Privacy & cookies
Last updated: 25 July 2026
Who we are
TodayPicked is a curated calendar of what's on, operated by the TodayPicked team. For anything on this page, contact us at hello@todaypicked.com.
What we collect
- Event submissions. When you submit an event, we collect the details you enter (title, venue, time, description, optional image) and a contact email so we can verify or ask about the submission. Adding your email is up to you; it helps us check the listing.
- Admin access. The team signs in to a private review tool to check submissions. One functional session cookie, no profiling.
- Server logs. Our hosting keeps standard technical logs (for example request info) to run the site securely. We do not log full personal email addresses in application logs.
- Analytics. We keep tracking as light as possible. We use privacy-friendly, aggregated analytics that set no tracking cookies and build no advertising profile, and we may log anonymous, aggregated usage on our own servers to see which events and pages are useful. This includes counting, per channel, how many visitors an event page gets from another site: we keep only the referring site's name (like instagram.com or google.com) and any campaign tag in the link, so organisers can see where their audience comes from. To tell visits apart within a single day without cookies, we count sessions using a key that changes every day and is derived from technical details of the request; we store no IP address and set no cookie, and because the key resets daily it is not a persistent identifier that can follow you over time. We never store the full link or anything that identifies you. We don't sell your data or share it with advertising networks. With your consent, we also set one first-party analytics cookie (
tp-visitor) that gives your browser a random ID, so we can count unique visitors per event and show venues real reach. It contains no personal details, is never shared, and you can withdraw any time. Without your consent we set no such cookie and nothing changes from the cookieless counting above. - Source material. We build the calendar partly by harvesting events from public newsletters and venue pages. So the team can verify a listing during review (that the date, venue and price are right, and that nothing is duplicated or mis-read), we keep the source text a listing came from. We strip obvious contact details, like email addresses and phone numbers, from the source text we store, and this text is only ever visible to the team in the review tool, never published. Separately, when a venue or organiser appears in a source we harvest, we may keep their public contact address so we can reach out about listing their events. That address is used only by our team, is never published, and you can ask us to remove it at any time via the contact page.
- Reports & corrections. The "Something off?" flag on an event page lets anyone send us a short free-text message about a listing, completely anonymously: no name or email is asked for. We keep the message together with which event it was about, so the team can review it. Because the message is free text, it could contain personal details if you choose to include them; we don't ask for or expect that, and the message is only ever visible to the team, never published.
What we publish
Approved event details (title, venue, time, description, image) appear publicly on the calendar. Your contact email is used only by our team and is never published. If you submit an image, you confirm you have the right to share it.
Why we use it (legal basis, GDPR/AVG art. 6)
- Publishing and checking events: our legitimate interest in running an accurate public calendar, and acting on the submission you sent us.
- Contacting you about a submission: our legitimate interest in handling the event you asked us to consider, using the contact email you provided.
- The admin session cookie: strictly necessary to operate the service.
- Security logs and aggregated analytics: our legitimate interest in running the site securely and seeing what is useful.
- Analytics that use a cookie or identifier: your consent (GDPR/AVG art. 6(1)(a)). You can withdraw it at any time via "Cookie choices", as easily as you gave it.
- Keeping source material for verification: legitimate interest in running an accurate, trustworthy calendar.
- Keeping a venue or organiser's public contact address: legitimate interest in reaching out about listing their events.
- Keeping a record of reports and corrections: legitimate interest in fixing mistakes, and in being able to show that a removal request was received and handled.
Cookies
We use up to four first-party cookies, and no advertising cookies:
admin_session(necessary) signs the team in to the review tool. It's httpOnly, expires after 7 days, and is never used for advertising or tracking.venue_session(necessary) signs venue partners in to their own dashboard. Same httpOnly, 7-day expiry, never used for advertising or tracking.tp-consent(functional) remembers your cookie choice, so we can respect it and not ask again. It stores only that choice.tp-visitor(analytics, only after you opt in) is a random ID that lets us count unique visitors per event. It's httpOnly, expires after 13 months, holds no personal details, and is never shared.
Because we now offer an optional analytics cookie, we show a consent banner and you can change or withdraw your choice at any time via "Cookie choices" in the footer. Our privacy-friendly, aggregated analytics stay cookieless either way.
Who processes your data (third parties)
We use a few trusted providers to run the site: Vercel (hosting), Supabase (database) and Resend (email delivery). They process data on our behalf under their own security terms.
Supabase (our database, in Frankfurt) and Resend (email, in Ireland) process data within the EU. Vercel (hosting) may process some data outside the EEA, in the United States; those transfers are covered by the EU Standard Contractual Clauses and/or the EU-US Data Privacy Framework. You can request a copy of the relevant safeguards at hello@todaypicked.com.
The map page loads its background map from OpenFreeMap, a non-profit map service with servers in the EU. When you open the map, your browser requests map tiles from their servers, which briefly process your IP address to deliver them. This happens only on the map page and sets no cookies. If you use "Near me", your location is read by your browser and stays on your device; we never receive or store it.
We take reasonable technical and organisational measures to keep your data secure.
How long we keep it
Published event information stays as part of the calendar. We delete personal data we no longer need: contact emails and declined or expired submissions are removed periodically, and we aim to remove them within 12 months. Source text kept for verification is deleted together with its event when the event is removed or expires, and in any case within 12 months. A venue or organiser's harvested contact address is removed once they tell us they don't want to be contacted, or after 12 months without contact, whichever comes first. Reports and corrections are kept until the team has actioned them, and in any case within 12 months.
Analytics visitor data (the tp-visitor identifier and the per-visitor event log) is kept for at most 13 months and then deleted automatically.
Your rights
Under the GDPR/AVG you can ask us to access, correct, delete, restrict, or port your data, or object to how we use it. Email hello@todaypicked.com and we'll handle it by hand. You can also complain to your data protection authority (in the Netherlands: the Autoriteit Persoonsgegevens).
Changes
If this statement changes, we'll update this page and the date above.