This Privacy Policy is designed to help you understand what information we collect, how we use it, and what choices you have.
When we talk about ";we,"; ";our,"; or ";us"; in this policy, we are referring to LNO Ltd, and our brands including TheatreBoxOffice.org, TheatreTickets.net, LocalNightsOut.com, TheatreVouchers.net and any other websites we operate.
LNO Ltd acts as an agent for Encore Tickets Ltd. Encore Tickets, the UK’s largest independent ticket company, sells tickets to their affiliates for a huge range of West End theatre, off West End, fringe and touring shows, attractions, exhibitions, river cruises, concerts and events.
We are a data Controller for the purposes of the General Data Protection Regulation (GDPR), and other data protection laws applicable in the United Kingdom and Member states of the European Union. Our registered address is –
LNO Ltd
27 Old Gloucester Street
London WC1N 3AX
Phone: 00442084329810
Email: GDPR@LNOLtd.com
Encore Tickets Ltd is the company we work very closely with, and who will always process transactions for the purpose of our customers purchasing tickets for any events. Encore Tickets Ltd will collect additional data separate to the data we collect. As such, under the GDPR rules they are Joint Controllers of our customer data. We have a separate contract with Encore Tickets Ltd to cover this situation under GDPR rules for joint control of subject data. We would advise that you also look at their Privacy Policy, which you will find here: Encore Tickets Ltd Privacy Policy
Generally, we collect personal information about you when you make a ticket purchase from us, during email or phone calls, if you create an account with us, make box office purchases operated or administered by us, and when you use our websites or social media channels.
In general, LNO Ltd use this information to provide tickets to you, to maintain and improve our services, and to provide information on our products and services. We need your basic personal data in order to provide you with these services in line with this overall privacy policy. We will not collect any personal data from you that we do not need in order to provide the services described in this Privacy Policy.
The personal data we collect from you when you make a booking, will usually be required to be passed on to the venue, together with your booking reference, in order to facilitate your access to that venue and to allow our venue partners to verify that purchasers are genuine, to avoid ticket touting, and for fraud checking purposes. Such purposes are in our, and the venue’;s legitimate interests.
Our venues are also joint ";Controllers"; with regard to your personal data. For more information on how they handle your data please consult their privacy policy. If the venue is based outside the EU this may involve an international transfer of your personal data in order for us to deliver the contract you have made. For more information on who we share personal data with, please see the Data Sharing section below.
Directly. Most of the personal data we hold about you is collected directly, for example when you make a purchase from the website, when you subscribe to receive marketing, or when you contact our customer services team. We might also collect your personal data if you create an account with us, enter a competition or free prize draw, register for a promotion, post a comment on our website, ask us a question, email us or otherwise interact with our staff and call centres.
Indirectly. We may also collect some anonymous data indirectly through your use of our websites and email. We use cookies and other technologies such as pixel tags on our websites and in our emails to collect information about your usage, and to better target our advertising to you. For more information on how we provide our marketing services please see the Marketing section below. To learn more about how cookies work, please see our Cookies Policy.
From Third Parties. We may also collect personal data from publicly available sources. For example, if you choose to use an integrated social media feature on our website, this third party will give us certain information about you, which could include your name and email address. Further information about the third parties from whom we obtain information is available below in the Data Sharing section.
You have significant rights regarding your personal data. For more information please see the Rights section below.
We take the security of your personal information very seriously. All web transactions made with our partner Encore Tickets use 128-bit Secure Socket Layer (SSL) encryption which encrypts all your personal information, including your credit card number, name, and address, so that it cannot be read if intercepted by a malicious third party.
Card transactions made on our partner white-label sites are processed by their payment partners Verifone, and Encore do not process such card payments directly, nor will we have any access to any of your card details. Payment information is stored only in a tokenised form on Encore’s systems. Encore are PCI DSS compliant and do not process card details by email - please do not send your card details for payment in this way.
Our sites and services are meant for adults. We will never knowingly collect personal information from children. If you are a parent or legal guardian and believe your child has given us personal information, please contact us.
LNO collect and process various categories of personal data, each of which are detailed below. This list is not exhaustive and, in specific instances, we may need to collect additional data for the purposes set out in this Policy.
LNO process personal data relating to the following categories of data subject:
For more information on what data we process if you are a customer, business contact, or other contact, please see the section on Data Subjects below.
As a customer, we, or our partner Encore, may process the following categories of information about you:
LNO (and trusted partners acting on our behalf) use our customers’ personal data for the following purposes:
In order to make certain services available to you, we may need to share your personal data with some of our service partners. LNO only allow our service providers to handle your personal data when we have confirmed that they apply appropriate data protection and security controls. We will never sell or rent our customer data to other organisations for marketing purposes.
LNO may share personal data with the following categories of recipient:
Third Parties. We also use web analytics services from some Third Parties to track how visitors reach our site and the path they take through it, so that we can tailor the content of our site to fit the needs of our site’s visitors. Such information is provided anonymously and used statistically with the purpose of improving our site.
With our Service Providers and Suppliers. In order to make certain services available to you, we may need to share your personal data with some of our service partners. LNO only allows its service providers to handle your personal data when we have confirmed that they apply appropriate data protection and security controls, or have put a written agreement in place protecting your information, including necessary safeguards for the international transfer of personal data.
Your Personal data may be processed by our IT Service Providers in line with the purposes outlined above. Our data storage is provided by our hosting partners in the UK, who securely store all personal data held in our systems. In addition to our server provision we also store personal data in backup form to ensure continuity and data integrity. Some of our software systems are cloud based and as such constitute a sharing of personal data. This may in some cases also constitute an international transfer of data, as some multinational software providers maintain global networks of secure data centres. Our software providers may also have access to our systems for maintenance and hosting purposes, and our software development partners may from time to time require access to live systems for development and testing purposes. Such access is strictly for these purposes only and regulated by contract.
If we are required to send you tickets, marketing or other content by mail, we may share your name and address with the postal service or courier.
With Legal Authorities. We may share your data with governmental bodies, regulators, law enforcement agencies, courts or tribunals, insurers, and other partners where we are required to do so;
With any successor to all or part of our business. Where permitted by law, we may pass your information to a successor organisation, provided processing is for the purposes set out in this Policy.
Our partner, Encore, is a major authorised ticket agent with tens of thousands of partners with whom they are required to share certain personal data as part of their ticketing operations. We are therefore unable to provide a list of all specific recipients of personal data, controlled by Encore, who share personal data with the following categories of recipient:
LNO. LNO only receive data from Encore for those customers who purchase tickets from one of our websites.
Within the Encore group. The Encore Group and its group companies do not maintain any separate staff, with the exception of Stargreen Box Office, and their brands do not involve the use of separate systems or staff. Any sharing will therefore not usually involve any physical transfer or sending of data, and is only performed according to the purposes outlined above.
With Commercial Partners: Encore also provide ticketing services in collaboration with, and on behalf of other commercial partners. If you purchase tickets to an event through one of their commercial partners, or take part in a promotion or rewards programme provided by another party, which involves Encore, they will receive and/or share your personal information with that company in order to fulfil your ticket purchase. Their partners may include ticket agents, gift experience companies, tour operators, travel agents, box offices, venues, concierges, ecommerce partners, GTOs, and educational organisations. If you book a ticket with Encore through one of their ticketing partners directly, they should also inform you of how they handle your data, including the sharing of data with Encore.
Where both parties are involved in supplying the tickets, such as where their partner processes a payment but Encore provides ticket fulfilment, some personal data such as your name and booking information may be shared by Encore for legitimate cross-referencing and reporting purposes. Such information shall always be kept to the minimum necessary for this purpose. This is the case where Encore’s ticket offering is available on their ecommerce partner’s own websites. In some cases, Encore may also provide branded customer services in the partner’s name. For more information you should consult the relevant partner’s privacy policy, or contact them at dpo@encore.co.uk for more information.
If you purchased a voucher from a gift experience company that you then redeem with Encore, they are required to submit information on that redemption to the gift provider, including some personal information, usually via their online portal.
If your booking involves a Broadway show in New York, Encore will pass your booking information to their partners at Broadway Inbound, and your personal data may be shared with the venue in New York to allow you access to that performance.
If you make a hotel or rail booking, you will be redirected to Encore’s breaks page which is created in partnership with, and maintained by their partners at Holiday Extras. When you book with Holiday Extra, they will provide the hotel and travel tickets, and Encore will provide the theatre and other event ticket inventory through the Holiday Extras site. For more information on how Holiday Extra handle your information please consult their privacy policy.
With their Venues and Event Partners. Encore may share a minimal amount of personal information about your ticket booking (such as your name and surname, and those of any other attendees, along with quantity and booking reference) with their event partners, so that they can deliver the event for which tickets have been purchased, enabling them to fulfil the order, to cross check with their records and verify the ticket holder’s identity, and on some occasions allow you entry if you have mislaid your ticket. This might include any restaurants, hotels, venues, theatres, or attractions you have booked with us. Encore’s venue and event partners are joint Controllers with regard to the Personal Data, and may process such Personal Data for purposes other than those described here. In most cases the venue will be clear from your ticket and booking information but if in any case this is not clear please do not hesitate to contact us. For more information on how Encore’s venue partners handle your information you should consult their privacy policy.
The transfer of your information under the purposes of this Policy and LNO’s Cookies Policy may involve the transfer of your information to other countries, including those outside Europe. Such countries may not provide the same level of protection for your personal information, however we ensure that appropriate technical and contractual safeguards are put in place to protect your personal data, in accordance with applicable laws including the GDPR.
If you purchase tickets for an event outside the EU, such as for a Broadway show in New York, Encore may pass your information to the relevant theatre, based in the United States, to allow them to fulfil your ticket purchase, allow you access to the venue, and for cross-referencing purposes. Such transfers are performed on the basis of a contract concluded in the interest of the ticket purchaser. These ticket purchases also involve their ticketing partner in the United States, who require some personal data in order to fulfil your ticket purchase and are self-certified to the Privacy Shield.
Some multinational software and payment providers, including banking and cloud infrastructure, maintain an international network of secure data centres and as such your personal data may be transferred globally. Such transfers are covered by standard contractual clauses and binding corporate rules.
In general, LNO collects and uses customers’ personal data when it is necessary for:
Your Consent. We only rely on consent as a legal basis for processing in relation to sending of direct marketing communications to customers. Customers have the right to withdraw this consent at any time, and we will stop processing immediately. This is the case if you have made a positive and standalone decision to receive our marketing services.
We may however also rely on our legitimate interests with regard to the sending of some direct marketing communications to customers. We also rely on our legitimate interests in our marketing communications with our business-to-business contacts, and in the sending of some physical mailings. However, in all cases, we offer an unequivocal opt-out to direct marketing communications at all times, regardless of whether that processing is based on consent or legitimate interests.
Contractual Necessity. If the processing of personal data is necessary for the performance of a contract to which you as a data subject are a party, as is the case, for example, when you purchase a ticket with us and our processing is a targeted and proportionate means of supplying those goods or services, we rely on contractual obligations as our lawful basis for processing your personal data. This includes when we take your name and contact details to fulfil and send your tickets, and when we have to contact you if there’s a problem with your order. This also applies to any processing operations which are necessary for carrying out pre-contractual measures, for example if you were to inquire about our products or services. Failing to provide such data may result in us not being able to provide the services you have requested.
Vital Interests. In rare cases, the processing of personal data may be necessary to protect the vital interests of the data subject or of another natural person. This would be the case, for example, if a visitor were injured in our company and his name, age, or other vital information would need to be passed on to a doctor, hospital or other third party in order to save their life.
Legal Obligations. In some cases, processing of personal data is based on legal obligations. Such processing applies when we retain contractual records under the Limitations Act 1980, or where we maintain transaction records as part of our VAT requirements. We may also be required to share your data with governmental bodies, regulators, law enforcement agencies, courts or tribunals, insurers, and other partners where we are required to do so;
Legitimate Interests. We rely on legitimate interests as a legal basis for processing only if that processing is in your interests, our legitimate interests, or the interests of a third party. Such processing must be necessary for the stated purpose, and we must have carefully evaluated whether such interests are overridden by your interests, privacy, and fundamental rights and freedoms. We process personal information for certain legitimate business purposes, which include some or all of the following processes, along with information on our balanced reasoning;
Whenever we process data for these purposes we will always ensure your Personal Data rights are held in high regard. We make sure to have conducted legitimate interests assessments for all our personal data processing made under our legitimate interests, and ensure you have a right to object to this processing if you so wish. If you would like to exercise this right, please consult the Rights section below. Please bear in mind that if you object in this way, you may affect our ability to carry out these tasks, which may impact on your benefit.
LNO will not retain your data for longer than necessary for the purposes set out in this Policy. Different retention periods apply for different types of data, however the longest we will normally hold any personal data is six years. We will process and store your personal data only for the period necessary to achieve the purpose of processing, or as far as this is required by the European legislator or other legislators in laws or regulations to which we are subject. For more information on how long any specific data is stored, you can contact us at GDPR@lnoltd.com
The criteria used to determine the storage (or "retention") period, is usually the statutory retention period – the legal requirement to retain data records. For example, we will keep personal data relating to the initiation and fulfilment of a contract, for the duration of that contract, followed by the legally required retention period – usually six years under the Limitations Act 1980.
Likewise, we will hold on to any contractual details on goods and services provided (such as your booking information) in our bookings database only for the period necessary to fulfil the contract, and for a maximum of six years in order to fulfil our legal requirements to keep VAT records for this period, and to maintain a record of the contract under our legal obligations. After expiration of this six year period, we will delete or anonymise any personal data held in our main database. Our primary record of your personal details, including your name, contact information and customer service history, are held within this bookings database and will therefore only be kept for a maximum of six years.
We also hold purchase information in our marketing department to allow us to tailor relevant content to meet your interests. We will only send you marketing if you have subscribed to receive marketing from us, and we will only keep this purchase history if you are an active customer. If you subscribed to receive marketing from us, we will hold your information until you unsubscribe, and for a further year in case you decide to re-subscribe within that period. If you decide not to re-subscribe after a year, we will remove all your personal data from our marketing database, although we will keep your email address on our suppression list to make sure we do not contact you again.
All websites or webpages operated by LNO or any of it’s brands use cookies. Cookies are small text files that are found on almost all websites, and are stored in a user’s computer system, specifically their internet browser. These cookies contain a so-called cookie ID – a unique identifier which consists of a character string through which internet pages and servers can be assigned to your specific Internet browser in which the cookie was stored. This allows visited sites and servers to differentiate the individual browser of the data subject from other Internet browsers that contain other cookies. A specific internet browser can be recognized and identified using this unique cookie ID.
This information is stored in your browser’s "log" files and may include the browser type and version used, the operating system used, the website from which an accessing system reaches our website (so-called "referrer"), any sub-websites, the date and time of access to the Internet site, an Internet protocol address (IP address), the Internet service provider of the accessing system, and any other similar data and information that may be used to trace users in the event of attacks on our information technology systems.
Through the use of cookies, we can provide the users of our websites with more user-friendly services than would be possible without the cookie setting, for example by allowing the shopping cart to store items so that they can be purchased at the checkout page. Cookies also show us how people tend to use the site. We use such information to ensure the proper functioning of the website, deliver content, inform site improvements, and occasionally to compile reports. We also use web analytics services from other companies to track how visitors reach our site and the path they take through it, so that we can tailor the content of our site to fit the needs of our sites’ visitors.
When using this general data and information, we do not draw any conclusions about the individual data subject. LNO analyses such data anonymously and uses the information statistically with the aim of optimising our web services and increasing the data protection and data security of our enterprise, and to ensure an optimal level of protection for the personal data we process. Any anonymous data contained in these log files is in any case stored separately from the personal data provided by our customers.
You may, at any time, prevent the setting of cookies through our website by various means, such as changing the settings in your Internet browser, which can permanently deny the setting of some, or all cookies. Cookies can also be deleted at any time in most popular Internet browsers or by using other software programs. However if the data subject deactivates the setting of cookies in the Internet browser used, not all functions of our website may be usable.
More information on cookies is available in our Cookie Policy.
With your consent, we will collect your personal data including your name and email address for the provision of advertising, including the sharing of promotional offers, and to update you about products and services which may be of interest and relevance. LNO informs its customers regularly about our products and services, by means of sending marketing about our offers. The personal data collected as part of a registration for marketing will only be used in the sending of such marketing, and can be terminated at any time by using the unsubscribe link included in each communication, or by contacting us using our contact details below.
Your privacy is of the highest importance to us, and we promise never to release your personal details to any other outside company for mailing or marketing purposes, other than those detailed in this Privacy Policy, without your consent.
You have the right to opt out of receiving promotional communications at any time, by:
If you have asked us to send you promotions and other special offers on products, we may use your purchase history to tailor content to match your interests, in order to deliver you more relevant content. We also use your approximate location so we can send information on shows that are nearby, and your "opens" and "clicks" history from the emails we send you, so we can tailor our email content to your interests.
In doing so, we will always ensure that meaningful control over such processing is in the hands of our staff, rather than based on automated processing, and that such profiling does not create legal or other significant effects on individuals.
You have a right to access this information we hold about you, and a right to contest or object to such processing, by contacting GDPR@lnoltd.com You can also opt-out of receiving marketing at any time. For more information on how to exercise your data rights please see the Rights section below.
We take your privacy rights seriously, and where possible we will offer you choice and control over how we use your data. When you interact with us we may occasionally ask for your explicit consent in order to collect, process or use your personal information for specified purposes. Such consent is only usually sought when we seek your permission to send marketing communications, although this is not always the case. If you have given your consent to the processing of personal data, you have the right to withdraw that consent at any time. If you wish to do so, please contact our GDPR Ambassador at LNO Ltd by writing to us at the address below, or by emailing GDPR@lnoltd.com For full details about how to exercise your data rights, please consult the Rights section below.
You can control the use of cookies and tracking tools. To learn how to manage the use of cookies and other tracking tools, please consult our Cookie Policy.
Don’t worry, even if you opt out of receiving marketing messages, we will still make sure to send you any necessary transactional and service messages, such as important information about any changes to your order.
If your personal information is held by LNO, you have the following rights to your personal data under the GDPR. If you wish to exercise your rights at any time, or if you have any questions about how we use your personal data that are not answered here, please contact GDPR@lnoltd.com, or write to us at our postal address.
Your rights request will be free, unless the request is manifestly unfounded or excessive, in which case LNO shall reserve the right, in accordance with Article 12 of the GDPR, to charge a fee or refuse the request. In the rare case of such a refusal, you will have the right to complain to the ICO as the Supervisory Authority, and to a judicial remedy without undue delay and at the latest within one month.
We will endeavour to respond promptly and in any event within one month of the latest of the following:
If the request is particularly complex, we may extend the period by a further two months, but shall in any case inform you of such an extension within the initial one month, giving our reasons for doing so.
You have the right to lodge a complaint with the Information Commissioner’s Office. Further information, including contact details, is available at https://ico.org.uk
Each data subject has the right to confirmation as to whether or not personal data concerning him or her is being processed. This Privacy Policy constitutes part of this right. If however this Privacy Policy cannot be fully accessed, or if any further information is requested, you may, at any time, contact our GDPR Ambassador using the contact details above, to request further information.
Each data subject has the right to information about his or her personal data stored, and a copy of this information, alongside the information already outlined in this Privacy Policy. Data subjects also have a right to obtain information as to whether personal data are transferred to a third country or to an international organisation. Where this is the case, the data subject shall have the right to be informed of the appropriate safeguards relating to the transfer.
If you wish to exercise your right to access, please contact our GDPR Ambassador using the contact details above, to request such information.
Each data subject has the right to rectify inaccurate personal data concerning him or her, without undue delay. Data subjects also have the right, taking into account the purposes of the processing, to have incomplete personal data completed, including by means of providing a supplementary statement.
If you wish to exercise this right to rectification, you may at any time contact our GDPR Ambassador using the contact details above.
Each data subject has the right to request the erasure of personal data concerning him or her without undue delay. The Controller shall have the obligation to erase personal data without undue delay where one of the following grounds applies;
If one the above reasons applies, and you wish to request the erasure of personal data stored by us, you may at any time contact our GDPR Ambassador using the contact details above, and we will ensure that the erasure request is complied with.
Where we have made such personal data public and are obliged pursuant to Article 17(1) to erase the personal data, we shall, take reasonable steps, taking account of available technology and the cost of implementation, to inform other controllers processing the personal data that the data subject has requested erasure by such controllers of any links to, or copy or replication of, those personal data, as far as processing is not required. The GDPR Ambassador at LNO Ltd will arrange the necessary measures in individual cases.
Each data subject has the right to obtain a restriction to processing where one of the following applies:
If one of the above conditions applies, you may request the restriction of processing by LNO by contacting our GDPR Ambassador using the contact details available above.
Each data subject has the right to receive their personal data in a structured, commonly used and machine-readable format, including the right to transmit that data directly to another Controller if it is technically feasible and when doing so does not adversely affect the rights and freedoms of others.
Such a right applies if processing is based on a subject’s consent, or contractual obligations, and such processing is carried out by automated means, as long as the processing is not necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
If you wish to exercise your rights to data portability, please contact the GDPR Ambassador using the contact details available above.
Each data subject has, on grounds relating to his or her particular situation, the right to object to processing of personal data concerning him or her which is based on the Controller’s legitimate interests. This also applies to profiling based on these provisions.
LNO shall no longer process the personal data in the event of the objection, unless we can demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defence of legal claims.
Where LNO processes personal data for direct marketing purposes, the data subject has the right to object at any time to the processing of personal data concerning him or her for such marketing, and we will no longer process the personal data for these purposes. This applies to profiling to the extent that it is related to such direct marketing.
If you wish to raise an objection, please contact the GDPR Ambassador using the contact details above.
Each data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her, or has similarly significantly effect. As a responsible company, LNO do not use automatic decision-making or profiling that has legal or similarly significant effects on individuals. Our profiling for marketing purposes requires significant human oversight, and we will always ensure that meaningful control over such processing is in the hands of our staff, rather than based on automated processing. However, if you wish to contest this, you may exercise your rights concerning automated individual decision-making at any time by directly contacting our GDPR Ambassador, using the contact information above.
LNO collects and processes the personal data of employees of our B2B partners, vendors and suppliers for the following purposes:
LNO will only keep your personal data for the duration of our business relationship. If we are aware that you have left your position, we will delete your personal data from our records unless we are legally required to keep that information. For example, if your name is included in a valid contract, or where we must keep a record of that contract under the Limitations Act 1980. If you interacted with us via email, the longest we will keep any email record for is six years. We will however keep an anonymised record of LNO’s business relationship with the Supplier organisation.
If you have any further questions or complaints about this Policy, any other privacy concerns, or you would like to exercise your data rights, please contact us by any of the following means:
Please do not include your credit card number or other financial or sensitive information in any email you send.
We may change this policy from time to time, and if we do we will post any changes on this page. Any update will have a different date from the current policy. If you continue to use the Services after those changes are in effect, you agree to the revised policy. Please check our site periodically for updates.
This Privacy Policy was last updated on 20th May 2018.