Privacy Policy

Last updated: April 2026

This Privacy Policy describes how EventFlow Experience, incorporated in the Province of Québec, Canada, collects, uses, discloses and protects your personal information when you use our platform, website or any related services (collectively, the "Services"). Please read this policy carefully.

1. Who We Are

EventFlow Experience is a technology company incorporated under the laws of the Province of Québec, Canada. We operate an online platform that enables event organizers to create, promote and manage events, and enables attendees to discover, register for and purchase tickets to those events.

For the purposes of applicable privacy legislation, EventFlow Experience acts as the data controller of the personal information you provide directly to us, and as a data processor for personal information that event organizers collect through our platform about their attendees.

Legal Entity

EventFlow Experience · Québec, Canada
📧 privacy@eventflow.click

2. Information We Collect

a) Information you provide to us

  • Account registration: name, email address, password, preferred language, profile photo (optional)
  • Event organizer profile: company name, address, phone number, tax identification number, payout bank details
  • Ticket purchase: billing address, ticket holder names, answers to organizer-defined questions (e.g. dietary preferences, T-shirt size)
  • Payment information: credit/debit card details and billing address — processed directly by our payment provider (Stripe). We never store full card numbers.
  • Communications: messages you send us via support, email or contact forms
  • User-generated content: event descriptions, images, banners and other content you upload

b) Information we collect automatically

  • Usage data: pages visited, features used, search queries, time spent on pages, referring URLs
  • Device & technical data: IP address, browser type and version, operating system, screen resolution, time zone
  • Cookies & similar technologies: as described in our Cookie Policy
  • Transaction data: purchase history, ticket IDs, check-in records, refund history

c) Information from third parties

  • Social login (Google): name, email address and profile picture from your Google account when you choose to sign in with Google
  • Payment processors: transaction status and fraud signals from Stripe
  • Analytics providers: aggregated demographic and behavioural data (only with your consent)

3. How We Use Your Information

We use personal information for the following purposes and legal bases:

Purpose Legal Basis
Create and manage your account Contract performance
Process ticket purchases and payments Contract performance
Send booking confirmations, tickets and receipts Contract performance
Provide customer support Contract performance / Legitimate interest
Detect and prevent fraud, abuse and security incidents Legitimate interest / Legal obligation
Improve, personalise and develop our Services Legitimate interest
Send platform updates and service announcements Legitimate interest
Send marketing communications and newsletters Consent (opt-in)
Display personalised ads via third-party networks Consent (cookie preferences)
Comply with legal and tax obligations Legal obligation

4. How We Share Your Information

We do not sell your personal information. We may share it in the following circumstances:

Event Organizers

When you purchase a ticket or register for an event, we share your name, email, ticket details and any registration answers with the event organizer. The organizer acts as an independent data controller for that information and is subject to their own privacy practices.

Service Providers (Sub-processors)

We engage trusted third-party service providers who process data on our behalf under strict data processing agreements:

Provider Service Location
Stripe Payment processing USA / Global
Google Analytics, Maps, Login USA / Global
Mailgun / SMTP Transactional email USA / EU
AWS / Hosting Cloud infrastructure Canada / USA

Legal Requirements

We may disclose your information when required by law, court order, or governmental authority, or when we believe disclosure is necessary to protect the rights, property or safety of EventFlow Experience, our users or the public.

Business Transfers

In the event of a merger, acquisition, or sale of all or substantially all of our assets, your personal information may be transferred. We will notify you before your information is subject to a different privacy policy.

5. Data Retention

We retain personal information for as long as necessary to fulfil the purposes outlined in this policy, unless a longer period is required by law:

  • Account data — kept for the duration of your account, plus 2 years after deletion (for fraud prevention and legal compliance)
  • Transaction & financial records — 7 years (required by Quebec and Canadian tax law)
  • Event attendee data — 2 years after the event date, or as directed by the organizer
  • Marketing preferences & consent logs — 3 years from last interaction
  • Support communications — 2 years after ticket resolution
  • Server logs & technical data — 90 days

When retention periods expire, data is securely deleted or anonymised.

6. Your Rights & Choices

Depending on your location, you may have the following rights regarding your personal information:

🔍 Access

Request a copy of the personal information we hold about you.

✏️ Correction

Request correction of inaccurate or incomplete data. You can update most data directly in your account settings.

🗑️ Erasure ("Right to be Forgotten")

Request deletion of your personal data, subject to legal retention obligations.

📦 Portability

Receive your data in a structured, machine-readable format.

🚫 Objection & Restriction

Object to processing based on legitimate interest, or request restriction of processing in certain circumstances.

📧 Withdraw Consent

Withdraw consent for marketing emails (unsubscribe link in every email) or cookies (via our Cookie Settings).

How to submit a privacy request

Email privacy@eventflow.click with the subject "Privacy Request". We will respond within 30 days (as required by PIPEDA / Law 25). We may need to verify your identity before processing the request.

If you are located in the EU/EEA and believe we have not adequately addressed your concern, you have the right to lodge a complaint with your local Data Protection Authority. For Quebec residents, you may contact the Commission d'accès à l'information (CAI).

7. Security

We implement technical and organisational measures designed to protect your personal information against accidental loss, unauthorised access, disclosure, alteration or destruction. These measures include:

  • TLS/HTTPS encryption for all data in transit
  • Passwords stored as salted cryptographic hashes (never in plain text)
  • Payment card data handled exclusively by PCI-DSS certified provider (Stripe)
  • Access controls and role-based permissions for internal staff
  • Regular security reviews and vulnerability assessments

No method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security. If you suspect a security breach, please contact us immediately at privacy@eventflow.click.

8. International Data Transfers

EventFlow Experience is based in Québec, Canada. Some of our service providers are located in the United States and other countries. When we transfer personal information outside Canada, we ensure an adequate level of protection is in place through:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions recognising the destination country's protections
  • Binding corporate rules or equivalent safeguards with sub-processors

Canada has been recognised by the EU as providing an adequate level of data protection under PIPEDA. For transfers to the USA, we rely on Standard Contractual Clauses or the service provider's compliance certifications.

9. Children's Privacy

Our Services are not directed to children under the age of 14. We do not knowingly collect personal information from children under 14 without verifiable parental consent. If you believe we have inadvertently collected such information, please contact us at privacy@eventflow.click and we will promptly delete it. For events specifically targeting minors, event organizers are responsible for obtaining appropriate parental consent.

10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements or other factors. The date at the top of this page indicates when the policy was last revised.

For material changes, we will notify registered users by email or by displaying a prominent notice on our platform at least 14 days before the change takes effect, as required by Law 25 (Québec). Continued use of our Services after that date constitutes acceptance of the updated policy.

11. Contact Us

For any questions, concerns or requests regarding this Privacy Policy or our data practices, please contact our Privacy Officer:

EventFlow Experience — Privacy Officer

PIPEDA Québec Law 25 GDPR LGPD CCPA