Closed events
Exactly who can see what in a Closed event - the table, the sensitive-field rules, and the narrow sale-day exception.
Closed mode has one job: personal details stay inside the buying group that actually needs them to buy tickets. This page is the precise version of that promise.
Who sees what
In a Closed event:
| Looking at another member… | Name, photo, who's-ready status | Their account email | Personal details (address, postcode, phone, and answers marked sensitive - registration numbers usually are) | Unmarked answers (coach pickup, travel…) |
|---|---|---|---|---|
| Someone in their buying group | ✓ | ✓ | ✓ | ✓ |
| Their own group's admin | ✓ | ✓ | ✓ | ✓ |
| The event coordinator / owner | ✓ | ✓ | - | ✓ |
| An admin of the event's community (who's also in the event) | ✓ | ✓ | - | ✓ |
| A different group's admin | ✓ | - | - | ✓ |
| Any other member | ✓ | - | - | ✓ |
The one-line summary: organisers can reach you, but they can't read you. Coordinators keep everyone's email so they can chase, and the who's-ready view so they can run the event - but a coordinator outside your group cannot read your personal details. (A coordinator who's also in your buying group sees what any group-mate sees - being in the group is what grants it, not the title.)
In an Open event, everyone in the event sees everything - with two footnotes. First, members who haven't yet re-confirmed after a Closed→Open switch stay under Closed rules until they do (their choice, covered in Open vs Closed). Second, another member's account email never appears on their profile page - with one operational exception: site administrators can inspect login emails for support and admin workflows.
What counts as "personal details"
- Your profile contact details - phone, postcode, address, social links - are in the protected set. (Social links have one opt-out: you can choose to share yours publicly from your profile settings, and only then do they show more widely.)
- Custom event questions are protected when the coordinator marks them sensitive (registration numbers, ID, anything personal). Unmarked questions are event-wide in every mode by deliberate choice - the whole Squad genuinely needs to see who's on which coach.
- If in doubt, the app fails private: anything it can't classify is treated as sensitive.
Members see a small reassurance on sensitive questions in Closed events - only your group can see - before they type anything.
Helpers
A helper docked to your group sees what a group-mate sees - that's what lets them buy for you. It's one-directional: the group doesn't gain access to the helper's own details.
The sale-day exception, precisely bounded
The one moment details cross a group wall: if your group gets its tickets, you might be able to help one other group get theirs on sale day - just their details, just for the day. It's a narrow, revocable, audited window that arms only on Closed named-ticket events during the sale window, and it's documented in full on the multiple-group fallback. Even then, the helping group never sees the target group's account emails.
Where this is enforced
Member data is filtered server-side through a shared authorization policy before anything is sent - the rules live in one place, not in per-page judgement calls - and generated artifacts (like sale-day snapshots) carry their own dedicated gates on top: all-groups snapshots simply aren't generated for Closed events, and tightening an event takes down any that already exist.