Privacy Policy
Last updated: 19 July 2026
1. Who we are
Near Here (https://nearhere.events) is a trading name of Furls Digital Ltd, a company registered in England and Wales (company number 17110533). Registered office: Belmont Suite Paragon Business Park, Chorley New Road, Bolton, Lancashire, England, BL6 6HG. VAT registration number: 519 9802 54.
Furls Digital Ltd is the data controller for personal data described in this policy.
Contact: hello@nearhere.events
We are not required to appoint a Data Protection Officer under UK GDPR. For any data protection queries, please use the contact above.
2. Data we collect
We collect minimal personal data. Depending on how you use the site, this may include:
- Analytics and advertising data (with consent), such as pages visited, device/browser type, approximate location, and aggregate interactions such as saving an event or adding one to a calendar. Save and calendar interaction counters do not include the public event ID, saved time, or contents of your saved list.
- Your browser location coordinates, if you choose to share them with us using the location button. We use them to find the nearest Near Here town and do not put them in a cookie. If you accept optional cookies, we store only that snapped town's identifier so we can personalise pages on future visits (see section 6).
- Basic technical logs needed for security, reliability, and abuse prevention.
- Information you send us directly by email, including your email address, message content, and any attachments or details you choose to include.
- If you sign up for the newsletter, your email address, the location you choose for updates, newsletter delivery and suppression status, one-time confirmation/manage tokens needed to operate the subscription, and consent audit records such as the version of the signup wording shown to you and HMAC-hashed IP address and browser/user-agent evidence.
- If you choose to sign in, your email address, email-verification status, short-lived single-use sign-in records, active session records, a short-lived HMAC-derived email key used to limit repeated sign-in emails, and any saved event public IDs with the time each was added to your account's saved list. We do not keep the sign-in IP address or browser user-agent in the account session.
- If you buy or fund an event boost, the buyer email address needed for receipts and transactional boost emails, stored by us in encrypted form with a separate email hash for audit and abuse prevention, plus the selected event, areas, weeks, payment status, payment, invoice, credit-note and refund references, and versioned terms or early-start acceptance needed to operate the boost.
- If you request a VAT invoice, Stripe may also collect the customer or business name, billing address and tax identification number needed for that invoice. Stripe keeps those billing details; Near Here stores only that an invoice was requested and the Stripe document references needed for support, accounting and refunds.
- When you accept boost terms at checkout, HMAC-protected evidence derived from the Cloudflare-provided IP address and browser user-agent. We do not store the raw values on the boost record.
- Basic sponsorship and advertising records, such as which advert or sponsored placement was shown in a newsletter or on a page, where needed to operate, audit, and report on paid placements.
- If you save an event while signed out, its public event ID and the time you saved it are kept in this browser's local storage. This is browser storage, not a cookie.
- If you sign in, valid current events saved in that browser are copied to your account where space allows. Their public event IDs and the times they joined the account list are kept in our Cloudflare D1 database.
Most of this information comes directly from you, your browser, or your device. Newsletter delivery, bounce, complaint, and suppression signals also come back to us from our email provider so we can keep the mailing list accurate and stop sending where we should not.
We do not intentionally collect special category data or children's data.
This service is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you are under 13, please ask a parent or guardian to use the site or sign up for the newsletter on your behalf. If you believe we may have collected data from a child under 13, please contact us at the address above and we will delete it.
3. How and why we use data
- To run and secure the website.
- To understand usage and improve content and performance.
- To respond to messages you send us.
- To send our email newsletter if you ask to receive it, confirm your subscription, let you manage or unsubscribe from it, and suppress further sends after bounces, complaints, or unsubscribe requests.
- To send a sign-in link, create and secure your account, and keep you signed in on the device you use.
- To process, confirm, audit, and support event boost purchases, including sending transactional boost confirmation emails.
- To show and manage clearly labelled advertising, sponsored placements, and commercial partner content on the site or in newsletters.
- To remember the public events you choose in this browser while signed out, or with your account while signed in, and return their latest public details when you open your saved page.
4. Legal bases (UK GDPR)
- Consent for analytics cookies, advertising cookies, and related tracking.
- Legitimate interests for site security, operation, and service improvement.
- Legitimate interests and steps requested by you when replying to contact messages.
- Consent for sending newsletter emails and related subscription management, including clearly labelled advertising or sponsored content within those emails.
- Contract and steps requested by you for account sign-in, plus legitimate interests for short-lived session security and abuse prevention.
- Legitimate interests for keeping limited newsletter consent evidence, such as HMAC-hashed IP address and browser/user-agent evidence, so we can demonstrate and audit consent without storing the raw IP address in the newsletter database.
- Contract and steps requested by you for processing event boost purchases, cancellations, and refunds, plus legitimate interests for keeping limited acceptance, audit, abuse-prevention, dispute, and support records for those purchases.
- Legitimate interests for operating, auditing, and reporting on sponsorship or advertising placements, provided this does not override your privacy rights.
- Legitimate interests for providing the saved-events feature you request, using browser storage while you are signed out or storing public event IDs and saved times with your account while you are signed in.
5. Newsletter
If you sign up for the Near Here newsletter, we email you first so you can confirm you actually want it before any newsletter emails begin.
For newsletter subscriptions, we store the email address you provide, the location you choose for local event updates, delivery metadata such as sent, delivered, bounced, complained, or unsubscribed state, and the one-time tokens needed to confirm or manage the subscription.
We also keep consent audit records for newsletter signup, confirmation, and unsubscribe actions. These records include the consent wording and policy versions in force at the time, the page or route used, and HMAC-hashed IP address and browser/user-agent evidence. We use the hash so we can audit and evidence consent without storing the raw IP address in the newsletter database.
We use this information to send the weekly local events newsletter you asked for, send the confirmation and management emails needed to run that subscription, provide unsubscribe and manage links, prevent duplicate subscriptions, process bounces and complaints, and avoid further sending where a suppression is required.
Newsletter emails may include clearly labelled advertising, sponsored placements, or commercial partner messages relevant to local events, venues, or services. We do not sell newsletter subscriber email addresses, and we do not share your email address with sponsors for their own marketing.
You can unsubscribe at any time using the links in the email or by contacting us using the address in this policy.
6. Cookies and consent
When you first visit the site, we show our own cookie consent banner. Google Analytics and Microsoft Advertising UET are only loaded if you click "Allow optional cookies". If you choose essential cookies only, those services are not loaded and no requests are sent to Google or Microsoft by those tags.
We use Google Consent Mode v2 and Microsoft's Basic Consent Mode. Optional analytics and advertising measurement stay blocked until you explicitly opt in. We also store a first-party cookie_consent cookie for up to one year to remember your choice.
You can change or withdraw your cookie consent at any time. The Cookie settings link in the footer of every page re-opens the consent banner so you can switch between accept and decline. Withdrawing consent stops further optional analytics and advertising measurement, clears the Google Analytics cookies ( _ga, _ga_<ID>), the first-party Microsoft UET identifiers on the Near Here domain that we can access, and the location preference cookie. We also send a denial signal to UET and use Microsoft's UET network kill switch. Withdrawing is as easy as giving consent in the first place. You can also clear cookies manually in your browser settings.
With your consent, UET measures visits and actions after Microsoft Advertising clicks so we can understand whether adverts are useful. We send Microsoft a sanitised page path for each page view rather than the full URL, and disable UET on account, sign-in, email-token, and payment-session routes. We do not deliberately send form contents, newsletter tokens, payment session IDs, saved-event lists, or precise location coordinates to UET.
On newsletter signup, newsletter manage-request, account sign-in, and event-boost checkout forms, we also load Cloudflare Turnstile as a strictly necessary anti-abuse measure to protect those forms and boost inventory from bots and automated misuse.
After a completed event-boost checkout, we set a short-lived, strictly necessary first-party cookie so the confirmation page can be refreshed without leaving the payment reference in the page URL. Its encrypted value is not available to page scripts and expires after 24 hours.
Location storage
If you accept cookies and choose to share your location, we store a snapped local town identifier in a first-party nearhere_location cookie for up to 30 days. We use this only to show more relevant nearby events and towns on future visits. We do not keep your precise coordinates in that cookie. If you decline cookies, we do not keep this location between visits and the site falls back to approximate IP-based location from Cloudflare headers.
The location cookie is only read by our site. We do not sell it or share it with advertisers. You can remove it at any time by clearing your browser's cookies.
Saved event storage
While you are signed out, we use strictly necessary browser local storage to keep up to 50 public event IDs and the time each was saved. This works without optional-cookie consent because you asked us to remember the list. It is not a cookie and stays on this device and browser unless you remove it. On a shared device, other people using the same browser may be able to see these signed-out saved events.
While you are signed in, we keep up to 50 public event IDs and the times they joined your account list in Cloudflare D1 instead. We do not store an event title, description, venue, calendar details, email address, or other event content in the saved-event record. When you sign in, existing account saves take priority and valid current browser saves fill any room left within the 50-event limit. We remove only the browser entries that the account confirms it now holds. A valid save that does not fit remains in that browser; events that have finished or no longer exist are tidied from the browser list as usual.
To avoid repeating the same transfer after a page reload, we keep a short-lived one-way hash of the account and saved-list snapshots in browser session storage. It contains no readable event or account identifiers and is discarded when that browser tab's session ends.
When you open the saved page, Near Here uses the public event IDs from the active list to return the latest public details. Signed-out requests do not send the saved times. Signed-in requests are tied to the account identified by the protected session cookie; the browser cannot choose another account ID.
Saved events belong to you. We use them only to provide the saved-list features you request. We do not sell saved-event data, use it to build a profile about you, or target advertising or promoted events from it. If you use an account on a shared device, sign out when you have finished so the next person cannot open your account's saved list.
The saved page lets you remove one event or clear the whole list. We also prune an event after the London calendar day on which it finishes, and remove IDs for events that no longer exist after a successful check. We do not clear the list when that check fails.
If we introduce any other third-party advertising cookies, sponsor tracking pixels, or sponsor-specific tracking that is not strictly necessary, we will update this policy and our cookie consent controls before using them.
Cookies we use
cookie_consent— first-party, strictly necessary, up to 1 year. Remembers your cookie preference so we don't ask again on every visit.nearhere_location— first-party, functional (set only with your consent and after you choose to share your location), up to 30 days. Stores a snapped local town identifier so we can show relevant nearby events on future visits.nearhere_boost_confirmation— first-party, strictly necessary, up to 24 hours. Holds an encrypted reference to a completed boost checkout so its confirmation page can be refreshed securely.__Host-nearhere-auth.session_token— first-party, strictly necessary, up to 30 days after your most recent signed-in visit. Keeps you signed in securely after you use a one-time email link. It is renewed at most once a day while you keep returning, is unavailable to page scripts, and is limited to this website host._ga,_ga_<ID>— Google Analytics, analytics, up to 2 years. Set only if you accept analytics cookies. Used to measure aggregate site usage and improve content._uetvid,_uetvid_exp,_uetsid, and_uetsid_exp— Microsoft UET, advertising measurement, up to 13 months for visitor identifiers and up to 1 day for session identifiers. Set only after you allow optional cookies._uetmsclkid— Microsoft UET, advertising measurement, up to 90 days. Set on the Near Here domain only after you allow optional cookies, so a consented Microsoft Advertising click can be linked to a later conversion.- Microsoft may also set identifiers such as
MUIDandMSPTCon Microsoft-owned domains after you allow optional cookies. Those third-party cookies are governed by Microsoft's privacy statement and your browser controls. Near Here cannot directly delete cookies on a Microsoft domain; withdrawing consent sends UET a denial signal and activates its network kill switch to stop further UET use. _uetmsdns— first-party privacy control, up to 1 year after consent is withdrawn. A value of 1 stops UET from sending further events and is removed if you later allow optional cookies again.- Cloudflare Turnstile may set short-lived cookies on newsletter signup, newsletter manage-request, account sign-in, and event-boost checkout forms as a strictly necessary anti-abuse measure.
7. Sharing data
We do not sell your personal data. We share limited data with:
- Cloudflare, which provides website delivery, edge security, D1 database services, and transactional email sending for account sign-in, newsletter, and boost purchase, cancellation, start, and finish messages.
- Amazon Web Services, including SES and SNS, which handle bulk newsletter digest delivery and related delivery, bounce, complaint, and suppression event processing.
- Stripe, which processes boost checkout payments, receipts, optional VAT invoices, credit notes, refunds, and related payment records. We do not store full card details ourselves or copy invoice billing details into Near Here.
- FreeAgent, our accounting provider, where boost payment, refund, fee, payout, and buyer transaction details are needed for bookkeeping, VAT, and statutory accounts.
- Google Analytics, but only where you have allowed optional cookies.
- Microsoft Advertising UET, but only where you have allowed optional cookies, for advertising measurement.
- If you choose Google Calendar or Outlook from a saved event, your browser sends that event's public title, date, description, location, and Near Here link to the provider you select so it can prepare the calendar entry. Apple Calendar uses a calendar file created locally in your browser. Your chosen calendar provider's own privacy terms apply.
- Sponsors or advertisers only in aggregated or operational form, such as placement reporting, unless we tell you clearly and have a valid legal basis to share more.
- Operational hosting or infrastructure providers where needed to run newsletter delivery or support tooling.
- Professional advisers, regulators, or law enforcement where we are legally required to share information or need to protect the service or our users.
8. International transfers
We use service providers in the UK and the European Economic Area (EEA), and some providers may also process data internationally depending on the service. Where personal data leaves the UK, we rely on the safeguards required by UK data protection law, such as UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to EU Standard Contractual Clauses, alongside equivalent contractual safeguards with each processor.
In particular, newsletter storage and delivery infrastructure are intended to remain in the UK and/or EEA, depending on the provider used. Some Cloudflare services can be configured with additional regional controls, but we do not promise that every Cloudflare Worker execution path will always stay UK-only or EU-only. We keep the actual platform configuration under review and will update this notice if our processing position changes in a way that materially affects newsletter personal data.
9. Retention
- Cookie consent preference: stored in a first-party cookie for up to 1 year.
- Location preference cookie: up to 30 days.
- Signed-out saved event browser storage: kept until you remove it, clear the list or your browser data, or until we prune an event after its final London calendar day or confirm that it no longer exists.
- Signed-in saved events: kept with your account until you remove them, clear the list, the event is pruned after its final London calendar day or confirmed missing, or the account is deleted. Deleting an account also deletes its saved-event records.
- Analytics data: retained according to configured analytics retention settings.
- Operational logs: retained only as long as reasonably necessary for security and troubleshooting.
- Email correspondence: kept while we deal with your query and manage any follow-up. If an enquiry does not lead to an ongoing issue, we will normally delete it within 12 months. We may keep emails for longer where reasonably necessary for complaints, legal issues, abuse prevention, or a short audit trail.
- Active newsletter subscription records: kept while your subscription is active.
- Unconfirmed pending newsletter subscription records and their related consent evidence: removed after up to 30 days if the subscription is never confirmed.
- Ended newsletter subscription records (for example unsubscribed, bounced, or complained) and their related consent evidence: retained for up to 2 years and then removed, unless we still need limited records for abuse prevention, suppression handling, or legal/compliance reasons.
- Newsletter confirmation and manage tokens: removed 30 days after expiry or use.
- Newsletter delivery message records: retained for up to 180 days and then removed by retention cleanup.
- Newsletter consent audit records: kept while the related subscription is active, and otherwise according to the newsletter retention windows above.
- Newsletter admin audit records: retained for up to 365 days and then removed by retention cleanup.
- Unused account sign-in records: expire after 5 minutes and are removed by daily retention cleanup.
- Account sessions: expire after 30 days without a signed-in visit and are removed by daily retention cleanup after expiry. Returning while signed in renews the session at most once per day.
- Account sign-in email rate-limit keys: expire after 60 seconds and are removed by daily retention cleanup.
- Account email records: kept while the account is active and normally removed after 12 months without a successful sign-in, or sooner if you ask us to delete the account, subject to any legal or security reason that requires limited records for longer.
- Newsletter suppression records: may be kept longer where reasonably necessary to make sure we do not accidentally email an address again after an unsubscribe, bounce, or complaint.
- Completed boost purchase, refund, and confirmation records, including the buyer email needed to identify the transaction: normally kept for 6 years after the end of the relevant accounting period for tax, accounting, disputes, and legal compliance, and longer only where a dispute or legal obligation requires it.
- HMAC-protected boost checkout IP and browser evidence: removed from the boost record by scheduled cleanup once 13 months has passed after payment.
- Expired or failed boost checkout reservations that never became purchases: normally removed by scheduled cleanup once 30 days has passed.
10. Your rights
Subject to applicable law, you may request access, correction, erasure, restriction, objection, and portability for personal data we hold about you.
To exercise rights, email hello@nearhere.events.
You can also delete your Near Here account and its saved events from My Account. Newsletter subscriptions and records we must retain for accounting, tax, disputes, or legal obligations are managed separately.
We aim to respond to rights requests within one month, extendable by up to two further months for complex or numerous requests. We may need to verify your identity before responding so we don't disclose your data to anyone else.
If we rely on your consent, you can withdraw that consent at any time. For newsletter emails, the easiest way to do that is to use the unsubscribe or manage links in the email, or to email us.
You also have the right to object to our use of your personal data for direct marketing at any time. If you object, we will stop those sends.
Providing newsletter information is optional, but if you do not give us an email address and chosen location we cannot send the newsletter you requested.
We do not engage in automated decision-making or profiling that produces legal or similarly significant effects on you, including with newsletter subscription data.
11. Complaints and data breaches
If you are unhappy with how we handle personal data, contact us first. You can also complain to the UK Information Commissioner's Office (ICO): ico.org.uk/make-a-complaint.
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware, and notify affected individuals directly where required by law.
12. Changes to this policy
We may update this policy from time to time. We will update the "Last updated" date when changes are made.