EVENTVIDIA INC, doing business as EventVidia ("we", "us", or "our"), operates https://eventvidia.com. This Privacy Policy explains how we collect, use, and protect your personal information when you use our platform. By using EventVidia, you agree to the practices described in this policy.
1. Information We Collect
Information you provide directly:
- Account details: name, email address, profile photo
- Event information: event names, dates, locations, descriptions
- Guest information: names, email addresses, phone numbers, RSVP responses
- Vendor information: business name, contact details, service categories
- Payment information: processed securely through Stripe — we do not store card numbers
- Communications: messages, support requests, feedback
Information collected automatically:
- Log data: IP address, browser type, pages visited, time spent
- Device information: operating system, device type, unique identifiers
- Usage data: features used, clicks, event creation and management activity
- Cookies and similar tracking technologies (see Section 5)
Information from third parties:
- Authentication providers (Google, Apple) when you sign in via those services
- Payment processors (Stripe) for subscription and billing information
2. How We Use Your Information
We use the information we collect to:
- Create and manage your account
- Provide, maintain, and improve our event planning services
- Process payments and manage your subscription
- Send invitations, notifications, and reminders on your behalf
- Connect you with vendors in our marketplace
- Respond to your support requests and inquiries
- Send product updates, tips, and marketing communications (you can opt out at any time)
- Detect, prevent, and address fraud, abuse, or security issues
- Comply with legal obligations
- Analyse usage patterns to improve our platform
We will never sell your personal information to third parties for their own marketing purposes.
4. Data Storage & Security
Your data is stored on secure servers hosted by Vercel and Neon (PostgreSQL), located in the United States. We implement industry-standard security measures including:
- Encryption in transit (TLS/HTTPS) and at rest
- Access controls and authentication requirements for all team members
- Regular security reviews and vulnerability assessments
- Automatic backups of your event data
No method of transmission over the internet is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security.
We retain your data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or billing purposes.
6. Your Rights
Depending on your location, you may have the following rights:
- Access: Request a copy of the personal data we hold about you
- Correction: Ask us to correct inaccurate or incomplete data
- Deletion: Request that we delete your personal data ("right to be forgotten")
- Portability: Receive your data in a machine-readable format
- Objection: Object to processing of your data for marketing purposes
- Restriction: Request that we limit how we process your data
To exercise any of these rights, email us at privacy@eventvidia.com. We will respond within 30 days.
You can delete your account at any time from Settings → Account → Delete Account. This will permanently remove all your events, guest lists, and personal data.
7. Children's Privacy
EventVidia is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us immediately at privacy@eventvidia.com and we will delete it promptly.
Jurisdiction-Specific Policies
8. United States — CCPA & CAN-SPAM
California Consumer Privacy Act (CCPA / CPRA)
If you are a California resident, you have the following additional rights under the CCPA and its amendment, the CPRA:
- Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected about you, the sources, the business purpose, and the third parties with whom we share it.
- Right to Delete: Request deletion of your personal information, subject to certain exceptions (legal obligations, fraud prevention, etc.).
- Right to Correct: Request correction of inaccurate personal information.
- Right to Opt-Out: We do not sell or share personal information for cross-context behavioural advertising. You therefore have no opt-out action required, but you may submit a request to confirm this.
- Right to Limit Use of Sensitive Data: We do not process sensitive personal information beyond what is necessary to provide the Service.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights — you will receive the same quality of service regardless.
To submit a CCPA request, email privacy@eventvidia.com with subject line "CCPA Rights Request". We will respond within 45 days. We may ask you to verify your identity before processing the request.
In the past 12 months, we have collected the following categories of personal information:
- Identifiers (name, email, IP address)
- Commercial information (subscription plan, payment history)
- Internet or network activity (pages visited, features used)
- Professional or employment-related information (for corporate accounts)
We have not sold personal information in the past 12 months and have no intention to do so.
CAN-SPAM Act (Email Communications)
All marketing emails we send comply with the CAN-SPAM Act:
- We clearly identify ourselves as the sender in every email
- Subject lines accurately describe the email content — no misleading headers
- Every marketing email includes a clear, functional unsubscribe link
- We honour opt-out requests within 10 business days
- Our physical mailing address is included in all commercial emails
To unsubscribe from marketing emails, click "Unsubscribe" in any email footer, or email privacy@eventvidia.com. Note: transactional emails (account confirmations, event invitations you trigger) cannot be opted out of while your account is active.
COPPA (Children Under 13)
EventVidia does not knowingly collect personal information from children under 13 years of age, in compliance with the Children's Online Privacy Protection Act (COPPA). If we discover we have inadvertently collected such data, we will delete it immediately. Parents or guardians may contact us at privacy@eventvidia.com to request removal of a child's information.
9. India — Digital Personal Data Protection Act 2023
Digital Personal Data Protection (DPDP) Act, 2023
India's DPDP Act governs the processing of digital personal data. EventVidia complies with this legislation as follows:
Lawful Basis for Processing
We process your personal data on the following lawful bases under the DPDP Act:
- Consent: For marketing communications, analytics, and optional features. You may withdraw consent at any time.
- Contractual necessity: To provide the EventVidia service you have signed up for.
- Legitimate use: For fraud prevention, security, and legal compliance.
Your Rights as a Data Principal
Under the DPDP Act, you (as a "Data Principal") have the right to:
- Access information: Know what personal data we hold and how it is processed
- Correction and erasure: Request correction of inaccurate data or erasure of data no longer needed
- Grievance redressal: Raise grievances with us — we will respond within 72 hours and resolve within 30 days
- Nominate a representative: Nominate another individual to exercise your rights on your behalf in the event of death or incapacity
To exercise these rights, email privacy@eventvidia.com with subject line "DPDP Rights Request — India". We will acknowledge within 72 hours.
Consent Management
- Consent is obtained before collecting personal data where required by law
- You may withdraw consent at any time without affecting the legality of prior processing
- We maintain a record of consents provided
- Children (under 18 in India) require verifiable parental consent before we process their data
Cross-Border Data Transfers
EventVidia stores and processes data on servers located in the United States (Vercel, Neon). By using EventVidia from India, you consent to the transfer of your personal data to the United States. We ensure adequate data protection standards are maintained through contractual agreements with our service providers.
We will comply with any notified restrictions on cross-border transfers under the DPDP Act as and when such restrictions are published by the Government of India.
Grievance Officer (India)
In accordance with the Information Technology Act, 2000 and the DPDP Act 2023, we have designated a Grievance Officer for India:
Grievance Officer — India
Email: grievance-india@eventvidia.com
Response time: Within 72 hours of receipt
Resolution time: Within 30 days
If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India once it is constituted under the DPDP Act.
IT Act 2000 Compliance
We comply with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 under the IT Act 2000:
- We maintain a comprehensive information security policy
- Sensitive personal data (financial info, passwords) is encrypted in transit and at rest
- We conduct periodic security audits
- We will notify affected users of any data breach within 72 hours of becoming aware
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make significant changes, we will notify you by email and display a notice in the app at least 14 days before the changes take effect. Your continued use of EventVidia after the effective date constitutes acceptance of the updated policy.
We encourage you to review this page periodically. The "Last updated" date at the top reflects the most recent revision.
11. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy, please contact us: