Privacy Policy

Last updated: 15 July 2026

Controller & Contact

Controller: Entvase Ltd.
Address: Rothenburgerstr, NΓΌrnberg, Deutschland
Email: info@entvase.com
Policy version: 2026-07-15

This Privacy Policy explains how Entvase processes personal data in the website, mobile app, and organizer tools. It covers account use, event discovery, checkout, support, live chat, organizer verification, AI-assisted features, recommendations, security, and analytics.

Information We Collect

  • Account and contact details such as name, email, phone, city, address, and profile preferences.
  • Ticket, checkout, order, refund, wallet, and event participation records.
  • Optional location data for nearby-event recommendations and last known location preferences.
  • Organizer verification data, including legal name, phone, selfies, and ID images when submitted.
  • Push tokens and security logs needed to provide requested services. Optional analytics identifiers and reel telemetry are created only after analytics consent.
  • Cookies and similar technologies, subject to consent where required.

How We Use Information

  • Provide accounts, event discovery, tickets, checkout, organizer tools, support, and notifications.
  • Personalize recommendations using preferences, event activity, and location only when enabled.
  • Review organizer trust requests and prevent fraud, abuse, and payment misuse.
  • Operate AI assistance and live chat, improve reliability, and comply with legal/payment obligations.

Legal Bases

We use contract necessity for accounts, checkout, ticket delivery, and organizer services; consent for location, push notifications, non-essential analytics, and organizer document processing; legitimate interests for security, fraud prevention, service reliability, and abuse prevention; and legal obligation for tax, accounting, payment, and regulatory records.

Analytics & Trackers

Functional persistence, analytics, and marketing are off by default on web and mobile until you explicitly opt in. Reel telemetry is minimized to playback events, device/platform context, errors, and engagement metrics. Before analytics consent, the mobile app does not create a telemetry identifier, queue events, or start upload timers. Withdrawing consent stops future collection, clears pending telemetry, and asks configured providers to opt out or reset. Currently configured web trackers:

  • Google Analytics 4
  • Plausible Analytics
  • PostHog

Consent Records & Your Choices

Your current versioned choice takes effect locally immediately. When you are signed in, it is synchronized to your account and changes are recorded in a consent audit history included in account export and deletion. A new policy version turns optional processing off until you choose again. Authentication, security, checkout, and explicitly requested drafts remain available when optional categories are rejected.

Newsletter & Marketing Email

Entvase sends newsletters, event selections, product news, and offers only after an explicit optional choice in the newsletter form, account signup, checkout, onboarding, or communication settings. Creating an account or buying a ticket does not by itself subscribe you. We record the email address, consent source, time, policy version, and technical evidence needed to demonstrate the choice. Every newsletter includes an unsubscribe link, and withdrawal applies to future marketing messages without affecting ticket confirmations or other requested service emails.

Processors & Recipients

Depending on the feature, data may be processed by hosting/database providers, Stripe for payments, Expo for push notifications, email delivery providers, storage providers for media, and AI providers such as OpenRouter, LLM7, or OpenAI for assistant features. Payment card details are handled by Stripe, not stored by Entvase.

Organizer Verification

Selfies and ID images are used only to review organizer verification requests. Access is limited to authorized reviewers. Managed verification files are deleted after approval/rejection or by retention cleanup, while the decision record is kept for security and trust purposes.

GDPR (EU/EEA)

You have rights to access, rectify, erase, restrict, object, data portability, and withdraw consent. You can manage location and push permissions in device settings, update preferences in the app, delete your account from account settings, or contact us for privacy requests. You may also complain to your local EU/EEA supervisory authority.

CCPA/CPRA (United States)

California residents have the right to know, delete, correct, and opt-out of the sale or sharing of personal information. We do not knowingly sell personal information. You can manage sharing/targeting in Cookie Settings via the Do Not Sell or Share My Personal Information option.

Data Retention & Security

We retain data only as long as needed for the purposes above or legal obligations. Verification images, expired mobile email verification tokens, revoked/expired refresh tokens, old telemetry, and abandoned-cart records are subject to retention cleanup. We use secure token storage, access controls, HTTPS, role checks, and managed storage deletion.

Contact

For privacy requests, contact us at info@entvase.com. Data protection contact: info@entvase.com.