AttendStack.
Back to AttendStack
TRUST & TRANSPARENCY · v1

Privacy notice

What we collect, why we use it, and the choices available to you.

Who handles your information

AttendStack handles information needed to run the platform and maintain accounts. Event organisers decide how attendee information is used for their events. AttendStack processes booking and check-in information to provide those tools. Depending on the circumstances and applicable law, the organiser and the platform may have different responsibilities for your information.

Information we collect

  • Account and workspace details: name, username, password hash, role and offline permissions.
  • Booking details: attendee name, email, phone number and country, event, ticket identifier, signed QR payload and booking time.
  • Payment records for paid events: provider, amount, currency, checkout and refund identifiers, and payment status. Card details are entered directly on the organiser’s Stripe or Razorpay checkout and are not stored by AttendStack.
  • Admission records: ticket, outcome, scan and receipt times, scanner account and device identifier.
  • Consent and preferences: accepted policy versions, acceptance time and marketing choices.
  • Security and support information, including sessions, operational logs and the information you provide in a privacy request.

The QR payload contains a ticket identifier, event identifier, attendee name and expiry, protected by a signature. A signature verifies authenticity; it does not hide those details from someone who can decode the QR.

Why we use it

We use this information to create accounts, issue tickets, send booking messages, verify entry, prevent duplicate admissions, support users and protect the service. Where applicable, these activities rely on providing the requested service, legitimate operational and security interests, or legal obligations. Optional AttendStack marketing uses your separate choice. Acknowledging this notice is not blanket consent to every use of your data.

Who receives it

Your organiser and its authorised staff receive the event information their permissions allow. Offline-enabled devices receive a local event pack. For paid events, the organiser’s Stripe or Razorpay account receives the payment and booking details needed for checkout and refunds. Resend processes ticket emails when email delivery is configured. Hosting and infrastructure providers process information needed to operate the deployed service. We do not sell attendee lists or install advertising trackers in this version of AttendStack.

Retention and deletion

Archiving an event does not erase attendee or admission records. Records currently remain until reviewed and removed through an authorised data-handling process; there is no automatic event-history deletion schedule. Retention may be needed for event administration, resolving disputes, security or applicable obligations. We review deletion requests and explain any information that needs to be retained. Offline copies and backups require separate handling and cannot always be removed immediately.

Your choices and rights

You can withdraw marketing permission, ask about your information, request correction or deletion, and exercise other rights available under applicable law. We may need to verify your identity and involve the relevant organiser. Use the data request form. You may also have the right to contact your local data-protection authority.

Security and international processing

We use access controls, password hashing, signed tickets and encrypted scan-sync uploads. These measures do not eliminate all risks. Processing locations depend on the deployment and service providers; contact us for details about your event and any applicable transfer safeguards. See how we handle data for the practical limits of offline storage.

Questions or a data request?

Contact the AttendStack service team: send a privacy request. For event admission, cancellation, or booking questions, contact the organiser shown on your event page.