evenclo.

Legal

Privacy policy

Last updated 5 August 2026

The short version

1. Who we are, and which hat we wear

evenclo is an event management platform operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS] ("evenclo", "we", "us"). It covers registration and ticketing, check-in and badge printing, exhibitor and lead capture, session programs, 1:1 meetings, and attendee communications, through the web platform at evenclo.com and the two mobile apps described below.

Which data-protection role we play depends on whose data it is, and the distinction decides who you should talk to:

So if you registered for, attended, or exhibited at an event, your primary relationship is with that event's organizer. You can still write to us, and we will route your request to the right organizer and help them answer it.

2. The apps this policy covers

AppPackageWho signs in
evenclo. On-sitecom.evenclo.evenclocheckinOrganizer staff, check-in crew, and exhibitor teams
evenclo. attendeecom.evenclo.attendeePeople attending an event

Both apps are clients of the same platform. Neither works without an account issued through an event.

3. What we collect

Account and sign-in

Name, email address, phone number where given, role, and the tenant or event the account belongs to. Staff passwords are stored only as a salted hash; several account types sign in with a one-time code sent by email instead of a password. Your session token is held in the Android Keystore through the operating system's secure storage, not in ordinary app storage.

Attendee and event records

Set by the organizer's own registration form, which is why the exact list varies per event. Typically: name, email, phone, company, job title, the answers to that form's questions, ticket and order details, the badge QR code we issue, check-in and check-out times, session attendance, booked meetings, survey responses, and certificates earned.

Lead capture

When you present your badge to an exhibitor and they scan it, you are choosing to share your contact details with that exhibitor. They receive your name, email, company, the answers to their qualifier questions, and any rating or note their staff add. That exhibitor becomes an independent controller of the lead record from that point.

Payments

Card payments are handled by our payment gateway. We never see or store full card numbers. We keep the order amount, currency, status, and the gateway's transaction reference. Where an organizer accepts bank transfers, the app lets an exhibitor photograph the transfer receipt and submit it as proof; that image is uploaded and visible to the organizer reviewing the payment. It is the only image either app transmits.

Device and notifications

If you allow notifications, we store a Firebase Cloud Messaging registration token and the platform name, so the organizer can reach you about your meetings and announcements. Push registration applies to exhibitor and attendee accounts; organizer staff devices are not registered. Revoking the notification permission or signing out removes the token.

Technical logs

Our servers record IP address, user agent, requested route, and timestamp for security, abuse prevention, and debugging.

What we do not collect

No location or GPS data. No access to your contacts, photo gallery, files, microphone, or calendar. No advertising identifiers. There is no advertising SDK and no third-party analytics SDK in either app.

4. The camera, specifically

Both the camera permission and what it is used for are narrower than the permission dialog can express, so plainly:

The camera is never accessed in the background, and never opens except on a scanning or receipt screen you navigated to.

5. What the on-site app stores on the phone

A venue's Wi-Fi is the least reliable part of any event, so the on-site app is built to keep working without it. It maintains a local database on the device (evenclo.db) holding, for the events you are signed in to:

This cache is deleted when you sign out, and removed with the app when you uninstall it. Because it contains other people's personal data, the device it lives on should have a screen lock, and organizers should sign out shared or borrowed devices at the end of an event.

6. Why we process it, and on what basis

PurposeBasis
Running the event you registered for — admission, badge, agenda, meetings, certificatesPerformance of a contract, or the organizer's legitimate interest in running their event
Providing the platform to our customers and supporting themPerformance of a contract
Payments, invoicing, and financial recordsContract and legal obligation
Security, fraud and abuse prevention, service reliabilityLegitimate interests
Marketing email or WhatsApp messages from an organizerConsent, or a soft opt-in where local law allows, always with a way to stop
Sharing a lead with an exhibitorYour consent, given by presenting your badge to be scanned

Where an organizer asks their attendees for sensitive information — dietary requirements or accessibility needs, for instance — that organizer is responsible for obtaining explicit consent. We do not require or encourage such fields.

7. Who else sees the data

We do not sell personal data, and we do not share it for advertising. It reaches only:

ProviderWhat it does
Google CloudHosting, application database, secret storage
Firebase Cloud MessagingDelivering push notifications
Mailchimp TransactionalSending transactional and campaign email
Meta WhatsApp BusinessSending WhatsApp messages where an organizer enables it
PaymobProcessing card payments

Organizers may connect further integrations to their own event. Anything they switch on is their choice and their responsibility.

8. Where data is held

Our infrastructure runs in Google Cloud, primarily in the [PRIMARY REGION] region. Some providers above operate internationally, so data may be transferred outside your country. Where that happens from the EEA or the UK, transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision.

9. How long we keep it

10. How we protect it

No system is perfectly secure, but if a breach affects your personal data we will notify the relevant organizer and, where the law requires, the supervisory authority and you.

11. Your rights

Depending on where you live, you may have the right to access your data, correct it, delete it, receive a portable copy, object to or restrict processing, and withdraw consent at any time. Withdrawing consent does not undo processing already carried out.

If you are an attendee or exhibitor, contact the organizer of the event you took part in — they control that data and can act directly. If you cannot reach them, write to us and we will identify the organizer and press them to respond.

If you are a customer of ours, or you are unsure, email privacy@evenclo.com. We answer within 30 days and may need to verify your identity first. You also have the right to complain to your local data protection authority.

To stop marketing messages, use the unsubscribe link in any email, reply STOP to a WhatsApp message, or turn off notifications in your device settings.

12. Children

evenclo is built for professional and business events and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has provided us with personal data, write to us and we will delete it.

13. Changes to this policy

We will post any revision here with a new date at the top. If a change materially affects how we handle your data, we will notify affected customers by email before it takes effect.

14. Contact

Privacy questions and data requests: privacy@evenclo.com
Postal: [LEGAL ENTITY NAME], [REGISTERED ADDRESS]
Data protection contact: [DPO OR RESPONSIBLE PERSON]

back to evenclo