Privacy Policy
Draft — last updated [DATE]. Pending final legal review before publication.
You're using an early/closed-beta version of EventOrbit Nova.
The operating company is not yet registered and the document below is an unfinished draft — it has not been reviewed by a lawyer and is not a final, enforceable agreement. It is shared here only so early users know, in plain terms, what to expect. Please don't rely on it for legal certainty, and treat all bookings, payments and payouts made during this beta as part of a trial with people you already know — not a public commercial launch.
EventOrbit Nova ("we", "us", "our") — currently an early-stage/beta project, ahead of formal company registration — operates the EventOrbit Nova website and mobile application (together, the "Platform"), a marketplace connecting Customers, Venue Owners, Vendors, Workers, Organizations and Admin users for event-related services. This Privacy Policy explains what personal data we collect, why, how we use and protect it, and the rights you have over it, in accordance with the Digital Personal Data Protection Act, 2023 and other applicable Indian law.
1. Information We Collect
- Account information: name, mobile number, email, password/OTP credentials, city/location.
- Role-specific verification information: for Venue Owners, Vendors, Workers and Organizations — government ID proof (e.g., Aadhaar/PAN), business registration/GST numbers, ownership/lease documents, bank account/UPI details, and portfolio material.
- Booking and transaction information: event details, service requests, task assignments, payment amounts and status, invoices.
- Location data: for near-me search and mapping of venues/service areas (with permission).
- Communications: messages exchanged through in-platform chat tied to a booking, and support/chatbot conversations.
- Device and usage data: IP address, device identifiers, app usage analytics, cookies (on web).
2. Why We Collect It (Purpose Limitation)
- To create and verify accounts, and to display the "Verified" badge only for Venue Owners, Vendors, Workers and Organizations who pass document verification.
- To enable bookings, task assignment, payments and communication between the relevant parties to an event.
- To send booking, task, and payment notifications.
- To improve search relevance and provide the AI assistant's recommendations.
- To detect fraud, resolve disputes, and comply with legal obligations.
- We do not use your verification documents for any purpose other than verification, fraud prevention and legal compliance.
3. Consent
We collect and process your personal data only after obtaining your clear, informed consent (or another lawful basis recognized under the DPDP Act, 2023, such as a legitimate use directly connected to the service you have requested). You may withdraw consent at any time through your account settings, subject to the effect this may have on your ability to use the Platform (e.g., withdrawing consent for document verification will mean your account cannot remain in "Verified" status).
4. How We Share Information
- With the other party to a specific booking/task (e.g., a customer's event details are shared only with the venue owner/vendor/worker assigned to that event, not with unrelated users).
- With payment gateway/aggregator partners strictly to process payments and payouts.
- With Admin, for verification review, dispute resolution, and platform safety.
- With law enforcement or regulators where legally required.
- We do not sell personal data to third parties for advertising.
5. Data Retention & Deletion
We retain account and transaction data for as long as the account is active and as required by applicable law (e.g., financial records for the period mandated under tax/company law). Verification documents are retained only as long as necessary for verification and legal record-keeping, after which they are securely deleted or anonymized. You may request deletion of your account and associated data from your account settings, subject to retention obligations under law.
6. Your Rights
- Right to access the personal data we hold about you.
- Right to correct inaccurate or incomplete data.
- Right to withdraw consent.
- Right to grievance redressal through our Grievance Officer (see Section 9).
- Right to nominate another individual to exercise these rights on your behalf in the event of death or incapacity, as provided under the DPDP Act, 2023.
7. Security
We use reasonable technical and organizational safeguards — encryption in transit and at rest for sensitive documents, role-based access control, and regular security reviews — to protect your data. No system is 100% secure, and we will notify affected users and the relevant authority of any data breach as required by law.
8. Children's Data
The Platform is intended for users who are 18 years or older (or the age of majority in their jurisdiction). We do not knowingly collect data from minors. Organization-role events involving student participants under 18 (e.g., school-level events) must be registered and managed by an adult authorized representative of the Organization.
9. Grievance Officer
In accordance with the Information Technology Act, 2000 and rules made thereunder, the contact details of our Grievance Officer are: [Name], [Designation], [Email], [Address]. Complaints will be acknowledged within 24 hours and resolved within 15 days, as prescribed.
10. Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be notified to you through the Platform or via email before they take effect.
This is a structural draft prepared for planning purposes and must be reviewed and finalized by a lawyer licensed in India before relying on it as your published policy.
