LUX · Amsterdam event discovery

Privacy policy

Last updated 25 September 2026. Applies to the website and everything reached from it.

The short version

No account is needed to browse. Nothing is measured until you say yes. An account holds only what you type in, is hidden from other people until you choose otherwise, and can be downloaded or deleted by you at any time, in one tap, without asking us. We use no third-party analytics, advertising or tracking service.

Who is responsible

LUX is a proof of concept run by Luk, in Amsterdam, the Netherlands. Luk is the controller of the personal data described on this page. The test is sponsored by Hostelworld, which receives only aggregate numbers (counts and rates) and never your account, profile, messages or measurement records. LUX is an unofficial guide and is not affiliated with, endorsed by or connected to Amsterdam Dance Event or its organisers.

Questions, requests and complaints about this policy: blueimpactfund@gmail.com. We answer within one month.

What we hold, why, and for how long

Each row is one purpose. “Contract” means the thing you asked the site to do for you; “consent” means you can withdraw it at any time.

PurposeDataLegal basisKept
Browsing the mapNothing on our servers. Your stars, theme, filters and picks stay in your browser.—Until you clear the site data
MeasurementA random id made in your browser, a session id, which pages and events you open, save, share and tap, the campaign link you arrived on, your answers to short questions, which version of the site you were shownConsentRaw records 90 days; totals after that
Signing inYour email address; a one-time link (stored hashed) with a salted hash of your IP address to stop abuseContractLink 15 minutes; email until you delete the account
Staying signed inA session token (stored hashed) in one cookieContract30 days, or until you sign out
Your profileAlias, visiting or local, interests, languages, dates in the city, first or repeat ADE, visibility choice, an optional photo (with camera metadata removed), your 18+ confirmationContractUntil you change or delete it
Beta Lounge verificationThat a founder saw your ID next to your face on a call or in person, who did it, when, and your year of birth; who invited you; which version of the Lounge terms you accepted. Never a copy, photo or number of your IDLegitimate interest: making sure everyone you can meet is a real adult; your acceptance of the termsUntil you delete the account; access log entries 12 months
Going and Here nowWhich event, when, and the visibility you picked. “Here now” is a manual check-in at event level; the site never reads your device locationContractHere now: 8 hours or 2 hours after the event ends, then 30 days for totals. Going: 90 days after the event
Meeting peopleRequests you send and receive, their short note, accepted or declined, and the contact method you chose to reveal after acceptanceContract; revealing a contact method is your explicit choice each time you acceptUnanswered requests 30 days; others 90 days after they are answered
BlockingWho you blockedLegitimate interest: your safetyUntil you unblock or delete the account
ReportingWho reported whom, the reason and note, what an operator decidedLegitimate interest: keeping the service safeOpen reports until handled; handled reports 12 months
Pro purchaseYour account id, what you bought, when, the amount, the campaign link, refunds. Never card details: in this test version the checkout is a mock page of our own that takes no payment; with real payments it will be the provider’s hosted pageContract; keeping records is a legal obligationAs long as tax law requires once real payments exist; in the lab, until you delete the account
Comparison testWhether your random id (and, once signed in, your account) was shown the version with or without the meeting-people featuresConsent, as part of measurementDeleted with the raw measurement records
Running the serverStandard short-lived server logs (IP address, page, time)Legitimate interest: security and operationDays, not weeks

What is never asked for: your name, phone number, precise location, contacts, a device fingerprint, or anything from other apps. If you choose WhatsApp as the contact method to reveal after an accepted request, that handle is your number; it is shown to nobody else.

What other people can see

Nothing, by default. Your profile starts hidden. When you choose to be visible, this is the whole of what is shown:

  • People going to the same event or, if you pick it, anyone signed in: your alias, visiting or local, interests and languages, plus that you are going or are there now. Your photo is not shown to others in this version. Never your email, your dates or your account id.
  • Someone whose request you accepted, or who accepted yours: additionally the one contact method you saved, if any. You can remove it at any time and it disappears for everyone.
  • Operators (the people running the test) see aliases and account ids in the moderation queue and the purchase list, never email addresses in the live deployment. They see who reported whom, by alias, in order to act on it. They can hide a profile or photo if it breaks the rules.
  • No other visitor sees whom you blocked, whom you reported, your measurement records or your answers to the short questions; the readout only ever shows totals.

Blocking is mutual and immediate: neither of you sees the other again, and any open request between you is closed.

The Beta Lounge

During the ADE test, seeing who is going and meeting people is open only to members of the Beta Lounge: people invited by a member and verified by one of the founders. Verification is done by showing, never sending: on a short video call or in person you hold your ID next to your face, and the founder checks that it is you and that you are 18 or over. We do not take a photo, screenshot or copy of your ID, and we do not store your document number. We record only that you were verified, by whom, when, and your year of birth. The rest of the map works without any of this.

You join through a personal invite link from a member. Joining asks for your email address, that you are 18 or over, and that you accept the Lounge terms. In the beta we do not send you mail to confirm the address; we keep it to find your account again and to contact you about the beta, and it is never shown to other members. If you lose access (a new phone, cleared cookies), a founder can make you a personal sign-in link that works once, for 24 hours; making one is written to the access log.

Founders and moderators look at private information (reports, the people involved, verification records) only to keep people safe, and every such action is written to an access log with who did it and why. The lab pages that show member data open only for a signed-in founder or moderator, and each view is logged. Access log entries are deleted after 12 months. When you delete your account, entries about you stay until then but point at an account number that no longer belongs to anyone. Your data download includes the Lounge records about you and the staff actions on them.

The “Share my night” message and the “Home safe” reminder are made on your own device and sent through your own messenger to a friend you choose. They never pass through our servers and never contain a location. We suggest sharing live location with a close friend through your phone’s own Find My or Google Maps, which we never see.

Measurement

The first time you open the map it asks whether we may count how it is used. If you say no, nothing is recorded and you are not asked again. If you say yes, the records listed in the table above are stored in our own database under a random id created in your browser; it is not derived from anything about you. When you sign in, records made from then on also carry your account’s number, so the readout can tell travellers from locals; deleting the account leaves a number that points at nobody.

Some visitors see a version without the meeting-people features so we can compare the two. Which version you get is random, decided from your random id, and stored as a word next to that id and, once you sign in, next to your account number, so every device gets the same version. No decision with a legal or similar effect on you is taken automatically; the only automation is the order of the attendee list, which puts people with shared interests first.

Your current choice on this device: ….

Cookies and your browser

Two cookies exist, both strictly necessary and set only when you use the feature: eb_session keeps you signed in for 30 days, and eb_labexists only for operators. There are no advertising or tracking cookies and no third-party cookies. Your browser’s local storage keeps the events you star, your theme, your saved filter sets, the artists you pick in Find my sound, your consent choice, a few small preferences (ADE or city mode, which prompts you have seen) and any measurement records waiting to be sent while you were offline. Clearing the site data removes them.

Who else receives data

Your account, profile, messages, purchases and measurement records stay on our own server and go to no one. Three things reach outside services, plus any outside link you tap yourself (tickets, directions, a WhatsApp share):

  • Map tiles: your device fetches them from the OpenStreetMap Foundation, which sees your IP address like any website you visit.
  • Find my sound: the artist names you type in that box, and any “describe a vibe” sentence, are sent from our server (not from your device, so without your IP address or any id) to music catalogues to find out how an artist sounds: Deezer (France), MusicBrainz (MetaBrainz Foundation, United States) and, when configured, Last.fm (United Kingdom) and Google’s Gemini (United States) for a short description. Nothing else about you travels with the text. The sound-matching model itself is fetched once from Hugging Face and runs on our server.
  • The pager and venue pages use a hosted database (Supabase) when it is configured; in this deployment it is not, so they store nothing.

Before the public launch two processors are added and named here: a hosting provider in the EU and an email provider for the sign-in links, each under a data processing agreement. Your personal data is never sold and is never shared with sponsors or advertisers in a form that identifies you; the sponsor sees totals only.

Your rights

Under the GDPR you have the following rights, and each has a button rather than a form:

  • Access and portability: Download my data on your profile page gives you everything we hold about you as a JSON file, other people shown by alias only.
  • Rectification: every field on the profile page can be changed by you; to change the email address, write to us.
  • Erasure: “Delete my account” on the profile page removes your profile, photo, sign-ins and sign-in history, check-ins, requests, contact method, blocks and your place in the comparison test at once, and erases the text of any report you wrote. What remains: the fact of reports made by or about you (with the account number pointing at nobody), an operator’s record of any moderation action on the account, one entry noting the deletion, purchase records the law requires us to keep, and measurement rows that carry that same number until their 90 days are up.
  • Withdrawing consent to measurement: the Measurement section on this page, on each device. After that nothing on the server can be linked to you; send us the id shown there and we delete its records the same day.
  • Objection and restriction: write to us at blueimpactfund@gmail.com.
  • Complaint: you can complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or the authority of the country you live in.

Security

Sign-in links and session tokens are stored only as hashes. Cookies are HttpOnly and, in production, sent over HTTPS only. Anything that touches your account needs your signed-in session and either a JSON request or a method a cross-site form cannot send, and the few anonymous endpoints (measurement, the sign-in request, sponsor counts, the comparison test) are limited per address. Attendee cards carry a short-lived token instead of an id, so accounts cannot be enumerated. The meeting-people features have a kill switch an operator can flip in seconds, and a moderation queue. If a breach were to affect you, we would tell the supervisory authority within 72 hours and you without undue delay.

Photos

A profile photo is optional, limited to 200 KB, re-encoded in your browser before upload where the browser can, and always stripped of camera metadata (position, time, device) the moment it arrives; a file we cannot process is refused rather than stored. In this version it is shown only to you; an operator can hide it if it breaks the rules. Deleting it or the account removes it.

Pro and sponsors

ADE Pro is a one-off purchase. In this test version the checkout page is our own and takes no payment; with real payments it will be a payment provider’s hosted page. Either way we never see card details. Some rows on the map are sponsored: always labelled, only in two agreed places, never changing how the rest of the list is ordered. That a sponsored row was shown to you or opened is counted once a day under the same random id as everything else, and only if you said yes to measurement. Merchandise links open the shop in a new tab; we count the tap and nothing else, and the shop’s own privacy terms apply there.

Map tiles and sharing

The background map is drawn from tiles served by the OpenStreetMap Foundation. When you move the map, your device requests those tiles directly from their servers, which see your IP address, as with any website you visit. Their policy is at osmfoundation.org. When you share an event, the site hands a link and a short caption to your phone’s share sheet; what happens next is governed by the app you pick. Find my sound looks the artists you type up in the music catalogues named above, through our server; the artists you pick are saved in your browser only.

The pager and event hosts

The site carries a pager (messaging a friend by scanning their code) and venue-submission pages inherited from the map it grew from. When configured they use Supabase as their database: the pager stores an anonymous identity with the public half of a key pair made on your device, your pager number and emoji, and messages encrypted on your device before they are sent, which nobody can read; venues and promoters sign in with a one-time link and their email address is stored to know who submitted what. In this deployment neither is configured and nothing is stored for them.

Age

The events listed are nightlife events for adults. The site is not directed at children and we knowingly collect no data from anyone under 18. Becoming visible to others or contacting anyone requires confirming you are 18 or over.

Changes

If any of this changes, this page changes with it and the date at the top moves. Anything that would use your data for a new purpose is asked for, not assumed.

made by luk :) have fun