EVNTS is operated by Lumo Autonomous LTD, United Arab Emirates ("we", "us"). This policy covers the EVNTS app on iPhone and Android, and this website. It applies during the private beta and will be updated, with the date above, before anything in it changes.
What we collect
The short version is on What we collect.
When you sign in
You sign in with Apple or Google. We receive the identifier the provider assigns to you for EVNTS, your name if you share it, and your email address — or, with Apple, the private relay address Apple creates if you choose to hide yours. We never see a password. With Apple we also receive a one-time authorization code, which we exchange for the credential Apple requires us to revoke when you delete your account; that credential is stored encrypted and is used for nothing else.
Your profile
What you enter: your name, handle, headline, bio, photo, interests, goals, and any experience or projects you add. Your time zone, so times show correctly. Which role you last used, host or guest.
Events
As a host: the events, invitations, guides, registration questions and ticket tiers you create, and your organisation's name. As a guest: the events you join, your answers to a host's registration questions, your tickets and orders, and — when the door scans your ticket — that it was scanned, and when.
Your devices
An identifier the app creates for each installation, the phone's model name (so your device list reads "iPhone 15 Pro" rather than "iPhone"), the app and OS version, and — only if you turn notifications on — the token that lets us send them.
Technical records
Our servers keep request logs — the time, the endpoint, the outcome and a request identifier — for operating the service. They deliberately never record an invitation code, a token or a password. The website itself sets no cookies and runs no analytics.
Why
- To run the service: sign you in, show you your events, get your ticket to the door, sync between your devices.
- To let hosts run their events: who has joined, who has a ticket, who has arrived.
- To keep the service safe: rate limits, refusing reused sign-in tokens, ending sessions you did not start.
We do not sell personal data, do not show advertising, and do not build profiles for anyone else.
Who else is involved
- Apple and Google for sign-in. They process it under their own policies.
- Google for venue search: when a host looks up a venue by name, the host's search text goes to Google's Places service. Guests' data does not.
- Google Cloud hosts our servers and storage, in the Mumbai region (
asia-south1). - Apple and Google push services deliver notifications, if you turn them on.
- A payment processor, when paid tickets launch; this policy will name it before the first paid ticket is sold. Card details will go to the processor, never to us.
The processors we use today, and those added at launch, are listed on Sub-processors.
Hosts see what their guests share with the event: name, profile, registration answers, ticket status and arrival. A host does not see your email address or your other events.
Where it is kept, and for how long
On our servers in Google Cloud, in transit only over TLS. Sign-in tokens are stored as hashes; the ticket secrets the door reads, and the provider credential mentioned above, are stored encrypted. On your phone the app keeps a copy of what you have seen so it works offline; signing out deletes that copy.
We keep your data while you have an account. Change records used to sync devices are kept for 45 days. During the beta we are still setting retention windows for logs and notifications and will publish them here.
Deleting your account
Settings → Account → Delete account, in the app; how deleting works has the steps. The deletion is scheduled and then carried out: your profile, sign-in identities, sessions, devices, tokens, itinerary, follow-ups and notifications are deleted, and the credential Apple issued for your sign-in is revoked at Apple. Records that other people's events depend on — a seat that was taken, a ticket that was scanned — are kept with your identity removed, so a host's numbers still add up. Free-text you wrote in some places may survive the beta's current deletion; we are closing that and will note it here when done.
Your choices
- Notifications are off until you turn them on, and can be turned off in Settings.
- Every phone signed into your account is listed in Settings → Devices, and any of them can be signed out from another.
- You can read, correct or delete what you have entered from inside the app; for anything else, write to us at the address under Contact.
Children
EVNTS is not for anyone under 16, and we do not knowingly collect their data. If you believe a child has an account, write to us and we will delete it.
Changes
When this policy changes, the date at the top changes with it, and a change that matters is announced in the app before it takes effect.
Contact
nicholas@getevnts.com — put "Privacy" in the subject.