Privacy
Dooflist is a list of Auckland dance gigs and a calendar feed of the same. It has no accounts, no logins, no newsletter and no advertising. This page says exactly what it does keep, why, and how to get rid of it. It is written for the New Zealand Privacy Act 2020, and the “we” throughout is Dooflist, reachable at [email protected].
In your browser
These live on your device, not on our servers. Nothing in them says who you are, and clearing your browser data removes all of them. Everything here is optional: the site works without any of it.
- The key to your Going list. So the gigs you tick stay ticked when you come back, with no account. Kept: 2 years from the day the list was made, or until you clear your browser data.
- A copy of which gigs you have ticked. So the page can paint your ticks instantly without asking the server. Kept: Until you clear your browser data.
- Your Going list's public code. So the Subscribe menu can offer you a calendar feed of just your list. Kept: Until you clear your browser data.
- Light or dark. So the site opens in the look you chose. Kept: Until you clear your browser data.
- Your location, if you pressed Near me or allowed it on the map. To sort gigs by distance from you. It stays on your device: it is never sent to Dooflist, never put in a link, and it is forgotten when the tab closes. Kept: Until you close the tab.
On our servers
- Going lists: a random code, a scrambled copy of the edit key, and the gigs on the list. So a list you made in one browser can be opened as a page or a calendar feed anywhere. There is no account and nothing in the list says who made it. Today a list can only be emptied, not deleted; email us with your list's code and we will delete it by hand.
- Gigs sent through the List a gig form, including the name you gave (optional) and the email or Instagram handle you left. So a person can check a detail with you before the gig goes on. The contact is never shown on the site and is not used for anything else. Kept while the submission is being decided. Today it is not deleted afterwards; email us and we will remove your contact details on request.
The contact you leave on the List a gig form is the only thing Dooflist holds that identifies a person. Everything else is a gig, a venue, or a random code.
Counting visits
Two systems count page views, both without a cookie, a fingerprint, or a profile of you: Cloudflare Web Analytics and Vercel Web Analytics. Neither lets us tell one visitor from another, which is why there is no consent banner: there is nothing to consent to. Beyond page views, exactly two things are counted:
- That a ticket link was clicked, and which ticket seller it went to. So we know whether the list sends people to the box office. Not which gig, and not who.
- That Subscribe was pressed, and which calendar app and which feed. The number the whole project steers by is calendars that stay subscribed.
The calendar feed itself is not logged by Dooflist. We read Cloudflare’s overall request counts to guess how many calendars are subscribed, and chose not to count by address.
Who else sees a request
Dooflist is run on other companies’ computers, and each of them sees what any web server sees: your IP address, your browser’s name, and the page you asked for. None of them is given anything more by us, and none of them may use it for their own purposes beyond running the service.
- Supabase: The database that holds the gigs, Going lists and submissions. Hosting. Their servers are in Singapore, so anything above that is stored leaves New Zealand.
- Vercel: Renders the pages and resizes gig posters. Hosting. Vercel sees the same request any web server sees, and keeps a resized copy of each poster for up to 30 days.
- Cloudflare: Serves the calendar feed and sits in front of the site. Hosting and traffic counts. Cloudflare Web Analytics counts page views without a cookie and without a profile of you; the feed is not logged by Dooflist at all.
- Vercel Web Analytics: Counts visits and the two clicks under Counting visits, without a cookie and without a profile of you. So we know whether anybody uses the thing. Nothing it records can be tied back to you by us.
- CARTO: Draws the map tiles behind the map page, venue pages and the venue hover panels. Map imagery, from OpenStreetMap data. Your browser fetches the tiles directly, so CARTO sees that request like any image host would.
Because the database is in Singapore and the pages are served from wherever you are, anything listed under On our servers is stored outside New Zealand. It is held for us, under contract, and is not disclosed to anyone else.
Your rights
You can ask what we hold about you, ask for it to be corrected, or ask for it to be deleted, by writing to [email protected]. Because almost nothing here is tied to a person, the useful things to include are your Going list’s code (it is in the page address, after /going/) or the gig you submitted. We answer within a few days. If you are not satisfied, you can complain to the Office of the Privacy Commissioner.
Not here
- No accounts, passwords, or sign-in with anything.
- No email list. We will never email you unless you emailed us first.
- No advertising, no ad networks, no selling or sharing of anything to anyone.
- No social media buttons that report your visit before you press them.
- Ticket links go straight to the seller. What you do there is between you and them.
Children
Dooflist lists events that are mostly R18 and collects nothing that would tell us how old a visitor is. If you are a parent and believe a child has left contact details through the List a gig form, email us and we will remove them.
Changes
When this page changes in substance the date at the bottom changes with it. The list of what the site stores is checked by an automated test against the site’s own code on every change, so it cannot quietly fall behind.
Last changed 2026-09-24. Questions: [email protected].