Legal
Privacy Policy
Last updated: 26 June 2026
1. What Data We Collect
We collect the following categories of personal data when you use the evtOS Platform:
Account information: Name, email address, and role (organiser or attendee) provided at registration. Organisers may also provide business name and contact details.
Ticket and order data: Ticket purchase history, order details, QR code identifiers, and check-in timestamps associated with your account.
Payment information: We do not store your card details. All payment data is handled directly by Paystack. We receive only a payment confirmation reference and transaction status from Paystack.
Location data: We derive your approximate geographic region from your IP address for fraud prevention and security purposes. We do not request or store precise GPS location data.
Usage data: Technical data including IP address, browser type, pages visited, and interaction timestamps. This is used for Platform performance monitoring and security.
Communication data: If you contact us or use the Platform's messaging features, we retain records of those communications.
2. How We Use Your Data
We use your personal data for the following purposes:
- Creating and managing your account
- Processing ticket purchases and sending ticket confirmation emails with QR codes
- Enabling gate entry validation at events
- Sending event communications on behalf of organisers (push notifications, email blasts) where you have opted in or purchased a ticket for that event
- Providing organisers with attendee data for their own events (see Section 4)
- Operating and improving the Platform
- Fraud prevention and Platform security
- Responding to support requests
3. Data Sharing
With event organisers: When you purchase a ticket to an event, the organiser of that event will receive your name, email address, ticket details, and check-in status. This is necessary for them to manage attendance. Organisers are responsible for handling your data in compliance with applicable data protection laws for their own purposes.
With payment processors: Payment data is shared with Paystack as necessary to process your transaction. Please review Paystack's privacy policy for details of how they handle your data.
With service providers: We use Supabase for database and authentication infrastructure, and Resend for transactional email delivery. These providers process your data on our behalf under strict data processing agreements.
We use Sentry for error monitoring and session replay. Sentry may process your IP address, browser metadata, and session recordings when Platform errors occur. Data processed by Sentry may be stored on servers in the United States.
Legal disclosure: We may disclose your data if required to do so by law, court order, or regulatory authority in Kenya or another applicable jurisdiction.
We do not sell your personal data to third parties. We do not share your data with advertisers.
4. Data Storage
Your data is stored on Supabase-managed infrastructure. Supabase stores data in data centres in Ireland (EU). Payment confirmation data is processed and stored by Paystack on their own infrastructure. Error monitoring data is processed by Sentry on servers in the United States. Email delivery data is processed by Resend on servers in the United States. We take reasonable steps to ensure all service providers maintain appropriate security standards and operate under data processing agreements consistent with applicable data protection law.
Data is encrypted in transit using TLS and at rest using industry-standard encryption.
5. Your Rights
Under applicable data protection principles, you have the following rights:
- Access: You may request a copy of the personal data we hold about you.
- Correction: You may request correction of inaccurate personal data. You can update most account information directly within the Platform.
- Deletion: You may request deletion of your account and associated personal data. Note that some data (such as transaction records) may be retained for legal and financial compliance purposes.
- Portability: You may request your data in a structured, machine-readable format.
- Objection: You may object to certain processing of your data, including direct marketing communications.
These rights are provided in accordance with the Kenya Data Protection Act 2019. You also have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) at odpc.go.ke if you believe your data has been handled unlawfully.
To exercise any of these rights, contact us at hello@evtos.io or via our contact form. We will respond within 30 days.
6. Cookies and Local Storage
We use cookies and browser local storage as described in our Cookie Policy. In brief: we use essential authentication cookies (via Supabase Auth) and store your theme preference in local storage. We do not use advertising or tracking cookies.
7. Children's Privacy
The evtOS Platform is not intended for use by persons under the age of 18. We do not knowingly collect personal data from minors. If you are a parent or guardian and believe your child has created an account or purchased a ticket without your consent, please contact us immediately at hello@evtos.io and we will take appropriate action.
Ticket purchases for events with minimum age requirements are subject to the organiser's entry policies.
8. Data Retention
We retain your account data for as long as your account is active. If you request account deletion, we will delete your personal data within 30 days, except where retention is required for:
- Financial and transactional records (retained for a minimum of 7 years for accounting purposes)
- Fraud prevention and security records
- Legal obligations or active disputes
Anonymised or aggregated data that cannot be linked back to you may be retained indefinitely for analytics purposes.
9. Contact for Privacy Requests
For all privacy-related requests and queries, please contact:
- Email: hello@evtos.io
- Contact form: evtos.io/contact
We take data protection seriously and will address all requests promptly.