WeVite Privacy Policy

How WeVite Protects Organizers and Attendees in Our Event Ticketing Platform

Effective date: August 21, 2025 • Last updated: August 21, 2025

This Privacy Policy is designed for event ticketing and registration software users, ensuring both Organizers and Attendees understand how their data is protected. This Privacy Policy explains how WeVite Inc. ("WeVite," "we," "us," or "our") collects, uses, shares, and protects Personal Data when you use our websites, services, and applications (collectively, the "Services"). WeVite provides event ticketing privacy and community tools to Organizers and their Attendees. In some cases we act as a controller of Personal Data (e.g., account, billing, marketing). In other cases—primarily for Attendee data we process on behalf of Organizers—we act as a processor.



Our Roles

Controller: WeVite is the controller for Personal Data we collect directly (e.g., Organizer accounts, platform usage telemetry, marketing).
Processor: For Attendee data that Organizers import or collect through the Services (e.g., ticket purchases, check-ins), WeVite acts as a processor under our Data Processing Addendum (DPA). Organizers are responsible for providing appropriate notices and obtaining any required consents from Attendees.

Information We Collect

Categories of Personal Data depend on who you are and how you use the Services:

  • Account & Profile (Organizers): name, email, password, business details, phone, role, preferences.
  • Billing & Payments: billing address, tax IDs, payout details. Payment method data (e.g., card numbers) is collected and processed by Stripe; WeVite receives tokens and limited instrument metadata.
  • Event & Attendee Data (processor context): event details, tickets sold, attendee contact info, check-in scans, custom form responses.
  • Device & Usage: IP address, device identifiers, browser type, pages viewed, referrers, timestamps, crash/diagnostic logs.
  • Cookies/Similar Tech: identifiers used for session management, analytics, fraud prevention, and (with consent where required) marketing.
  • Support & Communications: messages sent to us (e.g., support tickets, chat), call/chat recordings where permitted by law.

Sensitive Personal Data: WeVite does not intend to collect sensitive categories. Organizers should avoid collecting such data unless lawful and necessary and should configure the Services accordingly.

How We Use Information (Purposes & Legal Bases)

We use Personal Data to:

  • Provide the Services (create/manage accounts, ticketing, check-in, payouts, support) — Contract performance (GDPR Art. 6(1)(b)).
  • Improve and secure the Services (diagnostics, analytics, testing, fraud/abuse prevention) — Legitimate interests (Art. 6(1)(f)).
  • Bill and collect fees; remit Organizer payouts — Contract; legal obligations (tax, accounting).
  • Communicate about service changes, security, and policy updates — Legitimate interests; legal obligations.
  • Marketing (emails, product updates, promotions) to Organizers — Consent or legitimate interests (with opt-out).
  • Comply with law and enforce terms — Legal obligations; legitimate interests.

Where we rely on consent (e.g., optional cookies/marketing in certain regions), you may withdraw it anytime through Cookie Preferences or unsubscribe links. See also our Terms of Service and Data Processing Addendum for additional information about our event software data protection practices.

How We Share Information (Subprocessors & Partners)

We share Personal Data with trusted service providers who act on our behalf (“Subprocessors”) under data protection terms, and with partners where necessary to deliver the Services. Key examples include:

  • Payments: Stripe (payment processing and payouts).
  • Infrastructure & Hosting: Cloud providers and content delivery networks.
  • Analytics & Product Tools: Google Tag Manager, analytics tools, error monitoring.
  • Sales/Support: CRM and support platforms (e.g., HubSpot).

We maintain an up-to-date list at /legal/subprocessors. We may disclose data to comply with law, to protect rights/safety, or in connection with a merger/acquisition. We do not sell Personal Data. In jurisdictions where "sharing" for cross-context behavioral advertising is defined, you may opt-out via Do Not Sell or Share My Personal Information.

Cookies & Tracking

We use cookies and similar technologies for authentication, security, analytics, and—where permitted—marketing. You can manage preferences in our Cookie Preferences center and through your browser settings. We honor consent choices in regions where required. For detailed information about the cookies we use, see our Cookie Policy.

Do Not Track: Because no common industry standard exists, we do not respond to DNT signals.

Data Retention

  • Account & Organizer data: retained while your account is active and for up to 24 months after inactivity or closure, unless we must keep it longer (e.g., tax, fraud prevention).
  • Transaction & payout records: retained for up to 7 years (tax/accounting).
  • Backups: typically retained 30–90 days on a rolling basis.
  • Aggregated/De-identified data: retained indefinitely for analytics and service improvement.

Security

We use administrative, technical, and physical safeguards appropriate to the nature of the data, including encryption in transit, access controls, and least-privilege practices. Our event software data protection measures are designed to protect how we protect organizer and attendee data across all touchpoints. No system is 100% secure. If we discover a breach affecting your Personal Data, we will notify you and regulators as required by law. Report security issues to support@wevite.io.

International Transfers

If you reside outside the United States, your data may be processed in the U.S. and other countries with different data protection laws. Where required, we use Standard Contractual Clauses (SCCs) or other lawful transfer mechanisms, supplemented by appropriate safeguards.

Your Privacy Rights

EEA/UK/Swiss residents (GDPR/UK GDPR) have rights to access, rectify, erase, restrict or object to processing, and data portability. Where we process based on consent, you may withdraw it at any time.

U.S. state residents (e.g., CA, CO, CT, UT, VA) may have rights to access, delete, correct, portability, limit use/disclosure of sensitive data, and opt-out of sale/sharing/targeted advertising. We do not sell Personal Data. You can exercise relevant rights here:

WeVite Inc.
Attn: Privacy
Support: support@wevite.io

We will verify your request and respond within the time required by law. Authorized agents may submit requests when permitted by applicable law.

Organizer & Attendee Notices

Organizers: You are responsible for the lawfulness of the Personal Data you collect from Attendees and for providing them with appropriate notices. Our DPA governs our processing on your behalf.

Attendees: We process your data primarily under instructions from your Organizer. Please contact the Organizer first for data rights requests regarding an event. We will support Organizer requests as required by our DPA and applicable law.

Children’s Privacy

The Services are not directed to children under 13, and we do not knowingly collect Personal Data from them without verifiable parental consent. Organizers who host youth events must ensure any collection complies with applicable laws (e.g., COPPA).

Changes to This Policy

We may update this Policy to reflect changes to our practices or legal requirements. If we make material changes, we will provide notice (e.g., by email or through the Services) and update the “Last updated” date. Your continued use of the Services after an update constitutes acceptance.

How to Contact Us

WeVite Inc.
Attn: Privacy
Support: support@wevite.io


CPRA Category Disclosures (California)

The table below summarizes our disclosures over the past 12 months. “Yes” indicates we collected the category for at least one business purpose.

Category Examples Collected Sold/Shared Business Purposes
Identifiers Name, email, IP, device IDs Yes No sale; “sharing” only for ads where applicable with opt-out Account, security, analytics
Customer Records Billing details, transaction history Yes No Billing, payouts, support
Commercial Information Purchases, event/ticket info Yes No Provide Services
Internet/Network Activity Usage, logs, diagnostics Yes Potential “sharing” for ads (opt-out available) Security, analytics, improve Services
Geolocation (coarse) IP-based region Yes No Fraud prevention, localization
Sensitive Data Gov IDs, precise location, health No (not intended) No