Privacy policy
Last updated 16 August 2026
Template for review. Placeholder legal copy for the Swordfish demo build. Have counsel review before production use.
This policy explains what data is collected when you book an event on Swordfish, how it is used, who it is shared with, and the choices you control. It is written to align with India's Digital Personal Data Protection Act, 2023.
1. Scope and roles
When you book an event, the event organizer decides why and how your data is used. Under the DPDP Act the organizer is the data fiduciary for attendee data, the party you may know elsewhere as the controller. Swordfish processes that data on the organizer's instructions, as its technology provider.
For accounts on the Swordfish platform itself, such as organizer dashboard users, Swordfish is the data fiduciary.
2. What we collect
At checkout, before payment, we collect your name, phone number, and email address. Alongside your order we record the tickets you chose, the amount paid, and your consent choices.
We also collect device and usage data: pages viewed, funnel steps completed, and technical details of your browser. If you arrived from an ad or a campaign link, we capture attribution data: UTM parameters and ad click identifiers such as fbclid and gclid.
3. How your data is used
We use your data to fulfil your booking: process the order, issue your ticket, and send transactional messages such as the order confirmation and event reminders. Transactional messages are part of the service and are exempt from marketing consent.
Separately, and only with your explicit consent given by the marketing checkbox at checkout, the organizer may send you marketing messages and include you in advertising audiences.
4. Advertising and tracking
Organizers run advertising tools on their event pages, including the Meta Pixel, the Meta Conversions API, and Google tags. As you move through the booking funnel, events such as page views, ticket selections, checkout starts, and purchases are shared with those platforms, so organizers can measure their ads and reach people who showed interest.
Where personal identifiers are sent to an ad platform, they are hashed first with SHA-256. Your raw email address and phone number are not sent to ad platforms.
You control the marketing side of this. You can decline the marketing checkbox and still complete your booking; declining changes nothing about your ticket. Retargeting audiences and ad audience exports are built only from contacts who gave marketing consent.
5. Consent record
Both consent choices you make at checkout, the required terms consent and the optional marketing consent, are stored with a timestamp against your order and checkout session. This record is what the organizer relies on to demonstrate consent, and what the platform checks before including you in any audience export.
6. Sharing
Your data is shared with:
- The event organizer, who is the seller of your ticket.
- The organizer's payment gateway, to process your payment.
- Messaging providers, to deliver confirmations and reminders by email, WhatsApp, or SMS.
- Ad platforms, as configured by the organizer and described in section 4.
Your data is never sold.
7. Retention
Order and ticket data is retained for as long as the organizer needs it to run the event, meet legal and tax obligations, and handle disputes. Abandoned checkout data is kept for a short recovery window and then removed. Tracking events are retained in aggregate for reporting.
When data is no longer needed for the purpose it was collected, it is deleted or anonymised.
8. Your rights under the DPDP Act
As a data principal you have the right to:
- Access a summary of your personal data and how it has been processed.
- Correction of data that is inaccurate or incomplete.
- Erasure of data that is no longer needed for the purpose you gave it.
- Grievance redressal within the timelines the law prescribes.
- Nominate a person to exercise these rights on your behalf if you are unable to.
Send requests to the event organizer you booked with, or to grievance@swordfish.demo, a placeholder address for the demo build.
The DPDP Act also provides for registered Consent Managers, an interoperable framework through which you can give, manage, review, and withdraw consent. Requests routed through that framework will be honoured once it is operational for this service.
9. Security
All data moves over encrypted connections. Access to attendee data is limited by role, and platform staff access is logged in an audit trail. When platform support views an organizer account, personal identifiers are masked.
Identifiers shared with ad platforms are SHA-256 hashed before they leave the platform. No card details are stored on Swordfish; payment runs through the organizer's gateway.
10. Children
The platform is not directed at children, and events may carry their own age limits set by the organizer. We do not knowingly process a child's personal data without the verifiable parental consent the DPDP Act requires. If we learn we hold such data without it, we delete it.
11. Changes
When this policy changes, the date at the top changes with it. Material changes are flagged on the booking page before checkout. Continued use after a change means the updated policy applies.
12. Grievance officer
Complaints and rights requests can be addressed to the grievance officer:
Grievance Officer: To be appointed
Swordfish, No. 00, Placeholder Street
Bengaluru 560001, Karnataka, India
Email: grievance@swordfish.demo
Hours: Monday to Friday, 10:00 to 18:00 IST
Appoint a named officer and replace this block before production use.