EVENTualley Privacy Policy
Effective Date: 12 June 2026 | Last Updated: 12 June 2026
1. Introduction
EVENTualley ("EVENTualley", "we", "our", or "us") provides an event operations platform for professional wedding, corporate, MICE, and large-event planning teams. The platform helps organisers manage event guests, RSVP collection, WhatsApp-based communication, room and stay coordination, hotel check-in document collection, transport coordination, check-in, run-of-show operations, issue management, team workflows, exports, and related event-day operations.
This Privacy Policy explains how we collect, use, store, disclose, protect, and delete personal data when organisers, planning teams, guests, vendors, hotel teams, transport teams, drivers, support users, and website visitors use EVENTualley, our websites, web applications, mobile or progressive web applications, WhatsApp Business messaging flows, guest links, QR links, support channels, and related services (collectively, the "Services").
This policy is intended to be available publicly at https://eventualley.com/privacy and to apply to EVENTualley's web application, guest links, WhatsApp Business messaging flows, event operation tools, and related services.
2. Publication and Company Details
| Item | Details |
|---|---|
| App / Service name | EVENTualley |
| Website | https://eventualley.com |
| Operator | EVENTualley |
| Country / region of operation | India-first, with potential international event operations |
| Business location | Ahmedabad, Gujarat, India |
| Privacy contact | privacy@eventualley.com |
| Grievance / data rights contact | privacy@eventualley.com |
| Effective date | 12 June 2026 |
| Last updated | 12 June 2026 |
| Recommended privacy URL for Meta | https://eventualley.com/privacy |
| Recommended data deletion URL for Meta | https://eventualley.com/data-deletion |
3. Who This Policy Covers
This policy applies to the following categories of users and individuals whose data may be processed through EVENTualley:
- Customers and account users: event planners, event companies, owners, admins, team leads, staff members, and other authorised users of an EVENTualley workspace or event.
- Guests and invitees: individuals whose information is uploaded by an organiser or collected through guest links, RSVP pages, hotel check-in document upload pages, check-in pages, WhatsApp flows, or event operation forms.
- Vendors, hotel teams, venue teams, transport teams, drivers, artists, security, entry teams, and other operational contacts: individuals or teams added to an event for coordination, assignments, manifests, access links, or issue resolution.
- Website visitors and support contacts: people who visit our website, contact us, request demos, apply for pilots, or communicate with us for support or business purposes.
4. Our Role in Handling Data
For account, billing, demo, support, website, and platform administration data, EVENTualley generally decides why and how that data is processed and acts as the controller or data fiduciary, as applicable under relevant law.
For guest lists, RSVP data, rooming details, hotel check-in documents, transport details, check-in data, event notes, and other event records uploaded or controlled by an organiser, the organiser or event customer usually decides why the data is collected and how it should be used. In those situations, EVENTualley processes the data to provide the Services to that organiser and may act as a processor/service provider or data processor, depending on applicable law and contract terms.
Organisers are responsible for having the necessary authority, consent, notice, or other lawful basis to upload guest, vendor, team, hotel, and operational data into EVENTualley and to send communications through WhatsApp, SMS, email, or other channels.
5. Personal Data We Collect
The exact data collected depends on the features used by the organiser and the information provided by users, guests, or operational teams. We collect and process only data that is reasonably required to provide and improve the Services, maintain security, support compliance, and operate events reliably.
| Category | Examples |
|---|---|
| Account and workspace data | Name, business name, role, email address, phone number, login credentials, authentication data, team membership, permissions, organisation details, and workspace settings. |
| Guest and invitee data | Guest name, phone number, email address, RSVP status, group or family association, companion count, tags, side or party labels, notes, guest link activity, and organiser-provided optional fields. |
| Identity and hotel check-in documents | Where hotel stay, accommodation, or guest check-in support is enabled: government-issued identity document images or PDFs, ID type, issuing country or region where provided, masked ID number or last digits where visible, document upload status, verification status, uploader identity, upload timestamp, expiry or deletion status, and secure hotel-sharing status. |
| RSVP and guest journey data | RSVP responses, Maybe/No/Yes status, companion confirmations, guest notes, link clicks, journey state, menu selections, help requests, and response timestamps. |
| Messaging and WhatsApp data | WhatsApp phone number, message templates, campaign targets, message body where applicable, delivery status, opt-in/opt-out status, replies received through supported flows, timestamps, operator information, and suppression-list records. |
| Rooming and stay data | Hotel or venue name, room number, building/floor, room capacity, room assignment, stay dates where used, rooming notes, room conflict flags, room exports, and room change history. |
| Transport and pickup data | Pickup requirement, arrival/departure location, arrival/departure date and time, flight/train details where provided, passenger count, luggage or operational notes, assigned car/driver, driver manifest, and transport change flags. |
| Check-in and attendance data | QR or link-based check-in records, manual check-in records, timestamp, operator/staff user, function or event context, check-in count, pending sync status, and audit logs. |
| Run-of-show and operations data | Function schedules, locations, cues, cue owners, statuses, issues, severity, task assignments, broadcast records, notes, and live operations activity. |
| Vendor, venue, hotel, team, and driver data | Names, phone numbers, email addresses, role, organisation, assignment details, access-link activity, driver manifests, vendor notes, and permission settings. |
| Files and assets | Venue/floor layout images or PDFs, event documents, exported sheets, uploaded templates, hotel check-in document files where enabled, and operational attachments where supported. |
| Device, usage, and technical data | IP address, browser type, device information, operating system, app logs, crash logs, error logs, time zone, language, cookie identifiers, session data, and security logs. |
| Support and communication data | Messages sent to our support team, demo requests, feedback, issue reports, call notes, and other communications with EVENTualley. |
| Future finance module data, if enabled | Budget categories, payment milestones, vendor documents, invoices, quotes, contracts, wallet/cost-centre records, and approval status. EVENTualley is not designed to collect full payment card numbers or bank account credentials. |
6. Sensitive Data and Identity Documents
EVENTualley is an event operations platform and is not designed to collect unnecessary sensitive personal data. Organisers should not upload caste or religion labels, medical records, biometric data, full payment card numbers, full financial account numbers, passwords for third-party accounts, or other highly sensitive information unless strictly required for a lawful event-operational purpose and properly disclosed to the individual concerned.
For events involving hotel stays, accommodation, or guest check-in support, EVENTualley may allow guests or authorised organisers to upload government-issued identity documents such as passport, driving licence, voter ID, masked Aadhaar, or other hotel-accepted identity proof. This feature is used only for limited purposes such as hotel check-in facilitation, accommodation verification, guest registration, and compliance with requirements of the assigned hotel, venue, accommodation partner, or applicable law.
Where an organiser uploads an identity document on behalf of a guest, the organiser is responsible for ensuring that they have the guest's permission or other lawful authority to provide that document to EVENTualley for the stated purpose. EVENTualley may log the organiser user, guest record, event, hotel or stay assignment, upload time, and sharing actions for accountability.
For Aadhaar documents, users are encouraged to upload only masked Aadhaar where accepted by the hotel or accommodation partner. EVENTualley may reject, flag, or request replacement of documents that expose unnecessary identity information.
Identity documents are subject to stricter controls than ordinary guest data. Access may be limited to authorised organiser users, EVENTualley personnel with a legitimate support or security need, and the assigned hotel, venue, or accommodation partner where necessary. Identity documents should not be included in general guest exports, vendor exports, driver manifests, team views, or ordinary event reports unless a specific hotel-check-in export or secure sharing flow is enabled.
EVENTualley does not sell identity documents, use them for advertising, use them for unrelated profiling, or use them for purposes unrelated to event accommodation and lawful check-in operations.
7. How We Collect Data
We collect data in the following ways:
- Directly from account users when they create accounts, configure events, upload lists, import CSV/Excel files, create rooming or transport plans, send messages, use check-in, or manage run-of-show operations.
- From organisers and authorised team members who upload or enter guest, vendor, hotel, driver, venue, transport, room, schedule, and hotel check-in document data.
- From guests and invitees when they respond to RSVP links, guest forms, secure ID upload links, WhatsApp journeys, check-in pages, QR links, help requests, or event communication flows.
- From organisers who upload identity documents on behalf of guests after confirming they have permission or other lawful authority to do so.
- From Meta/WhatsApp APIs and webhooks when we send messages, receive delivery statuses, process replies, or manage WhatsApp Business Platform functionality.
- Automatically from devices, browsers, cookies, server logs, security tools, and analytics tools when the Services are accessed.
- From third-party service providers, integration partners, or public business sources when needed to support account verification, communication, security, or event operations.
8. How We Use Personal Data
We use personal data for the following purposes:
- To create, manage, and secure EVENTualley accounts, workspaces, events, teams, roles, permissions, and access links.
- To import, maintain, deduplicate, search, update, and export guest master data.
- To collect and manage RSVP responses, companion counts, guest notes, and guest journey states.
- To collect, verify, organise, and securely share identity documents with assigned hotels, venues, or accommodation partners for hotel check-in, accommodation verification, guest registration, room handover, and lawful compliance purposes.
- To send event-related WhatsApp template messages, reminders, alerts, updates, confirmations, helpdesk responses, secure upload links, and operational communications where permitted.
- To track message status, failed messages, opt-outs, suppression lists, and communication logs.
- To manage room assignments, room conflicts, room exports, hotel/front-desk lists, and rooming change history.
- To manage transport intake, driver/car assignments, manifests, pickup confirmations, changes, and transport conflicts.
- To operate check-in, QR/manual search flows, counters, offline check-in queues, and attendance records.
- To operate run-of-show live mode, function schedules, cues, issues, broadcasts, status updates, and event-day command workflows.
- To provide support, training, troubleshooting, debugging, product updates, and customer success.
- To maintain audit logs, security records, abuse prevention, access controls, fraud prevention, and service integrity.
- To generate reports, exports, operational analytics, usage insights, product improvements, and aggregated statistics.
- To comply with legal obligations, enforce agreements, respond to lawful requests, and protect EVENTualley, our users, guests, and partners.
9. Lawful Bases and Consent
Where applicable law requires a lawful basis for processing personal data, we rely on one or more of the following: consent, performance of a contract, legitimate or permitted use, compliance with legal obligations, protection of legal claims, security, fraud prevention, and other lawful grounds available under applicable law.
For WhatsApp communications, organisers and businesses using EVENTualley must ensure that recipients have provided their phone number and have opted in or otherwise lawfully agreed to receive relevant event-related communications. EVENTualley may provide tools to record opt-in, opt-out, suppression, template, and message history, but organisers remain responsible for ensuring their contact lists and message purposes are lawful.
For hotel check-in documents, the guest should be shown a clear notice before upload explaining what identity document is requested, why it is needed, who it may be shared with, how long it may be kept, and how the guest can request deletion or support. When the organiser uploads a document on behalf of a guest, the organiser must ensure the guest has been informed and that the organiser has permission or other lawful authority to upload and share the document for the stated purpose.
Individuals may withdraw consent or opt out of WhatsApp communications by using the opt-out mechanism in the message, replying with an opt-out instruction such as STOP where supported, contacting the organiser, or contacting privacy@eventualley.com. Withdrawal may limit the ability to receive event updates, hotel check-in support, RSVP links, transport updates, or other operational communications.
10. WhatsApp Business Platform and Meta
EVENTualley may use the WhatsApp Business Platform and other Meta developer tools to provide messaging, template management, delivery tracking, customer-care replies, and WhatsApp-based guest journeys. This may involve sending event-related messages through approved templates, tracking delivery status, processing replies, and maintaining message logs.
We use WhatsApp-originated data only as reasonably necessary to support event-related messaging and service delivery. We do not sell WhatsApp message data, use it for unrelated advertising, or share it with unauthorised third parties.
Where EVENTualley needs a guest to provide identity documents for hotel check-in, WhatsApp messages should contain a secure EVENTualley upload link and should not ask the guest to send full identity documents, full identity numbers, payment card numbers, financial account numbers, or other sensitive identifiers directly inside WhatsApp chat.
Users should also review the privacy policies and terms of Meta and WhatsApp, as their services are governed by their own rules. EVENTualley customers are responsible for complying with applicable Meta and WhatsApp policies, including opt-in, template, messaging category, and opt-out requirements.
11. Sharing and Disclosure of Data
We may share personal data only as reasonably necessary for the purposes described in this policy and subject to applicable law, contract, and permissions. We do not sell guest personal data or identity documents.
| Recipient category | Purpose of sharing |
|---|---|
| Event organisers and authorised account users | To allow organisers and their teams to operate events, manage guests, send messages, assign rooms/transport, check-in guests, and resolve issues according to their permissions. |
| Assigned hotels, venues, and accommodation partners | To support rooming, hotel check-in, front-desk preparation, guest registration, room handover, lawful compliance, and accommodation coordination. Identity documents are shared only where necessary and through controlled hotel-check-in flows or secure hotel-only exports. |
| Vendors, drivers, security, entry, artists, and operational partners | To provide only the operational information needed for their role, such as driver manifests, entry lists, vendor schedules, or access links. Identity documents should not be shared with these parties unless specifically required by law or authorised for hotel/accommodation check-in. |
| Meta/WhatsApp and messaging providers | To send and receive WhatsApp messages, manage templates, track delivery status, process replies, and maintain compliance records. |
| Cloud hosting, storage, security, analytics, email, support, and infrastructure providers | To host, secure, monitor, back up, analyse, support, and operate the Services. |
| Professional advisers, auditors, insurers, legal authorities, or regulators | To comply with law, enforce agreements, respond to lawful requests, protect rights, investigate security incidents, or resolve disputes. |
| Business transfers | If EVENTualley is involved in a merger, acquisition, investment, financing, reorganisation, or sale of assets, data may be transferred subject to appropriate confidentiality and legal safeguards. |
12. Access Controls, Roles, and Audit Logs
EVENTualley is designed for multi-user event teams. Access may be controlled by workspace, event, role, permission, feature, module, guest segment, access link, or other settings. Organisers are responsible for assigning appropriate roles and removing access when a person no longer needs it.
Sensitive operations may be logged, including guest edits, RSVP changes, message sends, opt-outs, room moves, transport assignments, check-ins, run-of-show actions, issue changes, document uploads, identity document views/downloads/shares, and permission changes.
Identity document access should use stricter permissions than ordinary guest data. EVENTualley may record who uploaded, viewed, downloaded, exported, shared, replaced, or deleted an identity document. These logs may be retained to demonstrate accountability, security, compliance, and dispute resolution.
13. Offline Mode and Local Device Storage
EVENTualley may store limited data locally on authorised devices or browsers to support poor-network or offline use, including guest lists, room/transport assignments, check-in queues, run-of-show cues, and pending actions. Offline data is intended to sync back to the server when connectivity returns.
Identity document files should not be cached offline on staff devices by default. Where offline access is required for hotel check-in, it should be limited to authorised users, time-limited, encrypted where technically feasible, and logged. In most cases, staff should see only ID status such as requested, uploaded, verified, shared with hotel, or deleted.
Users should protect their devices with strong passcodes, avoid sharing logged-in devices, and immediately report lost devices or unauthorised access. Organisers should revoke access for staff, vendors, or temporary event users when their role ends.
15. Aggregated and De-identified Data
We may create aggregated or de-identified data that does not reasonably identify a specific person, guest, organiser, or event. We may use such data to improve the Services, understand product usage, create benchmarks, develop analytics, and support business planning.
Identity documents are not used to create advertising profiles. If EVENTualley later introduces industry benchmarking or monetised insights, those features should use aggregated or de-identified data and should not include identity document images, full identity numbers, or guest-identifiable document data unless separate consent or contractual permission is obtained and lawful.
16. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this policy, unless a longer retention period is required or permitted by law, contract, dispute resolution, audit, security, backup, or legitimate operational needs.
Unless otherwise agreed in writing, customer account and event workspace data is retained while the customer account remains active. Organisers may request deletion or export of event data, subject to account permissions, contractual obligations, legal requirements, backup cycles, audit needs, and abuse-prevention needs.
Identity documents are treated with shorter retention expectations than ordinary event data. Unless a shorter retention period is configured or a longer period is required by law, hotel compliance, security, dispute resolution, or contract, identity document files are intended to be deleted from active systems within 30 days after the relevant event, check-out, or hotel check-in purpose is completed. We may retain limited metadata such as upload status, deletion status, audit logs, or opt-out/security records where necessary for compliance, security, or dispute resolution.
When data is deleted from active systems, it may remain in encrypted backups and disaster recovery systems for a limited period until overwritten through normal backup cycles. We may retain limited audit logs, opt-out records, security logs, and legal records where necessary to demonstrate compliance, protect users, prevent abuse, or resolve disputes.
17. Data Deletion and Meta App Data Deletion Instructions
Users and guests may request deletion of their personal data by contacting privacy@eventualley.com. Organisers may also delete or request deletion of event data through account tools or by contacting us. To help us verify and process a request, please include the relevant name, phone number, email address, event name if known, organiser name if known, and the type of request.
For identity document deletion requests, guests may contact the organiser or EVENTualley at privacy@eventualley.com. If the document has already been shared with a hotel or accommodation partner, EVENTualley may help route the request, but deletion by the hotel may depend on the hotel's legal, registration, security, and operational obligations.
For Meta/Facebook/WhatsApp-related data deletion requests, users may send a request to privacy@eventualley.com or use our recommended public data deletion page at https://eventualley.com/data-deletion. Once verified, we will delete or anonymise personal data that we are required to delete from active systems, unless retention is necessary for legal, security, audit, dispute, anti-abuse, or compliance reasons.
Where EVENTualley acts as a processor for an organiser, we may need to forward or coordinate the request with the organiser who controls the event data. We aim to respond to verified data rights and deletion requests within the timelines required by applicable law.
18. Individual Rights
Subject to applicable law and verification, individuals may have rights to access, receive information about, correct, update, delete, or withdraw consent for their personal data. They may also have rights to nominate another person to exercise rights on their behalf, raise grievances, or object to certain processing where applicable.
Guests whose data was uploaded by an organiser may contact the organiser directly or contact EVENTualley at privacy@eventualley.com. If we process the data on behalf of the organiser, we may coordinate with the organiser to complete the request.
We will not discriminate against individuals for exercising privacy rights. However, deleting certain data may limit or prevent use of event links, RSVP features, WhatsApp updates, hotel check-in support, room handover, transport updates, check-in, or support features.
19. Security
We use reasonable technical, organisational, and administrative safeguards designed to protect personal data from unauthorised access, disclosure, alteration, loss, misuse, or destruction. These safeguards may include encryption in transit, encryption or secure storage at rest where appropriate, role-based access controls, least-privilege access, audit logs, secure authentication, monitoring, backups, and internal access restrictions.
Identity documents require stronger controls than ordinary guest profile fields. Such controls may include restricted permissions, signed or time-limited links, limited downloads, document access logs, secure deletion workflows, encrypted storage, hotel-only sharing, and exclusion from general exports.
No internet-based service can guarantee absolute security. Users and organisers are responsible for protecting their passwords, devices, access links, QR links, exported files, and credentials. Organisers should avoid sharing export files or access links with unauthorised parties.
20. International Data Transfers
EVENTualley is India-first but may use cloud infrastructure, service providers, support tools, and Meta/WhatsApp systems that process data in India or other countries. Where personal data is transferred internationally, we use contractual, technical, and organisational safeguards as required by applicable law and by the terms of our service providers.
Organisers running events involving guests from other jurisdictions are responsible for ensuring that their use of EVENTualley complies with any privacy, telecom, consent, hotel-registration, identity-document, or messaging laws applicable to those guests.
21. Children and Minors
EVENTualley is intended for use by event organisers, business users, and authorised event teams. It is not directed to children as account users. Event guest lists may include minors when provided by an organiser, such as family members attending an event. In such cases, the organiser is responsible for ensuring that the data is provided and used lawfully, including obtaining parental or guardian consent where required.
Identity documents of minors should not be uploaded unless required for hotel/accommodation check-in or lawful event operations and the organiser has obtained appropriate parental or guardian permission or other lawful authority.
We do not knowingly use children's personal data for behavioural advertising or profiling. If a parent or guardian believes a child's data has been entered into EVENTualley without proper authority, they may contact privacy@eventualley.com.
22. Automated Processing and AI Features
EVENTualley may use automation to suggest, filter, classify, flag conflicts, or prioritise operational information. EVENTualley should not automatically move guests between rooms, cars, or committed assignments without human confirmation. Future AI features, if enabled, are intended to assist organisers with suggestions and anomaly detection, not to make final decisions without user review.
Identity documents should not be used for unrelated AI training, behavioural profiling, advertising, or automated eligibility decisions. Any document-related automation should be limited to operational checks such as upload status, file quality, duplicate detection, expiry warning, or hotel-sharing status, and should remain subject to human review where appropriate.
Users should review AI-assisted or automated suggestions before acting on them, especially for rooming, transport, guest communication, finance, identity document handling, or high-stakes event operations.
23. Third-Party Links, Exports, and Integrations
The Services may include links, exports, integrations, or shared views involving third-party platforms, including WhatsApp, Meta, cloud storage, email, calendars, payment tools, spreadsheets, hotel systems, or customer systems. Third-party services are governed by their own privacy policies and terms.
Organisers are responsible for controlling who receives exported guest lists, room lists, driver manifests, access links, QR links, PDFs, spreadsheets, or other event data outside EVENTualley. Once data is exported or shared outside EVENTualley, its handling may depend on the recipient and the platform used to share it.
Identity documents should be excluded from normal guest exports, vendor exports, driver manifests, team views, and ordinary event reports. If identity document sharing is required for hotel check-in, it should use a hotel-only secure link, controlled document export, or other restricted workflow with access logs and retention limits.
24. Changes to This Policy
We may update this Privacy Policy from time to time to reflect product changes, legal requirements, security improvements, or business changes. When we make material changes, we will update the "Last updated" date and, where required, provide additional notice through the Services, website, email, or other appropriate means.
Continued use of the Services after an updated policy becomes effective means the Services will be governed by the updated policy, subject to applicable law.
25. Contact Us
For privacy questions, data rights requests, deletion requests, identity document deletion requests, WhatsApp opt-out concerns, security concerns, or grievances, contact us at:
EVENTualley
Ahmedabad, Gujarat, India
Email: privacy@eventualley.com
Website: https://eventualley.com
If you are a guest and your data was added by an event organiser, please include the event name and organiser name if you know them. This helps us route and verify the request faster.