Privacy
Privacy Notice
This notice explains what personal data Sociotech IT Services (“Jamao”) collects, why, for how long, and how you can control it. It is written to meet the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. If anything here is unclear, write to grievance@jamao.in.
Last updated: 14 September 2026
In short
- We collect the minimum needed to run events: your name, email, optionally your phone number and city.
- We never see your card, UPI or bank details. Payments are handled by Razorpay on their pages.
- Organizers of events you register for receive your name, email and phone so they can run the event, and are bound by a data-processing addendum.
- Marketing (the weekly digest) is opt-in and separate. You can withdraw any consent in one click from your dashboard or by email.
- Data is stored in India. You can export or delete your data on request; we respond within 7 days.
1. What we collect
| Data | When | Required? |
|---|---|---|
| Email address | Sign-in (one-time code or Google) | Yes: it is your account identifier |
| Google account (optional) | If you sign in with Google: your Google account id, verified email, name and profile picture. We never receive your Google password or contacts. | No: email codes work without it |
| Name | First sign-in | Yes: shown on your ticket and to the organizer |
| Phone number | If you add it for WhatsApp reminders or during a paid checkout | No |
| City | If you set it, to personalise discovery | No |
| Registrations, tickets, check-in times | When you register or attend | Yes, to provide the service |
| Answers to organizer questions | Only if the event asks them | Depends on the organizer |
| Payment metadata | Order id, amount, fee breakdown, gateway payment id, status. Never card, UPI or bank details. | Yes, for paid orders |
| Payout details (organizers) | Legal name, entity type, PAN, GSTIN (optional), bank account and IFSC or UPI ID | Yes, to sell paid tickets |
| Technical data | IP address, browser, pages viewed, timestamps, in server logs | Collected automatically |
| Consent records | Timestamp and text of each consent you give or withdraw | Kept as evidence under the DPDP Act |
2. Purposes and lawful basis
Under the DPDP Act we process personal data either with your consent or for a “legitimate use” listed in section 7 of the Act. Each purpose is itemised below.
| Purpose | Data used | Basis |
|---|---|---|
| Creating and securing your account | Email, name, technical data | Consent (sign-up); legitimate use: you voluntarily provided it for this purpose |
| Registering you for events and issuing tickets | Name, email, phone, registration data | Consent given when you register |
| Sending transactional messages: confirmation, reminders, changes, cancellation, receipts | Email, phone | Necessary to provide the service you asked for |
| Processing payments, refunds and commitment deposits | Payment metadata, name, email, phone | Necessary for the contract; legal obligation (RBI, GST, Income-tax) |
| Sharing attendee lists with the organizer | Name, email, phone, ticket, status, answers | Consent given when you register; the organizer is a separate Data Fiduciary |
| Issuing invoices and receipts, tax reporting (GST-TCS, TDS) | Name, email, GSTIN, PAN, payment metadata | Legal obligation |
| Organizer payouts and KYC | Payout details | Contract; legal obligation (payment partner KYC) |
| Weekly event digest and marketing | Email, phone, city, interests | Separate, optional consent only |
| Invitations from organizers whose events you attended, registered for or follow | Name, email, phone, your attendance history with that organizer | Legitimate use (existing relationship); one-click opt-out in every invite and on your dashboard; never sold or shared with other organizers |
| Product analytics, fraud and abuse prevention | Technical data, aggregated usage | Legitimate use: security and integrity of the service |
| Responding to legal requests and disputes | Any relevant data | Legal obligation |
3. Consent and withdrawal
- Consent to these terms and this notice is recorded when you sign in for the first time, with a timestamp.
- Marketing consent (the weekly digest, WhatsApp broadcasts) is a separate, unticked checkbox. We record the date you opted in.
- You can withdraw any consent at any time: unsubscribe links in every digest, the “Notifications” section of your dashboard, or an email to grievance@jamao.in. Withdrawal is as easy as giving consent and takes effect within 24 hours.
- Withdrawing consent does not affect processing already done, and does not undo registrations you have already made; we still need to send you transactional messages about those events.
5. Sub-processors
| Provider | Purpose | Location |
|---|---|---|
| Razorpay Software Pvt Ltd | Payments, refunds, organizer linked accounts (Route) | India |
| Meta Platforms (WhatsApp Business Platform) | WhatsApp one-time codes, confirmations and reminders | India / global; message content is end-to-end encrypted between Meta and the recipient |
| Resend / Amazon SES | Transactional email | US (email delivery); data in India otherwise |
| Vercel, Supabase (AWS ap-south-1, Mumbai) | Hosting and database | India (database); global edge for static assets |
| Cloudflare R2 | Event cover images uploaded by organizers | Nearest region; public images only |
6. Retention
| Data | Kept for |
|---|---|
| Account (email, name, phone, city) | Until you delete your account, or 3 years after your last sign-in, whichever is earlier |
| Registrations and check-ins | Life of the account; anonymised 3 years after the event |
| Payment metadata, invoices and receipts | 8 years from the end of the financial year (Income-tax Act and GST record-keeping requirements) |
| Organizer payout and KYC details | As long as you have an active payout account, then 5 years (PMLA record-keeping via our payment partner) |
| Consent records | As long as the related processing continues, plus 3 years |
| Notification logs (what was sent, when, to whom) | 12 months |
| Server logs with IP addresses | 90 days |
| Analytics page views (no IP address) | 90 days, then deleted automatically |
When the retention period ends, data is deleted or irreversibly anonymised. Backups roll off within 35 days after deletion.
7. Your rights
Under the DPDP Act you have the right to:
- Access a summary of the personal data we hold about you and the processing we do.
- Correct or update inaccurate or incomplete data (name, phone and city can be edited from your dashboard).
- Erase your data, subject to the retention obligations above (we must keep invoices, for example).
- Withdraw consent as described in section 3.
- Nominate a person to exercise these rights on your behalf in the event of death or incapacity.
- Complain to the Data Protection Board of India if we do not resolve your grievance.
To exercise any right, email grievance@jamao.in from your registered email address. We respond within 7 days and complete requests within 30 days. Data exports are provided as a JSON or CSV file.
8. Security
- Encryption in transit (TLS 1.2+) and at rest (database and object storage).
- Sign-in by one-time codes: there are no passwords for us to leak.
- Role-based access: organizers see only their own events' attendees; staff access is logged and limited to support needs.
- Payment details are handled entirely by Razorpay (PCI-DSS Level 1).
- Breach response: we notify the Data Protection Board and affected users without undue delay, and within 72 hours of confirming a breach, as required by the DPDP Rules.
9. Children
Jamao accounts are for people 18 and over. Some events (student hackathons, college fests) welcome younger attendees; for those, the organizer must obtain verifiable parental consent and collect no more than name and institution. We do not knowingly process data of children for tracking, behavioural monitoring or targeted advertising, and we will delete a child's data on request from a parent or guardian.
11. Analytics
We measure how the site is used so we can fix what is broken and build what people actually visit. This is deliberately the smallest amount of data that answers that question.
- What we collect. For each page view: the path you visited (never the query string), the type of page, the event or city it relates to, the website you arrived from (its domain only), your country, whether you were on a phone, tablet or computer, whether you were signed in, and the time.
- No IP address is ever stored. Your IP is used for a fraction of a second to compute a one-way code and is then discarded. The code mixes in today's date, so it changes every night: it cannot be linked to you, and it cannot be linked to your visits on any other day.
- Why. To understand which events and cities people are looking for, to show organizers how many people viewed their event page, and to keep the service secure and working. Lawful basis: legitimate use under section 7 of the DPDP Act (security and integrity of the service), on data that does not identify you.
- How long. 90 days, after which page-view records are deleted automatically.
- No cookies, no third-party trackers, no advertising. We also use Cloudflare Web Analytics, which is cookie-less by design, collects no personal data and does not follow you across sites.
- How to object. Email grievance@jamao.in and we will exclude you and delete anything we hold. Browser “Do Not Track” and any content blocker that blocks our beacon also work: we do not attempt to work around them.
12. Grievance officer
In line with the DPDP Act and the Information Technology (Intermediary Guidelines) Rules, 2021, our grievance officer is:
Grievance Officer, Jamao
Sociotech IT Services
Koramangala, Bengaluru 560034, Karnataka, India
We acknowledge grievances within 24 hours and resolve them within 15 days.
General questions: hello@jamao.in. If you are not satisfied with our response, you may approach the Data Protection Board of India.