Privacy Policy

Last Updated: August 31, 2026

At Eventist, your privacy matters. This Privacy Policy explains how Eventist ("we," "us," or "our") collects, uses, discloses, and protects your personal information when you use our website www.eventist.ca, our mobile applications, and all related services (collectively, the "Services").

By using the Services, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please do not use the Services.

About this policy: The categories, examples, providers, and integrations described below illustrate how the Services work and are not exhaustive. Words such as "including" and "such as" mean "including without limitation." The platform changes over time — features, service providers, and available integrations are added, changed, and removed — and the practices described here apply to those changes as well. Where we make a material change to how we handle your information, we will update this policy as described in Section 18.

1. Information We Collect

We collect information in the following categories:

a) Information You Provide

  • Account Information: Name, email address, phone number, and password when you create an account.
  • Profile Information: Profile photo, organization name, and other details you choose to add.
  • Event Information (Organizers): Event descriptions, venue details, pricing, schedules, seating and venue maps, staffing and task data, and media you upload.
  • Payment Information: Billing address and payment method details. Payment card information is collected and processed directly by our third-party payment processors (Stripe and Square) and is not stored on Eventist servers.
  • Registration and Ticket Data (Attendees): Information provided when registering for or purchasing tickets to events, including custom form fields set by Organizers. Organizers choose what these fields ask for, and they may request information beyond what Eventist itself requires.
  • Communications: Messages you send to us through support channels, contact forms, or email.
  • Waiver, Contract, and Signature Data: If an Organizer requires you to sign a waiver, a contract, or provide consent as part of registration or staffing, that document and your drawn or typed signature are collected and stored through the platform. See Section 6 for important information about how these files are stored.
  • Uploaded Files: Images, documents, audio and video files, PDFs, run-of-show and music files, spreadsheets, and any other files you or an Organizer upload to the platform. See Section 6.
  • Prompts and Content Submitted to AI Features: Anything you type into, paste into, or attach to our AI features. See Section 3.

b) Information Collected Automatically

  • Usage Data: Pages visited, features used, actions taken, time and date of visits, referring URLs, and error and crash reports.
  • Product Analytics Events: We record structured events describing how the Services are used — for example logging in, completing a profile, or initiating a ticket transfer — and associate them with your email address once you are signed in. See Section 12.
  • Device Information: Browser type and version, operating system, device type, screen resolution, and unique device identifiers.
  • IP Address and Location: Your IP address, which may be used to determine your approximate geographic location (city/region level).
  • Email Engagement: Whether you opened an email we sent on an Organizer's behalf and which links in it you clicked. See Section 12.
  • Referral and Link Data: When you arrive through a referral, discount, or promoter link, we record that attribution so the correct party is credited.
  • Precise Location (Mobile App): When you use the in-person payment features of our mobile app (Tap to Pay or a connected card reader), your device's precise geographic location is collected by our payment processor, Stripe, to authorize the transaction, as required by Stripe and payment card network rules and to help detect and prevent fraud. It is accessed only while you are actively using these features, never in the background, and Eventist does not store your location — it is used only to complete the payment through Stripe. See Section 15.
  • Camera (Mobile App): Our mobile app uses your device's camera to scan tickets and QR codes. The camera reads codes on your device only; we do not capture, store, or transmit photographs or video. See Section 15.
  • Cookies and Local Storage: See Section 12 for details.

c) Information from Third Parties

  • Payment Processors: Transaction status, payment confirmations, and fraud screening results from Stripe and Square.
  • Social Login Providers: If you sign in using a third-party service (e.g., Google), we receive your name, email address, and profile picture as authorized by that service.
  • Social Media and Advertising Platforms (Organizers): When an Organizer connects their Facebook Page, Instagram Business Account, or advertising account to Eventist, we receive page and account access tokens, page and account names, linked account identifiers, and advertising performance and audience statistics via the Meta (Facebook) API.
  • Marketing and CRM Platforms (Organizers): Where an Organizer connects a third-party marketing platform, we may receive contact, list, and engagement data back from that platform.
  • Organizers: Organizers may import attendee lists, contact lists, or other information to the platform. Where an Organizer uploads information about you that you did not give us directly, the Organizer is responsible for having the right to do so.
  • Organizers' Own Websites, Funnels, and Forms: Where an Organizer connects an external landing page, funnel builder, form, or automation tool to their Eventist account, we may receive your contact information from that page even though you never visited Eventist. See Section 5(d).
  • Any Other Service an Organizer Connects: More generally, we may receive information about you from any third-party tool or service an Organizer chooses to connect to their account. The Organizer is responsible for the lawfulness of that collection.

d) Publicly Listed Event Information

Our event discovery features include publicly listed events gathered from public event sources and ticketing websites. This information concerns events — titles, dates, venues, descriptions, images, and links — and, where an event listing publicly names its organizer or performers, that publicly listed name may appear as part of the event record. If you are named in a listing we have gathered and you would like it corrected or removed, email [email protected].

2. How We Use Your Information

We use your information for the following purposes:

  • Providing the Services: Processing transactions, managing accounts, delivering tickets, sending order confirmations and event updates.
  • Communication: Responding to your inquiries, sending service-related announcements, and providing customer support.
  • Improving the Services: Analyzing usage patterns, diagnosing technical issues, and developing new features.
  • Personalization: Recommending events and content based on your interests and activity.
  • AI Features: Generating and analyzing content at your request, as described in Section 3.
  • Marketing: Sending promotional emails, newsletters, and event recommendations (with your consent or where permitted by law). You can opt out at any time.
  • Safety and Security: Detecting and preventing fraud, abuse, and security threats. Enforcing our Terms of Service.
  • Legal Compliance: Complying with applicable laws, regulations, legal processes, or government requests.

3. Artificial Intelligence Features

Eventist offers optional features powered by artificial intelligence, including an assistant that helps Organizers set up and manage events, generated event descriptions and images, generated advertising copy and creatives, transcription and extraction of information from documents and images you attach, and automated suggestions and recommendations.

These features are available to signed-in Organizers and their staff. They are not offered to Attendees, and Eventist does not operate a public-facing chatbot.

a) AI Providers We Use

To provide these features we send data to third-party AI providers, currently OpenAI and Anthropic. These providers process the data on our behalf under their commercial API terms.

b) What Is Sent to AI Providers

Depending on the feature you use, the following may be sent to an AI provider:

  • The prompt, message, or instruction you type, and your previous messages in the same conversation.
  • Files, images, screenshots, and documents you attach to an AI feature.
  • Information about the event you are working on, which is supplied to the assistant so it can answer accurately — including event settings, schedules, ticket types, pricing, sales and revenue figures, tasks, and staffing.
  • Attendee personal information, where you ask for it. The assistant can look up registrations and purchases by name or email in order to answer questions such as whether a specific person checked in or received their confirmation. When you make such a request, the matching attendee's details are sent to the AI provider as part of answering it.

c) Limits We Place on AI Use

  • We do not permit our AI providers to use your data to train their models. Data sent through our commercial API accounts is excluded from provider model training under those providers' business terms.
  • AI providers may retain data briefly for abuse monitoring in accordance with their own policies before deleting it.
  • We store your AI conversations, prompts, attachments, and the resulting outputs on our servers so you can revisit and undo them. They are retained with your account and deleted according to Section 9.
  • Eventist staff may review AI conversations where necessary to investigate a support issue, a billing dispute, or suspected abuse.

d) Automated Decisions

AI features assist you; they do not make decisions about you. We do not use AI to make automated decisions that produce legal or similarly significant effects about any person — we do not use it to approve or deny access, set individual pricing, screen applicants, or evaluate anyone's eligibility for anything. Actions the assistant proposes are executed only after a signed-in human user approves them, and can be undone.

e) AI Output Is Not Advice, and Is Not a Support Service

AI output may be inaccurate, incomplete, or misleading, and must be reviewed before you rely on it. Our AI features are business tools for operating events. They are not a counselling, medical, legal, financial, or crisis-support service, and they are not monitored by a human in real time. If you are in distress or thinking about harming yourself, please do not use these features to seek help — contact your local emergency number, or in Canada and the United States call or text 988 for the Suicide and Crisis Lifeline.

f) Declining AI Features

AI features are optional. You are not required to use them, and choosing not to use them does not affect your access to the rest of the Services. Organizers should not enter personal information about Attendees into AI features beyond what is necessary for the task at hand.

4. No Sale of Your Data

We will never sell your personal information to third parties. We do not share your data with third parties for their own independent marketing or advertising purposes.

This does not prevent an Organizer from directing us to send their own attendee data to a marketing, advertising, or CRM platform that the Organizer controls, as described in Sections 5(c), 5(d), and 5(e), or from sending it anywhere else through the general-purpose mechanisms in Section 5(d). In those cases the Organizer, not Eventist, decides where the data goes.

5. How We Share Your Information

We may share your information in the following circumstances:

a) With Organizers

When you register for or purchase a ticket to an event, the Organizer of that event receives your registration information (such as your name, email address, and any data you provided in the registration form). Once your data is shared with an Organizer, their use of your data is governed by their own privacy practices, not this Privacy Policy. Organizers can export this data at any time. Deleting your Eventist account does not delete data that Organizers have already received or exported, and we cannot recall it on your behalf.

b) With Service Providers

We share information with trusted third-party service providers who perform services on our behalf. These providers are contractually obligated to use your data only for the purposes of providing services to us and to maintain appropriate security measures. They include:

  • Payment Processing: Stripe and Square, for transaction processing, payouts, and fraud screening.
  • AI Providers: OpenAI and Anthropic, as described in Section 3.
  • Email and SMS: Communication service providers for sending transactional and marketing messages.
  • Hosting, Storage, and Content Delivery: Cloud hosting, object storage, and content delivery providers that store and serve our platform and uploaded files.
  • Product Analytics and Error Monitoring: PostHog, as described in Section 12.
  • Mapping and Geocoding: Providers that turn addresses into map locations and render maps.

We change service providers from time to time as the platform evolves. Where we engage a new provider in one of these categories, it is bound by the same obligations described above, and this list may not always name every current provider. A current list is available on request from [email protected].

c) With Platforms an Organizer Connects

Organizers can connect third-party marketing, CRM, e-commerce, advertising, analytics, automation, and productivity platforms to their Eventist account. When an Organizer connects such a platform, we send that Organizer's contact and event data — which may include your name, email address, phone number, and purchase or registration activity — to the connected platform at the Organizer's direction.

Platforms that can be connected currently include Mailchimp, Klaviyo, Brevo, HubSpot, GoHighLevel, Shopify, Meta (Facebook and Instagram), Google, Microsoft, LinkedIn, and WhatConvertsand any other tool, service, or destination an Organizer chooses to integrate with, including through the general-purpose mechanisms described in Section 5(d). We add, change, and remove available integrations over time, and this list will not always be complete or current. The categories of data and the roles described in this section apply to every such integration, whether or not it is named here.

Eventist does not control what a connected platform does with data once it is sent, and we do not vet, endorse, or audit the destinations Organizers choose. The Organizer is the data controller for that transfer and is responsible for having a lawful basis for it. Your relationship with that platform is governed by the Organizer's and that platform's own privacy policies, not this one.

d) Webhooks, Embeds, and Other General-Purpose Connections

Beyond the named integrations above, the Services provide general-purpose mechanisms that let an Organizer move data between Eventist and any other system they choose. Because the Organizer supplies the destination, Eventist has no advance knowledge of, and no control over, where data sent through these mechanisms goes.

  • Outgoing webhooks. An Organizer can register one or more URLs of their choosing to receive an automatic notification each time a registration or purchase completes on their event. The notification is sent to that URL as it happens and contains the registrant's name, email address, phone number, ticket type, price and currency, the answers to any custom registration or checkout questions the Organizer configured, and the referral source and referring page URL for the order. Deliveries are signed so the receiving system can verify they came from us, and are retried if the destination does not respond. We store a record of each delivery — including the data sent and the response returned — so Organizers can troubleshoot failures.
  • Incoming webhooks and lead capture. An Organizer can generate a secret URL that lets an external landing page, funnel builder, form, or automation tool push contact information — such as a name and email address — into their Eventist account. Information can therefore reach us about you from a page you visited that is not operated by Eventist. The Organizer is responsible for the lawfulness of that collection and for telling you about it.
  • Embedded components. Organizers can embed Eventist checkout and event content directly into their own websites. When you use an embedded component, Eventist receives the information you enter into it and the technical information described in Section 1(b), even though you are on the Organizer's website. The surrounding page is the Organizer's, and anything it collects independently is governed by the Organizer's own privacy policy.
  • Exports and reports. Organizers can download registration, purchase, attendance, and contact data as files at any time and use it in any system they choose. Exported data is no longer protected by our access controls and is outside our technical control.
  • Automation and connector tools. An Organizer may route data through general automation or connector services, which can in turn pass it to further systems we have no relationship with or visibility into.

In every case above, the Organizer decides the destination and acts as the data controller for the transfer. If you want to know where a specific Organizer sends your data, ask that Organizer. If you would like us to tell you whether a given event has such a connection enabled, email [email protected].

e) Advertising Audiences

Where an Organizer uses our advertising tools, we may upload contact information for that Organizer's own attendees and contacts to Meta in order to build a custom audience — so the Organizer can advertise to their existing attendees — or to seed a "lookalike" audience of people with similar characteristics.

  • Email addresses and phone numbers are irreversibly hashed (SHA-256) on our servers before being sent. We do not send Meta the plain-text values.
  • This is done only at an Organizer's direction and only with that Organizer's own attendee data.
  • Hashing reduces but does not eliminate exposure: Meta matches the hashes against its own users.
  • If you do not want your information used this way, contact the Organizer of the event you registered for, or email us at [email protected] and we will pass your objection on.

f) For Legal Reasons

We may disclose your information if required to do so by law or if we believe in good faith that disclosure is necessary to:

  • Comply with a legal obligation, court order, or government request.
  • Protect and defend the rights, property, or safety of Eventist, our users, or the public.
  • Detect, prevent, or address fraud, security, or technical issues.

g) Business Transfers

If Eventist is involved in a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your personal information.

6. Uploaded Files and Content Delivery

Files uploaded to the Services — such as event images and posters, profile photos, venue and seating maps, documents, and signed forms — are stored in cloud object storage and delivered through a content delivery network so that they load quickly for attendees.

a) How Access to Files Works

Each file is addressed by a long, randomly generated link. Files are not listed, are not indexed by search engines, and cannot be found by browsing or guessing.

Access is controlled by the link itself rather than by a sign-in, which is a common approach for delivering event media and documents at speed. Anyone you share a file's link with can open that file. Treat file links the way you would treat any other private link, and share them only with people who should have access.

b) Retention of Files

Uploaded files are retained for as long as they may be needed to provide the Services. They are not deleted automatically when the content referencing them is changed or removed, and cached copies may remain available for a period after a file is deleted from storage.

To have a specific file permanently deleted, email [email protected] identifying the file, and we will remove it from storage and request that caches be purged.

c) Choosing What to Upload

Upload only what your event actually requires. We recommend against storing identity documents, health records, or financial account details in the platform; where you need to handle material of that kind, use a system designed for it.

7. Data Controller and Processor Roles

  • Eventist as Controller: Eventist is the data controller for personal information collected to operate the platform, including account data, usage and analytics data, and payment data.
  • Eventist as Processor: When Organizers collect Attendee data through custom registration forms, waivers, contracts, signatures, uploads, or connected integrations, Eventist processes that data on the Organizer's instructions and on their behalf. The Organizer is the data controller for it. The Organizer decides what to collect, whether to collect it at all, what questions to ask, what documents to require, how long to keep the result, who in their organization may see it, and where to send it. Organizers are responsible for having a lawful basis for that collection, for providing their own privacy notice to their Attendees, and for their own compliance with privacy laws.

If you are an Attendee, the practices of the event you registered for — including what you were asked for and why — are set by that Organizer, not by Eventist.

If you are an Attendee and want data deleted that an Organizer collected from you, we will act on your request for the copy we hold, and will direct you to the Organizer for the copies they hold or have exported.

8. Data Security

We take reasonable technical and organizational measures to protect personal information against unauthorized access, alteration, disclosure, or destruction. These include encryption of data in transit (TLS/SSL), authenticated access to accounts and administrative functions, role-based permissions within an Organizer's account, and separation between data belonging to different Organizers.

Different parts of the Services use different protections. Account and transactional data held in our systems is reachable only through authenticated requests. Uploaded files are delivered by link as described in Section 6, which is a different model, and you should read that section before uploading anything you consider sensitive.

We do not represent that our security is comprehensive, independently audited, certified, or sufficient for any particular purpose, and we make no security warranty. No method of transmission over the internet or electronic storage is completely secure. While we work to protect your information, we cannot guarantee its security, and you provide it at your own risk.

9. Data Retention

We retain your personal information only as long as necessary to fulfill the purposes described in this Privacy Policy, including:

  • Active Accounts: Data is retained for the duration of your account.
  • After Account Deletion: Upon account deletion, we will delete or anonymize the personal information in your account within 90 days, except where retention is required for legal, tax, accounting, or fraud prevention purposes.
  • Uploaded Files: Retained indefinitely unless specifically deleted. See Section 6(b).
  • Data Already Received by Organizers: Not deleted by us, and outside our control. See Section 5(a).
  • AI Conversations: Retained with your account so you can review and undo actions, and deleted with the account.
  • Webhook Delivery Records: Records of data sent to an Organizer's chosen destination, including the payload and the response, are retained so Organizers can troubleshoot delivery failures, and are deleted with the event.
  • Analytics Data: Retained for up to twenty-five (25) months.
  • Inactive Accounts: Accounts that have been inactive for more than five (5) years may be deleted after notice.
  • Transaction Records: Financial and transaction records may be retained for up to seven (7) years as required by tax and accounting laws.

10. Data Breach Notification

In the event of a data breach that poses a real risk of significant harm to individuals, we will:

  • Notify affected users without unreasonable delay.
  • Report the breach to the relevant privacy authorities as required by law (including the Office of the Privacy Commissioner of Canada under PIPEDA).
  • Provide information about the nature of the breach, the data affected, and steps being taken to mitigate harm.

11. Your Rights

Depending on your location, you may have the following rights regarding your personal information:

a) All Users

  • Access: Request a copy of the personal information we hold about you.
  • Correction: Request that we correct inaccurate or incomplete information.
  • Deletion: Request that we delete your personal information, subject to legal retention requirements and the limits described in Sections 5(a) and 6(b).
  • Withdrawal of Consent: Where processing is based on your consent, you may withdraw consent at any time.

To exercise these rights, email us at [email protected] from the address associated with your account. We will respond within 30 days.

b) Canadian Residents (PIPEDA)

Under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), you have the right to:

  • Access and challenge the accuracy of your personal information held by us.
  • Withdraw consent for the collection, use, or disclosure of your personal information (subject to legal or contractual restrictions).
  • File a complaint with the Office of the Privacy Commissioner of Canada if you believe your privacy rights have been violated.

c) European Economic Area, UK, and Swiss Residents (GDPR)

If you are located in the EEA, UK, or Switzerland, our legal bases for processing your personal information include:

  • Contract: Processing necessary to perform our contract with you (e.g., providing the Services).
  • Consent: Processing based on your explicit consent (e.g., marketing emails).
  • Legitimate Interest: Processing necessary for our legitimate business interests (e.g., fraud prevention, product analytics, service improvement), balanced against your rights.

In addition to the rights above, you also have the right to:

  • Data Portability: Receive your personal data in a structured, machine-readable format.
  • Restriction: Request restriction of processing in certain circumstances.
  • Object: Object to processing based on legitimate interests, including profiling.
  • Automated Decision-Making: Not be subject to a decision based solely on automated processing that produces legal or significant effects. As described in Section 3(d), we do not make such decisions.

You may lodge a complaint with your local supervisory authority.

International Data Transfers: Your data may be transferred to and processed in Canada and the United States, including by our AI, analytics, payment, and communication providers. Where required, we use appropriate safeguards such as Standard Contractual Clauses (SCCs) to protect your data during international transfers.

d) California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act and California Privacy Rights Act:

  • Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected, the sources, the business purposes, and the categories of third parties with whom we share it.
  • Right to Delete: Request deletion of your personal information.
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Opt Out: Opt out of the "sale" or "sharing" of your personal information. Eventist does not sell your personal information. Where an Organizer directs us to share their attendee data with an advertising platform as described in Section 5(e), you may opt out by emailing [email protected].
  • Right to Limit Use of Sensitive Personal Information: We do not use or disclose sensitive personal information for purposes other than providing the Services.
  • Non-Discrimination: We will not discriminate against you for exercising your CCPA/CPRA rights.

To exercise these rights, email [email protected] or use the privacy controls in your account settings.

12. Cookies, Analytics, and Tracking

a) Cookies and Local Storage

The cookies and browser storage we use are:

  • Session Cookie: Used to keep you logged in and authenticate your requests. This is essential for the Services to function.
  • Preference Storage: Used to remember choices such as your selected city on the discover page, or your last-used view within the Organizer portal, so you do not have to choose them each visit.
  • Analytics Cookie: Set by our product analytics provider to recognize a returning browser across visits. See below.

Managing Cookies: You can control and delete cookies through your browser settings. Disabling cookies may prevent you from logging in or may affect certain preferences.

b) Product Analytics

We use PostHog to understand how the Services are used, to diagnose errors, and to improve the product. PostHog records page views, feature interactions, structured product events (for example logging in, completing a profile, or starting a ticket transfer), device and browser information, and automatically captured error and exception reports.

Once you sign in, these events are associated with your email address, so that we can trace an individual account's experience when diagnosing a problem or supporting a request.

Analytics requests are routed through a first-party path on our own domain (/ingest) rather than directly to the provider's domain. We do this so that the measurement is not blocked by network filters — you should be aware that, as a result, common ad and tracker blockers will not block this collection. PostHog acts as our processor and does not use this data for its own purposes.

To object to analytics collection, email [email protected].

c) Email Open and Click Tracking

Emails we send on an Organizer's behalf may include a small invisible image (a tracking pixel) and links that redirect through our servers. These tell us and the Organizer whether the email was opened and which links were clicked, along with the approximate time. This information is used to measure campaign performance.

Most email clients allow you to block remote images, which prevents open tracking.

Transactional emails such as receipts and ticket confirmations are also delivered through these systems.

d) Referral, Discount, and Promoter Links

Links that carry a referral, discount, or promoter code record that you arrived through them, so that the correct party is credited for a resulting purchase. This attribution is stored with the resulting order.

e) Do Not Track

Some browsers send "Do Not Track" (DNT) or Global Privacy Control (GPC) signals. We honour GPC signals where we are legally required to do so. Because we do not use cross-site advertising trackers, these signals do not otherwise change our behaviour. We do not track you across third-party websites.

f) Organizer Tracking Pixels

Organizers may configure their own tracking pixels — such as Meta Pixel, Google Analytics, or conversion tags — on their event storefronts and checkout pages. These are set by the Organizer, not by Eventist, may send data to those third parties for the Organizer's advertising purposes, and are governed by the Organizer's own privacy practices, not this Privacy Policy. Eventist does not control what those pixels collect.

13. Children's Privacy

The Services are not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at [email protected] and we will delete it promptly.

Organizers who run events for minors are responsible for obtaining any parental or guardian consent required by law before collecting a child's information through the platform.

14. Social Media Integrations

Organizers may connect their Facebook Page and Instagram Business Account to Eventist to automatically post event announcements when events are published, and to run advertising. When an Organizer connects via Meta (Facebook):

  • Data Collected: We receive and store a page access token, Facebook Page ID and name, Instagram Business Account ID and username, and, where advertising is used, ad account identifiers and campaign performance statistics.
  • Data Use: This information is used only to publish posts and manage advertising on the Organizer's connected accounts on their behalf.
  • Data Storage: Access tokens and account information are stored securely on our servers for as long as the connection is active.
  • Disconnecting: Organizers can disconnect their Facebook and Instagram accounts at any time from their Account Settings. Disconnecting immediately removes all stored access tokens and account information from our servers.
  • Data Deletion: To request deletion of all Meta-related data stored by Eventist, Organizers can either disconnect their account in Account Settings, delete their Eventist account, or email [email protected].

Eventist does not access or store any content from the Organizer's Facebook Page or Instagram account beyond what is necessary to publish event posts and manage advertising the Organizer has asked us to run.

15. Mobile Application

Our mobile app is used by Organizers and their staff to run events in person — for example, scanning tickets at the door and accepting payments. This section explains the device permissions the app uses and how account management works on mobile.

a) Device Permissions

  • Camera: Used to scan tickets and QR codes at the door. Codes are read on your device; no photos or video are captured, stored, or sent to us.
  • Precise Location: Used only when you accept in-person payments. Stripe and payment card networks require the device's location to authorize Tap to Pay and card-reader transactions and to help prevent fraud. Location is accessed only while the payment feature is in use, never in the background. It is sent to Stripe to process the payment; Eventist does not store your location.
  • NFC and Bluetooth: Used to accept contactless (Tap to Pay) payments and to connect to supported external card readers. These are used only to complete in-person transactions.

You can grant or revoke any of these permissions at any time in your device settings. Denying a permission disables the related feature — for example, revoking camera access prevents ticket scanning.

b) Account Creation and Deletion

You cannot create an Eventist account from within the mobile app; new accounts are created on our website. To request deletion of your account and associated personal information, email us at [email protected] from the email address associated with your account. We will verify and process deletion requests as described in Section 9 (Data Retention).

16. Third-Party Links and Services

Our Services may contain links to third-party websites, services, or applications. We are not responsible for the privacy practices or content of these third parties. We encourage you to review the privacy policies of any third-party service you access through our platform.

17. Electronic Communications

By using the Services, you consent to receiving electronic communications from us. See our Terms of Service for details on the types of communications you may receive and how to manage your preferences.

18. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top and may notify you by email or through the Services. Your continued use of the Services after changes are posted constitutes your acceptance of the revised Privacy Policy.

19. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal information:

If you are not satisfied with our response, you may file a complaint with the Office of the Privacy Commissioner of Canada at www.priv.gc.ca.