Privacy Policy
How Utsavs collects, uses, and protects your personal information — written to be clear, not just compliant.
1. Who This Policy Applies To
This Privacy Policy applies to all users of Utsavs (utsavs.app), including event organisers who create and manage events, attendees who register for events, and visitors who browse the platform. By using Utsavs, you agree to the collection and use of information as described in this policy.
2. Information We Collect
When you create an account, we collect your name, email address, and authentication credentials. Organisers additionally provide event details such as titles, descriptions, venue addresses, and banner images. Attendees provide their name and email address when registering for an event.
Paid ticket transactions are processed by Razorpay. We do not store your card number, CVV, UPI ID, or bank account details. Razorpay provides us with a transaction reference and payment status to confirm successful purchases.
We collect standard server logs including IP addresses, browser type, device type, and pages visited. This information is used for security monitoring, debugging, and improving platform reliability.
When you register for an event, we collect the details you submit (name, email, and any custom fields requested by the organiser). This information is shared with the event organiser so they can manage attendance.
When you apply a promo code at checkout, we record the code used, the discount amount, and associate it with your registration. This data is used for transaction records, organiser reporting, and to enforce usage limits on promo codes.
3. How We Use Your Information
- To create and manage your account on Utsavs.
- To process event registrations and deliver QR-coded tickets to attendees via email.
- To share attendee registration details with the organiser of the event registered for.
- To send transactional emails such as booking confirmations, ticket receipts, and event reminders.
- To process payments and verify transaction status through Razorpay.
- To respond to support queries and resolve disputes.
- To improve platform features, fix bugs, and monitor uptime and performance.
- To detect and prevent fraud, abuse, and security incidents.
4. How We Share Your Information
We do not sell your personal information. We share it only in the following circumstances:
- With event organisers: your name and email are shared when you register for their event.
- With Razorpay: payment and transaction details are processed and stored by Razorpay under their Privacy Policy.
- With Supabase: our infrastructure provider stores platform data (accounts, events, registrations) in secure, managed databases.
- With law enforcement or regulatory authorities: where required by law or valid legal process.
- With professional advisors: lawyers, accountants, or auditors where necessary and under confidentiality obligations.
5. Cookies and Tracking
Utsavs uses essential cookies and session tokens required for authentication and platform security. We do not use third-party advertising cookies or sell your browsing data to advertisers. You may disable cookies in your browser settings, but this may affect your ability to log in and use the platform.
6. Data Retention
- Account information is retained for as long as your account is active.
- Event and registration records are retained for financial, legal, and operational purposes as required by Indian law.
- Payment transaction records are retained for a minimum of 7 years in accordance with GST and accounting requirements.
- Server logs are retained for up to 90 days for security and debugging purposes.
- You may request deletion of your account and personal data by contacting us at privacy@utsavs.app.
7. Your Rights
Under the Digital Personal Data Protection Act, 2023 (DPDP Act) and other applicable Indian data protection laws, you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request erasure of your personal data, subject to legal retention obligations.
- Withdraw consent to data processing where consent was the basis for processing.
- Nominate a person to exercise your rights on your behalf.
- Raise grievances with our Data Protection Officer.
8. Data Security
We implement industry-standard security measures to protect your data, including:
- TLS encryption for all data in transit between your browser and our servers.
- Encrypted storage and access-controlled databases via Supabase.
- Authentication tokens with expiry and revocation capabilities.
- Row-level security policies ensuring users can only access their own data.
9. Third-Party Links and Services
Utsavs integrates with third-party services including Razorpay (payments), Supabase (infrastructure), Resend (email delivery), and DiceBear (avatar generation). Utsavs may also contain links to third-party websites (such as Google Maps or Google Calendar). We are not responsible for the privacy practices of those services. Event organisers may also embed third-party content or links in their event pages — please review those parties' privacy policies independently.
10. Children's Privacy
Utsavs is not directed at children under the age of 13. We do not knowingly collect personal data from children. If you believe a child has provided us with personal information, please contact us and we will take steps to delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy as the platform evolves or as legal requirements change. Material changes will be reflected with an updated date at the top of this page. Continued use of Utsavs after changes are posted constitutes your acceptance of the revised policy.
12. Grievance Officer
In accordance with the Information Technology Act, 2000 and the DPDP Act, 2023, you may contact our Grievance Officer for any privacy-related queries or complaints at privacy@utsavs.app. We aim to acknowledge grievances within 72 hours and resolve them within 30 days.