Privacy Policy
Effective date: 21 September 2026 · MindPair Labs Private Limited ("MindPair Labs", "we", "us", "our")
This Privacy Policy explains how MindPair Labs Private Limited, a company incorporated in India with its registered office at 47A, Gobind Park, Krishna Nagar, Delhi – 110051, India, collects, uses, shares, and protects personal information. It applies to:
- Our website — mindpairlabs.com and any pages we operate on this domain.
- Our products — EventHelm, our event operations platform, including its web application, ticket landing pages, check-in tools, and related services.
By using our website or products, you agree to the practices described in this policy. If you do not agree, please do not use them.
1. The roles we play
We handle personal data in two distinct capacities, and your rights work slightly differently in each:
- As a data fiduciary / controller — for data about website visitors, people who contact us, and EventHelm account holders (organizers and their team members). Here, we decide how and why data is processed, and you should contact us directly about it.
- As a data processor — for guest and attendee data that event organizers upload to EventHelm (names, email addresses, phone numbers, ticket assignments, check-in records). The organizer is the controller of this data; we process it only on their instructions to deliver the service. If you are an event guest, the organizer who invited you is your first point of contact for privacy requests, and we will assist them in fulfilling those requests.
2. Information we collect
Information you give us directly:
- Email enquiries — your email address and whatever you include in your message, when you write to the addresses listed on mindpairlabs.com. Our website has no contact form; email is the only way it invites you to reach us.
- Account information — name, email address, optional phone number, profile photo, timezone, and language, when you create an EventHelm account. We use passwordless sign-in, so we never collect or store a password.
- Organization information — organization name, logo, branding, industry, country, timezone, and currency.
- Support communications — the contents of support requests, feature suggestions, and chat messages you send us.
Information organizers provide about their guests (processed on the organizer's behalf):
- Guest names, email addresses, and phone numbers, uploaded manually or by spreadsheet import.
- Ticket details — ticket type, ticket ID, RSVP status, tags, and any custom fields the organizer defines.
- Event participation records — ticket delivery outcomes, check-in time, gate, and the staff member who performed the check-in.
Information collected automatically:
- Usage and device data — IP address, browser type and version, pages viewed, and actions taken, used for security, debugging, and service improvement.
- Sign-in and session data — device descriptor, approximate location, and last-active time for each active session, shown to you so you can review and revoke sessions you don't recognize.
- A device fingerprint, on the web app only. When you sign in on the web, your browser reads your screen size and colour depth, your timezone, your language preferences, your platform, your processor core count, and a canvas rendering hash — a small image drawn off-screen, whose exact result varies with your graphics hardware, driver, and installed fonts. Your browser combines these into a one-way hash and sends us only that hash; the underlying values never leave your device. We use it for a single purpose: to decide whether to issue the one-time free credits granted to a new organization, so the same device cannot claim them repeatedly. It is never used to identify you, to build a profile, to track you across websites, or to decide whether you may sign in — if your browser blocks any part of it, you sign in exactly as normal. Our mobile apps do not do this; they send only a description of the device (type, platform, model, and app version). Section 11 says how long we keep it.
- Replies to our WhatsApp messages — if you reply to a WhatsApp message we send, your reply is recorded. That number is not monitored: nobody reads the replies and nothing acts on them, so replying is not a way to reach us and not a way to opt out. Please use the contacts in section 17 instead.
- Cookies and similar technologies — see section 7.
We do not knowingly collect sensitive personal data (such as health, biometric, or financial account data) through our services, and we ask organizers not to place such data in guest fields.
3. How we use information
- Provide the service — create and manage accounts and organizations, generate tickets, deliver them, validate them at check-in, and produce reports for organizers.
- Transactional communication — send one-time sign-in codes, ticket deliveries, delivery-failure notices, low-balance warnings, and requested reports.
- Respond to you — answer enquiries and support requests you send us.
- Secure and improve — detect fraud and abuse, monitor reliability, debug issues, and understand aggregate usage to improve the product.
- Comply with law — meet our legal, tax, and regulatory obligations, and enforce our Terms of Use.
We do not sell personal information, and we do not use guest data uploaded by organizers for our own marketing.
4. Legal bases and consent
We process personal data under Indian law, including the Digital Personal Data Protection Act, 2023 (DPDP Act), and, where it applies to users in other jurisdictions, on the following bases: your consent (e.g., writing to us with an enquiry, opting into product updates), performance of a contract (providing EventHelm to account holders), our legitimate interests (service security, fraud prevention, improvement), and compliance with legal obligations. Where consent is the basis, you may withdraw it at any time without affecting processing already carried out.
5. Messaging communications (Email, WhatsApp, and SMS)
EventHelm delivers event tickets and related transactional messages over Email, WhatsApp, and SMS (text message). Our messaging practices are:
- Transactional only. Messages sent through EventHelm relate to a specific event the recipient is invited to — a ticket link, a delivery confirmation, or an event-critical notice. We do not send marketing messages to guests, and our Terms of Use prohibit organizers from using the platform for unsolicited messaging.
- Consent through the organizer. Guests receive messages because an event organizer — who has a direct relationship with them — provided their contact details for ticket delivery. Organizers warrant to us that they have the right to use those details for this purpose.
- Opting out. Replying STOP to an SMS stops further SMS to that number, and replying HELP returns our contact details; our SMS provider applies both automatically. WhatsApp and email carry no automatic opt-out keyword — replying to them does not reach anyone. To stop messages on any channel, contact the event organizer who invited you, or us at admin@mindpairlabs.com, and we will suppress your contact details for that organizer's events. We honour opt-out requests promptly.
- Delivery infrastructure. Messages are delivered through vetted communications providers acting as our processors under data-processing agreements. Phone numbers and email addresses are shared with them only to deliver the specific message, never for their own marketing.
- No marketing use of mobile information. Mobile information (including phone numbers and SMS opt-in data and consent) will not be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties.
6. Ticket landing pages
Each delivered ticket includes a personal, unguessable link to a ticket landing page that displays the ticket without requiring a login. Treat this link like the ticket itself: anyone with the link can view that ticket. We design these URLs to be cryptographically unguessable, we never publish them, and we exclude them from our analytics and error-reporting tools.
7. Cookies and analytics
- Strictly necessary cookies — a sign-in cookie that keeps you signed in, set so that scripts cannot read it, and, on public registration pages, a short-lived cookie that remembers you have passed the bot check. These cannot be switched off, because the service does not work without them.
- No analytics cookies, because we run no analytics. We currently use no third-party product analytics on our website or in our application — no Google Analytics, no tag manager, no session recording, and no profiling. What we measure, we measure from our own server-side records (section 2).
We do not use third-party advertising cookies, and we do not track you across unrelated websites. If we ever introduce a third-party analytics tool, we will update this policy first and, where the law requires consent, ask for yours before the tool runs.
8. Sharing and processors
We share personal data only with the service providers named below, each bound by contractual confidentiality and data-protection obligations and permitted to use the data only to provide their service to us. None of them may use it for their own marketing.
- Amazon Web Services — runs our application servers and stores uploaded images, ticket files, and guest import spreadsheets.
- MongoDB Atlas — the managed database holding account, organization, event, and guest records.
- Cloudflare — serves our websites and registration pages, provides DNS and protection against attacks, and runs the Turnstile bot check on public forms.
- Twilio — delivers SMS and WhatsApp messages (section 5), and checks whether a number is able to receive them.
- Meta Platforms — operates the WhatsApp network over which those WhatsApp messages travel.
- EnableX — delivers SMS to Indian mobile numbers, under India's DLT registration scheme.
- ZeptoMail, a Zoho service — delivers our email, including sign-in codes and ticket deliveries.
- Sentry — receives crash and error reports so we can diagnose faults. We remove personal data, ticket links, and IP and location information before a report is sent.
- Better Stack — monitors whether our services are reachable and whether scheduled jobs have run.
- Slack — receives our internal operational alerts, which can contain fault details.
- Google — provides "Sign in with Google", issues Google Wallet passes for tickets, distributes our Android app, and serves the web fonts our pages use, which means your IP address and browser details reach Google whenever one of our pages loads.
- Apple — provides "Sign in with Apple", issues Apple Wallet passes for tickets, and distributes our iOS app.
- Paddle — our merchant of record for credit purchases, including its hosted checkout and the scripts that checkout loads. Payment card details are entered on Paddle's checkout and never touch our systems; we receive only confirmation of payment and invoice metadata.
- Professional advisers and authorities — where required to comply with law, enforce our terms, or protect rights, safety, and security.
If MindPair Labs is involved in a merger, acquisition, or asset sale, personal data may transfer as part of that transaction, subject to the commitments of this policy and notice to affected users.
9. Where your data is stored, and international transfers
MindPair Labs is based in India, but your data is stored in the United States. Our application servers, our database, and our file storage all run in Amazon Web Services' US East (Northern Virginia) region, and crash and error reports sent to Sentry are processed in the United States as well.
Two providers process data elsewhere: ZeptoMail, which delivers our email, and EnableX, which delivers SMS to Indian numbers, both operate from data centres in India. Cloudflare serves our pages from a worldwide network, so a request is answered from the location nearest the visitor. Our remaining providers may process data in the countries in which they operate.
Where data crosses borders, we rely on contractual protections with each processor and on choosing providers with recognized security and compliance practices.
10. Security
- Encryption of data in transit; passwordless authentication with one-time codes and rate limiting.
- Cryptographically signed ticket QR codes that cannot be forged or predicted from another ticket.
- Role-based access control enforced server-side, organization-level data isolation, and session revocation that takes effect immediately.
- Audit logging of security-relevant actions with actor and timestamp.
No system is perfectly secure; if we become aware of a breach affecting your personal data, we will notify affected users and authorities as required by applicable law.
11. Retention
We keep personal data only as long as we need it. In plain terms:
- Sign-in codes — 5 minutes.
- Sessions — deleted 7 days after the session expires.
- Guest lists uploaded as a spreadsheet — the uploaded file itself is deleted after 30 days. The guest records it created stay in the organizer's workspace until the organizer removes them.
- Ticket files and wallet passes — 7 days after the event ends.
- Delivery records, meaning what was sent to whom and whether it arrived — 12 months.
- Activity history on an event, an organization, or a guest — 12 months.
- Error logs, which include IP address, country, and browser — 90 days.
- Account security history, such as sign-ins and changes to an account — 90 days.
- Our platform audit trail, which records who changed what and includes IP addresses — 2 years.
- Guest and event data — for as long as the organizer's workspace holds it. Organizers can delete guests, events, and the whole organization at any time.
- Invoices and transaction records — for the periods tax and company law require.
- Support correspondence — for as long as needed to resolve and evidence the matter.
When you delete your account, deletion is immediate — there is no grace period and no recoverable copy. Two small records deliberately survive it. Neither can identify you and neither can be reversed: each stores your email address, and where one exists the device fingerprint described in section 2, only as an irreversible keyed hash.
- A free-credit record, kept indefinitely to prevent fraud, so that deleting and recreating an account cannot be used to claim the one-time free credits again.
- One row recording why you left, if you chose to tell us, kept indefinitely so that we can improve the product.
When data is no longer needed, we delete or anonymize it.
12. Your rights
Depending on your jurisdiction, you may have the right to access a copy of your personal data, correct inaccuracies, request deletion, receive data in a portable format, object to or restrict certain processing, withdraw consent, and nominate a person to exercise your rights in the event of death or incapacity (as provided by the DPDP Act). To exercise any of these rights, contact admin@mindpairlabs.com. We will respond within the timelines required by applicable law and may need to verify your identity first.
If your data was uploaded by an event organizer, we may refer your request to that organizer as the controller and assist them in fulfilling it. If you are unsatisfied with our response, you may complain to your local data-protection authority; in India, this is the Data Protection Board of India.
13. Grievance redressal
In accordance with Indian law, questions, concerns, and grievances about this policy or our data practices may be addressed to our Grievance Officer:
Rajender Kumar, Director — Grievance Officer
MindPair Labs Private Limited
47A, Gobind Park, Krishna Nagar, Delhi – 110051, India
Email: admin@mindpairlabs.com
Phone and WhatsApp: +91 99588 44937
We acknowledge every grievance within 24 hours of receipt and aim to resolve it within 7 days.
14. Children
Our website and products are intended for adults and business use. We do not knowingly collect personal data from children under 18 for our own purposes. Organizers who include minors as event guests are responsible for obtaining any consent required from a parent or guardian.
15. Third-party links
Our website and messages may link to third-party sites (for example, a venue's website or Paddle's checkout). Their privacy practices are their own; this policy does not cover them.
16. Changes to this policy
We may update this policy from time to time. We will post the revised version on this page with a new effective date, and notify account holders by email of material changes before they take effect. Continued use of the services after the effective date constitutes acceptance of the revised policy.
17. Contact us
MindPair Labs Private Limited
47A, Gobind Park, Krishna Nagar, Delhi – 110051, India
Email: admin@mindpairlabs.com · Support: support@mindpairlabs.com