Version 1.0 · Effective 8 July 2026
This Privacy Policy explains how Entrio("we", "the Platform") and the event organiser whose site you are using ("the Organiser") collect and process your personal data when you use this ticketing service. It is issued in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and applies to users in India.
Who is responsible for your data. The Organiser is the Data Fiduciary — they decide why your data is collected (to sell you a ticket and admit you to their event). The Platform acts as a Data Processoron the Organiser's behalf, and as a Data Fiduciary for your account credentials. Contact details are in the "Grievance & Contact" section.
We collect only what is needed to create your account, sell you a ticket, deliver it, and admit you to the event.
| Data | Why we collect it (purpose) | Basis |
|---|---|---|
| Mobile number | To create and secure your account, send you a one-time passcode (OTP) to log in, and send your ticket / booking updates | Necessary to provide the service (your consent + contractual necessity) |
| Name (if you provide it) | To personalise your ticket, invoice, and notifications | Consent |
| Email (optional) | To send your ticket, GST invoice, and updates if you prefer email | Consent |
| Delivery address & precise location (latitude/longitude) — only if you choose home delivery | To deliver your physical pass to your address and let the delivery partner navigate to you | Consent (collected only at the delivery step) |
| Booking, order and payment references | To process your payment, issue your ticket and GST invoice, and support refunds/disputes | Contractual necessity + legal obligation (tax) |
| Inquiry / registration details you submit (message, any custom fields) | To let the Organiser review and respond to your request | Consent |
| Technical data at consent — your IP address and browser (User-Agent) | Recorded once, as legally required proof of when and how you gave consent | Legal obligation |
| Entry-scan records | To admit you at the gate and prevent ticket fraud/duplication | Contractual necessity + legitimate use |
We do not collect biometric or facial data in this version. We do not knowingly collect data from children — see section 8.
We share the minimum necessary with these service providers ("Data Processors"), who may only use it to perform their service:
We do not sell your personal data. We do not share it for third-party advertising.
Your data is hosted in India (DigitalOcean, Bangalore). Some processors above (Meta, Google, payment gateways) may process limited data on their own infrastructure; where this involves transfer outside India, it is done only as permitted under the DPDP Act and our agreements with those processors.
Access is restricted to the Organiser's authorised staff and the specific delivery partner assigned to your order. Sensitive Organiser secrets (payment keys, signing keys) are encrypted. Passwords and OTPs are stored only as one-way hashes, never in readable form. All access is over encrypted connections.
You have the right to:
To exercise any right, contact the Grievance Officer. We will respond within the timelines required by law.
We use only the storage necessary to keep you logged in and operate the site (session tokens). We do not use third-party advertising or tracking cookies.
This service is intended for users aged 18 and over. We do not knowingly collect the personal data of children without verifiable parental consent, and we do not track or serve targeted advertising to children, as required by DPDP §9. If you believe a child has provided us data, contact the Grievance Officer and we will delete it.
We may update this policy. When we make a material change we will update the version number above and ask you to review and accept the updated policy at your next login.