# A guest list app fills the room. It does not build a contact list

> Getting in and being written to are two different permissions. A guest list carries the first. Only one extra field carries the second.

Source: https://hiipe.io/blog/a-guest-list-is-not-a-contact-list
Published: 2026-09-17

Two different permissions get confused every night in every venue. One is permission to come in. The other is permission to be contacted afterwards. A guest list carries the first and almost never the second, and the distance between them is exactly one field wide.

**Key takeaways**

- Adding your name to get in is not an affirmative act of consent to marketing.
- The field that separates the two is a stored choice, with a timestamp and the wording shown.
- Plus-ones and names added by a third party never consented to anything at all.

## The moment where the two get merged

The door list closes at midnight. Four hundred and twelve names, most with an
email address because that is how the invite worked. The next morning someone
exports it, pastes it into the mailing tool, and the venue has a bigger audience.

Nothing in that sequence feels wrong, which is why it happens. But go back to
what each of those four hundred and twelve people actually did. They typed their
name to get through a door on a specific night. The act had a purpose and the
purpose was completed when they walked in.

[Recital 32 of the GDPR](https://gdpr-info.eu/recitals/no-32/) puts it in plain
terms: consent has to be a clear affirmative act, freely given, for a specified
purpose. Getting on a list is an affirmative act. It is just an affirmative act
about something else.

## What each list actually is

| | Guest list | Contact list |
|---|---|---|
| What the person did | Asked to come in, once | Agreed to hear from you, ongoing |
| What it is valid for | One night, one door | Until they say otherwise |
| What proves it | The door log | A stored choice, with time and wording |
| Who else can be on it | Plus-ones, names added by a promoter | Only people who acted themselves |
| What it is worth in March | Nothing you can send to | Everything |
| What it costs to get wrong | Complaints, spam reports, a poisoned domain | Nothing, if the record exists |

Read the fourth row twice. The guest list is the one document in your business
that is routinely populated by people who are not the person. A promoter adds
twelve names. Someone brings two friends. None of those fourteen ever saw a form,
let alone a consent line.

## The one field, and what it must contain

Not a checkbox. A record.

Three things have to sit on the person: the choice they made, the moment they
made it, and the exact wording they were shown when they made it. The last one is
the part everyone skips and the only one that helps you two years later, when
somebody asks why they are receiving this. "They ticked a box" is an assertion.
"On 17 September at 21:14 they ticked a box that said this sentence" is a record.

It also has to be separable. Consent to hear about future nights at this venue is
not consent to hear from the three other promoters who used the same door tool.
If those cannot be told apart in the data, they are the same thing legally and
the weakest one governs.

## The good news, which is that the door is a great place to ask

Everything above sounds like a restriction. In practice it is the opposite,
because the door is the single highest intent moment you will ever have with
these people. They are standing in your venue, on a night they chose, having
already said yes to being there.

Asking one question at that moment converts far better than asking the same
question in a feed three weeks later. It only needs to be one question, it needs
to be optional, and it needs to say what will actually happen: we run about one
night a month, we will tell you about them, that is all.

Do that and the four hundred and twelve names become a smaller number, maybe two
hundred and forty, which is worth far more than four hundred and twelve because
every one of them can be reached in March without a complaint.

## Where the mechanism lives

This is why the RSVP surface and the fanbase have to be the same system rather
than two exports that meet in a spreadsheet. In HIIPE the RSVP page collects the
entry, the consent and the source in one action, and the person lands in the
fanbase already carrying all three, so the segment "said yes to hearing from us,
at this event" exists without anyone building it.

The door is now part of the same object rather than the place where the record
stops. The RSVP issues a personal QR pass, and the entrance scans it from a web
reader opened with a per-event PIN: nothing for the guest to install, no account
for the person working the door. That detail is not a convenience, it is what
keeps the record whole. A scanner that lives outside the system produces a
second file, and a second file is exactly how entry and contact end up merged by
hand a month later. Here the scan writes back to the same profile, so attendance
and permission stay two separate fields on one person instead of two lists
somebody has to reconcile. [How the pieces connect](/solutions) is the part that
matters.

## The rule, in one line

**Entry is one permission. Contact is another. Never let an export merge them.**

If you already have a pile of old guest lists, do not delete them and do not mail
them. Treat them as attendance history, which is genuinely useful for
understanding who comes to what, and start the consent record from the next
event forward. The full argument for why the last event should be feeding the
next one is in [filling your next event from the last
one](/blog/fill-your-next-event-from-the-last-one), and what that record needs to
look like is in [what a fan CRM is](/blog/what-is-a-fan-crm).

**Read next** : [Fill your next event from the last one](/blog/fill-your-next-event-from-the-last-one) · [What an event CRM should do between two events](/blog/event-crm-what-it-should-do)
## Citable facts

- Under GDPR recital 32, consent requires a clear affirmative act. Adding a name to a door list is not one, because the act it performs is entry.
  Source: GDPR, recital 32
- Under Article 13 of the GDPR the purposes of processing must be given to the person at the moment their data is collected. A name taken at a door has been given one purpose, and marketing is not it.
  Source: Regulation (EU) 2016/679, Article 13

## FAQ

### Can I email everyone who was on my guest list?
Not on the strength of the guest list alone. They performed one act, which was asking to come in. Marketing consent is a separate affirmative act, and if it was never collected then the list is an attendance record rather than an audience.

### What single field turns a guest list into a contact list?
A consent choice, stored with a timestamp and the wording that was shown at the time. Not the checkbox itself, the record of it. Without the record you have an assertion, and an assertion is not a defence.

### Does the friend-of-a-friend on the list count as mine?
No, and this is the most common leak. Plus-ones and names added by someone else never saw your wording and never agreed to anything. They can come in. They cannot be added to a mailing list.

### Is a signed-in door app enough?
It is enough for the door. Whether it is enough for anything afterwards depends on one question: does it store, per person, what they agreed to and when? Most door apps do not, because that was never their job.

### Can I email people who bought a ticket?
About the event they bought, generally yes: that is part of delivering what they paid for. About next year, that is marketing and it needs its own basis, which in practice means a separate optional question asked at the time of purchase.

### What should the consent line actually say?
What will arrive, roughly how often, and from whom. One sentence. Vague wording is not safer, it is weaker, because a person who cannot picture what they agreed to is the person who reports the message as spam eight months later.

### Do plus-ones count as consent?
No. A plus-one added by someone else never saw your wording and never made a choice. They can come in, they can be counted, and they cannot be added to a list. This is the most common single leak in event data.

### What about people who gave a business card?
A card is a contact detail offered for a purpose, usually a conversation. It is not a subscription. If you want to add them to a list, the honest move is one message asking, sent once, and accepting silence as no.
