Privacy Policy
Eventnet Technologies Private Limited ("Eventnet", "we", "us") is committed to protecting your personal data. This policy explains what data we collect, why we collect it, how we use and protect it, and your rights as a Data Principal under the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000.
Last updated: July 2026 · Applies to: Eventnet Vendor Portal
1. Data Fiduciary
Eventnet Technologies Private Limited is the Data Fiduciary as defined under the DPDP Act 2023. We determine the purpose and means of processing your personal data. Our registered office is in Indore, Madhya Pradesh, India.
2. Data We Collect
2.1 Account and Identity Data
- Full name, mobile number, and email address
- Date of birth (for age verification where required)
- OTP verification metadata: timestamps, device fingerprint, success/failure logs
- Profile photo
2.2 Business and Verification Data
- Business name, category, city, and service area
- Government-issued business documents: Gumasta / Shop Establishment Certificate, GST Certificate, MSME / Udyam Registration, FSSAI Licence, Trade Licence, Company Registration
- Identity proof: Aadhaar card, PAN card, Voter ID, Passport or Driving Licence
- Bank account details: account holder name, bank name, account number, IFSC code, UPI ID
- Cancelled cheque image
2.3 Profile and Portfolio Data
- Business logo, cover banner, and portfolio photographs/videos
- Service packages, descriptions, pricing, add-ons, and availability settings
- Team member names and photos (if voluntarily added)
- FAQs and business descriptions
2.4 Transaction and Booking Data
- Booking requests, confirmations, cancellations, and status history
- Customer names, event details, and contact information associated with your bookings
- Payment amounts, advance amounts, payout records, and commission deductions
- TDS certificates and payment transaction records
- Support tickets, dispute records, and complaint communications
2.5 Technical and Usage Data
- IP address, device type, browser type and version, operating system
- Login timestamps, session duration, and feature usage logs
- Error logs and crash reports
- Cookie identifiers and similar tracking technologies
3. How We Use Your Data
We process your personal data only for the following specified purposes:
- Operating, maintaining, and improving the Eventnet Vendor Portal
- Verifying your identity and business credentials as required by law and platform policy
- Processing bookings, facilitating payments, and disbursing payouts
- Sending OTPs, booking notifications, payout alerts, and critical account communications
- Displaying your profile, packages, and portfolio to customers on the Eventnet marketplace
- Complying with legal and regulatory obligations including TDS deduction, GST compliance, and law enforcement requests
- Preventing, detecting, and investigating fraud, abuse, and policy violations
- Improving platform features, personalising your dashboard experience, and conducting analytics
- Marketing and promotional communications (with your consent; you may opt out at any time)
We do not use your sensitive personal data (Aadhaar, PAN, bank details, identity documents) for any purpose other than verification and payout processing.
4. Consent
Under the DPDP Act 2023, we rely on your free, specific, informed, and unambiguous consent as the lawful basis for processing your personal data, except where processing is permitted for legitimate uses specified under the Act.
By registering on the Vendor Portal, you provide consent to the collection and processing of your data as described in this policy. You have the right to withdraw consent at any time by contacting us at privacy@eventnet.in. Withdrawal of consent may affect your ability to use the platform.
Under the DPDP Rules, 2025, Consent Manager integration for exercising and managing consent becomes mandatory across covered platforms by November 2026. We will update this policy and our consent flows as that requirement takes effect.
5. Data Sharing and Disclosure
We share your data only as necessary and only with:
- Customers — your public profile, portfolio, contact details (phone/email), and booking status as required to facilitate the service transaction
- Payment processors (Razorpay) — for payment collection, payout disbursement, and fraud prevention, including calculating and applying No-Cost EMI subvention deductions to your payouts if you opt in to that feature
- Communication providers — for OTP delivery, email notifications, and WhatsApp alerts (e.g. Twilio, AWS SES, MSG91)
- Cloud infrastructure providers — Supabase (database and file storage), hosted on AWS infrastructure. Data is stored in secure servers; Supabase acts as a Data Processor under contractual data processing agreements
- Verification partners — for document authentication and KYC processing
- Professional advisors — accountants, auditors, and legal advisors bound by confidentiality
- Government authorities and law enforcement — where legally required under a court order, statutory obligation, or investigation under applicable law
We never sell, rent, or trade your personal data to any third party for commercial purposes.
Cross-border data transfers: Your data may be processed by our service providers outside India. We ensure such transfers are protected by contractual safeguards consistent with the DPDP Act 2023 and applicable data protection standards.
6. Data Retention
We retain your personal data for the following periods:
- Account and profile data: for the duration of your active account, plus 3 years after closure
- Verification documents (Aadhaar, PAN, GST, etc.): 7 years from the date of collection, as required by law and for dispute resolution
- Bank account and payout records: 8 years from the date of last transaction, as required by Indian financial regulations
- Booking and transaction records: 7 years, as required under GST and income tax laws
- Support and dispute records: 3 years from resolution
- Technical logs and usage data: 12 months from collection
After the applicable retention period, data is securely deleted or anonymised. You may request early deletion of your account data through Settings, subject to legal retention obligations described above.
7. Your Rights as a Data Principal
Under the DPDP Act 2023, you have the following rights:
- Right to access: Obtain a summary of the personal data we hold about you and how it has been processed
- Right to correction: Require us to correct inaccurate or incomplete personal data
- Right to erasure: Request deletion of your personal data, subject to legal retention obligations
- Right to grievance redressal: Lodge a complaint with our Data Protection Officer if you believe your rights have been violated
- Right to nomination: Nominate a person to exercise your rights in the event of your death or incapacity
- Right to withdraw consent: Withdraw consent for processing at any time (this will not affect processing carried out before withdrawal)
To exercise any of these rights, email our Data Protection Officer at privacy@eventnet.in. We will respond within 15 days.
8. Security Measures
We implement industry-standard technical and organisational security measures, including:
- TLS/HTTPS encryption for all data in transit
- AES-256 encryption for sensitive data at rest
- Row-level security (RLS) on all database tables — you can only access your own data
- Verification documents stored in access-controlled private Supabase storage buckets
- OTP-based authentication with rate limiting and expiry
- Role-based access controls limiting staff access to personal data on a need-to-know basis
- Regular security audits and vulnerability assessments
Security incidents: In the event of a personal data breach that is likely to result in risk to your rights or interests, we will notify the Data Protection Board of India (as required) and will inform you directly within 72 hours of becoming aware of the breach.
9. Cookies and Tracking
We use cookies and similar technologies to:
- Keep you signed in (authentication session cookies — essential, cannot be disabled)
- Remember your dashboard preferences (functional cookies)
- Measure platform performance and usage analytics (analytics cookies)
We do not use third-party advertising cookies. You can manage non-essential cookies through your browser settings. Disabling essential cookies will prevent you from using the platform.
10. Children's Data
The Eventnet Vendor Portal is not intended for persons under 18 years of age. We do not knowingly collect personal data from minors. If you believe a minor has registered, please contact us at privacy@eventnet.in and we will take immediate action to delete the relevant data.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in law, our practices, or platform features. Material changes will be communicated to you by email and/or in-app notification at least 7 days before they take effect. Continued use of the platform after the effective date constitutes acceptance.
12. Data Protection Officer / Grievance Officer
For any privacy-related questions, requests to exercise your rights, or complaints:
Data Protection Officer
Eventnet Technologies Private Limited
Email: privacy@eventnet.in
Address: Indore, Madhya Pradesh, India
Response time: Acknowledgement within 24 hours, resolution within 15 days
If you are not satisfied with our resolution, you may lodge a complaint with the Data Protection Board of India once it is constituted under the DPDP Act 2023.