Privacy Policy

What we collect, why we collect it, who else sees it, and how to get it back or get rid of it. Espeya runs no advertising or marketing trackers — so this is shorter and more concrete than most privacy policies.

Last updated

1. The short version

  • We collect what an events platform needs: your account details, the events you create, the registrations you make, and payment records.
  • We do not run Google Analytics, Google Tag Manager, Meta Pixel, PostHog, Hotjar, or any advertising or marketing tracker. Cloudflare Web Analytics (cookieless performance and usage metrics) is injected at our CDN edge — see section 4. That is why you are not being asked to dismiss a cookie banner.
  • We never sell your personal data, and we do not share it with advertisers.
  • We never see your card details. Payments go directly to Razorpay.
  • If you register for someone’s event, that host receives your registration details. They are responsible for how they then use them.

2. Who is responsible for your data

Espeya is the controller for your account, your billing records, and the operation of the platform. For an attendee list, responsibility is split: we process registrations on the host’s behalf, and the host is an independent controller of the attendee data they receive. If your concern is about how a host used your details, contact the host; if we can help you reach them, write to us.

Espeya’s registered legal name, registered address, and the named grievance officer required under India’s Digital Personal Data Protection Act, 2023 will be published here before public launch.

3. What we collect

DataWhy we have itWhen you give it
Email address, password (hashed), display name, avatarTo create and secure your account and to send you transactional emailSign-up
Events you create — title, description, images, date, venue, capacity, pricingTo publish and run the event. Public events are indexable by search engines.When you create an event
Registrations — name, email, phone (if the host asks), and answers to the host’s registration questionsTo issue your ticket, email reminders, and let the host run check-inWhen you register for an event
Payment records — amount, currency, plan or ticket bought, Razorpay order, payment and refund identifiers, and the payer email and phone Razorpay reports back to usTo grant what you paid for, to handle refunds and disputes, and to meet tax and accounting obligationsAt checkout
Approximate country, from your network connectionTo show prices in a sensible currencyAutomatically, on your first page view
Server logs — IP address, request path, user agent, timestampSecurity, abuse and rate-limit enforcement, and debuggingAutomatically

We do not ask for and do not want special-category data — health, religion, politics, biometrics. Please do not put it into a registration answer. If a host’s question invites it (for example dietary or access needs) that host is responsible for handling it lawfully.

4. Cookies, local storage, and site analytics

Every cookie Espeya sets is strictly necessary or functional. There are no advertising, profiling or cross-site cookies, and no analytics cookies. Switching these off would simply break signing in or paying. The complete first-party list:

NamePurposeTypeLifetime
espeya_atYour signed-in session (short-lived access token)Strictly necessary · HttpOnlyMinutes; refreshed as you browse
espeya_rtRefresh token, so you are not signed out mid-taskStrictly necessary · HttpOnlySession, or 30 days if you chose “remember me”
espeya_rmRemembers that you asked to stay signed inStrictly necessaryUp to 30 days
espeya_countryYour approximate country, so prices render in the right currencyFunctionalShort-lived
espeya_reg_‹event›Your registration for one specific event, so you can return to your ticket without an accountFunctional · HttpOnly1 year

We also keep a few things in your browser’s own storage. These never leave your device and are not readable by us:

KeyStorePurpose
espeya-reg:‹eventId›localStorageDraft registration details, so a refresh does not lose your form
espeya.onboarding.*localStorageWhich onboarding tips you have already dismissed
espeya:recent-placeslocalStorageVenues you recently searched, to speed up the next one
espeya:password-recoverysessionStorageCarries you through a password reset; cleared when you close the tab

You can clear all of this from your browser settings at any time. Clearing the cookies signs you out. On a clean visit to the public site while signed out, the only first-party cookie present is typically espeya_country; auth cookies appear only when you are signed in. Razorpay’s own cookies appear only when you open checkout.

Cloudflare Web Analytics

Our CDN (Cloudflare) injects a small cookieless script (static.cloudflareinsights.com/beacon.min.js) into HTML responses at the edge. That script is not shipped from this repository — it is enabled in the Cloudflare dashboard (Web Analytics). It measures aggregate performance and usage (for example page views and basic load timing). It does not set cookies, does not build an advertising profile, and does not show any UI. Because it is cookieless, it does not require a consent banner under the approach we take for this site.

This is separate from advertising and marketing trackers. We still do not use Google Analytics, Google Tag Manager, Meta Pixel, PostHog, Hotjar, or similar products.

If this ever changes, you will be asked. The moment we add cookie-based analytics, an advertising pixel, or any other non-essential tracker that needs a consent choice, we will publish it here and put that choice in front of you before it loads.

5. Who else processes your data

We keep the list short on purpose. Each of these acts on our instructions under a data processing agreement, and none of them receives your data for their own marketing.

ProcessorWhat they handle
RazorpayPayments, refunds and subscription billing. Card, UPI and netbanking details are entered on Razorpay’s own checkout and never reach Espeya’s servers.
SupabaseAuthentication and the application database
Azure Communication ServicesSending transactional email
VercelHosting and serving the web application
CloudflareCDN and DNS in front of the site, plus cookieless Web Analytics (see section 4). Event images and other static assets may also be served via the CDN.

Beyond these, we disclose personal data only to a host who is entitled to their own attendee list, or where we are legally compelled to — a valid court order, a tax or regulatory obligation, or to investigate fraud or a threat to someone’s safety.

6. Where your data goes

Espeya operates from India and serves attendees and hosts worldwide, so your data may be processed outside your country — including in India, the EU and the United States. Where we transfer personal data out of the UK or the European Economic Area we rely on the European Commission’s Standard Contractual Clauses or an adequacy decision, as applicable.

7. How long we keep it

DataRetention
Account and profileUntil you delete your account
Events and registrationsWhile the event is live and for a reasonable period after, so hosts and attendees keep their history
Payment and refund recordsAs long as tax, accounting and chargeback-dispute rules require — typically several years, and longer than your account
Server logsA short operational window, then discarded

Being straight with you about a gap we are still closing: our payment-webhook audit records currently retain the full payload our payment provider sends us, which can include a payer email and phone number, with no automatic expiry; and deleting your account does not yet erase registration rows you created as a guest without an account. Both are being fixed. In the meantime, if you ask us to erase that data we will do it by hand — see section 8.

8. Your rights

Whether you are in India under the Digital Personal Data Protection Act, 2023 or in the UK or EEA under the UK GDPR / GDPR, you can ask us to:

  • tell you what we hold about you, and give you a copy;
  • correct or complete anything that is wrong or out of date;
  • erase your data, where we do not need to keep it for a legal, tax or fraud-prevention reason;
  • restrict or object to a particular use, and — for GDPR — receive your data in a portable form;
  • withdraw consent where consent is what we relied on;
  • nominate someone to exercise these rights for you if you die or become incapacitated — a specific DPDP Act right.

Email [email protected]. We will respond within 30 days. We may ask you to confirm your identity first — we are not going to hand your data to someone who merely knows your email address.

If we get it wrong, you can complain to India’s Data Protection Board, to the UK Information Commissioner’s Office, or to your EU national supervisory authority. We would appreciate the chance to fix it first.

9. Our legal grounds (GDPR)

What we doGround
Run your account, publish your events, issue tickets, take paymentPerformance of a contract
Send transactional email — confirmations, tickets, receipts, remindersPerformance of a contract
Security, abuse prevention, rate limiting, service improvementLegitimate interests
Keep financial recordsLegal obligation
Optional marketing email, if we ever send itConsent — opt-in, and revocable at any time

Transactional email is part of the service, not marketing, so it has no unsubscribe link — a ticket or a payment-failure warning is not something we should let you accidentally opt out of. Delete your account and it stops.

10. Security

Passwords are hashed by our authentication provider and never stored in readable form. Session tokens are set as HttpOnly cookies so page scripts cannot read them. Traffic is encrypted in transit and data is encrypted at rest. Card data never touches our systems. If a breach affects you, we will notify you and the relevant regulator as the law requires.

11. Children

Espeya accounts are for people 18 and over. We do not knowingly collect data from children. If you believe a child has given us personal data, write to [email protected] and we will delete it.

12. Changes

If we change this policy materially we will email account holders and update the date at the top. Adding any non-essential tracking would be a material change and would come with a consent request, not just a new paragraph.

13. Contact

Privacy questions and rights requests: [email protected]. See also our Terms of Service and Contact Us page.

Privacy Policy — Espeya