Legal · Privacy
Privacy Policy
At Mepass, transparency is non-negotiable. This policy explains what data we collect, why we collect it, and exactly how it is used across all our platforms.
01
Overview
This Privacy Policy applies to all products and services operated by Mepass.
- Mepass Website
- Mobile App
- Event Ticketing Platform
- Event Manager SaaS
By using any Mepass platform, you agree to this policy.
02
Who We Are
Mepass is an event discovery and ticketing platform operating across India. We provide infrastructure for event organizers to sell tickets and for attendees to purchase, manage, and attend events seamlessly.
Our registered entity operates under Indian law and extends compliance to international users under applicable data protection frameworks including GDPR.
03
Data We Collect
| Data Type | Examples | When Collected | Purpose |
|---|---|---|---|
| Identity | Name, Date of Birth | Signup | Account creation |
| Contact | Email, Phone | Checkout | Communication |
| Payment | Card last 4, UPI ID | Purchase | Transactions |
| Location | City, IP address | App usage | Local content |
| Behavioral | Clicks, searches | Browsing | Recommendations |
| Device | OS, browser, device ID | Session start | Security |
04
How We Use Data
- Processing your ticket purchases and delivering order confirmations
- Personalizing your event discovery feed and recommendations
- Sending transactional notifications and support communications
- Detecting fraud, abuse, and unauthorized account access
- Improving platform performance and debugging issues
- Complying with legal obligations and regulatory requirements
05
Data Sharing
We do not sell your personal data. We may share it only in limited circumstances:
- With event organizers, to fulfill your ticket purchase and check-in
- With payment processors (Razorpay, Stripe) for secure transaction handling
- With analytics providers under strict data processing agreements
- With law enforcement when required by valid legal order
- With acquirers in the event of a business merger or acquisition
06
Data Retention
We retain your personal data only as long as necessary to fulfill the purposes described in this policy or as required by law.
- Account data: retained while your account is active
- Transaction records: 7 years for tax and compliance purposes
- Behavioral analytics: 24-month rolling window
- Support tickets: 3 years from resolution date
You may request deletion of your account and personal data at any time via settings or by contacting us.
07
Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
Access
View your stored data
Correction
Fix inaccurate data
Deletion
Request erasure
Portability
Export your data
Withdraw Consent
Opt out anytime
Object
Dispute processing
To exercise any right, email support@mepass.in or use in-app privacy settings.
08
Cookies
We use cookies and similar technologies to enhance your experience and understand platform usage.
Essential
Required for login sessions, cart, and security. Cannot be disabled.
Analytics
Help us understand traffic patterns and improve the platform.
Preferences
Remember your language, city, and display preferences.
Marketing
Show relevant event ads on partner platforms. You may opt out.
09
Security
We implement industry-standard security measures to protect your data from unauthorized access, alteration, or disclosure.
- TLS/SSL encryption for all data in transit
- AES-256 encryption for sensitive data at rest
- Two-factor authentication available for all accounts
- Regular third-party penetration testing and security audits
- Access controls and employee data minimization policies
10
Childrens Privacy
Our services are not directed at children under the age of 13. We do not knowingly collect personal information from anyone under 13.
If you believe we have inadvertently collected such information, contact us immediately at support@mepass.in and we will delete it promptly.
11
International Transfers
Your data is primarily stored in India. Where we transfer data internationally, we ensure adequate safeguards including Standard Contractual Clauses (SCCs) as required by GDPR.
EEA users have additional rights under GDPR, including the right to lodge a complaint with your local supervisory authority.
12
Contact Us
For any privacy-related questions, requests, or complaints, reach out to our team:
We aim to respond to all privacy requests within 30 days of receipt.