Privacy Policy
Effective Date: July 24, 2026 Last Updated: July 24, 2026
1. Introduction
This Privacy Policy explains how Eventrix ("Eventrix," "we," "us," or "our"), operated by The Ladders Tech, a company incorporated under the laws of India with its registered office at Pune, Maharashtra, India ("Company"), collects, uses, stores, shares, and protects personal data when you use the Eventrix mobile application, any associated web interfaces, and related services (collectively, the "App" or "Service").
This Policy is drafted to comply with the applicable provisions of the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000 and rules made thereunder, and, where relevant to users outside India, has regard to internationally recognized privacy principles (such as purpose limitation, data minimization, and user control) reflected in frameworks like the GDPR. It does not itself constitute a representation that the GDPR applies to your use of the App.
By creating an account or using the App, you agree to the collection and use of information as described in this Policy. If you do not agree, please do not use the App.
2. Definitions
- "Participant" means a user who browses, books, or attends events through the App.
- "Organizer" means a user who has applied for and/or holds organizer status to create and manage events.
- "Personal Data" means any data that identifies or relates to an identifiable natural person.
- "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.
- "Third-Party Service Provider" means an external company that processes data on our behalf or provides infrastructure the App relies on.
3. Information We Collect
3.1 Information You Provide Directly
| Category | Data Points | Applies To |
|---|---|---|
| Account/Identity | Email address, full name, phone number (optional), password (see §7), date of birth, gender | All users |
| Profile | Profile picture, bio | All users |
| Location | Free-text location/address, precise latitude/longitude coordinates | Participants (for nearby-event discovery) |
| Interests | Selected event categories | Participants |
| Organizer Profile | Company name, description, website, company logo | Organizers |
| Organizer Verification (KYC) | Identity proof document, address proof document, PAN card or Aadhaar card image, UPI ID (for payouts) | Organizers applying for verification |
| Booking Data | Event enrollments, ticket quantity, booking reference, payment amount and status | Participants |
| Community Content | Event reviews (rating and text), event group-chat messages, short-form video uploads and captions | Participants/Organizers who choose to post |
| Support Communications | Any information you provide when contacting support | All users |
3.2 Information Collected Automatically
- Push notification token: a device-specific identifier issued by Expo's push service, used to deliver notifications to your device. Only one token is stored per account (the most recently registered device).
- Notification preferences: your chosen categories (event reminders, nearby events, community updates, offers) and master on/off switches for push and email notifications.
- Standard technical/request metadata (such as IP address and request timestamps) may be logged by our hosting and infrastructure providers for security, abuse prevention, and reliability purposes, consistent with their own standard logging practices.
3.3 Information from Third-Party Sign-In
If you register or log in using Google, Apple, or Facebook, we receive and store:
- Your name, email address, and profile picture, as made available by that provider, and a provider-issued identifier used to link your social account to your Eventrix account.
We independently and cryptographically verify these sign-ins with the relevant provider before trusting any identity information they supply; we do not accept unverified claims from your device.
Signing in with Facebook specifically requires granting us access to your email address. If that permission is declined, sign-in is not completed — we do not create an account without a real, usable email address on file, since your email is how we deliver booking confirmations, receipts, and account-security notices.
3.4 Information We Do Not Collect
We do not collect card numbers, CVV, bank account numbers, or UPI PINs. Full payment credentials are entered directly into our payment gateway's own secure interface and never pass through or are stored on Eventrix's servers. See §9 (Payment Information).
4. How We Collect Information
- Directly from you, when you register, complete your profile, apply for organizer verification, book an event, post a review/chat message/short, or contact support.
- Automatically, through your device and app usage (push token, notification settings, standard request metadata via our infrastructure providers).
- From third parties, when you choose to authenticate via Google, Apple, or Facebook, and from our payment gateway (transaction status and a gateway-issued reference ID, never full payment credentials).
5. Why We Collect Information (Purposes)
| Purpose | Data Used |
|---|---|
| Creating and authenticating your account | Email, password (hashed), phone, social sign-in identifiers |
| Verifying your identity for organizer status | KYC documents, full name |
| Discovering and displaying nearby/relevant events | Location, latitude/longitude, interests |
| Processing event bookings and payments | Booking data, payment amount/status/gateway reference |
| Calculating and paying organizer payouts | Commission configuration, UPI ID, payment/booking records |
| Sending transactional communications | Email address, push token, notification preferences |
| Enabling community features | Reviews, chat messages, short-form videos |
| Preventing fraud, abuse, and enforcing our Terms | Account status, audit logs of administrative actions |
| Legal and regulatory compliance | KYC records, payment records, audit logs |
6. Legal Basis for Processing
Under the DPDP Act, our primary legal basis for processing your Personal Data is your consent, given at the time you create an account, grant a permission (e.g., location), or submit information (e.g., KYC documents). We may also process limited data on the basis of legitimate uses recognized under the DPDP Act, such as preventing fraud, responding to a legal obligation, or in connection with a grievance or dispute you raise with us. Where applicable to users in jurisdictions recognizing GDPR-style bases, our processing corresponds to: performance of a contract with you (providing the App), legitimate interests (security, fraud prevention), consent (marketing/location), and compliance with legal obligations (KYC, financial recordkeeping).
7. How Your Data Is Stored and Secured
- Your account data is stored in a managed PostgreSQL database hosted via our database infrastructure provider (Supabase).
- Passwords are never stored in plain text. They are hashed using the industry-standard bcrypt algorithm before storage; we cannot see or recover your actual password.
- One-time passcodes (OTPs) used for password reset and email verification are stored as one-way cryptographic hashes, not in plain text, and automatically expire after a short, fixed time window.
- Organizer KYC documents (identity proof, address proof, PAN/Aadhaar) are stored in a private storage bucket that is never publicly accessible. They can only be viewed via short-lived, admin-restricted, time-limited access links generated on demand.
- Data in transit between the App and our servers is encrypted using HTTPS/TLS.
- See our separate Security Policy for further detail.
8. Third-Party Services
We rely on the following categories of third-party service providers to operate the App. Each processes only the data necessary for its specific function:
| Provider Category | Purpose | Data Shared |
|---|---|---|
| Google, Apple, Facebook | Social sign-in/authentication | Sign-in token, resulting profile data (name, email, picture) |
| Supabase | Database and file storage hosting | All Personal Data described in this Policy; uploaded files/documents |
| Resend / SMTP email provider | Transactional email delivery (OTPs, booking confirmations, notifications) | Email address, email content |
| Expo | Push notification delivery; app build/distribution | Push token, notification title/body |
| Google Maps Platform | Reverse geocoding and map display for event discovery | Latitude/longitude coordinates |
| Vercel | Application hosting/infrastructure | Standard request metadata |
| Payment gateway (Razorpay) | Payment collection and processing | Booking amount, currency, and transaction status (see §9) |
We do not sell your Personal Data to third parties. We do not share your Personal Data with third parties for their own independent marketing purposes.
9. Payment Information
Paid ticket bookings are designed to be processed through Razorpay, an RBI-regulated payment aggregator, or another payment gateway we may engage from time to time. When you make a payment:
- Your card, net-banking, UPI, or wallet credentials are entered directly into the payment gateway's own secure, PCI-DSS-compliant checkout interface.
- Eventrix's servers never receive or store your full card number, CVV, bank account number, or UPI PIN.
- We store only the payment amount, currency (INR), payment status, and a gateway-issued reference/transaction ID needed to reconcile your booking.
Automated, fully live payment-gateway processing is in the process of being finalized for the App. This Policy, and our separate Payment Policy, will be kept accurate and up to date as this functionality is activated. We will not enable paid ticket collection for a given payment method until the corresponding gateway integration is live and secure.
10. Children's Privacy
The App collects a date of birth field but does not currently implement an automated minimum-age verification or parental-consent mechanism. The App is not intended for use by children under the age of 18, and organizer verification (which involves government identity documents) is inherently restricted to adults capable of providing such documents. If we become aware that we have collected Personal Data from a child without appropriate consent, we will take steps to delete that data. Parents or guardians who believe their child has provided us with Personal Data may contact us using the details in §16.
11. Data Retention
We retain Personal Data for as long as your account remains active, and thereafter as described in our separate Data Retention Policy, which covers retention periods for account data, booking/payment records (retained for statutory financial/tax purposes), KYC documents, and community content.
12. Your Rights
Subject to applicable law, you have the right to:
- Access the Personal Data we hold about you (available directly in-app via your Profile).
- Correct inaccurate profile information (available directly in-app via Edit Profile).
- Withdraw consent for optional features such as location sharing or notifications, via your device or in-app settings.
- Request deletion of your account, directly in-app via Settings → Delete Account, as described in our Account Deletion Policy.
- Request erasure of your Personal Data beyond a simple account deactivation, directly in-app via Settings → Delete My Data, under Section 12 of the Digital Personal Data Protection Act, 2023 — see §13 below and our Account Deletion Policy §7 and Data Retention Policy §5.2 for exactly what this erases versus what we remain legally required to retain.
- Raise a grievance regarding how your data is handled, as described in our Contact & Grievance Policy.
13. Account Deletion and Data Erasure
You may delete your account at any time directly within the App, from Settings → Delete Account. Deletion takes effect immediately: your session is ended and your account can no longer be used to log in. Full details of what is deleted, what is retained, and why, are set out in our Account Deletion Policy. If you are unable to access the App, you may also request deletion by contacting us using the details in §16.
Deleting your account deactivates it but does not, by itself, erase your Personal Data — certain records are retained as described in our Data Retention Policy. If you want your Personal Data erased beyond that retention, use Settings → Delete My Data instead, which requires confirming your identity (current password, or re-authentication with your linked sign-in provider) before proceeding. See our Account Deletion Policy §7 and Data Retention Policy §5.2 for the full mechanism, including exactly which data categories are erased outright versus retained under statutory obligation.
14. Data Transfers
Some of our third-party service providers (see §8) may process or store data on servers located outside India. Where this occurs, we require that providers maintain security and confidentiality standards consistent with this Policy.
15. Policy Updates
We may update this Privacy Policy from time to time to reflect changes in our practices, features, or applicable law. We will update the "Last Updated" date above when we do. Material changes will be notified to you through the App or via email before they take effect. Continued use of the App after an update constitutes acceptance of the revised Policy.
16. Contact Information
For any questions, requests, or concerns about this Privacy Policy or your Personal Data, please contact:
Support Email: support@eventrix.app Grievance Officer: See our Contact & Grievance Policy for statutory grievance-redressal contact details. Postal Address: Pune, Maharashtra, India