In The Light
Legal

Privacy Policy

Last updated: 10 July 2026

This Privacy Policy explains how Rowpe LTD ("we", "us", "our") collects, uses, and protects your personal data when you use In The Light (the "Service") at inthelight.events. We are the data controller for your personal data and are committed to protecting it in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who we are

In The Light is operated by Rowpe LTD, a company registered in England and Wales (company number 15727763), with its registered office at 20-22 Wenlock Road, London, N1 7GU, United Kingdom.

For any privacy questions or to exercise your rights, contact us via our contact form or at admin@rowpe.com.

2. Scope

This policy applies to visitors browsing events, people who subscribe to our updates or contact us, and event organisers who create an account. Attendees can browse and discover events without creating an account; only organisers register accounts with us.

3. The data we collect

Depending on how you use the Service, we may collect:

  • Organiser account data — when you register as an organiser: your name, email address, password (stored securely by our authentication provider), and optionally your organisation name, phone number, and website.
  • Organiser profile data — information shown on your public organiser profile, such as your name, description, logo, website, and contact email.
  • Event data — details you submit when listing an event, including title, description, dates, venue name and address, language, category, and images you upload.
  • Newsletter data — if you subscribe to updates, your email address.
  • Contact form data — if you contact us, your name, email address, and message.
  • Technical data — limited information needed to operate the site securely, such as essential session cookies. See 'Cookies and analytics' below.

Please remember that event listings and organiser profiles are public. Do not include personal information in event descriptions that you do not want to be publicly visible.

4. How we use your data and our legal bases

We use your personal data for the following purposes:

  • To provide the Service — creating and managing organiser accounts, publishing event listings and profiles, and displaying them to visitors (legal basis: performance of a contract, and our legitimate interests in operating the platform).
  • To respond to enquiries — handling messages you send us through the contact form (legal basis: our legitimate interests in responding to you).
  • To send newsletters and product updates — only where you have subscribed (legal basis: your consent, which you can withdraw at any time).
  • To keep the Service secure — preventing fraud, abuse, and unauthorised access (legal basis: our legitimate interests).
  • To understand and improve usage — through analytics, once enabled, and only with your consent (legal basis: your consent).
  • To comply with legal obligations where they apply (legal basis: legal obligation).

5. Cookies and analytics

We currently set only essential cookies that are necessary for the Service to work — for example, to keep organisers signed in. Essential cookies do not require consent.

We intend to use Google Analytics to understand how the Service is used so we can improve it. Analytics cookies are not essential, so we will only set them with your consent, which you will be able to give or decline through a cookie banner and change at any time. Until you consent, no analytics cookies are set. When enabled, Google Analytics is provided by Google, and its use of data is governed by Google's own privacy policy.

6. Who we share your data with

We do not sell your personal data. We share it only with service providers who process it on our behalf to run the Service:

  • Google Firebase (Google Cloud) — provides our authentication, database, and image storage. Account data, event data, and uploaded images are stored on Firebase.
  • Web3Forms — delivers messages submitted through our contact form to us.
  • Google Maps — event pages include links that open a location in Google Maps. We do not embed maps or share data with Google unless you choose to follow such a link.
  • Google Analytics — usage analytics, once enabled and only with your consent (see above).

We may also disclose personal data where required by law, to protect our rights, or in connection with a business transfer.

7. International transfers

Some of our providers (including Google and Web3Forms) may process personal data outside the United Kingdom. Where data is transferred internationally, we rely on appropriate safeguards such as UK adequacy regulations or the UK International Data Transfer Agreement/Addendum to ensure your data remains protected.

8. How long we keep your data

We keep personal data only for as long as necessary. Organiser account and profile data is retained while your account is active and for a reasonable period afterwards. Event listings are retained while published and while your account remains active. Newsletter subscriptions are kept until you unsubscribe. Contact-form messages are kept for as long as needed to deal with your enquiry and our records. We then delete or anonymise the data unless we must keep it to meet a legal obligation.

9. Your rights

Under UK data protection law you have the right to:

  • Access the personal data we hold about you.
  • Ask us to correct inaccurate or incomplete data.
  • Ask us to erase your data in certain circumstances.
  • Restrict or object to our processing in certain circumstances.
  • Data portability — receive certain data in a portable format.
  • Withdraw consent at any time where we rely on consent (for example, newsletters or analytics).

To exercise any of these rights, contact us via our contact form or at admin@rowpe.com. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk, though we'd appreciate the chance to help first.

10. Children

The Service is intended for organisers and visitors aged 18 or over and is not directed at children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

11. Security

We use reputable providers and appropriate technical and organisational measures — including encrypted connections (HTTPS) and access controls — to protect your data. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

12. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above, and material changes will be highlighted where appropriate. Please review this page periodically.

13. Contact us

If you have any questions about this Privacy Policy or how we handle your data, contact us via our contact form or at admin@rowpe.com.


Questions about this page? Reach us via our contact form.