Privacy Policy
DRAFT — placeholder written by engineering on 2026-09-18. Not reviewed by counsel. Not for publication.
A skeleton assembled from docs/security/data-protection.md, which is the engineering source of truth for classification, retention and deletion, and from docs/architecture/analytics-architecture.md for what analytics collects. Every DPDP Act 2023 question marked "confirm with counsel" in those documents is still open and is marked here too. Nothing below is legal advice.
1. Who processes your data
The data fiduciary, its registered address and its contact address are to be supplied. Whether Sotillion is a Significant Data Fiduciary, and what that adds, is for counsel (docs/security/data-protection.md, "Data-principal rights").
2. What we collect
| Kind | Examples |
|---|---|
| Account | name, email, username, password (hashed by the auth library, never in plain text), phone if you add one |
| Sensitive | date of birth (for the 18+ check only), organizer KYC status from the payment provider |
| Profile | display name, bio, avatar, city, interests, skills |
| Activity | posts, comments, messages, follows, community memberships, job applications, saved items |
| Commerce | orders, tickets, payment references, refunds, settlements |
| Technical | request logs with an IP-derived hash, device and app version, crash reports |
Not collected: card numbers (the payment provider's hosted checkout holds them and Sotillion stays in PCI SAQ-A scope) and precise location. Analytics never goes finer than country / state / city (docs/architecture/analytics-architecture.md).
3. Why we process it, and on what basis
Purposes: to run your account, to sell and deliver tickets, to admit you to events, to show you the feed and the modules you use, to keep the platform safe, and to meet financial record-keeping obligations. The lawful basis for each purpose, and the exact consent notice at sign-up, are counsel's to write — the platform records that you accepted a specific version of the Terms and this policy, with the moment you did.
4. Who we share it with
- The payment provider, for payments, refunds and organizer payouts.
- Event organizers: the attendee information an organizer needs to run their event. A recruiter on a job listing sees an applicant's profile summary, skills and note — never their email, phone or date of birth (
docs/security/data-protection.md, "Personal"). - Infrastructure and tooling providers (hosting, storage, email, SMS, product analytics, crash reporting). Cross-border transfer rules for these — in particular PostHog and Sentry — must be confirmed with counsel before launch.
- Authorities, where the law requires it.
We do not sell personal data.
5. How long we keep it
| Data | Retention |
|---|---|
| Payment records (order, attempt, ledger, refund, settlement) | 7 years from the transaction — period to be confirmed with the accountant |
| Audit log | 3 years |
| Application logs | 90 days in production, then archived up to a year |
| Webhook payloads | 1 year |
| Scan events | event end + 1 year |
| Security events | 90 days |
| Data exports | 7 days |
| Deleted-account grace copy | 14 days |
| Product analytics | 12 months rolling; your events are purged when your account is |
| Backups | 30 days |
Source: docs/security/data-protection.md, "Retention".
6. Your rights
- Access and correction — profile settings, and a full data export you can request in the app.
- Erasure — the deletion flow: a 14-day grace period, then hard delete. Financial records are kept for the statutory period without your personal data: the ledger references an account id and never a name, email, phone or date of birth, so the account becomes a tombstone and the financial history stays intact.
- Withdraw consent — where a purpose runs on consent. Which ones do is counsel's to state.
- Grievance — see §8.
- Nominate someone to exercise your rights (DPDP Act 2023): procedure to be written.
7. Security
Encryption in transit everywhere; encryption at rest; column-level encryption for KYC data; private object storage served through short-lived signed links; access to personal data restricted by role and audited; bulk exports restricted to the highest platform role. Sensitive values — passwords, tokens, cookies, emails, phone numbers, dates of birth, message text, QR tokens — are never written to logs or analytics.
Breach notification: to the Data Protection Board and to affected users within the mandated window. The window and the notice text are counsel's; the operational procedure is docs/devops/runbooks/security-incident-runbook.md.
8. Grievance officer
To be appointed. Name, designation and contact address are required here before launch.
9. Children
Sotillion is 18+. We do not knowingly create accounts for anyone under 18; date of birth is checked on the server at every door and is treated as sensitive personal data.
10. Changes to this policy
This policy carries the same version string as the Terms. When it changes you are asked to accept the new version, and the version and the moment you accepted it are recorded.
11. Contact
To be supplied.