Legal

Privacy policy

Last updated 1 August 2026

What we collect, why we collect it, who else sees it, and what you can ask us to do about it. Written to be read, not to be impenetrable.

Not yet reviewed by a lawyer. This document was drafted against Indian law as it stands in August 2026, but it is a starting draft, not legal advice. Every value marked in pink must be filled in, and the whole document should be reviewed by a qualified Indian advocate before Evento accepts real money. See docs/legal-checklist.md in the repository for the full list of what is outstanding.

1. Who is responsible for your data

Evento is operated by [legal entity name], registered office [full registered address]. For personal data you give to Evento itself, we are the Data Fiduciary under India's Digital Personal Data Protection Act, 2023 (“DPDP Act”), and the body corporate responsible under the Information Technology Act, 2000 and its rules.

For questions or requests about your data, contact [privacy email]. Our grievance contact and response timelines are on the support page.

2. An important split: us and the organiser

When you register for an event, your details are visible to two parties, and they are responsible for them separately:

  • Evento processes your data to run the platform — your account, your tickets, payments, and check-in.
  • The organiser of that event receives your name, email address and ticket details so they can run the event and admit you. They decide independently what else they do with it, and they are responsible for that. Our terms require them to handle it lawfully and forbid them from selling it, but their own privacy practices are theirs.

If you want an organiser to delete data they hold about you, contact that organiser. If you cannot reach them, we will help — write to [privacy email].

3. What we collect

DataWhy we have it
Name, email address, and optionally phone numberTo identify your account, issue tickets in your name, and email your tickets to you
Sign-in records and session informationTo keep you signed in and to detect unauthorised access
Google account name, email and profile picture, if you sign in with GoogleTo create and identify your account without a separate password
Your orders, tickets, ticket codes and check-in recordsTo sell you a ticket, admit you at the door, and prevent the same ticket being used twice
Clubs you have joinedTo show you their events, including members-only ones
Payment identifiers and amounts from RazorpayTo confirm your payment succeeded, issue your ticket, and keep financial records
Organiser business details: bank account, PAN, business name and address, contact detailsTo create the organiser's payout account with Razorpay so ticket money can reach them, and to meet Razorpay's and the law's verification requirements
Server logs, including IP address and browser typeTo keep the service working, investigate faults, and detect abuse

We do not collect or store your card number, UPI PIN, CVV, or bank credentials. Payment details are entered on Razorpay's own checkout and never reach our servers.

We do not knowingly collect data from children under 18. If you believe a child has given us data, write to [privacy email] and we will delete it.

4. Why we are allowed to use it

Under the DPDP Act, we process your personal data on these bases:

  • Your consent, given when you create an account or register for an event, for issuing tickets and communicating about them.
  • Legitimate uses permitted by the Act, including where you have voluntarily given us data for a purpose you would reasonably expect, and for compliance with law.
  • Legal obligation, for tax, accounting and financial records we are required to keep.

You can withdraw consent at any time, as easily as you gave it, by contacting [privacy email]. Withdrawing consent does not undo processing already done lawfully, and we may still need to keep records the law requires us to keep.

5. Who we share it with

We share your data only where necessary, and never sell it. Recipients are:

  • The organiser of an event you register for — your name, email and ticket details, as described in section 2.
  • Razorpay — to process payments and, for organisers, to create and verify payout accounts. Razorpay is an independent controller of the data it collects; see their own privacy policy.
  • Resend — our transactional email provider, to deliver your ticket and sign-in emails.
  • Our hosting and database providers — who store the data so the service can run.
  • Law enforcement, courts or regulators — where we are legally required to disclose, or where necessary to establish or defend a legal claim.
  • An acquirer — if Evento is sold or merged, in which case this policy continues to apply to data transferred until it is replaced with notice to you.

Some of these providers process data outside India. Where that happens, we rely on the DPDP Act's permission to transfer personal data outside India except to countries the Central Government has restricted.

6. How long we keep it

  • Account data: while your account exists, and for a reasonable period after closure to handle disputes.
  • Tickets and check-in records: retained after the event as the record of who bought and who attended, which is needed for refunds and disputes.
  • Payment and financial records: for as long as tax and accounting law requires — currently up to eight years for certain records.
  • Server logs: a short operational period, then deleted or aggregated.

When data is no longer needed for any of these purposes, we delete it or irreversibly anonymise it.

7. Your rights

Under the DPDP Act, you have the right to:

  • Access — a summary of the personal data we hold about you and how we process it, and the identities of others we have shared it with.
  • Correction and completion — to have inaccurate or incomplete data corrected, completed or updated.
  • Erasure — to have your data deleted, unless we are required to keep it by law or need it for a purpose it was collected for.
  • Grievance redressal — to complain to us and get a response, before going to the Data Protection Board.
  • Nomination — to nominate another person to exercise these rights on your behalf if you die or become incapacitated.

To exercise any of these, write to [privacy email]. We will respond within 30 days, and in any case within the 90 days the DPDP Rules allow. We may ask you to verify your identity first, so that we do not disclose your data to someone else.

If you are unhappy with our response, you may complain to the Data Protection Board of India.

8. How we protect it

Concretely, and not just as a promise:

  • Data is separated by organisation at the database access layer, so one organiser cannot read another's attendees, orders or revenue.
  • Ticket codes are 128-bit random values, so a valid code cannot be guessed from another one.
  • We never store your card, UPI or bank credentials — those go directly to Razorpay.
  • Access to production data is limited to people who need it to operate the service.
  • Traffic is encrypted in transit.

No system is perfectly secure. If a breach affects your personal data, we will notify the Data Protection Board and affected users as the DPDP Rules require, including a detailed report to the Board within 72 hours.

9. Cookies and similar technologies

We use a small number of cookies that are necessary for the service to work — principally to keep you signed in. We do not use advertising cookies or third-party tracking pixels, and we do not build advertising profiles.

Blocking essential cookies will prevent you from signing in.

10. Marketing

We send transactional email — sign-in links, tickets, and messages about events you registered for. We do not add you to marketing lists without asking, and any marketing email we do send will have a way to unsubscribe.

An organiser may contact you about their own event. If you would rather they did not, tell them, or tell us and we will pass it on.

11. Changes

If we change this policy, the “last updated” date changes, and we will give notice of material changes by email or in the product.

12. Contact

Questions, requests or complaints about privacy: [privacy email]. For anything else, or to escalate, see the support page.