Privacy Policy

Last updated: 19 Aug 2026

This explains what personal data Shindigs collects when you use this site, why we collect it, who else sees it, where it lives, and how long we keep it. It is written to be read, not to be survived.

Two things worth knowing up front. We never see your card or UPI details — the payment happens on our payment provider’s own page. And our database is hosted in Singapore, so your data is stored outside India; section 7 explains that.

1. Who is responsible for your data

Shindigs, a proprietary concern, of 34 Gangapuri, Purbaputiary, Kolkata 700093, West Bengal, India, is the Data Fiduciary for the personal data described here — meaning we are the ones who decide what is collected and why, and the ones you can hold to account for it.

Event organizers are separately responsible for what they do with attendee data we make available to them for their own events. Section 4 explains what that is.

2. What we collect, and why

We collect only what a ticketing service actually needs to work. Nothing here is gathered for advertising, and we do not sell personal data to anybody.

WhatWhy we need it
Your name, email address and phone numberTo issue your ticket, email you the confirmation and the PDF, let the organizer reach you about the event, and — because our payment provider requires a phone number — to create the payment at all.
Your account profile: name, email, phone, and a profile picture if you set one or sign in with GoogleTo sign you in, show your ticket wallet, and let you transfer a ticket to another account.
Your orders: what you bought, the amounts, the taxes and fees, the payment reference and the statusTo give you your tickets, to answer questions about a payment, to process refunds, and because we are required to keep financial records.
Your tickets: the codes on them, who holds them, and any transfer historySo a ticket can be checked at the door, and so a transferred ticket stops working for whoever sent it.
Check-in records: every scan at a door, including refused ones, with the result and the timeSo an organizer can settle a dispute at the gate, count who came in, and tell a broken QR code from a queue.
A one-way hash of your IP addressOnly to count requests to our AI chat against a daily limit, so one visitor cannot run up the bill for everyone. The address itself is not stored, and the hash cannot be turned back into it.
Technical data our hosting provider records to serve the pageTo deliver the site and keep it secure. We do not run analytics, advertising or tracking software on this site.

If you list events with us we also collect your business type, your GST registration status and GSTIN if you have one, and your bank account details so we can pay you. Those are held on a table that no public part of the site can read, and are used for payouts, invoicing and tax only.

We rely on your consent where you give it, and otherwise on the fact that we need the data to perform the contract you have entered into with us, and to meet our own legal and tax obligations.

3. Payment details — what we never see

We never receive, process or store your card number, CVV, UPI ID, net banking credentials or any other payment instrument. When you pay, you are taken to our payment provider’s own secure page and you enter those details there. They are handled by the provider under the Reserve Bank of India’s rules for payment aggregators.

All that comes back to us is whether the payment succeeded, how much was collected, and a reference number for it.

4. What organizers can see about you

When you buy a ticket, the organizer of that event can see your name, email address and phone number in their console, along with what you bought and whether you have been checked in. They need it to run the event and to contact you if something changes.

Organizers are contractually bound to use that only for the event you bought a ticket to. Selling it on, or using it to market unrelated events, is a breach of our terms. If an organizer misuses your details, tell us and we will act on it.

Organizers cannot see your payment details, your other orders, or any other event you have attended.

5. Who else we share data with

We use a small number of service providers to run the site. Each one gets only what it needs to do its job.

WhoWhat they getWhat for
SupabaseThe whole database and your account credentialsHosting our database and running sign-in
Cashfree PaymentsYour name, email, phone and the order amountTaking the payment
ZeptoMail (Zoho)Your name, email and your ticketSending confirmation, ticket and account emails
GoogleYour Google account details, only if you choose to sign in with GoogleSigning you in
OpenRouter, and the AI model provider it routes toThe text you type into the Elf chat, and our catalogue of public eventsProducing an answer in the chat
VercelThe technical data needed to serve a web requestHosting and delivering the site
GitHubA nightly encrypted backup of the database, which includes attendee names, emails and phone numbersKeeping a backup so that a failure does not lose your tickets

Beyond those, we share personal data only with the organizer of an event you bought a ticket to, where the law or a court requires it, and with a buyer or successor if the business is ever transferred. We do not sell it, rent it, or trade it.

6. Elf, and what happens to what you type

Elf is the chat box used to find events. When you send it a message, that message, the rest of that conversation, and a list of our currently published events are sent to OpenRouter, Inc., which routes it to the AI model that writes the reply — currently a model provided by Z.ai (Zhipu AI). Those services are outside India and your message is processed on their servers.

We do not store your Elf conversations on our servers. The transcript is kept in your own browser so it survives a page reload, and it is deleted automatically at midnight India time; the “Start over” button clears it immediately. We do not send your name, email, phone number or order history to the AI provider, and Elf is not used to profile you or to make decisions about you.

Because the message leaves our systems, please do not type anything personal or sensitive into it. It is a way to search for events.

7. Where your data is stored

Our database is hosted in Singapore (Supabase, Asia Pacific — Singapore region). That means the personal data described in this policy is stored outside India. Our email provider processes mail in its India data centre. Our hosting and backup providers, and the AI services behind Elf, operate internationally.

Transferring personal data outside India is permitted under the Digital Personal Data Protection Act, 2023 except to countries the Central Government restricts, and none of the countries involved here is restricted. We tell you because you are entitled to know where your data actually is, not because there is a problem with it being there.

8. How long we keep it

WhatHow long
Orders, payments, invoices and tax records8 years from the end of the financial year they relate to. This is not our choice — income tax, GST and books-of-account rules require it, and it applies even if you close your account.
Your account and profileUntil you ask us to delete it. After that, removed from our live systems within 30 days.
Tickets and transfer history12 months after the event, then deleted. The order record behind them is kept for the period above.
Door check-in and scan records12 months after the event.
The hashed IP counter behind the chat limitDeleted within an hour of being written.
Elf conversationsNot stored by us. Held in your browser and cleared nightly.
Encrypted database backups30 days, then destroyed. A deletion you ask for today disappears from backups within that window.

9. How we protect it

  • Everything travels over HTTPS, and is refused over anything else.
  • The database enforces access rules row by row, so one person’s orders and tickets are unreachable from another person’s session.
  • The most sensitive records — bank details, GST numbers, door codes and scan logs — sit on tables that no browser key can read at all, and are reachable only by our server after it has checked who is asking.
  • Door codes are stored hashed, never as text.
  • Backups are encrypted, and the repository holding them is private.

No system is perfectly secure. If a breach ever affects your personal data, we will notify you and the Data Protection Board as the law requires.

10. Your rights

Under the Digital Personal Data Protection Act, 2023 you can:

  • Ask what personal data we hold about you and get a copy of it.
  • Ask us to correct anything wrong, or complete anything missing.
  • Ask us to delete it — subject to the financial records we are legally required to keep.
  • Withdraw a consent you gave, as easily as you gave it.
  • Nominate someone to exercise these rights if you die or become incapacitated.
  • Complain to us, and then to the Data Protection Board of India.

To exercise any of these, write to support@shindigs.cc from the email address on your account. We will respond within 30 days. There is no charge.

11. Children

This service is not for children. You must be 18 or over to buy a ticket, and we do not knowingly collect personal data from anyone under 18. If you believe a child’s data has reached us, tell us and we will delete it.

12. Changes to this policy

If we change this policy, the date at the top of the page changes with it. If a change is significant — a new category of data, a new provider getting your data — we will say so on the site rather than leave you to notice.

13. Complaints

Write to support@shindigs.cc first. If that does not settle it, our Grievance Officer — named on our Contact page — can be reached at:

We acknowledge within 48 hours and aim to resolve within 30 days. You can escalate to the Data Protection Board of India if you are not satisfied.

What cookies we use, and why there is no consent banner, is set out separately in our Cookie Policy.