Privacy Policy
What we collect, why we collect it, who else sees it, and how to get it back or get rid of it. Espeya runs no advertising or marketing trackers — so this is shorter and more concrete than most privacy policies.
Last updated
1. The short version
- We collect what an events platform needs: your account details, the events you create, the registrations you make, and payment records.
- We do not run Google Analytics, Google Tag Manager, Meta Pixel, PostHog, Hotjar, or any advertising or marketing tracker. Cloudflare Web Analytics (cookieless performance and usage metrics) is injected at our CDN edge — see section 4. That is why you are not being asked to dismiss a cookie banner.
- We never sell your personal data, and we do not share it with advertisers.
- We never see your card details. Payments go directly to Razorpay.
- If you register for someone’s event, that host receives your registration details. They are responsible for how they then use them.
2. Who is responsible for your data
Espeya is the controller for your account, your billing records, and the operation of the platform. For an attendee list, responsibility is split: we process registrations on the host’s behalf, and the host is an independent controller of the attendee data they receive. If your concern is about how a host used your details, contact the host; if we can help you reach them, write to us.
Espeya’s registered legal name, registered address, and the named grievance officer required under India’s Digital Personal Data Protection Act, 2023 will be published here before public launch.
3. What we collect
| Data | Why we have it | When you give it |
|---|---|---|
| Email address, password (hashed), display name, avatar | To create and secure your account and to send you transactional email | Sign-up |
| Events you create — title, description, images, date, venue, capacity, pricing | To publish and run the event. Public events are indexable by search engines. | When you create an event |
| Registrations — name, email, phone (if the host asks), and answers to the host’s registration questions | To issue your ticket, email reminders, and let the host run check-in | When you register for an event |
| Payment records — amount, currency, plan or ticket bought, Razorpay order, payment and refund identifiers, and the payer email and phone Razorpay reports back to us | To grant what you paid for, to handle refunds and disputes, and to meet tax and accounting obligations | At checkout |
| Approximate country, from your network connection | To show prices in a sensible currency | Automatically, on your first page view |
| Server logs — IP address, request path, user agent, timestamp | Security, abuse and rate-limit enforcement, and debugging | Automatically |
We do not ask for and do not want special-category data — health, religion, politics, biometrics. Please do not put it into a registration answer. If a host’s question invites it (for example dietary or access needs) that host is responsible for handling it lawfully.
4. Cookies, local storage, and site analytics
Every cookie Espeya sets is strictly necessary or functional. There are no advertising, profiling or cross-site cookies, and no analytics cookies. Switching these off would simply break signing in or paying. The complete first-party list:
| Name | Purpose | Type | Lifetime |
|---|---|---|---|
espeya_at | Your signed-in session (short-lived access token) | Strictly necessary · HttpOnly | Minutes; refreshed as you browse |
espeya_rt | Refresh token, so you are not signed out mid-task | Strictly necessary · HttpOnly | Session, or 30 days if you chose “remember me” |
espeya_rm | Remembers that you asked to stay signed in | Strictly necessary | Up to 30 days |
espeya_country | Your approximate country, so prices render in the right currency | Functional | Short-lived |
espeya_reg_‹event› | Your registration for one specific event, so you can return to your ticket without an account | Functional · HttpOnly | 1 year |
We also keep a few things in your browser’s own storage. These never leave your device and are not readable by us:
| Key | Store | Purpose |
|---|---|---|
espeya-reg:‹eventId› | localStorage | Draft registration details, so a refresh does not lose your form |
espeya.onboarding.* | localStorage | Which onboarding tips you have already dismissed |
espeya:recent-places | localStorage | Venues you recently searched, to speed up the next one |
espeya:password-recovery | sessionStorage | Carries you through a password reset; cleared when you close the tab |
You can clear all of this from your browser settings at any time. Clearing the cookies signs you out. On a clean visit to the public site while signed out, the only first-party cookie present is typically espeya_country; auth cookies appear only when you are signed in. Razorpay’s own cookies appear only when you open checkout.
Cloudflare Web Analytics
Our CDN (Cloudflare) injects a small cookieless script (static.cloudflareinsights.com/beacon.min.js) into HTML responses at the edge. That script is not shipped from this repository — it is enabled in the Cloudflare dashboard (Web Analytics). It measures aggregate performance and usage (for example page views and basic load timing). It does not set cookies, does not build an advertising profile, and does not show any UI. Because it is cookieless, it does not require a consent banner under the approach we take for this site.
This is separate from advertising and marketing trackers. We still do not use Google Analytics, Google Tag Manager, Meta Pixel, PostHog, Hotjar, or similar products.
If this ever changes, you will be asked. The moment we add cookie-based analytics, an advertising pixel, or any other non-essential tracker that needs a consent choice, we will publish it here and put that choice in front of you before it loads.
5. Who else processes your data
We keep the list short on purpose. Each of these acts on our instructions under a data processing agreement, and none of them receives your data for their own marketing.
| Processor | What they handle |
|---|---|
| Razorpay | Payments, refunds and subscription billing. Card, UPI and netbanking details are entered on Razorpay’s own checkout and never reach Espeya’s servers. |
| Supabase | Authentication and the application database |
| Azure Communication Services | Sending transactional email |
| Vercel | Hosting and serving the web application |
| Cloudflare | CDN and DNS in front of the site, plus cookieless Web Analytics (see section 4). Event images and other static assets may also be served via the CDN. |
Beyond these, we disclose personal data only to a host who is entitled to their own attendee list, or where we are legally compelled to — a valid court order, a tax or regulatory obligation, or to investigate fraud or a threat to someone’s safety.
6. Where your data goes
Espeya operates from India and serves attendees and hosts worldwide, so your data may be processed outside your country — including in India, the EU and the United States. Where we transfer personal data out of the UK or the European Economic Area we rely on the European Commission’s Standard Contractual Clauses or an adequacy decision, as applicable.
7. How long we keep it
| Data | Retention |
|---|---|
| Account and profile | Until you delete your account |
| Events and registrations | While the event is live and for a reasonable period after, so hosts and attendees keep their history |
| Payment and refund records | As long as tax, accounting and chargeback-dispute rules require — typically several years, and longer than your account |
| Server logs | A short operational window, then discarded |
Being straight with you about a gap we are still closing: our payment-webhook audit records currently retain the full payload our payment provider sends us, which can include a payer email and phone number, with no automatic expiry; and deleting your account does not yet erase registration rows you created as a guest without an account. Both are being fixed. In the meantime, if you ask us to erase that data we will do it by hand — see section 8.
8. Your rights
Whether you are in India under the Digital Personal Data Protection Act, 2023 or in the UK or EEA under the UK GDPR / GDPR, you can ask us to:
- tell you what we hold about you, and give you a copy;
- correct or complete anything that is wrong or out of date;
- erase your data, where we do not need to keep it for a legal, tax or fraud-prevention reason;
- restrict or object to a particular use, and — for GDPR — receive your data in a portable form;
- withdraw consent where consent is what we relied on;
- nominate someone to exercise these rights for you if you die or become incapacitated — a specific DPDP Act right.
Email [email protected]. We will respond within 30 days. We may ask you to confirm your identity first — we are not going to hand your data to someone who merely knows your email address.
If we get it wrong, you can complain to India’s Data Protection Board, to the UK Information Commissioner’s Office, or to your EU national supervisory authority. We would appreciate the chance to fix it first.
9. Our legal grounds (GDPR)
| What we do | Ground |
|---|---|
| Run your account, publish your events, issue tickets, take payment | Performance of a contract |
| Send transactional email — confirmations, tickets, receipts, reminders | Performance of a contract |
| Security, abuse prevention, rate limiting, service improvement | Legitimate interests |
| Keep financial records | Legal obligation |
| Optional marketing email, if we ever send it | Consent — opt-in, and revocable at any time |
Transactional email is part of the service, not marketing, so it has no unsubscribe link — a ticket or a payment-failure warning is not something we should let you accidentally opt out of. Delete your account and it stops.
10. Security
Passwords are hashed by our authentication provider and never stored in readable form. Session tokens are set as HttpOnly cookies so page scripts cannot read them. Traffic is encrypted in transit and data is encrypted at rest. Card data never touches our systems. If a breach affects you, we will notify you and the relevant regulator as the law requires.
11. Children
Espeya accounts are for people 18 and over. We do not knowingly collect data from children. If you believe a child has given us personal data, write to [email protected] and we will delete it.
12. Changes
If we change this policy materially we will email account holders and update the date at the top. Adding any non-essential tracking would be a material change and would come with a consent request, not just a new paragraph.
13. Contact
Privacy questions and rights requests: [email protected]. See also our Terms of Service and Contact Us page.