Privacy Policy
Effective date: 2 August 2026 Last updated: 10 August 2026
This Privacy Policy explains how VibeCheck Innovations LLP ("VibeCheck", "we", "us", "our") collects, uses, shares and protects your personal data when you use the VibeCheck website at passvibecheck.com, our mobile applications, and related services (together, the "Platform").
We are a limited liability partnership registered in India under the Limited Liability Partnership Act, 2008.
| Registered name | VibeCheck Innovations LLP |
| Contact | nidhi@passvibecheck.com |
This policy is issued in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
1. Who this policy applies to
This policy applies to everyone who uses the Platform, including:
- Attendees — people who discover events and places, book tickets or tables, and post content
- Organizers — people and businesses who list and run events
- Venue owners — people who manage a venue listing, its offers and its bookings
- Housing societies and colleges — committees and administrators who run events for their residents or students
Where this policy says something applies only to one of these groups, it says so.
2. You must be 18 or older
The Platform is intended solely for users aged 18 years and above. We do not knowingly collect personal data from anyone under 18.
Under the DPDP Act, any person under 18 is a child, and processing a child's personal data requires verifiable consent from a parent or lawful guardian, together with a prohibition on tracking, behavioural monitoring and targeted advertising directed at children. Rather than operate those controls, we restrict the Platform to adults.
If we learn that we hold personal data of a person under 18, we will delete it. If you believe a minor has provided us data, contact our Grievance Officer (Section 12).
3. The personal data we collect
We collect only what the Platform needs to function. Some of this you give us directly; some is generated as you use the Platform.
3.1 Account and profile data
| Data | Source | Notes |
|---|---|---|
| Name, email address, profile photo | Google, when you sign in | Google Sign-In is the only way to create an account. We receive these from your Google account; we never receive or store your Google password |
| Display name, username/handle, bio | You | Optional beyond the display name |
| Profile photo and banner image | You | Optional; replaces the Google-provided photo if set |
| Role and permissions | Us | Whether you are an attendee, organizer, venue owner, society or college administrator |
We do not ask for or use a phone number to create an account. If a phone number is collected in future, or is required by an organizer for a specific booking, that will be stated at the point of collection.
3.2 Location data
- Precise location, obtained from your device with your permission through your browser or operating system, used to show events and places near you and to sort results by distance.
- Approximate location, such as a city or area you select yourself.
Precise location is requested through your device's standard permission prompt. You may refuse or withdraw it at any time in your browser or device settings, and the Platform remains usable — you can browse by selecting an area manually instead.
3.3 Content you post
- Photos, image carousels and short videos ("vibes"), and the cover images you upload for events
- Reviews, ratings, comments, questions and poll responses
- Messages you send through the Platform, including chats connected to an event
- Reports you submit about content, users, events or venues
Content you post publicly is visible to other users. Content you post in a restricted context — for example an event limited to your housing society or college — is visible according to that setting.
3.4 Booking, ticketing and payment data
- Events and venues you view, save, RSVP to or book
- Booking records: ticket type, quantity, attendee names you enter, table or slot reservations, waitlist entries, and check-in status
- Answers you give to an organizer's own registration questions, which may include your college or institution name where the organizer asks for it
- Promotional or referral codes you use
- Payment records: transaction identifiers, amounts, status and timestamps
We do not collect, see or store your card number, CVV, UPI PIN, net-banking credentials or any other payment instrument details. All payments are processed by our payment gateway (Section 6), which collects those details directly. We receive only confirmation of the transaction and the identifiers needed to reconcile it.
3.5 Community and membership data
- Housing society membership: the society you belong to, your residence details as provided to your committee, membership application status, and attendance or contribution records for society events
- College affiliation, where you provide it or where a college administrator records it
- Referral relationships, where you join through another user's referral link
3.6 Organizer and payout data
If you receive money through the Platform as an organizer or venue owner, we additionally process settlement records, commission calculations, payout status, and an internal trust score used to manage payout risk and platform integrity.
3.7 Technical and diagnostic data
-
Error diagnostics. When the Platform encounters an error, we record the error message, technical stack trace, the release version and the page you were on. This is collected to fix faults. It is not used to profile you and we do not currently share it with any third-party error-monitoring provider.
-
Server logs, generated by our hosting and infrastructure providers, which may include IP address, browser and device type, and timestamps, retained for security and abuse prevention.
-
Analytics. We record a fixed, limited set of product events — for example that the app was opened, an event was viewed, or a ticket was purchased. Analytics runs only if you accept analytics cookies; if you decline or make no choice, no analytics events are collected at all.
Since 10 August 2026 this is measured using Google Analytics 4, which acts as our processor. The tag is present on every page but held in Google's Consent Mode
deniedstate until you accept, in which state it sets no cookies and creates no identifier for you. Google may process this data on servers outside India, under Google's own privacy policy. Advertising features —ad_storage,ad_user_dataandad_personalization— are disabled unconditionally, so your usage is not used for advertising, remarketing or audience building.We do not send Google your name, email address, phone number or any other direct identifier. Events carry only identifiers for the content involved (such as an event or place id) and simple values such as an amount or a count. If we adopt a further analytics provider, we will update this policy and obtain your consent before it operates.
We do not use your data for automated decision-making that produces legal or similarly significant effects about you.
4. Why we use your data, and on what basis
Under the DPDP Act we process your personal data on the basis of your consent, or where the Act permits processing for certain legitimate uses — including where you voluntarily provide data for a specified purpose, and to comply with law.
| Purpose | What this means in practice |
|---|---|
| Providing the Platform | Creating your account, showing you events and places, running bookings and check-ins |
| Location-based discovery | Sorting and filtering events and places by distance from you |
| Payments and settlements | Processing ticket and reservation payments, calculating commission, paying organizers and venues |
| Communication | Booking confirmations, event changes and cancellations, and notifications you have enabled |
| Safety and integrity | Investigating reports, enforcing our Terms, detecting fraud and abuse, and moderating content |
| Legal compliance | Meeting obligations under tax, accounting, and information-technology law, and responding to lawful requests |
| Improving the Platform | Understanding which features are used, only where you have consented to analytics |
You may withdraw your consent at any time (Section 8). Withdrawing consent does not affect processing already carried out, and some withdrawals will mean parts of the Platform stop working — for example, withdrawing consent to process booking data means we cannot maintain your tickets.
5. Who we share your data with
We do not sell your personal data.
We share it only as follows:
5.1 With other users
Your public profile, and any content you post publicly, is visible to other users. Content posted to a restricted audience is shown only to that audience.
5.2 With organizers and venues you book with
When you book a ticket or reserve a table, the organizer or venue receives the details needed to run the event and admit you — typically your name, the attendee names you entered, your booking and ticket details, your check-in status, and your answers to any registration questions they asked.
Organizers and venues are independent parties. They are responsible for their own handling of your data and for their own compliance with the law. We require them by contract to use it only to run the event.
5.3 With your housing society or college
If you join a society or college on the Platform, its administrators can see your membership status and your participation in that community's events.
5.4 With service providers who process data for us
We use the providers listed in Section 6. They act on our instructions and are permitted to use your data only to provide their service to us.
5.5 For legal and safety reasons
We may disclose personal data where required by law, court order, or a lawful request from a government or law-enforcement authority, or where we believe in good faith that disclosure is necessary to prevent harm, fraud, or a serious violation of our Terms.
5.6 In a business transfer
If we are involved in a merger, acquisition, financing or sale of assets, personal data may be transferred as part of that transaction. We will give notice before your data becomes subject to a materially different privacy policy.
6. Service providers
| Provider | Role | Data involved | Primary location |
|---|---|---|---|
| Supabase | Database, authentication, file storage, backend functions | Account, profile, bookings, content and community data | India (Mumbai region) |
| Cloudflare | Website hosting, content delivery, media storage | Uploaded photos and videos; request and security logs | Global edge network |
| Razorpay | Payment processing | Payment instrument details (collected directly by Razorpay), transaction records | India |
| Sign-in | Your name, email address and profile photo | Global | |
| Google Analytics | Product analytics, only with your consent | Usage events (screens viewed, actions taken), an analytics identifier, approximate location derived from IP, device and browser type | Global |
Our primary database is hosted in India. Some providers — notably content-delivery and hosting infrastructure — operate globally, so certain technical data such as server logs and cached media may be processed on servers outside India. The DPDP Act permits transfer of personal data outside India except to territories the Central Government restricts by notification; we will comply with any such notification.
We update this table when our providers change.
7. How long we keep your data
| Data | Retention |
|---|---|
| Account and profile | Until you delete your account, then as set out below |
| Deleted accounts | Deactivated immediately; permanently purged 30 days after your deletion request. Signing in during those 30 days restores your account |
| Booking, payment and settlement records | Retained after account deletion for as long as required by tax, accounting and audit law |
| Content you posted | Removed from public view on deletion; residual copies may persist briefly in backups and caches |
| Error diagnostics and server logs | Kept only as long as needed for security and debugging |
We erase personal data when the purpose it was collected for is no longer being served and we are not required to retain it by law, as required by the DPDP Act.
8. Your rights
As a Data Principal under the DPDP Act, you have the right to:
- Access — obtain a summary of the personal data we process about you and the processing activities involved
- Correction and completion — have inaccurate or incomplete data corrected, completed or updated
- Erasure — have your personal data erased, subject to our legal retention obligations
- Grievance redressal — have a readily available means of raising a complaint with us (Section 12)
- Nominate — nominate another person to exercise your rights in the event of your death or incapacity
- Withdraw consent — as easily as you gave it
How to exercise them
Several of these are built into the Platform and are the fastest route:
- Access: Settings → Privacy & Security → Download my data exports the data we hold about you as a JSON file
- Correction: Edit Profile
- Erasure: Settings → Privacy & Security → Delete account, which begins the 30-day deletion described in Section 7
- Location consent: withdraw it in your browser or device settings at any time
- Analytics consent: change your choice at any time from the cookie settings in the app
For anything else — including nomination — contact our Grievance Officer (Section 12). We will respond within the timelines set by law. We may need to verify your identity before acting on a request.
9. Your duties as a Data Principal
The DPDP Act also places duties on you. In particular, you must not impersonate another person when providing personal data, must not suppress material information when providing data where legally required, and must not register a false or frivolous grievance or complaint. Please give us accurate information, and keep it current.
10. Security
We take reasonable security safeguards to protect personal data against unauthorised access, disclosure, alteration and loss, including:
- Encryption of data in transit using HTTPS/TLS across the Platform
- Row-level access controls in our database, so that a request can only reach data the requesting account is entitled to
- Restricted administrative access, and separation of privileged credentials from the application
- Payment details handled entirely by our PCI-DSS-compliant payment gateway, never by our own systems
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a personal data breach occurs, we will notify the Data Protection Board of India and affected users as required by the DPDP Act.
Keep your Google account secure — it is the only way into your VibeCheck account.
11. Cookies and local storage
We use cookies and browser local storage to keep you signed in, remember your preferences such as theme, and — only with your consent — to collect the analytics described in Section 3.7.
Your cookie choice is recorded in your browser's local storage, not in a cookie, and is respected until you change it. Declining analytics does not restrict any Platform feature.
See our [Cookie Policy] for the full detail.
12. Grievance Officer and complaints
In accordance with the Information Technology Act, 2000, the Intermediary Guidelines Rules, 2021, and the DPDP Act, 2023, the following officer may be contacted for any grievance regarding your personal data or content on the Platform:
| Grievance Officer | Nidhi Mulchandani |
| nidhi@passvibecheck.com |
We will acknowledge your complaint within 24 hours and resolve it within 15 days of receipt, as required by the Intermediary Guidelines Rules.
If you are not satisfied with our response, you may make a complaint to the Data Protection Board of India in the manner prescribed under the DPDP Act.
13. Changes to this policy
We may update this policy as the Platform changes or the law changes. When we make a material change we will update the "Last updated" date above and give notice through the Platform. Where a change requires your consent under the DPDP Act, we will ask for it before the change applies to you.
14. Contact us
| Privacy queries | nidhi@passvibecheck.com |
| Grievances | nidhi@passvibecheck.com |
| Safety and abuse reports | nidhi@passvibecheck.com |
This policy is provided in English. If we publish a translation and the versions conflict, the English version governs.