Join us for KotlinLeeds happening 15th October

Privacy Policy

Last updated: 7 September 2026

SwiftLeeds is a community-run, not-for-profit conference. This policy explains what personal data we collect when you use our website at swiftleeds.co.uk, buy a ticket, sign in with your ticket, use the SwiftLeeds mobile app, speak at the conference, or contact us. It also explains why we collect it, who we share it with and what rights you have.

SwiftLeeds also organises KotlinLeeds. Both conferences are run by the same people and share the same website platform, ticketing and mobile app code, so this policy applies to both.

We keep things simple: we only collect what we need to run the conference, we never sell your data, and we never use it for advertising.

Who we are and how to contact us

The organising team of SwiftLeeds is the data controller for the personal data described in this policy. If you have any questions about this policy or your data, email us at [email protected].

Browsing our website

You can browse swiftleeds.co.uk without telling us who you are. We use Plausible Analytics to understand how many people visit the site and which pages are popular. Plausible does not use cookies, does not collect personal data and does not track you across other websites. The statistics we see are aggregated and anonymous.

Our web servers keep short-lived technical logs, which include your IP address, browser type and the pages you request. We use these only to keep the site running securely and to diagnose problems.

The website only sets a cookie when you sign in with your ticket or, for organisers, an admin account. That cookie holds your session and nothing else.

Buying a ticket

Tickets are sold through Tito. When you buy a ticket, Tito collects your name, email address, company (optional), any answers you give to our registration questions, and your payment details. Payment is handled entirely by Tito and its payment processor. We never see or store your card details. Tito's own privacy policy describes how it handles your data.

When a registration completes, Tito notifies our organising team through a private channel in our team chat so we can keep track of ticket sales. That notification includes the purchaser's name, company (if given) and the number of tickets bought.

We access the ticket data held in Tito to run the conference: to check you in, print your badge, cater for dietary requirements you have told us about, and to send you essential information about the event you have a ticket for.

Signing in with your ticket

The website's Ticket Hub and the SwiftLeeds mobile app let you sign in using the email address and ticket reference from your Tito ticket. We check those details against Tito and, if they match, we sign you in.

  • On the website we store your ticket reference in a session cookie so you stay signed in. Signing out removes it.
  • In the mobile app we issue a signed token that contains your email address, ticket reference and ticket type. The app stores this token securely on your device so you do not have to sign in every time. Signing out deletes it.

While you are signed in we fetch your ticket details from Tito, including your name, company, profile picture (if you added one), ticket type and your answers to our registration questions, so we can show them to you and generate the QR code on your ticket. We cache those details on our server for a short time to keep the app responsive.

Drop-in sessions and other bookable activities

Some ticket types let you book limited-capacity sessions, such as one-to-one drop-in sessions with our experts. When you book a slot, we store your name and ticket reference against that slot so the host knows who to expect. For some ticket types, other participants who have booked the same session may also see the names of people attending. You can cancel a booking at any time from the Ticket Hub, which removes your name from the slot.

Badge scanning by sponsors

Your ticket includes a QR code. At the conference, sponsors may ask to scan it so they can follow up with you afterwards. Scanning is always your choice. If you allow a sponsor to scan your badge, the sponsor receives your name, company, email address and your answers to our registration questions. From that point the sponsor is responsible for how they use your details, so please only let a sponsor scan your badge if you are happy for them to contact you.

Speaking at SwiftLeeds

Talk proposals are submitted through Sessionize, which has its own privacy policy. When we review proposals we see the name, biography, photo, contact details and talk details you provide there.

If your talk is accepted, we publish your name, biography, photo, job title, company and any social media links you have given us on our website, in our mobile app, in our schedule and in our promotional material. Talks are recorded and published on our YouTube channel. Past years' speaker pages remain online as an archive of the conference. Speaker and sponsor images are stored with Amazon Web Services in London.

We also use your contact details to arrange travel, accommodation, speaker training and everything else involved in getting you to the stage.

The SwiftLeeds mobile app

Our mobile app lets you browse the schedule, speakers, sponsors and local information, and, once signed in, shows your ticket. The app collects the following:

  • Push notifications (iOS). If you allow notifications, the app sends us your device's push token so we can send you conference announcements, such as schedule changes. The token is not linked to your ticket. We delete push tokens after the conference.
  • Crash reports and usage statistics (Android). The Android app uses Firebase Crashlytics to report crashes and Firebase Analytics to record which screens are used. These reports include your device model, operating system version and a randomly generated app instance identifier. We have disabled collection of the advertising identifier. This helps us find and fix bugs and see which features matter to attendees.
  • Maps (Android). The local information screen uses Google Maps to show the venue and nearby places. When the map loads, Google receives your IP address and the map requests, as described in Google's privacy policy. The app does not ask for or use your device's location.

The app does not show adverts, does not use advertising identifiers and does not track you across other apps or websites.

Organiser and speaker accounts

Members of the organising team, and some speakers, have accounts on our website's admin area. For those accounts we store an email address and a securely hashed password. Passwords are never stored in plain text.

Contacting us

If you email us, post in our community Slack, or message us on social media, we will keep your message for as long as we need to deal with it and for a reasonable period afterwards in case you follow up.

Why we are allowed to use your data

Under UK data protection law we need a lawful basis for everything we do with your data. Ours are:

  • Performing our contract with you: selling you a ticket, signing you in, showing your ticket, managing bookings and getting you to the conference.
  • Our legitimate interests: keeping our website and apps secure and working, understanding how they are used, fixing crashes, and telling ticket holders about the event they are attending. We balance these interests against your rights and only rely on them where the impact on you is minimal.
  • Your consent: letting a sponsor scan your badge, and enabling push notifications. You can withdraw consent at any time by declining a scan or turning off notifications in your device settings.
  • Legal obligations: keeping financial records, and responding to lawful requests from authorities.

Who we share your data with

We never sell your personal data and we never share it for advertising. We share it only with the services we rely on to run the conference, and only as much as they need:

  • Tito for ticketing and payments.
  • Sessionize for speaker submissions.
  • Google Cloud, which hosts our website and database, and Amazon Web Services, which stores our images.
  • Plausible Analytics for anonymous website statistics.
  • Slack for our organising team's ticket notifications.
  • Apple, to deliver push notifications to iOS devices, and Google Firebase, for crash reporting, usage statistics and maps in the Android app.
  • Sponsors, only when you choose to let them scan your badge.
  • The venue and our suppliers, where they need attendee numbers or specific requirements, such as dietary or accessibility needs, to deliver the event.

Some of these providers process data outside the United Kingdom, including in the European Union and the United States. Where they do, we rely on the safeguards recognised under UK law, such as adequacy regulations, the UK Extension to the EU-US Data Privacy Framework, or the International Data Transfer Agreement.

How long we keep your data

  • Ticket and registration data stays in Tito for as long as we need it for the event and our financial records, in line with Tito's retention policy.
  • Drop-in session bookings and push notification tokens are deleted after the conference they relate to.
  • Ticket details cached on our server expire automatically within minutes.
  • Server logs are kept for a short period and then automatically deleted.
  • Speaker profiles remain published as part of the archive for that year's conference. You can ask us to remove yours at any time.
  • Analytics data is aggregated and anonymous, so it is not linked to you.

Your rights

You have the right to:

  • ask for a copy of the personal data we hold about you;
  • ask us to correct anything that is inaccurate;
  • ask us to delete your data;
  • ask us to restrict how we use it, or object to our use of it;
  • receive your data in a portable format; and
  • withdraw consent where we rely on it.

To exercise any of these rights, email us at [email protected]. We will respond within one month. If you are not happy with how we handle your data, you can complain to the UK Information Commissioner's Office at ico.org.uk.

Children

SwiftLeeds is aimed at professional and aspiring software developers. Our website and apps are not directed at children under 16 and we do not knowingly collect personal data from them. If you believe a child has given us personal data, please contact us and we will delete it.

Changes to this policy

We may update this policy from time to time, for example when we add a feature to the website or app. The date at the top shows when it was last changed. Significant changes will be announced on our website and social media.

Top