EVENTualley Privacy Policy

Effective Date: 12 June 2026 | Last Updated: 12 June 2026

This document is a public privacy policy draft for EVENTualley, including WhatsApp Business messaging and hotel check-in document flows. Review with qualified legal counsel before public launch.

1. Introduction

EVENTualley ("EVENTualley", "we", "our", or "us") provides an event operations platform for professional wedding, corporate, MICE, and large-event planning teams. The platform helps organisers manage event guests, RSVP collection, WhatsApp-based communication, room and stay coordination, hotel check-in document collection, transport coordination, check-in, run-of-show operations, issue management, team workflows, exports, and related event-day operations.

This Privacy Policy explains how we collect, use, store, disclose, protect, and delete personal data when organisers, planning teams, guests, vendors, hotel teams, transport teams, drivers, support users, and website visitors use EVENTualley, our websites, web applications, mobile or progressive web applications, WhatsApp Business messaging flows, guest links, QR links, support channels, and related services (collectively, the "Services").

This policy is intended to be available publicly at https://eventualley.com/privacy and to apply to EVENTualley's web application, guest links, WhatsApp Business messaging flows, event operation tools, and related services.

2. Publication and Company Details

ItemDetails
App / Service nameEVENTualley
Websitehttps://eventualley.com
OperatorEVENTualley
Country / region of operationIndia-first, with potential international event operations
Business locationAhmedabad, Gujarat, India
Privacy contactprivacy@eventualley.com
Grievance / data rights contactprivacy@eventualley.com
Effective date12 June 2026
Last updated12 June 2026
Recommended privacy URL for Metahttps://eventualley.com/privacy
Recommended data deletion URL for Metahttps://eventualley.com/data-deletion

3. Who This Policy Covers

This policy applies to the following categories of users and individuals whose data may be processed through EVENTualley:

4. Our Role in Handling Data

For account, billing, demo, support, website, and platform administration data, EVENTualley generally decides why and how that data is processed and acts as the controller or data fiduciary, as applicable under relevant law.

For guest lists, RSVP data, rooming details, hotel check-in documents, transport details, check-in data, event notes, and other event records uploaded or controlled by an organiser, the organiser or event customer usually decides why the data is collected and how it should be used. In those situations, EVENTualley processes the data to provide the Services to that organiser and may act as a processor/service provider or data processor, depending on applicable law and contract terms.

Organisers are responsible for having the necessary authority, consent, notice, or other lawful basis to upload guest, vendor, team, hotel, and operational data into EVENTualley and to send communications through WhatsApp, SMS, email, or other channels.

5. Personal Data We Collect

The exact data collected depends on the features used by the organiser and the information provided by users, guests, or operational teams. We collect and process only data that is reasonably required to provide and improve the Services, maintain security, support compliance, and operate events reliably.

CategoryExamples
Account and workspace dataName, business name, role, email address, phone number, login credentials, authentication data, team membership, permissions, organisation details, and workspace settings.
Guest and invitee dataGuest name, phone number, email address, RSVP status, group or family association, companion count, tags, side or party labels, notes, guest link activity, and organiser-provided optional fields.
Identity and hotel check-in documentsWhere hotel stay, accommodation, or guest check-in support is enabled: government-issued identity document images or PDFs, ID type, issuing country or region where provided, masked ID number or last digits where visible, document upload status, verification status, uploader identity, upload timestamp, expiry or deletion status, and secure hotel-sharing status.
RSVP and guest journey dataRSVP responses, Maybe/No/Yes status, companion confirmations, guest notes, link clicks, journey state, menu selections, help requests, and response timestamps.
Messaging and WhatsApp dataWhatsApp phone number, message templates, campaign targets, message body where applicable, delivery status, opt-in/opt-out status, replies received through supported flows, timestamps, operator information, and suppression-list records.
Rooming and stay dataHotel or venue name, room number, building/floor, room capacity, room assignment, stay dates where used, rooming notes, room conflict flags, room exports, and room change history.
Transport and pickup dataPickup requirement, arrival/departure location, arrival/departure date and time, flight/train details where provided, passenger count, luggage or operational notes, assigned car/driver, driver manifest, and transport change flags.
Check-in and attendance dataQR or link-based check-in records, manual check-in records, timestamp, operator/staff user, function or event context, check-in count, pending sync status, and audit logs.
Run-of-show and operations dataFunction schedules, locations, cues, cue owners, statuses, issues, severity, task assignments, broadcast records, notes, and live operations activity.
Vendor, venue, hotel, team, and driver dataNames, phone numbers, email addresses, role, organisation, assignment details, access-link activity, driver manifests, vendor notes, and permission settings.
Files and assetsVenue/floor layout images or PDFs, event documents, exported sheets, uploaded templates, hotel check-in document files where enabled, and operational attachments where supported.
Device, usage, and technical dataIP address, browser type, device information, operating system, app logs, crash logs, error logs, time zone, language, cookie identifiers, session data, and security logs.
Support and communication dataMessages sent to our support team, demo requests, feedback, issue reports, call notes, and other communications with EVENTualley.
Future finance module data, if enabledBudget categories, payment milestones, vendor documents, invoices, quotes, contracts, wallet/cost-centre records, and approval status. EVENTualley is not designed to collect full payment card numbers or bank account credentials.

6. Sensitive Data and Identity Documents

EVENTualley is an event operations platform and is not designed to collect unnecessary sensitive personal data. Organisers should not upload caste or religion labels, medical records, biometric data, full payment card numbers, full financial account numbers, passwords for third-party accounts, or other highly sensitive information unless strictly required for a lawful event-operational purpose and properly disclosed to the individual concerned.

For events involving hotel stays, accommodation, or guest check-in support, EVENTualley may allow guests or authorised organisers to upload government-issued identity documents such as passport, driving licence, voter ID, masked Aadhaar, or other hotel-accepted identity proof. This feature is used only for limited purposes such as hotel check-in facilitation, accommodation verification, guest registration, and compliance with requirements of the assigned hotel, venue, accommodation partner, or applicable law.

Where an organiser uploads an identity document on behalf of a guest, the organiser is responsible for ensuring that they have the guest's permission or other lawful authority to provide that document to EVENTualley for the stated purpose. EVENTualley may log the organiser user, guest record, event, hotel or stay assignment, upload time, and sharing actions for accountability.

For Aadhaar documents, users are encouraged to upload only masked Aadhaar where accepted by the hotel or accommodation partner. EVENTualley may reject, flag, or request replacement of documents that expose unnecessary identity information.

Identity documents are subject to stricter controls than ordinary guest data. Access may be limited to authorised organiser users, EVENTualley personnel with a legitimate support or security need, and the assigned hotel, venue, or accommodation partner where necessary. Identity documents should not be included in general guest exports, vendor exports, driver manifests, team views, or ordinary event reports unless a specific hotel-check-in export or secure sharing flow is enabled.

EVENTualley does not sell identity documents, use them for advertising, use them for unrelated profiling, or use them for purposes unrelated to event accommodation and lawful check-in operations.

7. How We Collect Data

We collect data in the following ways:

8. How We Use Personal Data

We use personal data for the following purposes:

10. WhatsApp Business Platform and Meta

EVENTualley may use the WhatsApp Business Platform and other Meta developer tools to provide messaging, template management, delivery tracking, customer-care replies, and WhatsApp-based guest journeys. This may involve sending event-related messages through approved templates, tracking delivery status, processing replies, and maintaining message logs.

We use WhatsApp-originated data only as reasonably necessary to support event-related messaging and service delivery. We do not sell WhatsApp message data, use it for unrelated advertising, or share it with unauthorised third parties.

Where EVENTualley needs a guest to provide identity documents for hotel check-in, WhatsApp messages should contain a secure EVENTualley upload link and should not ask the guest to send full identity documents, full identity numbers, payment card numbers, financial account numbers, or other sensitive identifiers directly inside WhatsApp chat.

Users should also review the privacy policies and terms of Meta and WhatsApp, as their services are governed by their own rules. EVENTualley customers are responsible for complying with applicable Meta and WhatsApp policies, including opt-in, template, messaging category, and opt-out requirements.

11. Sharing and Disclosure of Data

We may share personal data only as reasonably necessary for the purposes described in this policy and subject to applicable law, contract, and permissions. We do not sell guest personal data or identity documents.

Recipient categoryPurpose of sharing
Event organisers and authorised account usersTo allow organisers and their teams to operate events, manage guests, send messages, assign rooms/transport, check-in guests, and resolve issues according to their permissions.
Assigned hotels, venues, and accommodation partnersTo support rooming, hotel check-in, front-desk preparation, guest registration, room handover, lawful compliance, and accommodation coordination. Identity documents are shared only where necessary and through controlled hotel-check-in flows or secure hotel-only exports.
Vendors, drivers, security, entry, artists, and operational partnersTo provide only the operational information needed for their role, such as driver manifests, entry lists, vendor schedules, or access links. Identity documents should not be shared with these parties unless specifically required by law or authorised for hotel/accommodation check-in.
Meta/WhatsApp and messaging providersTo send and receive WhatsApp messages, manage templates, track delivery status, process replies, and maintain compliance records.
Cloud hosting, storage, security, analytics, email, support, and infrastructure providersTo host, secure, monitor, back up, analyse, support, and operate the Services.
Professional advisers, auditors, insurers, legal authorities, or regulatorsTo comply with law, enforce agreements, respond to lawful requests, protect rights, investigate security incidents, or resolve disputes.
Business transfersIf EVENTualley is involved in a merger, acquisition, investment, financing, reorganisation, or sale of assets, data may be transferred subject to appropriate confidentiality and legal safeguards.

12. Access Controls, Roles, and Audit Logs

EVENTualley is designed for multi-user event teams. Access may be controlled by workspace, event, role, permission, feature, module, guest segment, access link, or other settings. Organisers are responsible for assigning appropriate roles and removing access when a person no longer needs it.

Sensitive operations may be logged, including guest edits, RSVP changes, message sends, opt-outs, room moves, transport assignments, check-ins, run-of-show actions, issue changes, document uploads, identity document views/downloads/shares, and permission changes.

Identity document access should use stricter permissions than ordinary guest data. EVENTualley may record who uploaded, viewed, downloaded, exported, shared, replaced, or deleted an identity document. These logs may be retained to demonstrate accountability, security, compliance, and dispute resolution.

13. Offline Mode and Local Device Storage

EVENTualley may store limited data locally on authorised devices or browsers to support poor-network or offline use, including guest lists, room/transport assignments, check-in queues, run-of-show cues, and pending actions. Offline data is intended to sync back to the server when connectivity returns.

Identity document files should not be cached offline on staff devices by default. Where offline access is required for hotel check-in, it should be limited to authorised users, time-limited, encrypted where technically feasible, and logged. In most cases, staff should see only ID status such as requested, uploaded, verified, shared with hotel, or deleted.

Users should protect their devices with strong passcodes, avoid sharing logged-in devices, and immediately report lost devices or unauthorised access. Organisers should revoke access for staff, vendors, or temporary event users when their role ends.

14. Cookies and Similar Technologies

We may use cookies, local storage, session storage, device identifiers, and similar technologies to keep users signed in, remember preferences, improve performance, prevent fraud, analyse usage, and secure the Services. Users may control cookies through their browser settings, but disabling some cookies may affect login, event dashboards, guest links, secure upload links, or other core functions.

15. Aggregated and De-identified Data

We may create aggregated or de-identified data that does not reasonably identify a specific person, guest, organiser, or event. We may use such data to improve the Services, understand product usage, create benchmarks, develop analytics, and support business planning.

Identity documents are not used to create advertising profiles. If EVENTualley later introduces industry benchmarking or monetised insights, those features should use aggregated or de-identified data and should not include identity document images, full identity numbers, or guest-identifiable document data unless separate consent or contractual permission is obtained and lawful.

16. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes described in this policy, unless a longer retention period is required or permitted by law, contract, dispute resolution, audit, security, backup, or legitimate operational needs.

Unless otherwise agreed in writing, customer account and event workspace data is retained while the customer account remains active. Organisers may request deletion or export of event data, subject to account permissions, contractual obligations, legal requirements, backup cycles, audit needs, and abuse-prevention needs.

Identity documents are treated with shorter retention expectations than ordinary event data. Unless a shorter retention period is configured or a longer period is required by law, hotel compliance, security, dispute resolution, or contract, identity document files are intended to be deleted from active systems within 30 days after the relevant event, check-out, or hotel check-in purpose is completed. We may retain limited metadata such as upload status, deletion status, audit logs, or opt-out/security records where necessary for compliance, security, or dispute resolution.

When data is deleted from active systems, it may remain in encrypted backups and disaster recovery systems for a limited period until overwritten through normal backup cycles. We may retain limited audit logs, opt-out records, security logs, and legal records where necessary to demonstrate compliance, protect users, prevent abuse, or resolve disputes.

17. Data Deletion and Meta App Data Deletion Instructions

Users and guests may request deletion of their personal data by contacting privacy@eventualley.com. Organisers may also delete or request deletion of event data through account tools or by contacting us. To help us verify and process a request, please include the relevant name, phone number, email address, event name if known, organiser name if known, and the type of request.

For identity document deletion requests, guests may contact the organiser or EVENTualley at privacy@eventualley.com. If the document has already been shared with a hotel or accommodation partner, EVENTualley may help route the request, but deletion by the hotel may depend on the hotel's legal, registration, security, and operational obligations.

For Meta/Facebook/WhatsApp-related data deletion requests, users may send a request to privacy@eventualley.com or use our recommended public data deletion page at https://eventualley.com/data-deletion. Once verified, we will delete or anonymise personal data that we are required to delete from active systems, unless retention is necessary for legal, security, audit, dispute, anti-abuse, or compliance reasons.

Where EVENTualley acts as a processor for an organiser, we may need to forward or coordinate the request with the organiser who controls the event data. We aim to respond to verified data rights and deletion requests within the timelines required by applicable law.

18. Individual Rights

Subject to applicable law and verification, individuals may have rights to access, receive information about, correct, update, delete, or withdraw consent for their personal data. They may also have rights to nominate another person to exercise rights on their behalf, raise grievances, or object to certain processing where applicable.

Guests whose data was uploaded by an organiser may contact the organiser directly or contact EVENTualley at privacy@eventualley.com. If we process the data on behalf of the organiser, we may coordinate with the organiser to complete the request.

We will not discriminate against individuals for exercising privacy rights. However, deleting certain data may limit or prevent use of event links, RSVP features, WhatsApp updates, hotel check-in support, room handover, transport updates, check-in, or support features.

19. Security

We use reasonable technical, organisational, and administrative safeguards designed to protect personal data from unauthorised access, disclosure, alteration, loss, misuse, or destruction. These safeguards may include encryption in transit, encryption or secure storage at rest where appropriate, role-based access controls, least-privilege access, audit logs, secure authentication, monitoring, backups, and internal access restrictions.

Identity documents require stronger controls than ordinary guest profile fields. Such controls may include restricted permissions, signed or time-limited links, limited downloads, document access logs, secure deletion workflows, encrypted storage, hotel-only sharing, and exclusion from general exports.

No internet-based service can guarantee absolute security. Users and organisers are responsible for protecting their passwords, devices, access links, QR links, exported files, and credentials. Organisers should avoid sharing export files or access links with unauthorised parties.

20. International Data Transfers

EVENTualley is India-first but may use cloud infrastructure, service providers, support tools, and Meta/WhatsApp systems that process data in India or other countries. Where personal data is transferred internationally, we use contractual, technical, and organisational safeguards as required by applicable law and by the terms of our service providers.

Organisers running events involving guests from other jurisdictions are responsible for ensuring that their use of EVENTualley complies with any privacy, telecom, consent, hotel-registration, identity-document, or messaging laws applicable to those guests.

21. Children and Minors

EVENTualley is intended for use by event organisers, business users, and authorised event teams. It is not directed to children as account users. Event guest lists may include minors when provided by an organiser, such as family members attending an event. In such cases, the organiser is responsible for ensuring that the data is provided and used lawfully, including obtaining parental or guardian consent where required.

Identity documents of minors should not be uploaded unless required for hotel/accommodation check-in or lawful event operations and the organiser has obtained appropriate parental or guardian permission or other lawful authority.

We do not knowingly use children's personal data for behavioural advertising or profiling. If a parent or guardian believes a child's data has been entered into EVENTualley without proper authority, they may contact privacy@eventualley.com.

22. Automated Processing and AI Features

EVENTualley may use automation to suggest, filter, classify, flag conflicts, or prioritise operational information. EVENTualley should not automatically move guests between rooms, cars, or committed assignments without human confirmation. Future AI features, if enabled, are intended to assist organisers with suggestions and anomaly detection, not to make final decisions without user review.

Identity documents should not be used for unrelated AI training, behavioural profiling, advertising, or automated eligibility decisions. Any document-related automation should be limited to operational checks such as upload status, file quality, duplicate detection, expiry warning, or hotel-sharing status, and should remain subject to human review where appropriate.

Users should review AI-assisted or automated suggestions before acting on them, especially for rooming, transport, guest communication, finance, identity document handling, or high-stakes event operations.

23. Third-Party Links, Exports, and Integrations

The Services may include links, exports, integrations, or shared views involving third-party platforms, including WhatsApp, Meta, cloud storage, email, calendars, payment tools, spreadsheets, hotel systems, or customer systems. Third-party services are governed by their own privacy policies and terms.

Organisers are responsible for controlling who receives exported guest lists, room lists, driver manifests, access links, QR links, PDFs, spreadsheets, or other event data outside EVENTualley. Once data is exported or shared outside EVENTualley, its handling may depend on the recipient and the platform used to share it.

Identity documents should be excluded from normal guest exports, vendor exports, driver manifests, team views, and ordinary event reports. If identity document sharing is required for hotel check-in, it should use a hotel-only secure link, controlled document export, or other restricted workflow with access logs and retention limits.

24. Changes to This Policy

We may update this Privacy Policy from time to time to reflect product changes, legal requirements, security improvements, or business changes. When we make material changes, we will update the "Last updated" date and, where required, provide additional notice through the Services, website, email, or other appropriate means.

Continued use of the Services after an updated policy becomes effective means the Services will be governed by the updated policy, subject to applicable law.

25. Contact Us

For privacy questions, data rights requests, deletion requests, identity document deletion requests, WhatsApp opt-out concerns, security concerns, or grievances, contact us at:

EVENTualley
Ahmedabad, Gujarat, India
Email: privacy@eventualley.com
Website: https://eventualley.com

If you are a guest and your data was added by an event organiser, please include the event name and organiser name if you know them. This helps us route and verify the request faster.