How RotaSphere collects, processes, stores, protects, and retains personal data for event ticketing, payments, gate check-in scanning, and community operations.
Manage Your Privacy Preferences
Exercise your DPDP rights: download your registration data, revoke marketing consents, request data erasure, or file a privacy grievance directly from your personal dashboard.
This Privacy Policy explains how RotaSphere (operated by RotaSphere Platform Operations / Rotaract District 3192 Secretariat, hereinafter "RotaSphere", "we", "us", or "our") collects, uses, stores, shares, and protects personal data when you use the RotaSphere platform, including our websites, event registration services, ticketing infrastructure, organizer dashboards, gate check-in systems, and related communications.
This policy applies to both Attendees / Delegates purchasing passes or registering for events, and Event Organizers / Club Officers hosting events and operating gate verification terminals.
Indian Legal Framework: In accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the DPDP Rules, 2025, this standalone notice provides an itemized description of personal data collected, specific processing purposes, enabled services, data retention schedules, and mechanisms for withdrawing consent and exercising Data Principal rights.
2. Information We Collect
We collect personal data across clearly defined operational categories:
A. Account & Profile Information
Full name, email address, mobile phone number, profile photo (if uploaded), role/designation, affiliated Rotaract/Rotary Club name, and Clerk authentication user ID.
Organizers may request additional event-specific information through custom registration form fields (e.g., college/institution name, dietary preferences, T-shirt size, emergency contact, or delegate category). RotaSphere does not mandate or collect these fields by default; they are configured dynamically by the host organizer solely for event logistics.
3. Payment Information & PCI-DSS Separation
When you purchase tickets on RotaSphere, we process transaction metadata necessary for order fulfilment:
Order ID, Payment Gateway Transaction ID, Payment Status, Amount Paid, Currency (INR), and Transaction Timestamps.
For direct UPI settlement workflows: Attendee-submitted 12-digit UPI UTR Reference numbers and payment receipt screenshots submitted for organizer verification.
Non-Storage of Card & Banking Credentials: All pass payments are transacted directly via UPI (Unified Payments Interface) and Reserve Bank of India (RBI) authorized banking clearing networks (NPCI / BHIM / GPay / PhonePe / Paytm). RotaSphere never receives, stores, or processes complete card details or banking authentication credentials on its servers.
4. Technical, Log & Security Information
To prevent fraud, guarantee gate security, and maintain platform uptime, we automatically log:
IP address and approximate geographic location derived from IP (city/country level).
Browser user agent, device model, operating system, and screen resolution.
Login timestamps, authentication sessions, and security access audit trails.
Error logs, exception traces, and API rate-limiting metrics.
5. QR Code & Gate Check-In Verification Data
When an attendee presents their digital pass at an event entrance, the RotaSphere Check-In Scanner app records:
Scanned Ticket ID and cryptographically hashed QR token verification status.
Exact timestamp of gate check-in scan.
Gate Scanner Operator Account ID and gate entrance label.
Duplicate scan detection logs (flagging and preventing counterfeit or repeated entry attempts).
6. Location Data Policy (MapLibre / Ola Maps)
RotaSphere integrates MapLibre GL and Ola Maps solely for rendering interactive event venue maps and driving directions. We do NOT perform persistent background GPS tracking of users. Location data is strictly used on-demand when searching for nearby events in District 3192.
7. Specific Purposes for Data Processing
Personal data is processed exclusively for specified, lawful business purposes:
🎟️ Event Operations & TicketingIssuing digital QR passes, verifying attendance at venue gates, generating delegate credentials, and issuing participation certificates.
💳 Payments & SettlementProcessing direct UPI payments, validating UTR receipts, reconciling club accounts, and executing refunds.
📬 Critical CommunicationsSending booking confirmations, QR ticket delivery emails, event postponement notices, and payment receipts.
8. Notice, Consent & Consent Withdrawal
In strict accordance with the DPDP Rules 2025, RotaSphere enforces a clear separation between Necessary Transactional Processing and Optional Promotional Processing:
Necessary Processing: Providing your email and name is required to generate and deliver your event ticket, process your payment, and grant gate entry.
Optional Communications: Subscribing to district newsletters, promotional WhatsApp updates, or marketing emails is entirely voluntary and is never pre-bundled into Terms of Service acceptance.
Ease of Withdrawal: You can withdraw consent for any optional processing at any time with an ease comparable to giving it, via the Privacy Center.
9. Sharing & Third-Party Processors
RotaSphere enforces strict tenant-level isolation and never sells or rents personal data to third-party data brokers or advertisers. Data is shared strictly with:
Host Event Organizers: When you register for an event, your registration fields, ticket tier, and check-in status are shared solely with the authorized host Rotaract Club for gate admission and delegate kit distribution. Other clubs cannot access your data.
Payment & Banking Networks: National Payments Corporation of India (NPCI) and authorized UPI participating banking handles for direct peer-to-merchant settlements and UTR validation.
Law Enforcement & Statutory Bodies: Where required by valid court order, Indian law, or statutory regulations.
10. Purpose-Based Data Retention Schedule
In accordance with DPDP purpose-limitation guidelines, RotaSphere retains personal data only for as long as necessary:
Data Category
Retention Period
Statutory / Operational Basis
User Profile & Account
Until user requests deletion / account closure
Contractual service provision
Payment & Invoicing Records
7 Years (2,555 days)
Indian Income Tax Act & Companies Act statutory accounting compliance
Event Registration & Pass History
3 Years (1,095 days)
Certificate verification & dispute audit trail
Gate Scanner & Security Logs
1 Year (365 days)
Incident response, fraud prevention & audit
Temporary OTPs / Verification Tokens
24 Hours
Immediate hard-deletion post verification
11. Your Rights as a Data Principal
Under the DPDP Act 2023, you have guaranteed statutory rights over your personal data:
1. Right to Access & SummaryRequest a complete summary of personal data being processed and third parties with whom it has been shared.
2. Right to Correction & UpdateCorrect inaccurate, misleading, or incomplete profile and contact data.
3. Right to Erasure / DeletionRequest complete erasure of your personal data when the original processing purpose is complete (subject to legal retention holds).
4. Right of Grievance RedressalFile privacy grievances with our designated Grievance Officer, with escalation available to the Data Protection Board of India.
5. Right to Data Portability / ExportDownload a machine-readable JSON copy of all your passes, registrations, and profile records.
6. Right to NominateNominate an individual to exercise data rights on your behalf in the event of death or incapacity.
Encryption: TLS 1.3 encryption for all data in transit; AES-256 encryption at rest for database stores.
Row Level Security (RLS): PostgreSQL tenant-level policies guaranteeing that club organizers can only query their own registered delegates.
Cryptographic QR Tokens: Pass QR codes use SHA-256 cryptographic signatures with single-use replay protection.
Access Controls & MFA: Strict Role-Based Access Control (RBAC) and Multi-Factor Authentication for administrative consoles.
13. Data Breach Incident Notification (72-Hour SLA)
In the unlikely event of a verified personal data breach impacting RotaSphere delegates, RotaSphere maintains an incident response protocol compliant with DPDP Rules 2025:
Prompt notification to affected Data Principals detailing the nature of the breach, affected data categories, and recommended mitigation steps.
Formal statutory reporting to the Data Protection Board of India within 72 hours of incident confirmation.
14. Children's Personal Data & Age Policy
RotaSphere does not knowingly collect personal data from individuals under 18 years of age without verified parental/guardian authorization. Where youth or school-level Rotaract/Interact events require registrations for minors, the host organizer is contractually responsible for securing lawful parental consent prior to ticketing.
15. Grievance Officer & Statutory Redressal
If you have any questions, concerns, or grievances regarding the processing of your personal data, you may contact our designated Grievance Officer under the DPDP Act 2023:
Grievance Officer: Rotaract District 3192 Tech Team