Going · Legal
Privacy Policy
Who we are
Going is operated by Dumbledore Solutions Ltd (RC 1763934), a private company incorporated in Nigeria ("Going", "we", "us", or "our").
Our address is 422 Crescent, Citec Villa, 4th Avenue, Gwarimpa, Abuja, Nigeria. You can contact us about privacy at kunle@dumbledoretech.com.
For the personal data described in this Policy, Dumbledore Solutions Ltd is generally the data controller. An Event Creator may separately be responsible for personal data they collect outside Going or use for their own independent purposes.
Scope
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data when you:
- visit a Going website;
- create or use a Going account;
- create, invite people to, join, fund, attend, or manage an Event;
- participate in an Event Chat, poll, attendee roster, or ticket check-in;
- make a Contribution or receive a Payout;
- contact us, make a report, or exercise a privacy right; or
- otherwise use a Going product or service.
It does not govern an Event Creator's separate website, form, venue, mailing list, or other activity outside Going.
Personal data we collect
Depending on how you use Going, we may collect:
Account and identity data
- name, username, email address, verified phone number, profile image, Home City, and account identifiers;
- sign-in method, authentication status, consent versions and timestamps;
- identity, risk-review, and payout-verification results for Event Creators; and
- confirmation that a user is at least 18.
Event and social data
- Events you create, join, fund, save, or show interest in;
- event titles, descriptions, schedules, locations, visibility, capacity, Participation Options, Funding Goals, viability settings, and invitations;
- attendee and guest-pass records, friendships, blocks, reports, check-ins, and host roles;
- Event Chat messages, replies, reactions, polls, images, and other content you submit; and
- Critical Notices and notification preferences.
Location data
- an optional, foreground device location used to improve nearby results; and
- addresses and coordinates entered for Events.
We do not collect background location during the private beta.
Payment and financial data
- Contribution amounts, checkout totals, Going fees, payment-provider fees, currency, transaction references, payment status, refunds, chargebacks, receipts, and ledger records;
- Event Creator payout account details, bank name, account name, payout-recipient information, Payouts, reserves, Creator Debt, and transfer status; and
- fraud, dispute, reconciliation, and financial-limit information.
Attendee card, PIN, and similar payment credentials are entered into Paystack's or Flutterwave's payment experience. Going does not store full attendee card details.
Device, technical, and usage data
- IP address, browser and device type, operating system, app version, timestamps, referring pages, diagnostic logs, security events, and cookie or local-storage identifiers;
- feature interactions and performance data, if you opt into analytics; and
- privacy-masked session-replay data, if you separately opt in and the feature is active.
Communications and support data
- messages you send to us, complaints, reports, evidence, survey responses, and records of how we resolve them;
- emails and push notifications sent, delivered, opened, or acted upon where that information is available; and
- marketing preferences and consent.
How we obtain personal data
We obtain data:
- directly from you;
- from other users, such as when a host invites you or a purchaser assigns you a Guest Pass;
- automatically from your browser, device, and use of Going;
- from identity and sign-in providers such as Google and Firebase;
- from payment providers such as Paystack and Flutterwave;
- from service providers that help us operate, secure, analyse, and communicate through Going; and
- from lawful public sources or authorities where necessary for safety, fraud prevention, or compliance.
If you provide another person's details, you must have authority to do so and must tell them how to access this Policy.
Why we process personal data
We process personal data only where we have a lawful basis. Depending on the activity, the basis may be:
| Purpose | Typical lawful basis |
|---|---|
| Create and authenticate accounts | Contract; legitimate interests in account security |
| Operate Events, invitations, rosters, chats, tickets, Contributions, Refunds, and Payouts | Contract |
| Verify creators and payout accounts | Contract; legal obligation; legitimate interests in fraud prevention |
| Process payments, reconcile the Financial Ledger, and keep tax and accounting records | Contract; legal obligation |
| Send account, event, payment, safety, viability, Refund, and Payout notices | Contract; legal obligation; legitimate interests |
| Detect fraud, abuse, unsafe conduct, and security incidents | Legitimate interests; legal obligation |
| Moderate content, investigate reports, enforce our Terms, and establish legal claims | Legitimate interests; legal obligation |
| Use optional analytics and privacy-masked session replay | Consent |
| Send promotional email or push notifications | Consent |
| Use optional foreground location for nearby results | Consent |
| Respond to legal requests and protect vital interests | Legal obligation; public interest; vital interests, as applicable |
Where we rely on legitimate interests, we consider the necessity of the processing and its effect on your rights. Where we rely on consent, you may withdraw it without affecting processing already lawfully performed.
What other users can see
Going is social. Information you submit may be visible as follows:
- eligible viewers may see an Event's total Going count;
- before joining a Public Event, a viewer sees only their Friends who are Going;
- confirmed Participants may see the full Attendee Roster;
- users eligible to view a Friends or Private Event may see its roster before joining;
- hosts and Participants may see names, avatars, host badges, and content shared in the Event Chat;
- unnamed Guest Passes count toward attendance but do not display an identity; and
- an Event's complete location is visible to users eligible to view that Event under its visibility setting.
Event Creators receive a warning before publishing a location. Users receive relevant visibility information before joining or claiming a pass.
When we disclose personal data
We may disclose personal data:
- to other users as described in this Policy and the Event's visibility settings;
- to Event Creators and Co-hosts as needed to manage their Events;
- to Google/Firebase for hosting, authentication, databases, storage, functions, security, and related infrastructure;
- to Paystack or Flutterwave to collect payments, verify transactions, resolve payout accounts, make transfers, issue refunds, and manage disputes;
- to Resend to deliver transactional email;
- to PostHog for consent-based analytics and privacy-masked session replay, if enabled;
- to mapping, place-search, messaging, support, professional-adviser, security, and other operational providers we appoint;
- in a business reorganisation, financing, acquisition, or sale, subject to appropriate confidentiality safeguards;
- to regulators, courts, law-enforcement bodies, tax authorities, or other persons where required by law or reasonably necessary to protect rights, safety, and the integrity of Going; and
- with your direction or consent.
Service providers may use personal data only for the services they provide to us or as otherwise permitted by law. We do not sell personal data. We do not use advertising cookies during the private beta.
International transfers
Some providers may process personal data outside Nigeria. Where personal data is transferred internationally, we will use a lawful transfer basis and safeguards required by the Nigeria Data Protection Act, such as an adequacy decision, an approved transfer instrument, contractual necessity, consent where appropriate, or another lawful basis.
No internet or cloud service can guarantee that data will remain exclusively in one country. Contact us for available information about relevant transfer safeguards.
Retention
We generally apply the following periods:
- active account, profile, and current Event data: while the account or Event remains active;
- ordinary profile data after an eligible deletion request: deletion or anonymisation within 30 days;
- financial, Payout, Refund, tax, chargeback, Creator Debt, dispute, and consent records: 7 years;
- Event Chats and uploaded Event content: 2 years after the Event ends or is cancelled, followed by deletion or de-identification;
- expired OTP challenges and temporary security records: up to 30 days, unless needed for abuse investigation;
- consent-based analytics: up to 12 months; and
- deleted data in backups: up to 90 days before expiry through the backup cycle.
We may keep relevant data longer where required by law, a legal hold, litigation, fraud or safety investigation, or an unresolved payment or other dispute. We may retain de-identified information that no longer identifies a person.
Security
We use administrative, technical, and organisational measures designed to protect personal data, including access controls, owner-scoped records, server-side financial operations, restricted payout information, authentication controls, logging, and provider security features.
No system is completely secure. You are responsible for protecting your device, email account, one-time codes, and session. Tell us promptly if you believe your Going account or personal data has been compromised.
If a personal-data breach occurs, we will investigate, mitigate harm, and notify affected people and the Nigeria Data Protection Commission where required by law.
Your rights
Subject to applicable law, you may have the right to:
- be informed about processing;
- request access to and a copy of your personal data;
- correct inaccurate or incomplete data;
- request deletion of data;
- restrict or object to certain processing;
- withdraw consent;
- request portability of eligible data;
- object to direct marketing;
- request human review of a decision based solely on automated processing that has a legal or similarly significant effect; and
- complain to the Nigeria Data Protection Commission or seek another lawful remedy.
To make a request, email kunle@dumbledoretech.com. We may verify your identity and ask for information needed to locate the relevant data.
Deletion may be delayed while you own an active Event or have a pending payment, Payout, Refund, chargeback, complaint, investigation, or Creator Debt. Once the issue is resolved, we will delete or anonymise ordinary profile data while retaining limited records required by law or this Policy. Shared chat history may remain attributed to "Deleted user."
Your choices
- Marketing: promotional messages require a separate opt-in and include an unsubscribe method.
- Service notices: account, event, payment, safety, viability, Refund, and Payout messages are part of the service and may not be disabled where they are necessary or legally required.
- Analytics and replay: optional analytics and privacy-masked session replay require opt-in consent and may be disabled without losing core service access.
- Location: foreground device location is optional and may be denied or withdrawn through device settings.
- Push notifications: you may change browser or device notification permissions, although important notices may still be sent by email or shown in-app.
Session replay, if active, will be configured to exclude OTP codes, chats, payment fields, bank details, precise addresses, and Private Event content. We do not use solely automated decisions that produce legal or similarly significant effects without an available form of human review.
Children
Going accounts are for people aged 18 or older. We do not knowingly create accounts for children or directly collect their account data during the private beta.
A minor may attend only as an unnamed Guest Pass holder under the responsibility of the adult purchaser and subject to the Event's and venue's age restrictions. If you believe a child has created an account or provided personal data directly to Going, contact us.
Third-party services
Going may link to an Event Creator, venue, payment provider, map, or other third-party service. That third party's own privacy notice governs its independent processing. Review it before providing personal data.
Changes to this Policy
We may update this Policy prospectively. We will publish a new effective date and give reasonable notice of material changes. Where required, we will ask for renewed affirmative acknowledgement or consent. A change will not retroactively remove an accrued payment, Refund, Payout, or privacy right.
Contact and complaints
Dumbledore Solutions Ltd (RC 1763934) 422 Crescent, Citec Villa, 4th Avenue Gwarimpa, Abuja, Nigeria Email: kunle@dumbledoretech.com
You may also lodge a complaint with the Nigeria Data Protection Commission through the contact methods published on its official website.