Legal
Privacy policy
The short version
- evenclo is software that event organizers use to run their events. Most of the personal data in it is theirs, not ours — we hold it on their behalf.
- The camera in our apps reads badge QR codes. Frames are processed on the device and never stored or sent. The one exception is a payment receipt you deliberately photograph and submit.
- The on-site app keeps an offline copy of the attendee list on the phone so check-in survives venue Wi-Fi. It is deleted when you sign out or uninstall.
- We do not sell personal data, and there is no advertising or third-party analytics SDK in either app.
- Questions, or a request to see or delete your data: privacy@evenclo.com.
1. Who we are, and which hat we wear
evenclo is an event management platform operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS] ("evenclo", "we", "us"). It covers registration and ticketing, check-in and badge printing, exhibitor and lead capture, session programs, 1:1 meetings, and attendee communications, through the web platform at evenclo.com and the two mobile apps described below.
Which data-protection role we play depends on whose data it is, and the distinction decides who you should talk to:
- We are the controller for the accounts of our own customers — the organizations that license evenclo — including their staff users, billing records, support correspondence, and visitors to our website. We decide why and how that data is handled.
- We are a processor for everything belonging to an event: attendees, exhibitors, leads, orders, sessions, survey answers. The event organizer is the controller. They decide what questions their registration form asks, who may see the answers, how long to keep them, and who to contact. We act on their documented instructions.
So if you registered for, attended, or exhibited at an event, your primary relationship is with that event's organizer. You can still write to us, and we will route your request to the right organizer and help them answer it.
2. The apps this policy covers
| App | Package | Who signs in |
|---|---|---|
| evenclo. On-site | com.evenclo.evenclocheckin | Organizer staff, check-in crew, and exhibitor teams |
| evenclo. attendee | com.evenclo.attendee | People attending an event |
Both apps are clients of the same platform. Neither works without an account issued through an event.
3. What we collect
Account and sign-in
Name, email address, phone number where given, role, and the tenant or event the account belongs to. Staff passwords are stored only as a salted hash; several account types sign in with a one-time code sent by email instead of a password. Your session token is held in the Android Keystore through the operating system's secure storage, not in ordinary app storage.
Attendee and event records
Set by the organizer's own registration form, which is why the exact list varies per event. Typically: name, email, phone, company, job title, the answers to that form's questions, ticket and order details, the badge QR code we issue, check-in and check-out times, session attendance, booked meetings, survey responses, and certificates earned.
Lead capture
When you present your badge to an exhibitor and they scan it, you are choosing to share your contact details with that exhibitor. They receive your name, email, company, the answers to their qualifier questions, and any rating or note their staff add. That exhibitor becomes an independent controller of the lead record from that point.
Payments
Card payments are handled by our payment gateway. We never see or store full card numbers. We keep the order amount, currency, status, and the gateway's transaction reference. Where an organizer accepts bank transfers, the app lets an exhibitor photograph the transfer receipt and submit it as proof; that image is uploaded and visible to the organizer reviewing the payment. It is the only image either app transmits.
Device and notifications
If you allow notifications, we store a Firebase Cloud Messaging registration token and the platform name, so the organizer can reach you about your meetings and announcements. Push registration applies to exhibitor and attendee accounts; organizer staff devices are not registered. Revoking the notification permission or signing out removes the token.
Technical logs
Our servers record IP address, user agent, requested route, and timestamp for security, abuse prevention, and debugging.
What we do not collect
No location or GPS data. No access to your contacts, photo gallery, files, microphone, or calendar. No advertising identifiers. There is no advertising SDK and no third-party analytics SDK in either app.
4. The camera, specifically
Both the camera permission and what it is used for are narrower than the permission dialog can express, so plainly:
- Reading codes. Scanning a badge or ticket QR code to check someone in, capture a lead, or admit them to a session. The camera preview is processed live on the device to decode the code. No frame is written to storage and no frame leaves the device. What we receive is the decoded code, which is an identifier we issued.
- One receipt photo. On the payment-proof screen, and only when you press the shutter yourself, the app takes a single compressed photograph of a bank transfer receipt and uploads it with the amount and reference you type.
The camera is never accessed in the background, and never opens except on a scanning or receipt screen you navigated to.
5. What the on-site app stores on the phone
A venue's Wi-Fi is the least reliable part of any event, so the on-site app is built to keep working without it. It maintains a local database on the device (evenclo.db) holding, for the events you are signed in to:
- the attendee list — name, email, badge QR code, attendee type, tags, notes, check-in and check-out times, and registration form answers;
- scans made while offline, queued until they can be sent;
- leads captured at a stand, including any not yet synced.
This cache is deleted when you sign out, and removed with the app when you uninstall it. Because it contains other people's personal data, the device it lives on should have a screen lock, and organizers should sign out shared or borrowed devices at the end of an event.
6. Why we process it, and on what basis
| Purpose | Basis |
|---|---|
| Running the event you registered for — admission, badge, agenda, meetings, certificates | Performance of a contract, or the organizer's legitimate interest in running their event |
| Providing the platform to our customers and supporting them | Performance of a contract |
| Payments, invoicing, and financial records | Contract and legal obligation |
| Security, fraud and abuse prevention, service reliability | Legitimate interests |
| Marketing email or WhatsApp messages from an organizer | Consent, or a soft opt-in where local law allows, always with a way to stop |
| Sharing a lead with an exhibitor | Your consent, given by presenting your badge to be scanned |
Where an organizer asks their attendees for sensitive information — dietary requirements or accessibility needs, for instance — that organizer is responsible for obtaining explicit consent. We do not require or encourage such fields.
7. Who else sees the data
We do not sell personal data, and we do not share it for advertising. It reaches only:
- The event organizer whose event you are part of, and the staff they authorize.
- Exhibitors you chose to share your details with by having your badge scanned.
- Service providers who process data on our instructions, under contract, listed below.
- Authorities, where we are legally compelled — and we will tell the affected customer unless prohibited from doing so.
- An acquirer, if the business is sold or merged, with notice before your data becomes subject to a different policy.
| Provider | What it does |
|---|---|
| Google Cloud | Hosting, application database, secret storage |
| Firebase Cloud Messaging | Delivering push notifications |
| Mailchimp Transactional | Sending transactional and campaign email |
| Meta WhatsApp Business | Sending WhatsApp messages where an organizer enables it |
| Paymob | Processing card payments |
Organizers may connect further integrations to their own event. Anything they switch on is their choice and their responsibility.
8. Where data is held
Our infrastructure runs in Google Cloud, primarily in the [PRIMARY REGION] region. Some providers above operate internationally, so data may be transferred outside your country. Where that happens from the EEA or the UK, transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision.
9. How long we keep it
- Event and attendee data — for as long as the organizer keeps it. When they delete a record it is removed from live systems, and from backups within 30 days. When a customer's account is terminated, their data is deleted within 90 days unless they ask for it sooner.
- Financial records — retained as long as tax and accounting law requires.
- Server logs — around 30 days.
- Push tokens — until you sign out, uninstall, or revoke the permission.
- On-device caches — until sign-out or uninstall.
10. How we protect it
- All traffic between the apps and our servers is encrypted with HTTPS/TLS.
- Data is encrypted at rest by our hosting provider; payment gateway credentials get a second layer of AES-256-GCM encryption with a key held in a managed secret store.
- Session tokens live in the operating system's secure keystore on the device.
- Access is role-based, and a user's role and active status are re-checked against the database on every request — so removing someone's access takes effect immediately rather than when their session expires.
- Every record is scoped to its event and tenant, and queries are written so one organizer cannot reach another's data.
No system is perfectly secure, but if a breach affects your personal data we will notify the relevant organizer and, where the law requires, the supervisory authority and you.
11. Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, receive a portable copy, object to or restrict processing, and withdraw consent at any time. Withdrawing consent does not undo processing already carried out.
If you are an attendee or exhibitor, contact the organizer of the event you took part in — they control that data and can act directly. If you cannot reach them, write to us and we will identify the organizer and press them to respond.
If you are a customer of ours, or you are unsure, email privacy@evenclo.com. We answer within 30 days and may need to verify your identity first. You also have the right to complain to your local data protection authority.
To stop marketing messages, use the unsubscribe link in any email, reply STOP to a WhatsApp message, or turn off notifications in your device settings.
12. Children
evenclo is built for professional and business events and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has provided us with personal data, write to us and we will delete it.
13. Changes to this policy
We will post any revision here with a new date at the top. If a change materially affects how we handle your data, we will notify affected customers by email before it takes effect.
14. Contact
Privacy questions and data requests: privacy@evenclo.com
Postal: [LEGAL ENTITY NAME], [REGISTERED ADDRESS]
Data protection contact: [DPO OR RESPONSIBLE PERSON]