Legal Documentation

Privacy Policy

This Privacy Policy governs our collection, use, disclosure, retention, and protection of personal data across our iOS app, Android app, and web platform. It applies to all user categories including Attendees, Event Creators, Vendors, and Venue Owners.

Introduction & Scope

Eventflutter LLC ("Eventflutter," "we," "our," or "us") is an Africa-first, all-in-one mobile and web SaaS platform for event management, ticketing, vendor and venue marketplace services. Our mission is to empower every individual and organisation to create, manage, and celebrate events effortlessly by connecting every stakeholder — attendees, vendors, venue owners, and event creators — through seamless technology. Our vision is to become Africa's number one event management, venue and vendor marketplace platform, starting with Nigeria.

This Privacy Policy ("Policy") governs our collection, use, disclosure, retention, and protection of personal data across our iOS app, Android app, and web platform. It applies to the following user categories:

This Policy does not apply to third-party websites or services linked from our platform. We encourage you to review the privacy policies of any third parties you interact with independently.


Consent

By accessing, registering for, or using the services provided by Eventflutter (“Eventflutter,” “we,” “our,” or “us”) on our website or mobile applications, you acknowledge and consent to the collection, use, disclosure, storage, and processing of your personal data in accordance with this Privacy Policy and applicable data protection laws.

Where required by applicable law, Eventflutter will obtain your explicit consent before:

  • Processing sensitive personal information;
  • Sending marketing or promotional communications;
  • Using cookies or similar tracking technologies that are not strictly necessary;
  • Sharing your information with third parties for purposes beyond core platform operations; or
  • Processing personal data for any purpose requiring additional consent under applicable regulations.

You may withdraw your consent at any time where consent serves as the lawful basis for processing. Withdrawal of consent shall not affect the lawfulness of processing conducted prior to such withdrawal. Certain services or platform functionalities may become unavailable if consent necessary for those services is withdrawn.

Eventflutter maintains records of consent where legally required and implements mechanisms allowing users to manage communication preferences, cookie settings, and privacy choices.

Eligibility

To access or use the Eventflutter platform, you represent and warrant that:

  • You are at least eighteen (18) years of age, or the age of an adult in your jurisdiction;
  • You possess the legal authority and capacity to enter into binding agreements;
  • All information provided during registration or use of the platform is accurate, current, and complete; and
  • Your use of the platform complies with all applicable laws, regulations, and contractual obligations.

Individuals under the age of eighteen (18) must not use the platform and when detected will be banned from using the platform.

Eventflutter does not knowingly collect or process personal data from children in violation of applicable child data protection laws, including but not limited to the Children’s Online Privacy Protection Act (COPPA), the UK GDPR, EU GDPR, Nigeria Data Protection Act (NDPA), or similar regulations. If Eventflutter becomes aware that personal data has been collected from a child without appropriate authorisation, such information will be deleted promptly.

Eventflutter reserves the right to suspend, restrict, or terminate accounts that violate eligibility requirements or applicable laws.


Lawful Basis for Processing Data

Eventflutter processes personal data only where a valid lawful basis exists under applicable data protection and privacy laws, including but not limited to the EU General Data Protection Regulation (GDPR), UK GDPR, Nigeria Data Protection Act (NDPA), California Consumer Privacy Act (CCPA/CPRA), and other applicable regulations.

Depending on the nature of the processing activity, Eventflutter may rely on one or more of the following lawful bases:

Consent

We process personal data where you have provided clear and informed consent for specific processing activities, including marketing communications, optional analytics, or certain enhanced platform features.

Performance of a Contract

We process personal data where necessary to provide the Eventflutter platform and related services, including:

  • Account creation and authentication;
  • Event registration and ticketing;
  • Payment processing and vendor settlements;
  • Customer support;
  • Event communications; and
  • Platform functionality requested by users.


Legal and Regulatory Obligations

We may process personal data where necessary to comply with applicable legal obligations, including:

  • Financial reporting requirements;
  • Fraud prevention and anti-money laundering obligations;
  • Tax and accounting requirements;
  • Law enforcement requests;
  • Regulatory compliance obligations; and
  • Security and incident response requirements.


Legitimate Interests

We may process personal data where necessary for our legitimate business interests, provided such interests are not overridden by the rights and freedoms of data subjects. Such legitimate interests may include:

  • Platform security and abuse prevention;
  • Service improvement and analytics;
  • Business operations and administration;
  • Enforcement of platform policies and agreements;
  • Risk management and fraud detection;
  • Product development and feature optimisation; and
  • Internal reporting and operational monitoring.


Protection of Vital Interests

In limited circumstances, Eventflutter may process personal data where necessary to protect the vital interests, safety, or security of users or other individuals.

Where required by law, Eventflutter conducts assessments to ensure that processing activities relying on legitimate interests are balanced against the privacy rights and expectations of affected individuals.

Users may exercise applicable privacy rights, including rights of access, correction, deletion, objection, restriction, portability, and withdrawal of consent, subject to applicable legal limitations.


Information We Collect

Information You Provide Directly


Data Category

Examples

Affected Users

Account & Identity

Full name, email address, hashed password, phone number, profile photo, user role

All users

Event Creators Event Data

Event name, description, date, location, ticket types, pricing, images, budget records, guest lists, RSVP configurations

Event Creators

Vendor Profile

Service categories, pricing packages, portfolio images/videos, availability calendar, business name, bank account for payouts

Vendors

Vendor Job Applications

Proposed price, cover message, portfolio attachments, application status

Vendors

Venue Owner Profile

Venue name, photos, location (Google Maps), capacity, amenities, pricing, availability calendar

Venue Owners

Billing & Payment

Tokenised transaction details, billing address, bank account details (for payouts), transaction history, tax ID / TIN / CAC Registration Number

All transacting users

KYC Data

Bank Verification Number (BVN), National Identification Number (NIN) — collected only where mandated by CBN/NDPC regulations for payout accounts

Vendors, Venue Owners, Event Creators

Attendee Registration

Custom event fields (dietary needs, session choices, accessibility requirements, t-shirt sizes), RSVP responses

Attendees

Contracts & Bookings

Service agreements, booking confirmations, milestone records, dispute communications

Event Creators, Vendors, Venue Owners

Reviews & Ratings

Star rating (1–5), written review text, post-event feedback

All Users

Support & Communications

Support ticket content, in-app messages (Event Creators ↔ Vendor, Event Creators ↔ Venue Owner), email correspondence

All Users

Onboarding Preferences

Selected event types, budget range, location preferences, vibes — for personalised event recommendations

All Users




Information Collected Automatically

  • Device & Browser Data: IP address, browser type, operating system, device model, device identifiers, screen resolution. Optimised for older Android devices and low-bandwidth environments common in African markets.
  • Log Data: Pages and screens visited, timestamps, feature interactions (ticket purchase flow, RSVP actions, vendor browsing, job marketplace activity), error reports.
  • Location Data: City/country-level geolocation from IP address; precise GPS only with explicit user consent via mobile app. Used for local vendor/venue search (Google Maps API) and event discovery ('Use my location').
  • Cookies & Tracking: See Section 11. We use session tokens, CSRF cookies, analytics (Amplitude/Mixpanel pseudonymised), and marketing pixels where consented.
  • Payment Metadata: Transaction IDs, gateway responses (Paystack/Flutterwave/Stripe), fraud signals. 
  • QR & Check-in Data: Ticket scan events, RSVP check-in timestamps, validation outcomes — single-use enforcement logged per ticket/RSVP ID.
  • Real-Time Interaction Data: booking status updates, and task progress visible in real-time dashboards.

Information from Third Parties

  • OAuth Providers (Google, Apple): Basic profile data (name, email, photo) per your authorisation.
  • Payment Gateways (Paystack, Flutterwave, Stripe): Transaction confirmations, payout status, fraud-risk signals.
  • Identity Verification service providers: KYC verification outcomes for Creators/Vendor/Venue Owners.
  • Google Maps API: Location data for venue listing, event location, and local vendor search.
  • Cloudinary: Metadata associated with uploaded portfolio and event images.


How We Use Your Personal Data


Purpose

Description

Legal Basis (NDPA/GDPR/US)

Platform Delivery

Account creation, event lifecycle (create/publish/manage), ticketing, RSVP, QR check-in, vendor/venue marketplace, job posting and hiring.

Contract Performance

Personalisation

Onboarding preference capture; 'Just For You' event recommendations; personalised vendor suggestions based on event type and location.

Consent; Legitimate Interest

Escrow & Payments

Holding escrow funds, processing ticket sales, Vendor payouts, automated fee deductions, receipt/invoice generation, refund management.

Contract Performance; Legal Obligation

KYC & Identity Verification

Verifying Creators, Vendor and Venue Owner identities to comply with Nigerian CBN/SCUML requirements and fraud prevention obligations.

Legal Obligation; Legitimate Interest

Transactional Notifications

RSVP confirmations, ticket receipts, booking alerts, event reminders (24h/2h), payout notifications — via push, email, and SMS.

Contract Performance

Marketing Communications

Promotional emails and push notifications about new platform features, curated events, and Vendor spotlights — where consented.

Consent

Vendor Advertising

Displaying featured/promoted Vendor and Venue listings to Event Creators browsing the marketplace.

Contract Performance; Legitimate Interest

Security & Fraud Prevention

JWT authentication, RBAC enforcement, QR single-use validation, duplicate ticket/RSVP prevention, anomaly detection, rate limiting.

Legitimate Interest; Legal Obligation

Dispute Resolution

Accessing message logs, booking records, and transaction history to resolve disputes between Event Creators, Vendors, and Venue Owners.

Legitimate Interest; Legal Obligation

Analytics & Improvement

Aggregated platform usage analytics (Amplitude/Mixpanel), A/B testing, performance monitoring, post-event dashboard insights for Creators.

Legitimate Interest; Consent (cookies)

Legal & Regulatory Compliance

Responding to orders from Nigerian courts, NDPC, IRS/FIRS, and other authorities; financial record-keeping; audit log maintenance.

Legal Obligation

How We Share Your Personal Data

We do not sell, rent, or trade Personal Data to third parties for their own marketing. We share data only as described below:

Between Platform Users (Core Platform Function)

  • Event Creator ↔ Vendor/Venue Owner: Relevant contact and booking details shared when a booking is confirmed to enable service fulfilment.
  • Event Creator↔ Attendees: Registration data (name, email, RSVP status, ticket details) shared with the event's creator.
  • Vendor Profiles: Service name, category, portfolio, ratings, and pricing visible to registered creators in the marketplace.
  • Venue Profiles: Venue name, location, photos, capacity, and pricing visible to Creators browsing the venue marketplace.
  • Job Marketplace: Job postings by creators are visible to relevant Vendors; Vendor proposals are visible to the posting Creators only.

Third-Party Service Providers and Sub-Processors


Eventflutter may engage trusted third-party service providers, vendors, contractors, and technology partners (“Sub-Processors”) to support the operation, delivery, security, maintenance, and improvement of the platform and related services.

These Sub-Processors may assist with services including, but not limited to:

  • Cloud hosting and infrastructure;
  • Payment processing and financial transactions;
  • Identity verification and fraud prevention;
  • Customer communications and email delivery;
  • Push notifications and messaging services;
  • Media storage and content delivery;
  • Analytics and performance monitoring;
  • Authentication and account security;
  • Mapping and geolocation services; and
  • Customer support and operational services.

Where Sub-Processors process personal data on behalf of Eventflutter, such processing is conducted pursuant to appropriate contractual, confidentiality, data protection, and security obligations designed to ensure compliance with applicable privacy and data protection laws.

Eventflutter undertakes reasonable measures to ensure that its Sub-Processors implement appropriate technical, administrative, and organizational safeguards to protect personal data against unauthorized access, disclosure, misuse, alteration, or destruction.

Certain Sub-Processors may process or store personal data in jurisdictions outside the user’s country of residence. In such circumstances, Eventflutter implements appropriate safeguards and transfer mechanisms required under applicable data protection laws to protect personal data during international transfers.

Eventflutter may update or change its Sub-Processors from time to time as part of normal business operations, technological changes, legal requirements, security improvements, or service enhancements.

Business Transfers

In the event of a merger, acquisition, or asset sale, Personal Data may be transferred. Affected users will receive email and in-app notice with the right to object where required by law.

Legal Disclosures

We may disclose Personal Data to comply with applicable Nigerian law (NDPA, EFCC, SCUML, CBN directives), valid court orders, or US/EEA legal process; and to protect the safety, rights, or property of Eventflutter, our users, or the public.

Aggregated & Anonymised Data

Anonymised, aggregated data (e.g., total events created per month, top vendor categories in Lagos) may be shared with partners or published publicly without restriction.


Data Retention

Eventflutter retains personal data only for as long as necessary to fulfil the purposes for which the information was collected, including providing and maintaining the platform, complying with legal and regulatory obligations, resolving disputes, enforcing agreements, preventing fraud, maintaining security, and supporting legitimate business operations.

The retention period applicable to personal data depends on the nature, sensitivity, and purpose of the information collected, as well as applicable legal, contractual, tax, accounting, regulatory, and operational requirements.

Eventflutter may retain personal data for the following general periods:

  • Account registration and profile information: retained for the duration of the user relationship and for a reasonable period thereafter to comply with legal obligations, resolve disputes, or enforce agreements;
  • Transactional and payment-related records: retained as required by applicable financial, tax, anti-fraud, anti-money laundering, and accounting regulations;
  • Event participation, ticketing, vendor, and booking records: retained for operational, audit, reporting, dispute resolution, and legal compliance purposes;
  • Customer support communications and platform activity logs: retained for service improvement, security monitoring, fraud prevention, and incident investigation purposes;
  • Marketing preferences and communication records: retained until consent is withdrawn or the user opts out, unless a longer retention period is legally required;
  • Security logs, device information, and monitoring records: retained for cybersecurity, fraud detection, abuse prevention, and compliance purposes.

Where personal data is no longer required, Eventflutter will securely delete, anonymise, or de-identify such information in accordance with applicable laws and internal retention and destruction procedures.

In certain circumstances, Eventflutter may retain information for longer periods where necessary to:

  • Comply with legal, regulatory, tax, or audit obligations;
  • Establish, exercise, or defend legal claims;
  • Detect, investigate, or prevent fraud, security incidents, or illegal activities;
  • Enforce contractual agreements or platform policies; or
  • Maintain business continuity and backup recovery processes.

Users may request deletion of their personal data, subject to applicable legal, regulatory, contractual, and operational retention obligations. Certain information may continue to be retained where required or permitted by law, including for compliance, fraud prevention, dispute resolution, or security purposes.

Eventflutter implements administrative, technical, and organisational safeguards designed to protect retained personal data against unauthorised access, disclosure, alteration, or destruction throughout the retention lifecycle.

International Data Transfers

Eventflutter processes data in Nigeria, the United States, and other jurisdictions where our sub-processors operate (including AWS and Google Cloud regions). We implement the following safeguards:

  • Nigeria to United States / Third Countries: Transfers comply with NDPA Sections 43–44, using Standard Contractual Clauses (SCCs) approved by the NDPC, supplemented by encryption in transit (TLS 1.2+) and at rest (AES-256).
  • EEA/UK to United States: European Commission-approved SCCs and where applicable the EU-U.S. Data Privacy Framework.
  • Low-Bandwidth Considerations: Where data is processed in Nigeria for Nigerian users, we prioritise local infrastructure in compliance with NDPA localisation guidance.

You may request details of applicable transfer mechanisms by contacting dpo@eventflutter.com.


Your Privacy Rights


Right

Nigeria (NDPA 2023)

GDPR (EEA/UK)

California (CCPA/CPRA)

Access / Know

Yes — s.34 NDPA

Yes — Art. 15 GDPR

Yes — s.1798.100 CCPA

Correction

Yes — s.34 NDPA

Yes — Art. 16 GDPR

Yes — CPRA

Deletion / Erasure

Yes — s.34 NDPA

Yes — Art. 17 GDPR

Yes — s.1798.105

Data Portability

Yes — s.34 NDPA

Yes — Art. 20 GDPR

Yes — CPRA

Object to Processing

Yes — s.34 NDPA

Yes — Art. 21 GDPR

Limited

Restrict Processing

Yes

Yes — Art. 18 GDPR

Limited

Withdraw Consent

Yes — s.34 NDPA

Yes — Art. 7(3)

Yes

Opt-Out of Sale/Sharing

N/A

N/A

Yes — s.1798.120

Limit Sensitive PI Use

Yes (consent-based)

Yes — Art. 9 GDPR

Yes — CPRA

Non-Discrimination

Yes — s.34 NDPA

Implicit in GDPR

Yes — s.1798.125

Lodge Complaint

NDPC — ndpc.gov.ng

Local DPA / ICO (UK)

California AG / CPPA


How to Submit a Request

  • Email (US/Global/Nigeria): dataprivacy.office@eventflutter.com
  • US Toll-Free: +1 (800) 000-0000 — Mon–Fri, 9 AM–6 PM ET
  • Nigeria Line: +234 (0) 000-000-0000 — Mon–Fri, 9 AM–5 PM WAT


Requests acknowledged within 72 hours; substantive response within 30 days (extendable by 60 days for complex cases with prior notice). Identity verification may be required.

NDPC Complaints

Nigerian residents may direct unresolved complaints to: Nigeria Data Protection Commission (NDPC), No. 5 Donau Crescent, Off Amazon Street, Maitama, Abuja — ndpc.gov.ng.


Cookies & Tracking Technologies

Eventflutter uses cookies, pixels, SDKs, and similar tracking technologies to operate, secure, maintain, and improve the platform and user experience.

These technologies may be used to:

  • Enable core platform functionality;
  • Remember user preferences and settings;
  • Maintain account sessions and authentication;
  • Analyse platform performance and usage trends;
  • Personalise content and user experiences;
  • Measure the effectiveness of communications and marketing activities; and
  • Detect fraud, abuse, security incidents, or unauthorized activity.

Certain cookies and tracking technologies may be provided by trusted third-party service providers that support analytics, communications, advertising, authentication, payment processing, or other operational services.

Users may control or manage certain cookie preferences through browser settings, device settings, or available platform consent tools. Disabling certain cookies or technologies may affect the functionality, availability, or performance of portions of the platform.

Where required by applicable law, Eventflutter will obtain consent before using non-essential cookies or tracking technologies.

Manage preferences at: eventflutter.com/cookie-settings. Blocking certain cookies may impact platform functionality.


Security

Eventflutter implements commercially reasonable administrative, technical, organisational, and physical safeguards designed to protect personal data against unauthorised access, disclosure, alteration, misuse, loss, or destruction.

Our security programme includes measures intended to safeguard platform infrastructure, user accounts, payment-related activities, communications, and stored information. These measures include encryption technologies, secure authentication controls, access management, network protection mechanisms, monitoring systems, fraud prevention processes, backup and recovery procedures, and incident response protocols.

Eventflutter also works with trusted third-party providers and service partners that maintain industry-standard security practices and compliance obligations appropriate to the services they provide.

While Eventflutter takes reasonable steps to protect personal data and maintain platform security, no method of electronic transmission, storage, or processing can be guaranteed to be completely secure. Accordingly, Eventflutter cannot guarantee absolute security of information transmitted to or stored on the platform.

In the event of a security incident or personal data breach requiring notification under applicable law, Eventflutter will take appropriate steps to investigate, mitigate, document, and notify affected individuals and relevant regulatory authorities in accordance with applicable legal and regulatory requirements.

Additional Disclosures for Nigerian Residents (NDPA 2023)

The Nigeria Data Protection Act 2023 (NDPA) and NDPC regulations govern processing of personal data in Nigeria. As an Africa-first platform with Nigerian operations, the following supplementary disclosures apply:

Legal Bases Under the NDPA

  • s.25(1)(b) — Contract Performance: Delivering platform services, processing payments, managing bookings.
  • s.25(1)(c) — Legal Obligation: Nigerian financial law (FIRS, CAMA, CBN), SCUML anti-money laundering requirements, and court orders.
  • s.25(1)(f) — Legitimate Interest: Security monitoring, fraud prevention, Vendor advertising, product analytics — subject to balancing tests documented in our Legitimate Interest Assessments.
  • s.25(1)(a) — Consent: Marketing communications, non-essential cookies, and any sensitive personal data processing.

BVN and NIN Collection

Bank Verification Numbers (BVN) and National Identification Numbers (NIN) are collected from Vendors and Venue Owners strictly for CBN-mandated KYC compliance and payout account verification. This data is processed only by licensed identity verification providers (Smile Identity, verifyme, Youverify etc), retained for a minimum of 5 years per CBN directive, and never used for any other purpose.

Data Localisation

Eventflutter maintains infrastructure capable of storing Nigerian users' data within Nigeria where required by applicable NDPC guidance. Cross-border transfers comply with NDPA Sections 43–44, relying on NDPC-approved SCCs or adequacy determinations.

NDPC Registration

Eventflutter is registered (or in the process of registering) as a Data Controller with the Nigeria Data Protection Commission. NDPC Registration Number: [To be inserted upon registration]. Our designated Nigeria DPO can be reached at datatprivacy.office@eventflutter.com.

Do Not Sell or Share

While we do not sell personal data for monetary value, certain advertising activities (Meta Pixel, Google Ads for Vendor featured listings) may constitute ‘sharing’ under applicable laws. Opt out at: email dataprivacy.office@eventflutter.com with subject 'CCPA Opt-Out.'

Sensitive Personal Information

We collect limited Sensitive PI (financial account details for payouts data). Used only to deliver requested services. You may request limitation of use via email.

Marketing Communications

  • Email: Click 'Unsubscribe' in any marketing email.
  • Push Notifications: Manage in app Settings → Notifications.
  • SMS: Reply STOP to any marketing text.
  • General: Email dataprivacy.office@eventflutter.com with subject 'Unsubscribe'.


Unsubscribing does not affect transactional notifications (booking confirmations, RSVP updates, event reminders, payment receipts) which are necessary for platform service delivery.

Vendor & Venue Owner — Specific Privacy Notices

Public Profile Visibility

Vendor and Venue Owner listing information (name, service description, portfolio, pricing, availability, ratings) is visible to registered Event Creators in the marketplace. Profiles may be indexed by search engines if public listing is enabled. Visibility settings are configurable in your account dashboard.

Job Marketplace Data

When Event Creators post jobs, your proposal data (proposed price, message, portfolio) is visible only to the posting Event Creators. Your application status (pending/accepted/rejected) is visible to you. Rejected Vendors are notified automatically when a job is awarded.

Financial & Payout Data

Bank account details, BVN, and tax IDs are shared only with our payment processor (Paystack,etc) for payout execution and with regulatory authorities as legally required. All financial data is encrypted at rest and in transit.

Advertising Data

Advertising campaign spend, impressions, click-throughs, and performance data are used solely to manage and optimise your promoted listings. Not shared with third parties for their own marketing.

In-Platform Messages

In-platform Messages between users are stored for 2 years post-booking for dispute resolution and contract enforcement. Eventflutter staff access message content only to resolve a reported dispute or comply with legal obligations.

Reviews & Ratings

Reviews submitted by Users are public on your profile. You may dispute inaccurate reviews by contacting support@eventflutter.com.


Changes to This Policy

  • We will email registered users at least 30 days before material changes take effect.
  • An in-Platform notification will be displayed.
  • Where required by the NDPA or GDPR, we will require affirmative re-acceptance.


Continued use of the Platform after the effective date constitutes acceptance of the updated Policy.


Contact Us


Channel

Details

Privacy Team

Dataprivacy.office@eventflutter.com

Data Protection Officer

dpo@eventflutter.com

Legal / Compliance

legal@eventflutter.com

Support

support@eventflutter.com

Privacy Request Portal

Email dataprivacy.office@eventflutter.com

Cookie Settings

eventflutter.com/cookie-policy


Last updated 15 August 2026

Your dream event is just a step away

© 2026 Eventflutter. All rights reserved.