Who this policy covers
This policy explains how Eventikit handles personal information about the people who visit our website, sign in to the Eventikit portal, and administer events for an organization ("customers").
When you register for an event run on Eventikit, the organization running that event decides what it collects and how it uses it. Eventikit processes that information on the organizer's behalf. The Attendee Privacy Notice describes that relationship, and the organizer's own privacy policy governs their use of your information.
Information we collect
- Account information
- Your name, email address, password (stored only as a hash by our authentication provider), profile photo, multi-factor authentication enrollment, and the organizations and roles you belong to.
- Organization information
- Organization name, workspace addresses, custom domains, branding, plan, token balance and billing contacts.
- Content you create
- Events, pages, registration forms, email and SMS templates, waivers, reports and saved views.
- Payment information
- Subscription and token purchases are processed by Stripe. We receive a customer reference, the last four digits and expiry of your card, and invoice history; we never receive or store full card numbers.
- Usage and device information
- Pages viewed, actions taken in the portal, IP address, browser type, and timestamps. Portal actions are also written to your organization's activity log.
- Communications
- Messages you send to support, feedback you share, and the delivery status of email we send you.
How we use information
- Provide the service: sign you in, enforce your role's permissions, publish your events and deliver your messages.
- Bill for subscriptions and tokens, and prevent fraud and abuse.
- Keep the service secure, including detecting unusual sign-in activity and investigating incidents.
- Support you, and tell you about changes to the service, your plan or these terms.
- Understand how the portal is used so we can improve it. We use aggregated or de-identified data for this where we can.
- Meet legal obligations, such as tax and accounting requirements.
We do not sell personal information, and we do not use registrant data from your events to advertise to anyone.
Legal bases for processing
Where the GDPR or UK GDPR applies, we rely on: performance of our contract with you or your organization; our legitimate interests in operating, securing and improving the service; compliance with legal obligations; and your consent where we ask for it, which you can withdraw at any time.
How information is shared
- With members of your organization, according to the roles your organization assigns.
- With service providers that run parts of Eventikit for us, listed on our Subprocessors page, under contracts that limit their use of the data.
- With integrations your organization connects, such as Salesforce, HubSpot, Mailchimp, Stripe or Adyen. Those providers handle the data under their own terms.
- When required by law, or to protect the rights, safety or property of our customers, registrants, the public or Eventikit.
- As part of a merger, acquisition or sale of assets, with notice to affected customers.
How long we keep information
Account information is kept while your account is active. Organization data is kept for the life of the subscription, and organizations can set retention periods for registration, payment, CRM and uploaded-file data in Settings. The default for each is 90 days after an event ends.
When an organization requests deletion, we remove its data from active systems within 30 days and from backups within a further 35 days. Invoices and records we must keep for tax or legal purposes are retained for as long as the law requires.
Your rights and choices
Depending on where you live, you may have the right to access, correct, export or delete your personal information, to object to or restrict certain processing, and to withdraw consent.
- Update your name, photo and password from My profile.
- Organization owners can export or delete organization data from Settings → Privacy.
- For anything else, email privacy@eventikit.com. We respond within 30 days and will not discriminate against you for exercising a right.
- If you registered for an event, contact the organizer first; they control that data. We will help them respond.
- You can also complain to your local data protection authority.
Security
Data is encrypted in transit with TLS and at rest by our infrastructure providers. Access is restricted by role, integration secrets are held in an encrypted vault, and multi-factor authentication is available to every user and can be required by an organization. No system is perfectly secure; if we learn of a breach affecting your information we will notify you as the law requires.
International transfers
Eventikit is operated from the United States, and our providers primarily store data there. Where we transfer personal information out of the EEA, UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses or another lawful transfer mechanism.
Children
The Eventikit portal is not intended for anyone under 16. Organizers who run events for minors are responsible for obtaining any required parental consent through their registration forms and waivers.
Changes to this policy
We will post changes on this page and update the date at the top. If a change materially affects how we use your information, we will tell organization owners by email at least 30 days before it takes effect.
Contact
Questions about this policy or our privacy practices: privacy@eventikit.com.