Privacy notice
This notice describes how the RSVP Engine platform (operated by exp-er) processes guest and staff information for events hosted for clients such as Warehouse47. It is written for transparency under typical GDPR / India DPDP expectations. It is not legal advice — event hosts remain responsible for how they use guest lists.
Who is responsible
- Platform operator (processor / platform controller for platform systems): exp-er — contact [email protected]
- Event host (controller for guest-list use at the event): the tenant organising the event (e.g. Warehouse47 for AX-PUNE-FW26)
What we collect
Depending on what you submit or how you sign in, we may process:
- Name and optional companion (+1) name
- Email, phone, WhatsApp, Instagram, and/or LinkedIn
- Profession / notes you choose to share
- Consent timestamp and RSVP / check-in activity
- If you use Google sign-in: Google account email, name, and subject ID (for session and prefill only)
- Technical data needed to run the service (e.g. session cookies, basic request logs on Cloudflare)
Why we collect it
- Create and manage your RSVP / guest-list place
- Send confirmation (email) with QR / pass when an email is available
- Door check-in and event-day operations for authorised staff
- Basic event analytics (counts, check-in rates) for the host
- Respond to privacy / deletion requests
Legal bases we rely on in practice: consent (RSVP form checkbox) and, for staff tooling, legitimate interests / contract to run the event securely.
Where data is stored
Data is stored on Cloudflare (Workers, D1, KV, Pages). Subprocessors may also include Google (optional OAuth) and our transactional email provider (Resend and/or Cloudflare Email Sending).
Retention
Guest RSVP and check-in records are kept for the life of the event operations window, then targeted for deletion or anonymisation within 90 days after the event ends, unless the host asks us to retain them longer for a documented reason, or a deletion request is processed sooner.
Your choices
- You can decline the form — we will not create an RSVP without consent.
- You may request access, correction, or deletion of your guest record.
- Staff Google sessions use short-lived HttpOnly cookies; you can sign out from ops.
Cookies / local storage
Essential cookies: signed session cookies for Google-assisted RSVP prefill and ops authentication. Optional on ops devices only: an “Event cache” toggle may store a guest list snapshot in the browser (IndexedDB) for offline door use — staff-controlled, not used on the public RSVP form.
Request deletion
Submit the form below. We log a request for the host/platform team to process (typically remove matching RSVP and related check-in rows). You can also email [email protected].
Last updated: 8 August 2026 · Event hosts may publish an additional notice for brand-specific terms.