Branded public content and website sections
Public organization, Brand, Series and Event pages expose eligible published content. Draft records and private staff settings do not become public because a URL can be guessed. Hostname-based sites resolve an exact organization/venue/ Series target and can redirect to the current canonical address.
Ticketing Settings → Websites includes website sections: choose which eligible Events to show, the target organization/venue/Series, and the website hostname and path prefix. Optional navigation links point to the rest of the business's site. The settings supply copy/download controls for the supported Worker and configuration files plus preview/link controls. Creating a section does not by itself prove the customer's DNS/hosting integration is operating.
/website-section/<publicId>/... renders the section and
/site/<hostname>/... renders hostname-resolved content. Event pages show public
description/date/time and continue into the canonical ticket checkout.
CRM analytics consent mounts only after resolving the exact business and retains
that source's consent rules.
After Soupy confirms an embedded purchase, the default Back to event action returns to that installed widget's listing. It retains the widget instance and its original embedding website; a configured custom post-purchase button keeps its own destination. The frame resizes to the current checkout, confirmation or returned listing so the host page can show the full content.
Ticketing product explanation
The public /product/ticketing page shows the current mobile Ticket Wallet
inside an iPhone frame, using a fictional Event and holder with a non-admission
QR. It explains the ticket and aftercare controls,
including PDF and Apple/Google Wallet options subject to purchased policy and
issuer readiness. The illustration is not a live ticket or proof of a native
device save.
A separate interactive example explains seller charges: a £25 ticket contains £20 admission and a £5 drink; an optional £25 artist T-shirt and £12 supper add to the total. Visitors can change each item's seller and include or remove the extras to see lines grouped into seller charges. These are fictional prices before applicable fees. Controls change only the example; they do not configure an Event, reserve inventory or take payment.
The page also describes Shared Add-ons for artist merchandise presales and confirmed collection using a web voucher. Whole included lines are individually assignable; they are not percentage splits of one line. Multi-seller eligibility, account setup and issuer conditions remain explicit. The page changes product explanation, not checkout, permissions or fulfilment.
Public route directory
| Route family | User purpose / governing boundary |
|---|---|
/, /product, /product/<slug>, /tour, /suppliers | Soupy public marketing and product explanation; not an authenticated entitlement report |
/download | Current public installer availability and browser fallback |
/privacy, /workforce/privacy | Public service and workforce privacy information |
/workforce/support | Authenticated data/deletion/support requests plus help without sign-in |
/whats-on, /whats-on/<orgSlug>, /org/<orgSlug>, /org/<orgSlug>/brand/<brandSlug>, /group/<groupSlug> | Published business/Brand/Series/Event discovery |
/org/<orgSlug>/c/<categorySlug>, /org/<orgSlug>/<eventSlug>, /<slug> | Eligible public listing/category/detail surfaces |
/embed/<orgSlug>/<seriesSlug>, /embed/v1/<publicId> | Ticketing embeds and their registered scope |
/embed/forms/<publicId> | Published versioned Inbox form |
/org/<orgSlug>/book/..., /embed/<orgSlug>/book/<venueId>, /embed/bookings/v1/<publicId> | Published Bookings journey/widget |
/services/..., /consumer/... | Separate external-service discovery and customer authority |
/desktop/sign-in, /desktop/complete, /desktop/provider, /desktop/background | Desktop authentication handoff/coordinator surfaces; not business grants |
/accept-access/<token> | Reviewed workplace access invitation flow |
/clock/<token> | Source-governed attendance-point entry |
/assets/scan/<token>, /maintenance/report/..., /maintenance/contractor/<token> | Bounded asset/report/contractor access owned by Operations |
/contracts/<accessId>, /sign/<token>, /talent/portal, /talent/commitments, /supplier | Purpose-specific signing, representative and supplier journeys |
Checkout, basket, order status, ticket Wallet, resale, Booking management/payment, preorders, feedback and Lost Property recovery retain their owning commercial or operational chapters. Their bearer links authorize their exact purpose, not a staff workspace. Design-preview and acceptance-test routes are fixtures, not ordinary navigation or proof that a feature is publicly released.
Privacy and account requests
The public privacy policy explains service/workplace responsibilities, handled information, uses, Gmail limited use, optional AI, recipients, retention, security, rights and contact. Disconnecting Google access stops future provider authority; it is separate from asking Soupy to delete already retained information.
Workforce privacy explains workplace identity/membership, operational records, notification registrations and device evidence. Camera/files/photos are requested when scanning or attaching. A configured clocking policy can request a one-time location reading; the app does not request background location.
/workforce/support accepts account deletion, data access and application support
requests after sign-in. Users unable to sign in can use the published email route.
Identity and authority are checked before handling data. A receipt is not completed
deletion: review identifies records retained for employment, accounting, audit or
dispute purposes, with their reason and expiry.