Privacy Policy
Last updated: 15 Sep, 2026
This Privacy Policy applies to Eventu, a product of RiDiscovery Pvt. Ltd. ("RiDiscovery," "Eventu," "we," "us," or "our"). It explains how we collect, use, store, share, and protect personal information across all Eventu platforms - the Android app on Google Play, the iOS app on the Apple App Store, and the Eventu web application - collectively referred to as "the App" or "the Service." This policy applies equally across all three platforms except where a section specifically calls out a difference between them.
RiDiscovery Pvt. Ltd. is based in Surat, Gujarat, India. This policy is written primarily to comply with India's Digital Personal Data Protection Act, 2023 (DPDP Act), and also extends the protections required under the EU/UK GDPR and the California CCPA/CPRA to users in those regions, even though Eventu is not currently marketed there as a primary audience.
By creating an Eventu account or otherwise using the Service, you agree to this Privacy Policy. If you do not agree, please do not use the Service.
1. Who We Are
Eventu is operated by RiDiscovery Pvt. Ltd., a company registered in India, as part of its portfolio of SaaS products. For the purposes of applicable data protection law, RiDiscovery Pvt. Ltd. is the data controller responsible for your personal information.
Registered Address: 309, Unique Square, Singanpor, Katargam, Surat, Gujarat, India - 395004
Contact: ridiscovery.official@gmail.com | +91 82005 50680
2. Who This Policy Covers
Eventu serves two kinds of people, and this policy governs how we handle data for both. Hosts are users who register an account, build events and ceremonies, assemble guest lists, and manage RSVPs. Guests are the people a host invites - some guests register their own Eventu account and interact with the app directly, while others are simply added to a host's guest list and receive invitations and updates without ever creating an account themselves. Section 4 explains how each group's data is handled, and Section 6.3 specifically addresses guests who never register.
3. Age Requirements
- The general minimum age to create an Eventu account is 13 years old.
- For users located in the European Economic Area, United Kingdom, or Switzerland, the minimum age is 16 without parental consent, in line with GDPR and UK GDPR requirements.
- Because no user under 13 is permitted on the Service anywhere, the U.S. Children's Online Privacy Protection Act (COPPA) does not apply to Eventu, since we do not knowingly collect data from children under 13 in any jurisdiction.
- If we become aware that an account belongs to someone below the applicable age threshold, we will deactivate the account and delete the associated data.
4. Information We Collect
4.1 Account Information
- When you register as a host or as a guest with your own account, we collect your name, mobile number, email address (if provided), profile photo, and login credentials.
- Authentication is handled through Firebase Authentication, with SMS/OTP verification provided by MSG91; we do not store your raw OTP codes at any point.
4.2 Event & Ceremony Information
- Hosts provide event names, dates, and ceremony or sub-event schedules, along with any location details they choose to add.
- At present, location is entered as address text rather than a map pin, since we do not yet use a dedicated maps provider - this will be updated here if that changes.
- Hosts may also upload event templates, images, and invitation designs, which are stored as part of the event record.
4.3 Guest Lists & Contact Information
- Hosts can add guests manually, providing names, phone numbers, and optional group or priority labels.
- If a host enables contact sync to check which of their phone contacts already use Eventu, that matching is performed using hashed identifiers processed locally on the host's device - we never upload, receive, or store the host's full, unmatched contact list on our servers.
- Only the specific contacts a host chooses to add to an event's guest list are stored by us, and only for that purpose.
4.4 RSVP & Preference Data
- When a guest responds to an invitation, we collect their attendance status, along with any meal preferences, dietary or allergy information, and answers to custom questions the host has set up (single choice, multiple choice, short text, or long text).
- This data is shared only with the relevant event's host and is used exclusively for planning that event.
4.5 Device & Usage Data
- We collect basic device and usage information - device type, operating system, app or browser version, and IP address - to operate and secure the Service.
- On Android and iOS, push notification tokens are managed through Firebase Cloud Messaging and used to deliver RSVP reminders, invites, and event updates.
- We do not currently use a dedicated analytics tool on any platform; if we add one in the future, this section will be updated to name it before it goes live.
- Platform-specific handling: on Android, we do not collect the Google Advertising ID or use it for tracking or advertising.
- On iOS, we do not collect Apple's Identifier for Advertisers (IDFA) or use cross-app tracking; if this changes, we will request permission through Apple's App Tracking Transparency prompt before any tracking begins, as Apple requires.
- On the web application, once available, we will use browser cookies or local storage to keep you logged in and remember preferences - see Section 13.
4.6 Uploaded Files
- Profile photos and event template images are stored in the same AWS Mumbai infrastructure used for our core hosting.
4.7 Payment Information
- Eventu does not currently charge users or process payments.
- If paid subscriptions are introduced in the future through Razorpay, this policy will be updated before that feature launches, and Razorpay's own privacy practices will govern the handling of payment details at that time.
5. Legal Basis for Processing
Where the GDPR or UK GDPR applies to you, we rely on the following legal bases: performance of a contract, to provide the core Service you've signed up for (account creation, event management, RSVP collection); consent, for optional features such as contact sync and, in the future, marketing communications or non-essential cookies; legitimate interests, for maintaining security, preventing abuse, and improving the Service, balanced against your rights; and legal obligation, where we must retain or disclose information to comply with applicable law. Under India's DPDP Act, our processing is based on your consent at the point of account creation and specific in-app actions (such as enabling contact sync), or as otherwise permitted under the Act's legitimate use provisions.
6. How We Use Your Information
We use personal information to create and manage your account; let you build, publish, and manage events, ceremonies, and guest lists; match synced contacts against existing Eventu users through local hashing as described in Section 4.3; collect and display RSVPs, including preference and questionnaire answers; deliver transactional push notifications such as invites, reminders, and event updates; generate event dashboards and RSVP reports for hosts; verify your identity at login and maintain account security; respond to support requests and in-app reports; maintain the reliability and security of the Service; and comply with applicable legal obligations.
We do not sell personal data, and we do not use your data for automated decision-making or profiling that produces legal or similarly significant effects on you. We also do not send promotional or marketing content to guests who have not created an Eventu account - non-registered guests receive only transactional messages tied to the specific event they were invited to, as described in the next section.
7. How Information Is Shared
When a guest submits an RSVP, their response and any preference or questionnaire answers are shared with that event's host. When a host publishes an event, the event and ceremony details are shared with the guests invited to it. Guest contact details a host adds to a list remain visible only to that host and are never shared with other guests.
Service providers. We share limited data with trusted vendors, strictly to operate the Service, and each is contractually limited to using that data only to provide their service to us, not for their own purposes. Our hosting and backend infrastructure runs on AWS in the Mumbai region, with MongoDB Atlas as our database. Authentication is handled through Firebase Authentication, with SMS and OTP verification provided by MSG91, and push notifications delivered through Firebase Cloud Messaging. We do not yet use an email service provider or a payment processor — if these are activated, we plan to use Resend for email and Razorpay for payments, and this section will be updated to confirm that before either goes live.
Non-app guests. Guests who are added to a guest list but never register on Eventu receive only transactional communications tied to the event they were invited to — the invite itself, RSVP confirmations, and reminders. They receive no promotional or marketing content and are not otherwise contacted by us.
Legal requirements. We may disclose information where required by law, or where we believe in good faith it is necessary to comply with a legal obligation, protect the rights, safety, or property of RiDiscovery, our users, or the public, or investigate a potential violation of our Terms & Conditions.
Business transfers. If RiDiscovery is involved in a merger, acquisition, or asset transfer, your data may be transferred as part of that transaction. We will provide notice before your data becomes subject to a different privacy policy.
8. International Data Transfers
Eventu's infrastructure - hosting, database, and authentication - runs on AWS's Mumbai, India region. If you're located outside India, using the Service means your data is transferred to and processed there. We apply the same protections described in this policy regardless of where you access Eventu from. If a future vendor stores or processes data outside India (for example, an email or analytics provider), we will disclose that specific transfer here before the feature is activated.
9. Data Retention
Account data is retained for as long as your account remains active. Event, guest list, and RSVP data is retained until the associated event is deleted by the host, or for up to 24 months after the event date, whichever comes first, unless a shorter or longer period is required for legal or security reasons. Support requests and in-app reports are retained for up to 12 months to allow for follow-up and pattern review. If you delete your account, we will delete or anonymize your personal data within 30 days, except where specific records must be retained longer to meet a legal obligation.
10. Data Breach Notification
If a breach involving your personal data occurs that is likely to result in risk to your rights, we will notify the India Data Protection Board and affected users as required under the DPDP Act, and will additionally notify the relevant supervisory authority and affected individuals within 72 hours where the GDPR applies, to the extent we are able to assess the breach within that window. Notifications will describe the nature of the breach, the data involved, and the steps we are taking in response.
11. Your Rights
If you are in India, the DPDP Act gives you the right to access your personal data, request correction or erasure, withdraw consent, and file a grievance about how your data is handled (Section 15). If you are in the EEA, UK, or Switzerland, the GDPR gives you the right to access, correct, delete, or restrict processing of your data, the right to data portability, the right to object to certain processing, and the right to lodge a complaint with your local supervisory authority. If you are in California, the CCPA/CPRA gives you the right to know what personal information we collect, to request deletion, and to opt out of the sale of personal information - though this right has no practical effect here, since RiDiscovery does not sell personal data.
To exercise any of these rights, contact us at ridiscovery.official@gmail.com. Some of these actions are also available directly in-app, including editing your profile and deleting your account.
12. Data Security
We apply encrypted data transmission via HTTPS/TLS, secure authentication through Firebase Authentication with OTP verification via MSG91, local hashed contact matching rather than raw contact upload (Section 4.3), access controls that restrict internal access to personal data, and infrastructure hosted on AWS Mumbai with MongoDB Atlas as our database layer. No system is completely secure, and we cannot guarantee the absolute security of information transmitted to the Service.
13. Cookies & Similar Technologies (Web Application)
This section applies once the Eventu web application is live. We intend to use only the cookies or local storage necessary to keep you logged in, remember your preferences, and maintain basic security - essential and functional cookies. We do not currently plan to use advertising or third-party tracking cookies; if that changes, we will request consent through a cookie banner where required by law, including for EEA and UK visitors, and this section will be updated before any such cookies are activated. You can control or delete cookies through your browser settings at any time, though disabling essential cookies may prevent you from staying logged in. We do not currently respond to browser "Do Not Track" signals, as we do not engage in cross-site tracking that this signal is designed to address.
14. App Store & Google Play Disclosures
This Privacy Policy is published to meet the requirements of both the Apple App Store's App Privacy disclosures and Google Play's Data Safety section, and is kept consistent with what is declared in both listings. The data categories described in Section 4 reflect what is actually collected on each platform today. As features are added - payments, analytics, or maps, for example - we will update this policy and both platforms' data disclosures together, so they never fall out of sync. Neither the Android nor the iOS app currently uses data for third-party advertising or tracking.
15. Grievance Officer / Data Protection Contact
In accordance with India's DPDP Act, 2023, you may direct privacy-related grievances to RiDiscovery Pvt. Ltd. at ridiscovery.official@gmail.com or +91 82005 50680, at the registered address in Section 1. A dedicated Grievance Officer has not yet been formally designated by name; the contact details above serve this function until one is appointed. This should be updated with a named individual and title before public launch, as the DPDP Act requires a specifically designated officer rather than a general company contact.
16. Third-Party Links
The Service may occasionally link to third-party websites or services (for example, a payment provider's checkout page once Razorpay is integrated). This Privacy Policy does not cover those third parties, and we encourage you to review their privacy practices separately.
17. Changes to This Policy
We may update this Privacy Policy as Eventu's features, vendors, or legal obligations evolve - particularly as payment processing, email, maps, or analytics tools are activated. The "Last updated" date at the top will reflect the latest revision. For material changes, we will notify you through an in-app notice or banner before the change takes effect, in addition to updating this page.
18. Contact Us
For any questions regarding these policy, please contact:
RiDiscovery Pvt. Ltd.
309, Unique Square, Singanpor, Katargam, Surat, Gujarat, India - 395004
Email: ridiscovery.official@gmail.com
Phone: +91 82005 50680
Subscribe for
early access to Eventu!
Be the first to experience Eventu and enjoy early access to smarter event management.
