← All policies

Data Retention Policy

Effective Date: July 24, 2026 Last Updated: July 24, 2026

This Data Retention Policy explains how long we keep different categories of Personal Data, and why. It supplements our Privacy Policy.

1. Guiding Principle

We retain Personal Data only for as long as necessary to provide the App, comply with our legal obligations, resolve disputes, and enforce our agreements — not indefinitely by default.

2. What We Retain, and For How Long

Data CategoryRetained WhileAfter Account Deletion
Account/profile data (name, email, phone, DOB, bio, location, profile picture)Account is activeDeleted/inaccessible immediately upon deletion (see §3)
Authentication data (password hash, social sign-in identifiers)Account is activeDeleted upon account deletion
Booking and payment recordsIndefinitely, for accounting/audit purposesRetained for statutory financial recordkeeping (generally up to 8 years, in line with applicable Indian tax and financial recordkeeping requirements)
Organizer KYC documentsWhile organizer status is active or under reviewRetained for statutory recordkeeping purposes for verified organizers, consistent with financial/compliance requirements
Refund and payout recordsIndefinitely, for accounting/audit purposesRetained for statutory financial recordkeeping
Reviews, chat messages, ShortsUntil you or an administrator removes them, or your account is deletedRemoved or de-identified upon account deletion, except where retained as part of another user's booking/event record
Audit logs (administrative actions)Indefinitely, for security and accountabilityRetained (these record actions taken by staff, not your personal browsing activity)
One-time passcodes (password reset / email verification)Until used or expired (short, fixed window)N/A — never retained beyond their validity window

3. Effect of Account Deletion

When you delete your account (Settings → Delete Account, see our Account Deletion Policy), your account is immediately deactivated and can no longer be logged into. Your profile data is no longer accessible or displayed within the App. Certain records — specifically completed booking, payment, refund, and payout records — are retained in our systems as required for financial recordkeeping and dispute resolution, even though they are no longer linked to an active, usable account.

4. Backups

Our database infrastructure provider maintains routine backups for disaster-recovery purposes. Data deleted from our live database may persist in backup snapshots for a limited additional period before being permanently purged as those backups age out and are replaced, consistent with our provider's standard backup rotation.

5. Deletion Procedures

5.1 Self-service account deletion (Settings → Delete Account) is a soft-delete: your account row is marked deleted and immediately excluded from all active queries and authentication, but is not instantly and irreversibly purged from the database (this preserves the retained records described in §2/§3 and supports fraud/dispute investigation).

5.2 Self-service data erasure (Settings → Delete My Data) goes further, exercising your erasure right under Section 12 of the Digital Personal Data Protection Act, 2023: we erase every category of Personal Data that has no independent statutory retention basis, immediately, upon a verified request. Because this Act permits (and Indian tax/financial recordkeeping law requires) us to retain certain records even after an erasure request, this feature works as follows:

  • Identity verification first. You must confirm your current password, or re-authenticate with the social sign-in provider linked to your account, before anything is erased — this prevents someone else who merely holds your logged-in session from erasing your data on your behalf.
  • Erased outright: your profile (name, email, phone, date of birth, bio, location, profile picture, password), interests, saved/favorited events, organizer follows, waitlist entries, registered devices, active login sessions, and linked social sign-in identities.
  • Pseudonymized, not erased: your account record itself is not deleted, because the statutorily-retained records below still need a valid reference to it. Instead, its identifying fields are replaced with generic, non-identifying values (e.g. your name becomes "Deleted User" and your email becomes a randomly generated address that does not reach you).
  • Retained, per §2 above: booking, payment, refund, and payout records; organizer KYC documents where applicable; and administrative audit logs. These remain linked to your now-pseudonymized account record, not to your real name, email, or phone number.
  • Logged. The fact that an erasure occurred, when, and what was erased versus retained, is itself recorded in our internal audit log, as evidence of compliance.

This is processed immediately once your identity is verified — it is not a manual or best-effort process. See our Account Deletion Policy §7 for the user-facing walkthrough of this feature.

6. Contact

Support Email: support@eventrix.app