01Scope & who we are
This Privacy Policy explains how Tonomous.IO (“Tonomous”, “we”, “us”, “our”) collects, uses, hosts, discloses and protects information in connection with the Nuvio platform, the website at tonomous.io, and all related software, APIs, applications and services (together, the “Services”).
Nuvio is a business-to-business platform. Our direct customers are venues, operators and their partners (each a “Client”). Through the Services, Clients sell tickets, take F&B and retail orders, run loyalty and memberships, coordinate operations, and analyse performance. In doing so, information about the Client’s own guests, members and visitors (“Guests”) passes through the platform.
By using the Services, you confirm you have read and understood this policy. Where a Client makes the Services available to you, the Client’s own privacy notice may also apply.
02Controller vs. processor — an important distinction
Whether Tonomous decides why and how data is used, or simply handles it on someone else’s instructions, changes who is responsible for it. Two situations apply across Nuvio:
- We act as controller
For data about our Clients and their staff — the people who buy, configure and administer Nuvio — and for our own website visitors and prospects. Here, we decide the purposes of processing and this policy governs. - We act as processor
For Guest data that flows through the platform on a Client’s behalf — bookings, orders, entry scans, loyalty activity and the like. The Client is the controller of that data; they determine what is collected and why. We process it under our agreement with them (including our Data Processing Terms) and only on their documented instructions.
03Data we collect as a controller
When you register for Nuvio, contact us, request a demo, or otherwise deal with us as a Client, partner or prospect, we collect information you provide directly. Depending on the interaction this may include:
| Category | Examples |
|---|---|
| Account & identity | Name, business email, phone, job title, company name, login credentials, user roles and permissions. |
| Business relationship | Organisation details, the venues or channels you operate, contract and order details, support history, correspondence. |
| Billing | Billing contact, tax/registration details, plan and usage records, and limited, non-PCI payment references. Card data is handled by our payment processors, not stored by us. |
| Prospect & marketing | Information you share when you request a demo, subscribe to updates, or attend an event, and your communication preferences. |
| Recruitment | If you apply for a role, the details in your application and any correspondence. |
You can choose not to provide requested information, but some features or the ability to use the Services may be limited as a result.
04Guest data we process on a Client’s behalf
Processor
To deliver the guest commerce experience, Nuvio processes information about a Client’s Guests on the Client’s instructions. The Client decides what is collected. Typical categories, mapped to the modules that generate them, include:
| Source | Data processed |
|---|---|
| Ticketing & access | Booking and order details, ticket type, timed-entry slots, scan/RFID/mobile entry events, and channel of purchase. |
| F&B & retail | Order contents, order-ahead and order-to-seat details, click-and-collect pickups, basket and transaction records. |
| Loyalty & memberships | Membership and pass status, tier, points, rewards and cross-venue recognition data. |
| Engagement | Behavioural triggers, journey touchpoints and offers, where the Client has configured guest communications. |
| Payments | Transaction and limited, non-PCI payment metadata. Card details are processed by the Client’s or our payment providers, not stored on the platform. |
We do not use Guest data for our own purposes, do not sell it, and do not build cross-Client marketing profiles from it. We use it only to provide, secure and support the Services, and to produce aggregated, de-identified statistics as permitted by our agreement with the Client and applicable law.
05Data collected automatically
When you use the website or the Services, some data is collected automatically through cookies, SDKs, logs and similar technologies. Alone or combined, this can be personal data:
- Device & connection: device and browser type, operating system, language, time zone, and hardware identifiers.
- Usage: pages and features viewed, actions taken, and session activity.
- Network: IP address, approximate location derived from it, referring URLs and access points.
- Diagnostics: logs, performance data and error reports used to keep the Services reliable and secure.
We use analytics tools to understand and improve the Services. Where required, we ask for consent before setting non-essential cookies — see Cookies.
06How we use data
As a controller, we use the data described above to:
- Provide, operate, maintain and secure the Services, and administer accounts and access;
- Process transactions, manage subscriptions and collect payment for paid features;
- Provide support, respond to requests, and send service and security notices;
- Improve, develop and troubleshoot the Services, including analytics and capacity planning;
- Send you updates, offers and marketing where permitted, with an easy way to opt out;
- Protect our rights, users and Services, prevent fraud and misuse, and enforce our terms;
- Comply with legal obligations and respond to lawful requests.
As a processor, we use Guest data only to deliver the Services on the Client’s instructions and as set out in Section 04.
07Legal bases
Where data-protection law requires a legal basis, we rely on one or more of the following, depending on the activity: performance of a contract with you; our legitimate interests in running and improving a secure Service (balanced against your rights); your consent (for example, certain cookies and marketing), which you may withdraw at any time; and compliance with legal obligations. For Guest data we process as a processor, the legal basis is determined by the Client as controller.
09Data residency & international transfers
Data residency is built into Nuvio, not bolted on. Where a Client uses our Sovereign Stack option, their data is stored and processed within their chosen region — including GCC residency — under access controls the Client governs. The applicable region and hosting arrangements are set out in the Client’s order or agreement.
Outside of region-locked deployments, we and our service providers may process data in more than one country. Where personal data moves across borders, we put appropriate safeguards in place — such as standard contractual clauses or equivalent mechanisms recognised under applicable law — so that a comparable level of protection travels with the data.
10Security
We use industry-standard technical and organisational measures to protect personal data against unauthorised access, use, alteration or disclosure — including encryption in transit, access controls, monitoring, and staff training on privacy and security. No system is perfectly secure, but we work to reduce risk and to respond promptly if an incident occurs, including notifying affected parties and regulators where required.
11Retention
We keep personal data only as long as needed for the purposes described here, to provide the Services, and to meet legal, tax, accounting or security obligations — after which we delete or anonymise it. For Guest data we process as a processor, retention is governed by the Client’s instructions and our Data Processing Terms; on termination or on the Client’s request, we return or delete that data as agreed, subject to any retention the law requires.
12Your rights
Subject to your location and applicable law, you may have the right to access the personal data we hold about you, to correct or delete it, to object to or restrict certain processing, to withdraw consent, to data portability, and to lodge a complaint with a supervisory authority.
To exercise these rights over data we control, contact us at support@tonomous.io. We will verify your identity and respond within the timeframes set by applicable law. If your request concerns Guest data that a venue or operator controls, please contact that Client directly — as their processor, we will refer your request to them and support their response.
We do not discriminate against you for exercising your privacy rights.
14Children
The Services are intended for businesses and are not directed to children. We do not knowingly collect personal data directly from children through the website or Client-facing tools. Where a Client’s venue serves families, any processing of data relating to minors is done under the Client’s control and instructions, and subject to the Client’s own obligations and consents.
15Changes to this policy
We review and update this policy as the Services evolve. The “Last updated” date at the top shows the current version. For material changes we will take reasonable steps to notify Clients, for example by email or in-product notice. Your continued use of the Services after an update means you accept the revised policy.
16Contact us
Questions, requests or concerns about this policy or your data:
Email us at support@tonomous.io and we’ll route your message to the right team.