Skip to content
Knowledge base

Websites, public routes and privacy

Publish branded content and understand customer routes and privacy requests.

4 min read · 4 sections
On this page

Branded public content and website sections

Public organization, Brand, Series and Event pages expose eligible published content. Draft records and private staff settings do not become public because a URL can be guessed. Hostname-based sites resolve an exact organization/venue/ Series target and can redirect to the current canonical address.

Ticketing Settings → Websites includes website sections: choose which eligible Events to show, the target organization/venue/Series, and the website hostname and path prefix. Optional navigation links point to the rest of the business's site. The settings supply copy/download controls for the supported Worker and configuration files plus preview/link controls. Creating a section does not by itself prove the customer's DNS/hosting integration is operating.

/website-section/<publicId>/... renders the section and /site/<hostname>/... renders hostname-resolved content. Event pages show public description/date/time and continue into the canonical ticket checkout. CRM analytics consent mounts only after resolving the exact business and retains that source's consent rules.

After Soupy confirms an embedded purchase, the default Back to event action returns to that installed widget's listing. It retains the widget instance and its original embedding website; a configured custom post-purchase button keeps its own destination. The frame resizes to the current checkout, confirmation or returned listing so the host page can show the full content.

Ticketing product explanation

The public /product/ticketing page shows the current mobile Ticket Wallet inside an iPhone frame, using a fictional Event and holder with a non-admission QR. It explains the ticket and aftercare controls, including PDF and Apple/Google Wallet options subject to purchased policy and issuer readiness. The illustration is not a live ticket or proof of a native device save.

A separate interactive example explains seller charges: a £25 ticket contains £20 admission and a £5 drink; an optional £25 artist T-shirt and £12 supper add to the total. Visitors can change each item's seller and include or remove the extras to see lines grouped into seller charges. These are fictional prices before applicable fees. Controls change only the example; they do not configure an Event, reserve inventory or take payment.

The page also describes Shared Add-ons for artist merchandise presales and confirmed collection using a web voucher. Whole included lines are individually assignable; they are not percentage splits of one line. Multi-seller eligibility, account setup and issuer conditions remain explicit. The page changes product explanation, not checkout, permissions or fulfilment.

Public route directory

Route familyUser purpose / governing boundary
/, /product, /product/<slug>, /tour, /suppliersSoupy public marketing and product explanation; not an authenticated entitlement report
/downloadCurrent public installer availability and browser fallback
/privacy, /workforce/privacyPublic service and workforce privacy information
/workforce/supportAuthenticated data/deletion/support requests plus help without sign-in
/whats-on, /whats-on/<orgSlug>, /org/<orgSlug>, /org/<orgSlug>/brand/<brandSlug>, /group/<groupSlug>Published business/Brand/Series/Event discovery
/org/<orgSlug>/c/<categorySlug>, /org/<orgSlug>/<eventSlug>, /<slug>Eligible public listing/category/detail surfaces
/embed/<orgSlug>/<seriesSlug>, /embed/v1/<publicId>Ticketing embeds and their registered scope
/embed/forms/<publicId>Published versioned Inbox form
/org/<orgSlug>/book/..., /embed/<orgSlug>/book/<venueId>, /embed/bookings/v1/<publicId>Published Bookings journey/widget
/services/..., /consumer/...Separate external-service discovery and customer authority
/desktop/sign-in, /desktop/complete, /desktop/provider, /desktop/backgroundDesktop authentication handoff/coordinator surfaces; not business grants
/accept-access/<token>Reviewed workplace access invitation flow
/clock/<token>Source-governed attendance-point entry
/assets/scan/<token>, /maintenance/report/..., /maintenance/contractor/<token>Bounded asset/report/contractor access owned by Operations
/contracts/<accessId>, /sign/<token>, /talent/portal, /talent/commitments, /supplierPurpose-specific signing, representative and supplier journeys

Checkout, basket, order status, ticket Wallet, resale, Booking management/payment, preorders, feedback and Lost Property recovery retain their owning commercial or operational chapters. Their bearer links authorize their exact purpose, not a staff workspace. Design-preview and acceptance-test routes are fixtures, not ordinary navigation or proof that a feature is publicly released.

Privacy and account requests

The public privacy policy explains service/workplace responsibilities, handled information, uses, Gmail limited use, optional AI, recipients, retention, security, rights and contact. Disconnecting Google access stops future provider authority; it is separate from asking Soupy to delete already retained information.

Workforce privacy explains workplace identity/membership, operational records, notification registrations and device evidence. Camera/files/photos are requested when scanning or attaching. A configured clocking policy can request a one-time location reading; the app does not request background location.

/workforce/support accepts account deletion, data access and application support requests after sign-in. Users unable to sign in can use the published email route. Identity and authority are checked before handling data. A receipt is not completed deletion: review identifies records retained for employment, accounting, audit or dispute purposes, with their reason and expiry.

Available features depend on your workspace, permissions and connected services. Preview and setup requirements are described in each guide.

Back to the knowledge base