1. Who we are and scope
ENCOREATS PRIVATE LIMITED acts as the Data Fiduciary for personal data for which it determines the purpose and means of processing. This Policy applies to Encoreats websites, apps, user and partner accounts, event discovery, bookings, reservations, private-party requests, memberships, payments, QR access, customer support, verification, fraud prevention, marketing, and related operations that link to it.
2. Phased DPDP implementation
The Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025 have a phased commencement. Encoreats is adopting this Policy as a forward-looking baseline and will update operational timelines, notices, and rights workflows as the remaining provisions become effective. Nothing in this Policy reduces rights already available under other applicable law.
3. Personal data we may process
- Account data: name, mobile number, email, password-related authentication records, role, age or date-of-birth indicators.
- User profile and preference data: categories, budgets, preferred areas, accessibility preferences, saved events, and communications.
- Partner and verification data: professional profile, PAN, GST information, business constitution, bank or payout details, licences, addresses, identity or authority documents, portfolio and availability.
- Transaction data: booking, reservation, order, subscription, payment status, masked payment details, refunds, wallet or ledger entries, invoices, disputes, and payouts.
- Event and access data: tickets, QR codes, check-in records, event participation, capacity and safety records.
- Device and usage data: IP address, timestamps, browser, app version, device identifiers, log data, diagnostics, cookies, approximate location and, only where requested and permitted, precise location.
- Content and support data: messages, uploaded media, reviews, reports, complaint evidence, call or correspondence records.
4. Sources
We obtain data directly from you; from artists, venues, organisers or other transaction parties; from payment, identity, cloud, analytics, communication, fraud-prevention and support providers; from public or authorised sources used for verification; and automatically through your device when you use the Services.
5. Purposes and lawful processing
We process personal data for lawful purposes, including to create and secure accounts; provide requested marketplace, booking, ticketing, reservation, payment, payout and support services; verify partners; prevent fraud and abuse; personalise discovery; communicate transaction and safety notices; maintain records; comply with legal obligations; resolve disputes; and improve reliability. Where consent is the basis, the request will be clear, specific, informed, unambiguous, limited to necessary data, and accompanied or preceded by a notice describing the data, purpose, rights and complaint route. Certain processing may be carried out for legitimate uses expressly recognised by applicable law.
6. Consent and withdrawal
You may withdraw consent through the relevant account control or by contacting the privacy team. Withdrawal will be as easy as the method used to give consent where reasonably practicable. It does not affect processing already carried out lawfully and may not prevent retention or processing required by law, fraud prevention, dispute resolution, or completion of a transaction already requested.
7. Sharing and processors
We may share necessary data with the artist, venue, organiser, user, or partner involved in a transaction; payment and payout providers; cloud hosting, storage, communications, analytics, customer-support, verification, security and fraud vendors; professional advisers; insurers; acquirers in a corporate transaction; and authorities where required by law. Data Processors act under contractual instructions and are expected to use appropriate safeguards.
8. Payments
Full card credentials, UPI PINs, banking passwords, and one-time passwords must never be shared with Encoreats support. Payment credentials are normally collected and processed by the payment provider. Encoreats may receive provider order identifiers, transaction references, status, amount, masked instrument details, risk signals, settlement and refund data.
9. Retention and erasure
We retain personal data only for the period required for the specified purpose, legal compliance, taxation and accounting, fraud prevention, cybersecurity, contractual claims, chargebacks, dispute resolution, or enforcement. When the purpose is no longer served and no lawful retention requirement remains, data will be erased or anonymised and processors will be instructed accordingly. Transaction data and associated processing logs may be retained for minimum periods prescribed by applicable DPDP rules and other laws.
10. Security and incidents
We use reasonable technical and organisational safeguards, including role-based access, encryption in transit, secure authentication, logging, backups, monitoring, vendor controls, incident response, and least-privilege practices. No online service is absolutely secure. Where a personal data breach requires notification, we will notify affected individuals and the competent authority in the form and manner prescribed by applicable law.
11. Children
Under the DPDP framework, a child is a person below eighteen years. Before processing a child’s personal data where required, Encoreats will use reasonable measures to obtain verifiable parental or lawful-guardian consent. We do not knowingly undertake tracking, behavioural monitoring, or targeted advertising directed at children. Event age rules may separately restrict access.
12. Your rights and nomination
Subject to applicable law and commencement provisions, you may request: a summary of personal data and processing; information about sharing; correction, completion or updating; erasure where retention is not required; withdrawal of consent; grievance redressal; and nomination of another individual to exercise rights in the event of death or incapacity. We may verify identity before acting on a request.
13. Marketing and communications
Essential service, security, booking and legal messages may be sent regardless of marketing preference. Promotional messages will be sent only where permitted and will include a practical opt-out. Opting out of marketing does not cancel transactional messages.
14. International processing
Some processors may operate outside India. Cross-border processing will be subject to the DPDP Act, rules, notified restrictions, contractual safeguards, and any sector-specific localisation requirements. CERT-In log-retention and other Indian-jurisdiction obligations will be followed where applicable.
15. Contact and grievance
Privacy contact: privacy@encoreats.info. Data-protection contact person: AYUSH CHAURASIYA,CEO. You should first use our privacy grievance process. Once applicable, unresolved complaints may be taken to the Data Protection Board of India in the manner prescribed.
Launch and legal-review notice
This is a structured operational draft for Encoreats and not a substitute for advice from a qualified Indian advocate, chartered accountant, data-protection professional, or other specialist. Before publication, replace all bracketed fields, confirm that every email inbox and response workflow is operational, and ensure the wording matches the actual product, payment, refund, data-retention, verification, event, and partner processes.
