NNuvio
A Tonomous.IO platform

Privacy Policy

The data behind the flow.

Nuvio runs the guest journey for live venues — ticketing, F&B, retail, loyalty and the intelligence that ties them together. This policy explains what data we handle, who it belongs to, where it lives, and the choices you have.

Last updated: 15 July 2026 Applies to: the Nuvio platform, tonomous.io and related services

01Scope & who we are

This Privacy Policy explains how Tonomous.IO (“Tonomous”, “we”, “us”, “our”) collects, uses, hosts, discloses and protects information in connection with the Nuvio platform, the website at tonomous.io, and all related software, APIs, applications and services (together, the “Services”).

Nuvio is a business-to-business platform. Our direct customers are venues, operators and their partners (each a “Client”). Through the Services, Clients sell tickets, take F&B and retail orders, run loyalty and memberships, coordinate operations, and analyse performance. In doing so, information about the Client’s own guests, members and visitors (“Guests”) passes through the platform.

By using the Services, you confirm you have read and understood this policy. Where a Client makes the Services available to you, the Client’s own privacy notice may also apply.

02Controller vs. processor — an important distinction

Whether Tonomous decides why and how data is used, or simply handles it on someone else’s instructions, changes who is responsible for it. Two situations apply across Nuvio:

  • We act as controller
    For data about our Clients and their staff — the people who buy, configure and administer Nuvio — and for our own website visitors and prospects. Here, we decide the purposes of processing and this policy governs.
  • We act as processor
    For Guest data that flows through the platform on a Client’s behalf — bookings, orders, entry scans, loyalty activity and the like. The Client is the controller of that data; they determine what is collected and why. We process it under our agreement with them (including our Data Processing Terms) and only on their documented instructions.
If you are a Guest and want to exercise rights over your booking, order or membership data, the fastest route is usually the venue or operator you interacted with, since they control that data. We will always support our Clients in responding to you.

03Data we collect as a controller

When you register for Nuvio, contact us, request a demo, or otherwise deal with us as a Client, partner or prospect, we collect information you provide directly. Depending on the interaction this may include:

CategoryExamples
Account & identityName, business email, phone, job title, company name, login credentials, user roles and permissions.
Business relationshipOrganisation details, the venues or channels you operate, contract and order details, support history, correspondence.
BillingBilling contact, tax/registration details, plan and usage records, and limited, non-PCI payment references. Card data is handled by our payment processors, not stored by us.
Prospect & marketingInformation you share when you request a demo, subscribe to updates, or attend an event, and your communication preferences.
RecruitmentIf you apply for a role, the details in your application and any correspondence.

You can choose not to provide requested information, but some features or the ability to use the Services may be limited as a result.

04Guest data we process on a Client’s behalf

Processor

To deliver the guest commerce experience, Nuvio processes information about a Client’s Guests on the Client’s instructions. The Client decides what is collected. Typical categories, mapped to the modules that generate them, include:

SourceData processed
Ticketing & accessBooking and order details, ticket type, timed-entry slots, scan/RFID/mobile entry events, and channel of purchase.
F&B & retailOrder contents, order-ahead and order-to-seat details, click-and-collect pickups, basket and transaction records.
Loyalty & membershipsMembership and pass status, tier, points, rewards and cross-venue recognition data.
EngagementBehavioural triggers, journey touchpoints and offers, where the Client has configured guest communications.
PaymentsTransaction and limited, non-PCI payment metadata. Card details are processed by the Client’s or our payment providers, not stored on the platform.

We do not use Guest data for our own purposes, do not sell it, and do not build cross-Client marketing profiles from it. We use it only to provide, secure and support the Services, and to produce aggregated, de-identified statistics as permitted by our agreement with the Client and applicable law.

05Data collected automatically

When you use the website or the Services, some data is collected automatically through cookies, SDKs, logs and similar technologies. Alone or combined, this can be personal data:

  • Device & connection: device and browser type, operating system, language, time zone, and hardware identifiers.
  • Usage: pages and features viewed, actions taken, and session activity.
  • Network: IP address, approximate location derived from it, referring URLs and access points.
  • Diagnostics: logs, performance data and error reports used to keep the Services reliable and secure.

We use analytics tools to understand and improve the Services. Where required, we ask for consent before setting non-essential cookies — see Cookies.

06How we use data

As a controller, we use the data described above to:

  • Provide, operate, maintain and secure the Services, and administer accounts and access;
  • Process transactions, manage subscriptions and collect payment for paid features;
  • Provide support, respond to requests, and send service and security notices;
  • Improve, develop and troubleshoot the Services, including analytics and capacity planning;
  • Send you updates, offers and marketing where permitted, with an easy way to opt out;
  • Protect our rights, users and Services, prevent fraud and misuse, and enforce our terms;
  • Comply with legal obligations and respond to lawful requests.

As a processor, we use Guest data only to deliver the Services on the Client’s instructions and as set out in Section 04.

08Who we share data with

We share personal data only where necessary and under appropriate safeguards, with:

  • Service providers that support the Services — hosting and infrastructure, payment processing, communications, analytics and support tooling — bound by contract to process data only on our instructions.
  • Our Clients, for data generated through their use of the platform, and the partners they authorise (such as resellers and OTAs connected to their inventory).
  • Authorities and advisors, where required by law or legal process, or to protect our rights and the safety of our users and the public.
  • A successor in the event of a merger, acquisition, financing, restructuring or sale of assets, subject to this policy.

We do not sell personal data, and we do not share it for third-party direct marketing.

09Data residency & international transfers

Data residency is built into Nuvio, not bolted on. Where a Client uses our Sovereign Stack option, their data is stored and processed within their chosen region — including GCC residency — under access controls the Client governs. The applicable region and hosting arrangements are set out in the Client’s order or agreement.

Outside of region-locked deployments, we and our service providers may process data in more than one country. Where personal data moves across borders, we put appropriate safeguards in place — such as standard contractual clauses or equivalent mechanisms recognised under applicable law — so that a comparable level of protection travels with the data.

Clients with strict isolation or regulatory needs (for example, sector-specific residency requirements) should speak to us about a dedicated deployment before onboarding.

10Security

We use industry-standard technical and organisational measures to protect personal data against unauthorised access, use, alteration or disclosure — including encryption in transit, access controls, monitoring, and staff training on privacy and security. No system is perfectly secure, but we work to reduce risk and to respond promptly if an incident occurs, including notifying affected parties and regulators where required.

11Retention

We keep personal data only as long as needed for the purposes described here, to provide the Services, and to meet legal, tax, accounting or security obligations — after which we delete or anonymise it. For Guest data we process as a processor, retention is governed by the Client’s instructions and our Data Processing Terms; on termination or on the Client’s request, we return or delete that data as agreed, subject to any retention the law requires.

12Your rights

Subject to your location and applicable law, you may have the right to access the personal data we hold about you, to correct or delete it, to object to or restrict certain processing, to withdraw consent, to data portability, and to lodge a complaint with a supervisory authority.

To exercise these rights over data we control, contact us at support@tonomous.io. We will verify your identity and respond within the timeframes set by applicable law. If your request concerns Guest data that a venue or operator controls, please contact that Client directly — as their processor, we will refer your request to them and support their response.

We do not discriminate against you for exercising your privacy rights.

13Cookies & similar technologies

We use cookies, web beacons and similar technologies to keep the site working, remember preferences, measure performance and improve the Services. You can manage non-essential cookies through our cookie controls where shown, and through your browser settings — though disabling some may affect functionality. Because browser “Do Not Track” signals are not applied consistently, we do not currently respond to them.

14Children

The Services are intended for businesses and are not directed to children. We do not knowingly collect personal data directly from children through the website or Client-facing tools. Where a Client’s venue serves families, any processing of data relating to minors is done under the Client’s control and instructions, and subject to the Client’s own obligations and consents.

15Changes to this policy

We review and update this policy as the Services evolve. The “Last updated” date at the top shows the current version. For material changes we will take reasonable steps to notify Clients, for example by email or in-product notice. Your continued use of the Services after an update means you accept the revised policy.

16Contact us

Questions, requests or concerns about this policy or your data:

Email us at support@tonomous.io and we’ll route your message to the right team.