Afterhours
Last updated 27 August 2026.
Afterhours is a ticketing platform operated by Dhaka Music Festival, a registered partnership in Dhaka, Bangladesh. We are the data controller for the information described here.
To create an account: your name, your email address or mobile number, and a chosen handle.
To verify your identity (required once, before a ticket can be scanned at the door): your full legal name, mobile number, a government identity document — National ID, birth certificate or passport, meaning its type, its number and a photo of the document — and your Instagram handle. Some events also require a gate photo, used only to match your face to your ticket at entry.
To take payment: the amount, the currency, your order reference code, the payment method you chose, the transaction ID, and the session identifier returned by the payment provider. We do notcollect or store your full card number, expiry date, CVV, PIN or bank login. Those are entered on the payment provider’s own secure page and never reach our servers.
Automatically: basic technical data such as device type, app version and crash logs, to keep the service working.
Account details identify you in the app. Identity details are used solely to verify your account once and to staff the entry gate at events, matching your face and name to a valid ticket. Payment details are used to take payment, confirm your order, issue your ticket and handle refunds or disputes. Technical data is used to diagnose faults.
We do not sell your data. We do not use identity or payment data for advertising, and we do not profile you for marketing.
We share only what each provider needs to do its job:
Other than the above, we disclose personal data only where the law requires it. Your name and profile photo are visible to other users in shared crews and on creator briefs; your government ID, mobile number and gate photo never are.
The site is served over HTTPS. Identity documents and gate photos are held in private storage that is not publicly addressable — they can only be opened through a short-lived, permission-checked link generated at the moment an authorised reviewer needs it. Database access is enforced row by row, so one account cannot read another’s records. One-time SMS codes are stored only as a keyed hash, never as the code itself, and expire ten minutes after they are sent.
Account and verification data is kept while your account is active. You can delete your account and its data at any time from /account/delete — no need to contact us first.
Purchase records are the exception. If you have orders on file we keep the transaction record after your account is deleted, for as long as accounting and tax rules require and to defend against payment disputes. Everything else is removed immediately.
You can view and correct your details in the app, delete your account and data yourself at the link above, or write to us to ask what we hold about you. If you want a copy of your data, or want something corrected or erased and can’t do it in the app, email us and we’ll respond within 30 days.
Questions about this policy, or any request about your data: