AfA
← Back to AforAudience

Draft — pending legal review

This page reflects our current plan, not a finalized legal document. It will be reviewed with our CA and a lawyer once the company is formally registered, and this notice will be removed once that review is complete.

Privacy Policy

Last updated: date to be set on publish

AforAudience ("we", "us", "the platform") connects comedians, poets, musicians, and other live performers with venues, event organisers, and audiences, starting in Pune, India. This policy explains what personal data we collect, why, and what rights you have over it.

Operated by: Legal entity name, once registered
Registered address: Address, once registered
Contact for privacy questions: privacy@aforaudience.com

1. What we collect

Account information — name (used as your login username), display name (optional, shown to others), email address, phone number, password (stored hashed, never in plain text), and your role on the platform (audience, artist, organiser, or venue owner).

Booking & payment information — event bookings, seat/section selections, and amounts paid. Payments themselves are processed by Razorpay; we do not see or store your card, UPI, or bank account details — Razorpay handles that directly and is PCI-DSS compliant in its own right.

Verification information — your phone number is verified via a one-time password sent through MSG91. We keep a record that verification succeeded, not the OTP itself beyond its short validity window.

Content you provide — event listings, artist profiles, venue details, lineup applications, and any feedback or bug reports you submit (including optional screenshots) through the in-app feedback tool.

Usage information — standard technical logs (IP address, browser/device type, pages visited) collected automatically to keep the service secure and working.

We do not knowingly collect information from anyone under the age of 13 / 16 / 18 without appropriate consent, and the platform is not directed at children.

2. How we use it

  • To create and run your account, and to let you book, sell, or manage tickets and venue bookings.
  • To send you transactional communications — booking confirmations, tickets (PDF + email via Resend), phone verification codes, password resets, and important account or event updates.
  • To process payments and refunds through Razorpay.
  • To respond to support requests and feedback.
  • To detect and prevent fraud and abuse (for example, validating tickets at check-in so the same ticket can't be used twice).
  • To improve the product — understanding which features are used and where things break.

We do not sell your personal data to third parties, and we do not use your data to serve third-party advertising.

3. Who we share it with

  • Razorpay — to process payments and refunds.
  • Resend — to deliver transactional emails (tickets, confirmations, password resets).
  • MSG91 — to deliver phone verification codes.
  • Supabase (our database and infrastructure provider) and Vercel (our application hosting provider) — who host the infrastructure our app runs on, under their own data-processing terms.
  • Event organisers and venue owners, if you book a ticket or make a booking with them — they see the attendee/booking information reasonably needed to run their event (e.g. your name and ticket details for check-in), not your full account profile.
  • Law enforcement or regulators, only if legally required to do so.

We do not share your data with anyone else without your consent, except as described above.

4. Your rights

  • View and edit your profile information (display name, etc.) from your account settings.
  • Request a copy of the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your account and associated personal data, subject to what we're legally required to retain (e.g. transaction records for tax/audit purposes).

To exercise these rights, contact privacy email. We aim to respond within 30 days.

5. Data retention

We keep account and booking data for as long as your account is active, and for a reasonable period afterward to comply with tax, accounting, and legal obligations (typically X years for financial records under Indian law). Verification codes (OTPs) expire and are discarded within minutes of issuance.

6. Security

We take reasonable technical and organisational measures to protect your data — passwords are hashed, payment details are never stored on our servers, and access to production data is restricted. No system is perfectly secure, and we can't guarantee absolute security, but we treat this seriously and will notify affected users in the event of a breach as required by law.

7. Cookies

We use essential cookies to keep you logged in (authentication session cookies) and to remember basic preferences. We do not currently use third-party advertising or tracking cookies.

8. Grievance Officer

In accordance with the Information Technology Act, 2000 and rules made thereunder, the Grievance Officer for AforAudience is:

Name
Email
Address

9. Changes to this policy

We may update this policy from time to time. If we make material changes, we'll notify you via email or an in-app notice before they take effect.

10. Contact us

Questions about this policy: privacy email