Privacy policy
This policy explains the limited information WhenIsItLive? processes and the choices available to you.
Last updated: September 19, 2026Scope and contact
WhenIsItLive? operates this website and is responsible for the information practices described here. For privacy questions or requests, email privacy@whenisitlive.com.
Information you provide
- Event submissions: the suggestion or correction text, submission type, an optional referenced event, workflow status, and timestamps. The form does not request a name, account, or email address.
- Correspondence: your email address, message, and any information you choose to include when you contact us.
- Please do not submit sensitive personal information or personal information about another person unless it is necessary and lawful to do so.
Public sources and editorial research
We research event information from organizers, official announcements, public websites, and other published sources. Listings and research drafts can include public professional names, images, source links, and event details. Editors may provide this material and draft notes to AI research services, including ChatGPT from OpenAI, to check details and prepare suggestions. Editors decide what is published.
- The credential-protected research feed includes published events and pending editorial drafts. It does not include the submission inbox, administrator sessions, or OAuth credentials. Anyone given its private link can read the included draft text and source notes.
- An event disappearing from Upcoming or Recently Passed does not automatically delete its editorial record. Publication, research retention, and removal are separate editorial actions.
- If published information identifies you and you believe it is inaccurate, unnecessary, or unlawful, contact us using the privacy address below.
Information processed automatically
- Cloudflare processes ordinary network and security data needed to deliver and protect the site, which may include IP addresses, request URLs, timestamps, device or browser information, routing data, and security signals.
- Public forms use Cloudflare Turnstile to check for automated abuse. Opening a submission dialog loads this service, which processes browser and device signals. When a form is sent, we send the verification token and, when available, your IP address to Cloudflare for validation. The submission record itself does not include an IP-address field.
- Operational logs may contain request URLs, IP addresses, browser information, timestamps, response codes, and error details. Do not put confidential information into page URLs.
Cookies and browser storage
- The public site does not require an account. The application does not install advertising or audience-analytics trackers. Browser storage may remember a theme preference; clearing site data removes that preference.
- Administrator sign-in uses session and sign-in security cookies. The browser also remembers the administrator’s last selected sign-in provider. Our administrator session lifetime is seven days and may be renewed during use; signing out ends the current session.
- Cloudflare may use cookies or similar technologies for security and access control. Blocking necessary storage or scripts may prevent sign-in or the submission security check; you can send a suggestion or correction by email instead.
- You can manage cookies and local storage in your browser. We do not treat visiting this site or using a preference as consent to advertising or other unrelated tracking.
Administrator information
Invited administrators sign in through Better Auth using Google, Discord, GitHub, or Twitch when configured. We store the provider identifier, email and verification status, name and profile image if supplied, linked-account details, session tokens, session IP address and browser information, and sign-in timestamps. OAuth tokens may be stored encrypted for authentication, and short-lived sign-in state and rate-limit records help protect the service. Public visitors do not receive an administrator account. Cloudflare Access also protects the private staging environment.
How information is used
- To operate, deliver, maintain, and secure the website.
- To review event suggestions, correct listings, and respond to messages.
- To detect abuse, enforce the Terms of Use, debug failures, and comply with legal obligations.
- To establish, exercise, or defend legal claims when necessary.
Legal bases
Where data-protection law requires a legal basis, we rely on legitimate interests to deliver and secure the site, maintain editorial listings, prevent abuse, manage invited administrators, and respond to voluntary messages. We consider the effects on the people concerned and limit processing to what is reasonably necessary. We also process information where required by law and obtain consent where a particular activity requires it. Providing suggestions or correspondence is optional; without the information needed to understand a request, we may be unable to resolve it.
Service providers and disclosures
Cloudflare provides hosting, content delivery, security, database, and media storage services. Email providers handle correspondence, OAuth providers authenticate administrators, and AI research services process editorial material supplied to them. Information may also be disclosed to advisers or authorities when required by law or reasonably necessary to protect rights and safety, or in a transfer of the service subject to applicable privacy requirements.
- Read Cloudflare’s Privacy Policy and Turnstile Privacy Addendum for its handling of network and challenge information.
- Editorial material supplied to ChatGPT is also subject to OpenAI’s Privacy Policy and the settings of the account used for that research.
- External event links open services with their own privacy practices. This policy does not govern those services.
International processing
Our providers may process information in the United States and other countries where they operate. Where applicable law requires a transfer mechanism, transfers must use an applicable adequacy decision or appropriate contractual safeguards, such as standard contractual clauses. You may ask the privacy contact below for information about the safeguards relevant to your information.
No sale, targeted advertising, or profiling
We do not sell personal information or share it for cross-context behavioral advertising. We do not run targeted advertising or use personal information for solely automated decisions with legal or similarly significant effects. Because we do not conduct sale or targeted-advertising activities, a Global Privacy Control or Do Not Track signal does not change those practices. We will honor applicable opt-out obligations if our practices change.
Retention
Retention depends on why information was collected, whether a request remains unresolved, the need to support editorial corrections or security investigations, and applicable legal requirements. Submissions and drafts are managed by an administrator and have no automatic expiry. Closing a submission changes its review status without deleting its text; unpublished drafts can also be kept for further research. You may request removal of personal information using the privacy contact below.
- Correspondence is kept as needed to respond and follow up, document rights requests, or resolve a dispute. Requests to remove personal information are considered under the rights described below.
- Administrator sessions expire after seven days unless renewed during use. Related identity and security records may remain for administration, security, and applicable legal requirements; expiry of access is separate from deletion of those records.
- Infrastructure logs and backup copies follow separate provider or operator retention settings and applicable legal requirements. Removing information from the active website does not immediately remove it from existing backup copies.
Your privacy rights
Depending on where you live, you may have rights to know about, access, correct, delete, restrict, object to, or obtain a portable copy of personal information, and to appeal or complain to a regulator. You may also withdraw consent where processing relies on consent.
- To make a request, email privacy@whenisitlive.com.
- Because public submissions do not require identity information, we may be unable to connect an anonymous submission to you. We may request information reasonably necessary to verify and complete a request.
- Where applicable, an authorized agent may act for you after appropriate verification. To appeal a denied request, reply to our decision or use the same privacy address and explain what you would like reconsidered.
- We will respond within the period required by applicable law and will not discriminate against you for exercising an applicable privacy right.
Objecting and making a complaint
Where applicable, you have the right to object to processing based on legitimate interests because of your particular situation. You may raise a concern directly with the relevant data-protection authority without first contacting us.
- For the UK, contact the Information Commissioner’s Office. In the EEA, you can contact the authority where you live, work, or believe an infringement occurred; the European Data Protection Board lists those authorities.
Children
The service is intended for a general audience and is not directed to children under 13. We do not knowingly collect personal information from children under 13. A child under 13 should not send an event submission or email. If you believe a child provided personal information, contact us so it can be reviewed and deleted as appropriate.
Security
We use administrative, technical, and organizational safeguards designed for the limited information we process, including encrypted transport, restricted administrator access, defensive response headers, and managed Cloudflare infrastructure. No internet service can guarantee absolute security.
Policy changes
We may update this policy as the service or legal requirements change. The “Last updated” date identifies the current version. For material changes, we will provide additional notice and obtain consent where applicable law requires it; an updated policy alone does not provide consent for new processing that requires it.
Privacy contact
Email privacy@whenisitlive.com.