Privacy Policy
Effective date: 7 August 2026 · MindPair Labs Private Limited ("MindPair Labs", "we", "us", "our")
This Privacy Policy explains how MindPair Labs Private Limited, a company incorporated in India with its registered office at 47A, Gobind Park, Krishna Nagar, Delhi – 110051, India, collects, uses, shares, and protects personal information. It applies to:
- Our website — mindpairlabs.com, including the contact form and any pages we operate on this domain.
- Our products — EventHelm, our event operations platform, including its web application, ticket landing pages, check-in tools, and related services.
By using our website or products, you agree to the practices described in this policy. If you do not agree, please do not use them.
1. The roles we play
We handle personal data in two distinct capacities, and your rights work slightly differently in each:
- As a data fiduciary / controller — for data about website visitors, people who contact us, and EventHelm account holders (organizers and their team members). Here, we decide how and why data is processed, and you should contact us directly about it.
- As a data processor — for guest and attendee data that event organizers upload to EventHelm (names, email addresses, phone numbers, ticket assignments, check-in records). The organizer is the controller of this data; we process it only on their instructions to deliver the service. If you are an event guest, the organizer who invited you is your first point of contact for privacy requests, and we will assist them in fulfilling those requests.
2. Information we collect
Information you give us directly:
- Contact form submissions — name, email address, topic, and message content, when you write to us via mindpairlabs.com.
- Account information — name, email address, optional phone number, profile photo, timezone, and language, when you create an EventHelm account. We use passwordless sign-in, so we never collect or store a password.
- Organization information — organization name, logo, branding, industry, country, timezone, and currency.
- Support communications — the contents of support requests, feature suggestions, and chat messages you send us.
Information organizers provide about their guests (processed on the organizer's behalf):
- Guest names, email addresses, and phone numbers, uploaded manually or by spreadsheet import.
- Ticket details — ticket type, ticket ID, RSVP status, tags, and any custom fields the organizer defines.
- Event participation records — ticket delivery outcomes, check-in time, gate, and the staff member who performed the check-in.
Information collected automatically:
- Usage and device data — IP address, browser type, device identifiers, pages viewed, and actions taken, used for security, debugging, and service improvement.
- Sign-in and session data — device descriptor, approximate location, and last-active time for each active session, shown to you so you can review and revoke sessions you don't recognize.
- Cookies and similar technologies — see section 7.
We do not knowingly collect sensitive personal data (such as health, biometric, or financial account data) through our services, and we ask organizers not to place such data in guest fields.
3. How we use information
- Provide the service — create and manage accounts and organizations, generate tickets, deliver them, validate them at check-in, and produce reports for organizers.
- Transactional communication — send one-time sign-in codes, ticket deliveries, delivery-failure notices, low-balance warnings, and requested reports.
- Respond to you — answer contact-form enquiries and support requests.
- Secure and improve — detect fraud and abuse, monitor reliability, debug issues, and understand aggregate usage to improve the product.
- Comply with law — meet our legal, tax, and regulatory obligations, and enforce our Terms of Use.
We do not sell personal information, and we do not use guest data uploaded by organizers for our own marketing.
4. Legal bases and consent
We process personal data under Indian law, including the Digital Personal Data Protection Act, 2023 (DPDP Act), and, where it applies to users in other jurisdictions, on the following bases: your consent (e.g., submitting the contact form, opting into product updates), performance of a contract (providing EventHelm to account holders), our legitimate interests (service security, fraud prevention, improvement), and compliance with legal obligations. Where consent is the basis, you may withdraw it at any time without affecting processing already carried out.
5. Messaging communications (Email and WhatsApp)
EventHelm delivers event tickets and related transactional messages over Email and WhatsApp. Our messaging practices are:
- Transactional only. Messages sent through EventHelm relate to a specific event the recipient is invited to — a ticket link, a delivery confirmation, or an event-critical notice. We do not send marketing messages to guests, and our Terms of Use prohibit organizers from using the platform for unsolicited messaging.
- Consent through the organizer. Guests receive messages because an event organizer — who has a direct relationship with them — provided their contact details for ticket delivery. Organizers warrant to us that they have the right to use those details for this purpose.
- Opting out. A guest can stop receiving messages at any time by replying STOP to a WhatsApp message, using the unsubscribe mechanism in an email, or contacting the event organizer or us at admin@mindpairlabs.com. Opt-outs are honoured promptly.
- Delivery infrastructure. Messages are delivered through vetted communications providers acting as our processors under data-processing agreements. Phone numbers and email addresses are shared with them only to deliver the specific message, never for their own marketing.
6. Ticket landing pages
Each delivered ticket includes a personal, unguessable link to a ticket landing page that displays the ticket without requiring a login. Treat this link like the ticket itself: anyone with the link can view that ticket. We design these URLs to be cryptographically unguessable, we never publish them, and we exclude them from our analytics and error-reporting tools.
7. Cookies and analytics
- Strictly necessary cookies — used for sign-in sessions and security. These cannot be switched off.
- Analytics — we may use privacy-respecting product analytics to understand aggregate usage of our website and application. Where required by law, analytics run only after you consent via the cookie notice, and you can withdraw that consent at any time from the same notice.
We do not use third-party advertising cookies, and we do not track you across unrelated websites.
8. Sharing and processors
We share personal data only with service providers who help us operate, each bound by contractual confidentiality and data-protection obligations and permitted to use the data only to provide their service to us:
- Cloud hosting and infrastructure — to run the application and store data.
- Communications providers — to deliver email and WhatsApp messages (section 5).
- Payment processing — Paddle, our merchant of record, processes credit purchases. Payment card details are entered on Paddle's hosted checkout and never touch our systems; we receive only confirmation of payment and invoice metadata.
- Professional advisers and authorities — where required to comply with law, enforce our terms, or protect rights, safety, and security.
If MindPair Labs is involved in a merger, acquisition, or asset sale, personal data may transfer as part of that transaction, subject to the commitments of this policy and notice to affected users.
9. International transfers
We are based in India, and our service providers may process data in other countries. Where data crosses borders, we ensure appropriate safeguards through contractual protections with our processors and by choosing providers with recognized security and compliance practices.
10. Security
- Encryption of data in transit; passwordless authentication with one-time codes and rate limiting.
- Cryptographically signed ticket QR codes that cannot be forged or predicted from another ticket.
- Role-based access control enforced server-side, organization-level data isolation, and session revocation that takes effect immediately.
- Audit logging of security-relevant actions with actor and timestamp.
No system is perfectly secure; if we become aware of a breach affecting your personal data, we will notify affected users and authorities as required by applicable law.
11. Retention
We keep personal data only as long as needed for the purposes described here: account data for the life of the account plus a short wind-down period; guest and event data for as long as the organizer's workspace retains it (organizers can archive or remove guest data); invoices and transaction records for the periods required by tax and company law; and support correspondence for as long as needed to resolve and evidence the matter. When data is no longer needed, we delete or anonymize it.
12. Your rights
Depending on your jurisdiction, you may have the right to access a copy of your personal data, correct inaccuracies, request deletion, receive data in a portable format, object to or restrict certain processing, withdraw consent, and nominate a person to exercise your rights in the event of death or incapacity (as provided by the DPDP Act). To exercise any of these rights, contact admin@mindpairlabs.com. We will respond within the timelines required by applicable law and may need to verify your identity first.
If your data was uploaded by an event organizer, we may refer your request to that organizer as the controller and assist them in fulfilling it. If you are unsatisfied with our response, you may complain to your local data-protection authority; in India, this is the Data Protection Board of India.
13. Grievance redressal
In accordance with Indian law, questions, concerns, and grievances about this policy or our data practices may be addressed to our Grievance Officer:
Grievance Officer, MindPair Labs Private Limited
47A, Gobind Park, Krishna Nagar, Delhi – 110051, India
admin@mindpairlabs.com
14. Children
Our website and products are intended for adults and business use. We do not knowingly collect personal data from children under 18 for our own purposes. Organizers who include minors as event guests are responsible for obtaining any consent required from a parent or guardian.
15. Third-party links
Our website and messages may link to third-party sites (for example, a venue's website or Paddle's checkout). Their privacy practices are their own; this policy does not cover them.
16. Changes to this policy
We may update this policy from time to time. We will post the revised version on this page with a new effective date, and notify account holders by email of material changes before they take effect. Continued use of the services after the effective date constitutes acceptance of the revised policy.
17. Contact us
MindPair Labs Private Limited
47A, Gobind Park, Krishna Nagar, Delhi – 110051, India
Email: admin@mindpairlabs.com · Support: support@mindpairlabs.com