Effective Date: 1 July 2026
MEHMAAN ("we", "us", "our") is committed to protecting the privacy of all individuals who use our Platform. This Privacy Policy explains what personal data we collect, how we use it, with whom we share it, and the rights available to you under the Digital Personal Data Protection Act, 2023 (DPDPA) and other applicable Indian law.
By using the Platform, you acknowledge that you have read and understood this Policy.
When you register as an organiser or hall partner, we collect:
Full name, email address, and mobile number
Business or hall name (for hall partners)
Payment information (processed by our payment gateway; we do not store full card details)
Event details such as name, venue, date, function names, and configuration settings
Organisers upload guest lists containing:
Guest name and mobile phone number
Access zone assignments and companion allowance
Meal preference (optional)
VIP flag (optional)
This data is uploaded by the organiser. The organiser is responsible for ensuring appropriate consent from each guest for sharing this information with MEHMAAN for event access purposes.
Our gate scanner terminals automatically record:
Date, time, and gate of each entry attempt
Scan result (approved or denied, with reason code)
Terminal ID and operator
Number of companions added
Guests may voluntarily upload a selfie when responding to their invitation. This is used only for optional face-recognition entry at the gate.
Stored securely in Supabase cloud storage
Used only for matching at event entry
No profiling or secondary use
Optional feature (never mandatory)
When using the Platform, we automatically collect:
Browser type, operating system, device type
IP address and approximate location
Pages visited, timestamps, session duration
Crash reports and error logs
We use data for the following purposes:
Purpose
Data Used
Event access control
Guest name, phone, QR token, zones
Invitations (WhatsApp/SMS)
Name, phone, QR token
Payment processing
Organiser details, payment info
OTP verification at gate
Guest phone number, OTP
Face recognition entry
Guest selfie
Event monitoring
Gate logs, check-in counts
Platform improvement
Aggregated anonymised data
Legal compliance & fraud prevention
Account data, logs, IP address
We do not use personal data for advertising or profiling.
We process data under:
Contract performance – service delivery
Consent – e.g. optional selfie upload (withdrawable anytime)
Legitimate interests – security, fraud prevention, improvement
Legal obligation – compliance with Indian law
We do not sell or trade personal data. We share it only when necessary:
Service providers: Supabase, payment gateways, Twilio, Meta WhatsApp API
Event organisers: access logs for managing entry
Hall partners: limited operational event data
Legal authorities: when required by law
Business transfers: in case of merger/acquisition
All providers are contractually bound to protect data.
We retain data only as long as necessary:
Guest check-in logs: 90 days after event
OTP data: 24 hours
Selfies: 90 days after event or on request
Organiser accounts: 3 years after deactivation
Payment records: 7 years (tax compliance)
After retention, data is securely deleted.
We use industry-standard safeguards:
TLS 1.2+ encryption in transit
AES-256 encryption at rest (Supabase on AWS India)
QR tokens are single-use and cryptographically secure
Role-based access control with MFA
Minimal offline data storage on gate devices
No system is fully secure, but we actively monitor and mitigate risks.
You have the right to:
Access your personal data
Correct inaccurate data
Request deletion (subject to legal limits)
Withdraw consent (e.g. selfie usage)
Raise grievances
Requests can be sent to: legal@mehmaan.in
We respond within 30 days and may verify identity.
We use:
Strictly necessary cookies (login/security)
Analytics cookies (aggregated usage insights)
We do not use advertising or third-party tracking cookies.
The Platform is not intended for individuals under 18.
We do not knowingly collect data from minors.
If found, it will be deleted promptly.
We may link to third-party services (e.g., Google Maps).
We are not responsible for their privacy practices.
We may update this Policy periodically.
Material changes will be notified at least 14 days in advance via email.
MEHMAAN – Privacy & Grievance Officer
Email: mehmaanmfi@gmail.com
Website: https://themehmaan.com/
We aim to respond to all privacy concerns within 30 days.