Privacy policy
Effective 1 June 2026 · Sorted Technologies Inc.
What Sorted does
Sorted provides event-registration infrastructure: organizers create events and queues; students register for them. Sorted processes personal data on behalf of organizers (as a data processor) and on its own account for service operation (as a data controller).
Data we collect
How we use it
Operate and secure the service (legitimate interest / contract performance).
Send transactional email — registration confirmations, magic-link logins (contract performance).
Detect and prevent abuse (legitimate interest).
Comply with legal obligations.
We do not sell personal data or use it for advertising.
Data sharing
We share data only with the sub-processors required to operate the service.
Organizer event data (registrant lists) is accessible to the event's organizer via the API and dashboard.
Retention
Account and registration data is retained for as long as your account is active, and for up to 3 years after closure to comply with financial record-keeping obligations. You may request earlier deletion.
Your rights
Under GDPR and applicable law you can access the personal data we hold about you, correct it, request erasure subject to legal retention requirements, restrict or object to processing, take it elsewhere, and lodge a complaint with your supervisory authority.
Exercise any right by emailing privacy@sorted.fast . We respond within 30 days.
Security
Data is encrypted in transit (TLS 1.2+) and at rest. Passwords are never stored; authentication is via magic link or OAuth. API keys are hashed with bcrypt.
Changes
Material changes will be announced by email to registered organizers at least 14 days before taking effect. Continued use after the effective date constitutes acceptance.
Contact
Sorted Technologies Inc.
privacy@sorted.fast