Privacy Policy

Effective: 1 January 2026 · Version 1.0 · Last updated: 10 May 2026

Contents

1. Scope & who we are 2. What data we collect 3. How we use your data 4. Who we share data with 5. Data location & transfers 6. How long we keep data 7. Your rights (DPDP & GDPR) 8. Security measures 9. Children's data 10. Contact us

1. Scope & who we are

This policy describes how Event Super OS (the "Platform") collects, uses, shares, and protects personal data when you use:

This policy is published in compliance with India's Digital Personal Data Protection Act, 2023 (DPDP) and aligned with the EU General Data Protection Regulation (GDPR).

2. What data we collect

CategoryExamplesSource
Account dataEmail, password hash, full nameYou, at sign-up
Studio profileStudio name, tagline, logo, brand colors, phoneYou, in onboarding / settings
Event dataEvent name, dates, venue, vendors, crew, guests, RSVPs, photos, documentsStudios & their clients enter this
Guest dataGuest names, contact details, RSVPs, dietary preferences, accommodationStudios upload; guests respond via /rsvp
Payment dataCard last 4, payment status. Full card numbers are NEVER stored on our servers.Stripe / Razorpay (PCI-compliant)
Usage dataPages viewed, actions taken, IP address, browser, OSAutomatically, when you use the Platform
Marketing dataUTM parameters, referrer, ad campaign IDsIf you arrive via a campaign link

3. How we use your data

We do not sell your data. We do not use your event data to train AI models. We do not share guest contact details with third parties for advertising.

4. Who we share data with

ProcessorPurposeData location
Supabase Inc. (USA)Database & auth hostingAWS Mumbai (ap-south-1) by default
CloudflareCDN & static asset deliveryGlobal edge
Stripe / RazorpayPayment processingTheir respective regions
Resend / PostmarkTransactional emailUSA / EU
OpenAI (optional)AI co-pilot — only if you provide your own API keyUSA

Each sub-processor is bound by a data-processing agreement that requires equivalent or stronger safeguards than this policy.

5. Data location & transfers

Primary storage is in India (AWS Mumbai). Data may transit briefly through Cloudflare's global edge for delivery. We do not transfer your event data outside of India for storage without your consent. White-label resellers may select an alternative region in writing.

6. How long we keep data

7. Your rights

Under the DPDP Act and GDPR, you have the right to:

You can exercise data export and account deletion directly inside /event-manager → Settings → Privacy. Other requests: email us using the address below; we respond within 30 days.

8. Security measures

If you believe you've found a security vulnerability, email security@eventsuperos.com. We respond within 24 hours and will not pursue legal action against good-faith researchers.

9. Children's data

The Platform is not intended for users under 18. Studios may capture guest data that includes children (e.g., kids attending a wedding). In those cases, we treat such data with extra care and the studio is the data controller; we are merely a processor. Studios must obtain appropriate consent from parents/guardians before entering minors' data.

10. Contact us

Data Protection Officer
Email: dpo@eventsuperos.com
Postal: [Studio mailing address — to be filled in by Anthropic / studio operator]

India grievance officer (DPDP §10): grievance@eventsuperos.com · we acknowledge within 24 hours and resolve within 30 days.