Privacy Policy
Your privacy, personal data security, and confidentiality are foundational to Ventixo. This policy explains what information we collect, how we protect it, and your rights.
1. Introduction & Overview
Ventixo Technologies (“Ventixo,” “we,” “our,” or “us”) is committed to safeguarding your personal data in full compliance with applicable privacy regulations, including the Digital Personal Data Protection (DPDP) framework and global security standards.
This Privacy Policy explains the collection, utilization, processing, storage, and sharing of personal data gathered when you visit https://ventixot.online, purchase event passes, register as an organizer, or interact with our APIs.
2. Information We Collect
We collect information strictly necessary to provide seamless event ticketing and platform management:
- Identity & Account Data: Full legal name, preferred username, email address, password hash (encrypted via bcrypt), and verified mobile telephone number.
- Organizer Verification Data: Government ID (Aadhaar / PAN / Passport), organization registration certificate, business tax identifier (GSTIN), and verified payout bank account details.
- Ticketing & Attendance Records: Event booking identifiers, pass categories, check-in timestamps, entry scanner logs, and dynamic QR cryptographic nonces.
- Financial Transaction Information: Order references, payment provider tokens, transaction timestamps, and settlement records. (Raw debit/credit card numbers and UPI PINs are processed directly by our PCI-DSS Level 1 compliant gateway partners and are never stored on Ventixo servers.)
- Technical & Telemetry Data: IP address, browser user-agent, operating system details, device fingerprint, and session tokens used for brute-force defense and security auditing.
3. How We Use Your Information
We process personal information solely for legitimate operational and security purposes:
- Facilitating event discovery, booking transactions, and dynamic QR ticket issuance.
- Validating digital check-in passes at physical gates to prevent duplicate entry or fraudulent resale.
- Transmitting transactional messages: booking confirmations, invoice receipts, OTP verification codes, and event schedule alterations.
- Processing refund requests, chargeback reviews, and organizer settlement payouts.
- Detecting, preventing, and mitigating fraudulent transactions, bot-driven ticket scalping, and security threats.
4. Data Protection & Security Architecture
Ventixo implements state-of-the-art technical, physical, and organizational security controls:
- Encryption in Transit: All communications between your browser and Ventixo infrastructure are enforced with modern TLS 1.3 encryption, HTTP Strict Transport Security (HSTS), and secure cryptographic cipher suites.
- Encryption at Rest: Database records, authentication secrets, and storage objects are encrypted at rest using AES-256 standards.
- Infrastructure Defense: Distributed Redis sliding-window rate limiting protects endpoints against brute-force attacks, while UFW firewalls and automated intrusion prevention systems defend server environments.
- Role-Based Access Control (RBAC): Access to production databases is strictly restricted to authorized engineering personnel using multi-factor authentication and auditable logs.
5. Cookies & Local Session Management
Ventixo utilizes cookies and browser storage technologies strictly to deliver essential functionality:
- Essential Authentication Cookies: Cryptographically signed HTTP-only tokens used to authenticate your active session securely.
- Preferences & Themes: Storing UI preferences, active filters, and viewing choices locally.
- We do not sell your personal browsing habits to third-party advertisers or data brokers.
6. Third-Party Service Providers
We share minimal data with trusted infrastructure providers who assist us in operating our platform, bound by strict confidentiality and data-processing obligations:
- Payment Aggregators: Cashfree, PayU, and Razorpay for processing ticket purchases and automated refunds.
- Cloud & Edge Hosting: Cloudflare (Edge CDN, WAF, and DNS) and Vultr (backend VPS clusters).
- Database & Storage: Supabase PostgreSQL (managed database clusters) and Cloudflare R2 (media asset storage).
- Transactional Email: High-throughput SMTP infrastructure for delivering tickets, receipts, and security passcodes.
7. User Data Rights
You maintain fundamental rights over your personal data:
- Right to Access & Portability: You may view your profile, booking history, and ticket receipts directly within your dashboard at any time.
- Right to Rectification: You can update your contact numbers, display names, and billing profiles from your account settings.
- Right to Erasure: You may submit an account deletion and data scrubbing request by emailing privacy@ventixot.online (subject to statutory financial record retention requirements).
8. Data Retention Policy
We retain personal data only for as long as necessary to satisfy the purposes outlined in this policy:
- Active account records are preserved while your account remains active.
- Financial transactions, invoices, and ticket purchase records are retained for seven (7) years in accordance with applicable tax and statutory accounting laws.
- Security and access logs are routinely pruned after ninety (90) days unless active investigations require preservation.
9. Updates to this Policy
We may update this Privacy Policy from time to time to reflect evolving regulatory mandates or technical updates. Whenever significant changes occur, we will notify users through platform banners or direct email notification.
10. Grievance Officer & Privacy Inquiries
For data privacy inquiries, exercise of rights, or grievance escalation, you may reach our designated Data Protection & Privacy Officer:
Data Protection Officer: Ventixo Privacy Team
Email: privacy@ventixot.online
General Support: support@ventixot.online
Portal: https://ventixot.online