Features – Qwikr Events
⚡ Everything. Included. In production.

Every tool you need
to sell out every event.

Ticketing, email campaigns, CRM, revenue intelligence, QR check-in, abandoned checkout recovery, referral tracking, waitlists, event templates, automation, and a headless API — all built, all live, all included from day one. Not a roadmap. Not a prototype. Production infrastructure handling real events and real payments.

60+

Individual capabilities across 12 feature domains — ticketing, campaigns, CRM, revenue intelligence, check-in, automation, security, theming, localisation, and a complete headless API. Every one live and in production.

One deployment. Every client in their own world.

True isolation means every client company gets a separate Bunny Database instance. There’s no shared schema, no row-level filtering, no risk of cross-tenant data leaks. A bug in client A’s account physically cannot touch client B’s data.

🔒 Isolated databases

Each company gets its own Bunny Database (LibSQL/SQLite). The platform DB stores only encrypted metadata — no event, order, or attendee data is ever shared across tenants.

🔐 AES-256-GCM encrypted tokens

Each company’s database token is encrypted with AES-256-GCM before being stored in the platform DB. Tokens are decrypted in memory per request — never stored in plaintext.

🌐 Host-based routing

Tenant resolution happens on every request via the Host header. The correct company is identified by matching against custom_domain or subdomain in the platform DB, cached for 5 minutes.

⚡ Provisioned in seconds

New company provisioning calls the Bunny Database API, creates the isolated DB, runs the full schema, seeds admin credentials, and returns ready-to-use login details — all in under 10 seconds.

📄 Unlimited companies

One Edge Script deployment handles unlimited companies. There’s no per-tenant infrastructure to manage. Add a new company row and they’re live.

📋 Audit log

Every admin action is recorded in a tenant-scoped audit log. Who changed what, when, and from which IP. Non-repudiation baked in from day one.

Your client’s identity, everywhere.

Every touchpoint — the public ticketing site, checkout, ticket confirmation, QR code email, and admin dashboard — is fully branded per client. There’s no “powered by” badge, no shared domain, no indication they’re using third-party infrastructure.

  • 🏠
    Custom domain Point any domain or subdomain at the platform via CNAME. SSL is handled by Bunny. The ticketing site, checkout, and API all serve from the client’s domain.
  • 🎨
    Brand colours & fonts Primary colour, background, font stack, logo URL, and custom CSS are stored per tenant and applied to every page. Changes take effect immediately.
  • 📧
    Branded transactional email Confirmation, reminder, and check-in emails send from the client’s own Mailgun sending domain with their logo and colours. Attendees never see your infrastructure.
  • 🎟
    Branded ticket QR codes Ticket confirmation PDFs and QR code emails carry the event branding. Check-in staff see the event name, not a generic scanner UI.
  • 📄
    Custom CSS override Clients can inject arbitrary CSS for edge cases — custom fonts, layout tweaks, promotional banners — without touching the frontend codebase.
tickets.riverside-events.co.uk
Riverside Events
tickets.riverside-events.co.uk
Riverside Jazz Evening — VIP Table
£120.00
Attendee details
Pay £120.00 — powered by SumUp
Every pixel is Riverside Events. Not us.

Their payment account. Their revenue. Zero intermediary.

Each client connects their own Stripe or SumUp account. When a ticket is purchased, payment flows directly to the client — not through us. We never hold, process, or take a cut of their ticket revenue.

💳 Stripe Checkout

Full Stripe Checkout integration with webhook-verified payment confirmation. Supports all Stripe payment methods. Configuration stored encrypted per tenant.

💴 SumUp

SumUp checkout for clients who prefer it. The same pluggable provider interface — just a different payment button. Mix and match across your client base.

🔓 Encrypted credentials

Provider keys and secrets are stored AES-256-GCM encrypted per company. Decrypted only during payment operations — never logged, never exposed in API responses.

✅ HMAC webhook verification

Every incoming webhook is verified against the provider’s signature before any action is taken. Replay attacks are rejected. Idempotency keys prevent double-processing.

🔄 Pluggable provider interface

Adding a new payment provider means implementing a three-method TypeScript interface: createCheckout, handleWebhook, createRefund. That’s it.

🔷 Free ticket path

Zero-value orders bypass the payment provider entirely. Confirmation emails, QR codes, and attendee records are created identically — no special case handling needed.

Automated emails that feel personal. Blasts that convert.

Two layers of email: automated drip sequences tied to event timing, and manual blast campaigns to targeted audience segments. Both run through the client’s own Mailgun account.

⌛ Drip campaigns

Configure email sequences for each event: “send 7 days before”, “send on the day”, “send 3 days after”. Reusable templates with personalisation tokens for attendee name, event details, and ticket info.

📤 Email blasts

Send a one-off campaign to any audience segment — all attendees, a specific event’s guests, or a CRM segment like “lapsed customers”. Subject, body, filter, fire.

📈 Campaign attribution

Every blast generates a unique campaign ID. When an attendee clicks through and buys, the order is tagged. Revenue Intelligence shows exactly how much each campaign drove.

📨 Transactional confirmations

Instant booking confirmation with ticket summary and QR code. Reminder emails sent automatically before events. All using the client’s own sending domain.

📝 Reusable templates

Create and save email templates once, reuse across events. Personalisation tokens: {{name}}, {{event}}, {{date}}, {{venue}}, {{ticket_type}}.

🔹 Waitlist notifications

When a sold-out event gets a cancellation, waitlisted attendees receive an automated email with a time-limited claim link. First come, first served, fully automated.

🔁 Abandoned checkout recovery

When an attendee enters their details but doesn’t complete the purchase, qwikr.events triggers an automated three-stage recovery sequence: at 30 minutes, 4 hours, and 20 hours. Each message is fully customisable and can include a discount code. Sent count, recovery rate, and attributed revenue are all tracked.

Every edge case covered, out of the box.

Multiple ticket types per event, flexible sale windows, capacity management, discount codes, comp tickets, ticket transfers, and custom attendee fields. The full set from day one.

🎟 Multiple ticket tiers

Create Early Bird, General, VIP, Group, and any custom ticket types per event. Each type has its own price, capacity, sale window, and attendee fields.

📅 Sale windows

Set a start and end time for each ticket type. Early Bird closes automatically at the right moment. Sales stop when capacity is reached or the window closes — no manual intervention.

🆕 Discount codes

Percentage or fixed-value discounts. Per-code usage limits. Expiry dates. Codes can be restricted to specific ticket types or events. Full reporting on redemptions.

🆕 Comp tickets

Issue complimentary tickets to any attendee directly from the dashboard. Full audit trail. Comp orders bypass payment processing but follow the same QR code and confirmation flow.

🔄 Ticket transfers

Attendees can transfer their ticket to someone else via a secure tokenised link. The original ticket is voided and a new one issued to the transferee. Full check-in integrity maintained.

📌 Custom attendee fields

Define custom questions per ticket type: dietary requirements, t-shirt size, company name, accessibility needs. Answers captured at checkout, exported with attendee CSV.

⏳ Waitlist management

When an event sells out, attendees can join the waitlist. Cancellations trigger automatic waitlist notifications. Claim links expire after a configurable window.

🖼 Referral tracking

Generate unique referral links per attendee. Track how many tickets each referral drove. Reward your best promoters with discount codes or comp tickets.

📄 Attendee CSV export

Export the full attendee list for any event, including custom field answers, ticket types, order values, check-in status, and referral data. One click, clean spreadsheet.

📋 Event templates

Save any event as a reusable template — including all ticket types, pricing, capacity, sale windows, attendee questions, and drip email configuration. Recurring events (monthly nights, weekly sessions, annual fixtures) are created in seconds. Templates can be updated independently of events already created from them.

Know your audience. Act on it.

A lightweight CRM built around event history. Every customer’s attendance record, spend, notes, and tags are in one place. Audience segments are calculated automatically so you always know who to target.

  • 👤
    Customer profiles Every attendee gets a profile showing their full event history, total spend, ticket types, notes, and tags. Built from order data — no manual entry.
  • 📌
    Audience segments Six pre-built segments calculated on demand: lapsed (90+ days), new (first 30 days), high value (top 10% spend), single event, repeat, and at-risk.
  • 📋
    Notes & tags Admin staff can add private notes and custom tags to any customer record. Tags are filterable and exportable. Notes are timestamped with the author.
  • 📤
    Segment blasts Select any audience segment and fire a targeted email campaign directly from the CRM. No CSV export, no external tool, no manual list-building.
  • 🔍
    Flexible audience builder Beyond presets, build custom audiences by filtering on event attendance, spend range, date of last purchase, tags, and more.
Audience overview
High value (top 10% spend)
234
Repeat attendees (2+ events)
892
New this month
156
Lapsed (90+ days inactive)
341
At risk (spending declined)
89
Customer profile — Sarah Mitchell
VIP High value Repeat
14 events · £2,840 total spend · Last seen 8 days ago

Stop guessing what’s working.

Revenue Intelligence is a layer of analytics built on top of your real order and campaign data. No third-party tracking scripts, no GDPR headaches, no BI tool to configure. Everything lives in your client’s isolated database and answers the questions that matter.

📈 Campaign attribution

Every email campaign generates a campaignId that’s tracked through checkout. See exactly how much revenue each blast generated, how many orders it drove, and the conversion rate.

📋 Cohort retention

18 months of cohort analysis. See which monthly cohorts retained well, which churned early, and how retention trends have changed over time. Data per event and across the whole account.

👥 Audience segments

Six pre-calculated audience groups: lapsed, new, high-value, single-event, repeat, and at-risk. Segment counts update on demand. Each segment is blastable in one click.

🔴 At-risk detection

Customers whose average purchase frequency has dropped are automatically flagged. Re-engage them before they lapse — not after.

🆕 Event-level attribution

Attribution is tracked per event as well as at the account level. See which events drove the most returning customers, not just the most first-time buyers.

🔒 Privacy-first

All analytics data is derived from first-party order data in the client’s own isolated database. No third-party tracking scripts, no cookies, no cross-domain data sharing.

Any device. Any venue. No app required.

Venue staff scan QR codes using their phone’s camera. No app install, no dedicated hardware, no Wi-Fi dependency for the QR code itself. The check-in interface is a web page — open it, scan, done.

📱 Any device

The check-in page works on any smartphone, tablet, or laptop with a camera. iOS, Android, desktop — no app to install, no account required for scanning staff.

🔓 Rotatable check-in tokens

Check-in credentials are completely separate from admin credentials. Hand them to venue staff without any risk. Rotate them after the event with one click.

✅ Real-time validation

QR codes are HMAC-signed. Forgery is impossible. Duplicate scans are rejected with a clear “already checked in” status — no double admissions.

📊 Live check-in dashboard

Admins see a live count of attendees checked in vs total tickets sold. Drill down to individual attendee check-in times from the dashboard at any point.

📋 Attendee lookup

Staff can search by name or email on the check-in page for attendees whose phone battery is dead. Manual check-in with a full audit trail.

🆔 Multi-event support

Check-in tokens are scoped to a specific event. Staff at Event A can’t accidentally check in tickets for Event B.

Headless at the core. Bring your own frontend.

Every feature is available via a clean JSON API. The included frontend templates are a starting point — replace any part of them, or build something entirely your own. The platform is the API, not the UI.

  • 🔗
    REST JSON API Every operation — events, tickets, orders, attendees, campaigns, check-in, CRM — is a versioned JSON endpoint. Standard HTTP verbs, standard status codes.
  • Idempotency keys Checkout and mutation endpoints accept Idempotency-Key headers. Safe to retry on network failure without double-charging or double-provisioning.
  • 🔒
    JWT authentication HS256 JWTs for admin routes, scoped check-in tokens for venue staff, and separate platform JWTs for the operator. Fully decoupled auth layers.
  • Edge-native — globally deployed The API runs on Bunny Edge Scripting, serving from the nearest of Bunny’s global PoPs. Sub-50ms response times worldwide. No cold starts.
  • 📈
    Rate limiting Per-IP and per-tenant rate limiting on all public endpoints. Configurable thresholds. Abuse is blocked before it reaches the database.
// Example: list upcoming events GET /api/events?status=published // Response { "events": [{ "id": "a1b2c3d4...", "title": "Summer Festival 2026", "starts_at": "2026-07-01T18:00:00Z", "venue": "Hyde Park, London", "tickets": [{ "type": "General Admission", "price": 4500, "available": 388 }] }] }
Request API documentation →

The platform that runs itself. Quietly.

Timed reminders, drip sequences, abandoned checkout recovery, and job retry queues all run automatically. An operations dashboard gives you a live view of everything that’s happened — and a clear signal if anything needs attention.

⏱ Automated event reminders

Every event automatically triggers two reminder emails to ticket holders: 48 hours before and 2 hours before. No manual scheduling. No forgetting. Attendees arrive prepared and on time.

🔁 Abandoned checkout recovery

Three-stage automated recovery sequence at 30 minutes, 4 hours, and 20 hours after abandonment. Each email is fully customisable and can include a discount code to close the sale. Sent counts, recovery rates, and revenue attributed to recovery are all tracked.

⌛ Drip email sequences

Configure time-based email sequences per event: “send 7 days before”, “morning of”, “3 days after”. Runs fully automatically for every event. No per-event setup once the template is configured.

🔄 Failed job retry queue

If any outbound email (confirmation, campaign, recovery, reminder) fails to deliver, it is captured in a retry queue. Failed jobs are visible in the dashboard. Retry any job individually with one click. Nothing is silently lost.

📊 Automation status dashboard

A live dashboard view of all automation activity: reminder sends, drip sequences, abandoned recovery, job queue depth, and customer profile build status. Know immediately if any automation has stalled or fallen behind.

📋 Full audit trail

Every admin action — campaign sent, ticket comped, automation triggered, settings changed, job retried — is logged with actor, timestamp, IP, and context. Queryable from the dashboard. Essential for multi-staff accounts.

Security that never asks you to think about it.

AES-256-GCM encryption at rest for all credentials, HMAC-signed QR codes and webhook payloads, scoped JWT authentication, edge-native global deployment, and idempotent writes throughout. The security model is baked into the architecture — not bolted on.

🔓 AES-256-GCM credential encryption

Every payment provider key, database token, and API secret is encrypted with AES-256-GCM before being stored. Secrets are decrypted in memory at request time only — never logged, never stored in plaintext, never exposed in any API response.

🔒 HMAC-signed QR codes

Every ticket QR code contains an HMAC-SHA256 signature. Forgery is cryptographically impossible. Duplicate scans are rejected with a clear “already checked in” status. You cannot check in a ticket that wasn’t issued by the platform.

✅ HMAC webhook verification

Every incoming Stripe and SumUp webhook is verified against the provider signature before any action is taken. Replayed or tampered requests are rejected before they touch the database. Idempotency keys prevent double-processing on retries.

🔐 Scoped JWT authentication

Three completely separate auth layers: admin JWTs (HS256) for dashboard access, scoped check-in tokens for venue staff (no admin rights, rotatable post-event), and platform JWTs for operator access. A compromised check-in token cannot touch orders, settings, or customer data.

🚫 Per-IP and per-tenant rate limiting

All public endpoints (checkout, events, waitlist) are rate-limited per IP and per tenant before the request reaches the database. Abuse is blocked at the edge. Configurable thresholds per route. Brute-force credential attacks are throttled at the API layer.

⚡ Edge-native — no cold starts, global PoPs

The entire platform runs on Bunny Edge Scripting, deployed to Bunny’s global network of Points of Presence. Requests are served from the nearest PoP. No traditional servers, no cold starts, no single region as a single point of failure. Sub-50ms response times globally.

📄 True tenant data isolation

Each company gets a fully separate Bunny Database instance. There is no shared schema, no row-level isolation to misconfigure, no risk of a query accidentally returning another tenant’s data. Physical separation at the database layer, not the application layer.

✅ Idempotent writes throughout

Checkout, campaign send, and all mutation endpoints accept idempotency keys. Network failures and retries never result in double charges, double sends, or duplicate attendee records. Safe to retry any operation from any client.

Every brand feels like it was built from scratch.

Beyond logo and colour, the platform supports multiple page layout templates, configurable typography, custom CSS injection, per-tenant locale, timezone, and currency. Every public-facing page adapts completely to each organiser’s brand identity.

🎨 Full brand token system

Primary colour, accent colour, text colour, background colour, font stack, logo URL, and custom CSS URL are all stored per tenant. Every page — ticketing site, checkout, emails — inherits the brand automatically. Changes take effect immediately.

📄 Multiple page layout templates

Each tenant can select from multiple pre-built layouts for the homepage, event listing pages, and individual event pages. Layout templates control structure (hero-first, editorial, balanced, focused) independently of brand colours and fonts.

🛠 Configurable UI density & style

Button style (pill, rounded, square), card density (compact, comfortable, spacious), hero style (soft, bold, minimal), and header layout are all configurable per tenant. The same platform presents completely differently for a boutique jazz night and a large music festival.

📝 Custom CSS injection

Beyond the brand token system, organisers can provide a hosted CSS file that is loaded on every public page. Complete override capability for edge cases: custom fonts, layout adjustments, promotional banners, bespoke widget styling.

🌎 Localisation & timezone support

Currency, timezone, and locale are configurable per tenant. Event dates and times display correctly in the organiser’s local timezone. Currency symbols and formatting adapt to the configured locale. Multi-currency support is independent of the payment provider.

📩 Custom homepage content

Organisers configure their ticketing homepage headline, subheadline, and eyebrow text directly from the dashboard. Homepage sections (search, categories, featured events) are individually toggle-able. The homepage can be built around the brand voice, not a generic template.

Every feature. Live in under an hour.

Provisioning takes 10 seconds. Everything above is available from the moment your account is created — nothing to configure, nothing to wait for.

Request access → Ask us anything