store your card details. Payment is taken on Stripe's own checkout pages. Your card number never reaches our servers.
Purpose: selling you a ticket, admitting you to the event, and keeping our accounts
Lawful basis: performance of a contract (Article 6(1)(b)) for the sale and the guest list, and compliance with a legal obligation (Article 6(1)(c)) for the tax and VAT records we are required to keep.
If you tick the marketing box when you sign up, we store that you consented and the date and time you did so. If you do not tick it, we store the fact that you did not.
Purpose: sending you news about upcoming events, if you asked for it
Lawful basis: your consent (Article 6(1)(a)). Withdrawing it is always as easy as giving it - see section 10.
Like any website, ours is reached over the internet, so our hosting provider and the content networks described in section 5 receive your IP address and basic browser information as part of delivering the pages to you. We do not build a profile from it.
Purpose: serving the site, and keeping it available and secure
Lawful basis: our legitimate interests in operating a working, secure website (Article 6(1)(f)).
So that this is unambiguous, here is what we do not do:
We set exactly one cookie, and it is strictly necessary. Under the Privacy and Electronic Communications Regulations (PECR), strictly necessary cookies do not require your consent, which is why this site does not nag you with a consent banner offering choices that would not mean anything.
gb_session - strictly necessary
Holds a random session token so that you stay logged in and can see your own bookings. It is HttpOnly, so scripts in your browser cannot read it; Secure, so it only travels over HTTPS; and SameSite=Lax, which is what lets you come back to the site from Stripe after paying. It expires after 30 days. We store only a SHA-256 hash of the token, so the cookie value itself is not held in our database. Removing it logs you out; the site will not work as a logged-in account without it.
The site also keeps a small amount of information in your browser's own local storage - your signed-in name and email, and a local copy of your bookings - purely so the pages render correctly and you are not signed out unexpectedly. This never leaves your device and is also strictly necessary for the service you asked for. Logging out clears it, as does clearing your browser data.
We set no analytics cookies, no advertising cookies and no third-party marketing cookies. There is no Google Analytics, no Meta pixel, no consent management platform and no tracker on this site.
We use a small number of service providers. They are the only third parties that receive anything.
Stripe processes every card payment. When you check out you are sent to Stripe's own hosted page, and Stripe receives your email address and your card details directly from you. Stripe acts as our processor for taking the payment, and as an independent controller for its own fraud prevention and financial regulation duties. It returns to us only the checkout session reference and the payment status. Stripe's privacy policy is at stripe.com/privacy.
Our application and database run on Railway, deployed in its Amsterdam region in the Netherlands. Railway is our processor and holds the data described in section 2 on our behalf. It does not use it for anything of its own.
The site loads its styling and interactive code from cdn.tailwindcss.com and cdn.jsdelivr.net, and its typefaces from Google Fonts (fonts.googleapis.com and fonts.gstatic.com). Because your browser fetches those files directly, those providers necessarily receive your IP address and basic browser information whenever you load a page. We do not send them your name, email or any account data, and we do not use them to track you - but we want you to know the request happens. Google's handling of Fonts requests is described at developers.google.com/fonts/faq/privacy.
We may disclose personal data to our accountants or professional advisers where they need it, or to the police, a court, HMRC or a regulator where the law requires it. That is the complete list. Nothing is shared with advertisers or data brokers.
Our servers and database are in Amsterdam, in the Netherlands, so your account and booking data is stored inside the European Economic Area. The EEA is covered by UK adequacy regulations, so no additional safeguard is needed for that transfer.
Stripe, and the content delivery networks in section 5, are global and may process data outside the UK and the EEA, including in the United States. Where that happens, the transfer is covered by the safeguards those providers offer, which are the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum, or the UK Extension to the EU-US Data Privacy Framework where the provider is certified under it. You can ask us at hello@gatherby.uk for details of the safeguard applying to a particular provider.
No system is perfectly secure. If a breach ever occurs that is likely to risk your rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours and tell you without undue delay where the law requires it.
Under UK GDPR and the Data Protection Act 2018, and under EU GDPR if you are in the EEA, you have the following rights over your personal data:
Two of these you can exercise yourself, immediately, from your profile page: Download my data gives you a machine-readable export of your account, bookings and signups, and Delete my account closes and removes it. For anything else, email hello@gatherby.uk. We answer within one month, and we do not charge for it. If a request is unusually complex we may take up to two further months, and we will tell you within the first month if that happens.
We only send marketing to people who have positively opted in. The box is never pre-ticked, and creating an account or buying a ticket never signs you up by itself.
You can withdraw your consent at any time by using the unsubscribe link in any marketing message, by changing the setting in your profile, or by emailing hello@gatherby.uk. We will act on it promptly and we will not ask you to justify it. Withdrawing marketing consent has no effect on any ticket you have bought, and does not stop us contacting you about a booking if we ever need to.
If you think we have handled your personal data badly, please tell us first at hello@gatherby.uk and we will try to put it right. You do not have to, and you can go straight to the UK regulator, the Information Commissioner's Office:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline 0303 123 1113
ico.org.uk
If you live in the EEA, you can instead complain to the data protection authority in your own country.
Our events take place in bars and are intended for adults. This site is not for anyone under 18, and we do not knowingly collect personal data from anyone under that age. If you believe a child has given us their data, email hello@gatherby.uk and we will delete it.
If we change what we collect or what we do with it, we will update this page and change the date at the top. If a change materially affects you, we will tell you directly. This policy is written to describe what the site actually does today, and we intend to keep it that way.
Exclusive member events
Every ticket purchased through the platform makes users eligible to attend an exclusive private event held every two months, available only to platform members.
This closes your Gatherby account and removes your name, email and profile details. It cannot be undone, and you will be signed out straight away.
We have to keep the payment and VAT records for the tickets you have already bought, because tax law requires it. Those records will be kept for six years after the end of the financial year they relate to and used for nothing else.
If you have a ticket for an upcoming event, deleting your account does not cancel it or refund it — contact us first if that is what you want.