Privacy Policy
Last updated: [DATE]
⚠️ Not legal advice. This is a working draft written to reflect what this product actually does. Have a qualified lawyer review it — especially the data transfer, liability, and dispute sections — before it governs real users and real payments.
This Privacy Policy explains how [YOUR BUSINESS/TRADING NAME] ("we," "us," "the Platform") collects, uses, and protects information when you use our event website, ticketing, and guest-management service (the "Service").
If you are an event organizer, this policy also explains what we do with information about your guests on your behalf.
1. Information We Collect
From organizers (account holders)
- Name, email address, phone number (at signup)
- Event details you provide (event name, type, date, location, description, any photo you upload)
- Payment/payout details necessary to receive money from ticket sales (bank account details are collected and held by our payment processor, Paystack — see Section 4 — not stored directly by us)
From guests (ticket buyers / RSVPs)
- Name and phone number (required to RSVP or buy a ticket)
- Email address (optional, or auto-generated for payment processing if not provided)
- Purchase/RSVP history for the specific event(s) you interact with
- Check-in status and timestamp if you attend an event using our check-in system
Collected automatically
- Basic technical data (IP address, device/browser type) for security, fraud prevention, and service reliability
- Delivery status of WhatsApp/SMS messages we send you (sent, delivered, read, failed) — not the content of any reply you send back to us outside approved message templates
We do not collect or store
- Full card numbers or bank login credentials — payments are handled directly by Paystack's secure checkout; we never see or store your card details
- Any data from guests beyond what's needed to issue and verify a ticket or RSVP
2. How We Use Information
- To create and manage your account and your events
- To generate your AI-assisted event website from the details you provide
- To process ticket purchases and RSVPs, issue tickets, and verify them at check-in
- To send you transactional messages (ticket confirmations, RSVP confirmations, event reminders) via WhatsApp or SMS
- To detect and prevent fraud (e.g., unusual purchase patterns)
- To calculate and pay out organizer earnings from ticket sales
- To comply with legal obligations and respond to lawful requests
We do not sell your personal information to third parties, and we do not use guest data for advertising.
3. Legal Basis for Processing (where applicable)
Depending on your location, we process your information based on: your consent (e.g., when you RSVP or opt in to messages), the necessity of processing to perform a contract with you (e.g., issuing a ticket you paid for), our legitimate business interests (e.g., fraud prevention), and compliance with legal obligations.
4. Who We Share Information With
We share information only as needed to run the Service:
| Party | Purpose | What they receive |
|---|---|---|
| Paystack / Flutterwave | Payment processing | Payment amount, currency, buyer contact info needed to complete checkout |
| Supabase | Database and file storage hosting | All platform data, encrypted at rest |
| Meta (WhatsApp Business Platform) | Sending ticket/RSVP confirmations | Guest phone number, message content from approved templates |
| Termii | SMS fallback delivery | Guest phone number, message content, when WhatsApp delivery isn't available |
| Unsplash | Stock photography for AI-generated sites (when you don't upload your own photo) | No personal data — image search terms only |
| Vercel | Application hosting | Standard web request data |
We require these providers to protect your data and use it only to provide their service to us — not for their own independent purposes.
We may also disclose information if required by law, to protect the rights and safety of our users, or in connection with a business transfer (e.g., a merger or acquisition), in which case you'll be notified.
5. International Data Transfers
Our service providers may process data outside your home country (e.g., Supabase and Vercel infrastructure may be located outside Nigeria). Where this happens, we take reasonable steps to ensure your information receives an equivalent level of protection.
6. Data Retention
- Organizer accounts: retained while your account is active, and for a reasonable period after deletion to comply with financial record-keeping obligations (e.g., transaction and tax records).
- Guest data: retained for the duration of the event and a reasonable period after, primarily to handle refunds, disputes, and support requests.
- Ledger and payment records: retained as required by financial regulation, generally longer than other data categories.
You can request earlier deletion of your personal data (see Section 8), subject to our legal obligation to retain financial and transaction records.
7. Your Rights
If you are in Nigeria, you have rights under the Nigeria Data Protection Act (NDPA)/NDPR, including the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data, subject to our legal retention obligations
- Object to or restrict certain processing
- Request a copy of your data in a portable format
If you are located elsewhere, we extend these same rights to you as a matter of policy, regardless of where a specific law applies them.
To exercise any of these rights, contact us at [SUPPORT EMAIL].
8. How to Contact Us / Exercise Your Rights
Email: [SUPPORT EMAIL]
We will respond to legitimate requests within a reasonable timeframe, and no later than required by applicable law.
9. Security
We use industry-standard measures to protect your data, including encryption in transit and at rest, access controls limiting who can view sensitive data, and regular review of our systems. No system is perfectly secure, and we cannot guarantee absolute security, but we take reasonable steps to protect your information and will notify you as required by law in the event of a data breach affecting your personal data.
10. Children's Data
Our Service is intended for use by adults (18+) creating and managing events. We understand that event guest lists may include minors (e.g., a child attending a family wedding) — in that case, the minor's guardian is responsible for providing any necessary information on their behalf, and we do not knowingly collect data directly from children for account creation.
11. Changes to This Policy
We may update this policy from time to time. We'll update the "Last updated" date above, and for material changes, we'll make reasonable efforts to notify active organizers.
12. Contact
[YOUR BUSINESS/TRADING NAME] [Your contact address, if you have one] [SUPPORT EMAIL]