FYEO Privacy Notice

Version 1.1 | Effective date [PUBLICATION DATE]

FYEO is a product of Nom Online Services (OPC) Pvt. Ltd. ("NOM", "we", "us"). This notice explains how NOM handles personal data when you browse FYEO, join its waitlist, become a member, book entry, use invitations or social features, contact us, or work with us as a venue representative, promoter or door operator. Section 8 also explains music-identification devices at participating venues, including for visitors without a FYEO account.

This notice covers FYEO, not every future NOM product. A new NOM product requires its own notice or a clearly explained extension with any necessary fresh consent. Venue operations such as their CCTV, bar billing and independent marketing are described in their own notices. Our venue data-sharing agreement limits what venues may do with FYEO information; it is not a substitute for your privacy rights.

Responsible company: Nom Online Services (OPC) Pvt. Ltd. Registered office: [REGISTERED ADDRESS]. Privacy and grievance contact: [NAME AND DESIGNATION], [PRIVACY EMAIL], [PHONE], [POSTAL ADDRESS]. Requests and privacy choices: [PRIVACY REQUEST URL].

1 What information we handle and why

1.1 Accounts and eligibility

We handle your phone number, verification and account identifiers, display name, username, date of birth, chosen city and account status to authenticate you, operate membership, communicate about your account and apply age eligibility. Your date of birth is used to assess event eligibility; identity and alcohol checks remain the Venue's responsibility. An optional profile photo is used where you choose to display your profile. We may request limited verification information for recovery or a specific disputed identity; routine collection of a full Aadhaar copy is not required.

1.2 Bookings payments and entry

We handle event and Venue selections, ticket categories, party size and selected composition, amounts and discounts, booking references, payment-provider references and status, refunds, pass identifiers, entry time, admission count and relevant door decisions. This enables booking, admission, reconciliation, support and detection of duplicate use. Party composition can indicate personal characteristics; we use it only for the chosen booking and explained analysis, not to infer sexual orientation or create sensitive advertising profiles.

Payment details you enter in the payment provider's interface are handled by that provider. NOM receives transaction information needed for confirmation, refunds and reconciliation, which can include payment method and masked instrument information supplied by the provider. Razorpay Route also processes payment, transfer, reversal and settlement references and the necessary Venue Linked Account information. Venues receive the transaction information needed for their supply and reconciliation, not access to your full payment credentials. Our booking database does not need your full card number, CVV, banking password or UPI PIN. Do not send these in support messages.

1.3 Guest lists and information supplied by others

A person arranging your party, an authorised promoter or a Venue can provide your name, contact details, party size and guest-list request. We use these to administer the request, explain its status, validate entry and attribute the booking to the relevant list. The submitting person must be entitled to provide the data and share this notice with you. You can contact us even if you did not create an account. Their submission does not subscribe you to optional marketing.

1.4 Invitations waitlists and rewards

We handle invite and referral codes, who referred whom, redemption and membership status, waitlist position and qualifying milestones to operate access and prevent fabricated rewards. An inviter's name may be visible to someone opening their link. An inviter may receive confirmation that an invitation was used or a qualifying milestone was reached, but that does not entitle them to your phone number, financial details or detailed attendance history. We explain any additional disclosure before you participate.

1.5 Friends and taste features

Where enabled with your choice, friend connections, saved events, RSVPs and booking or attendance records help display friends going and your music or venue preferences. Accepted friends can see the name and chosen photo associated with a visible event attendance indication. Friends-of-friends information is presented as an aggregate count rather than a named list. A small aggregate can still reveal information, so visibility controls and minimum display thresholds apply.

An invitation may offer to connect you to its sender. We explain this and obtain your choice before making the connection; using an invite must not silently authorise all future social disclosure. Optional attendance sharing is separate from the information needed for the Venue to admit you. You can withdraw social-sharing permission through [PRIVACY REQUEST URL / VERIFIED ACCOUNT CONTROL]. Existing screenshots or copies made by other users cannot always be recalled, but we stop further sharing under our control.

1.6 Device service and analytics information

Our systems and service providers process IP addresses, device or session identifiers, app version, operating system, access times, errors and security logs to deliver and secure FYEO. Locally stored session and app-state information keeps you signed in and preserves your progress.

Where you opt into optional product analytics, we collect interactions such as event views, invitation actions, checkout steps, payment status and feature use. Device/session and account identifiers may link activity before and after sign-in. These are identifiable or pseudonymous records, not automatically anonymous data. We use them to understand and improve FYEO. Declining optional analytics does not block booking or essential security records. We do not use optional analytics consent as permission for unrelated advertising or another NOM product.

1.7 Communications and support

We handle your questions, complaint references, correspondence and proportionate supporting evidence to respond, resolve disputes and comply with legal obligations. Please redact unrelated identity, payment or health information. Sensitive information voluntarily supplied for an exceptional claim is restricted to that claim and applicable legal needs. Promotional messages require an appropriate separate choice; operational confirmations and safety or cancellation notices are handled independently.

2 Phone permissions and local storage

2.1 Contacts are optional. With device permission, FYEO reads names and phone numbers on your device so you can choose whom to invite. Contact searching stays on the device; FYEO does not upload your address book or contact-search text. If you choose a recipient and open your SMS or messaging app, that app receives the information needed for the message you choose to send and applies its own terms. We may record that a sharing action occurred, not the address book contents. You can revoke contact permission in device settings and use a copied invite link instead.

2.2 Photo-library access is used to choose an optional profile image. The selected image is uploaded when you submit it; other photos are not uploaded through this feature. The uploaded photo may appear with your profile and is currently delivered through a public asset URL, so anyone who obtains that URL may be able to view it. Avoid uploading confidential material. Removing it triggers deletion and cache handling subject to section 6.

2.3 Push permission enables notifications through Expo and the operating system's notification service. We store a push token and associate it with the current account. You can turn off push in device settings. Notifications can reveal a venue or event on your lock screen; your phone's preview settings control that display. Promotional messaging choices are separate from device permission.

2.4 FYEO's consumer app does not use your microphone for the venue music-identification service and does not require continuous GPS tracking or an uploaded address book to book admission. City information and IP-derived approximate location are different from precise GPS. If we later introduce a feature that needs additional access, we explain its purpose and ask separately before using it.

2.5 Essential cookies or local storage support authentication, security and app state. Optional analytics storage follows your analytics choice. Clearing local storage can sign you out, but does not delete your server account. We do not describe a website advertising tracker as essential merely because it benefits our business.

2.6 Playing a music preview or loading remotely hosted artwork can send the content request, IP address and technical connection information to the relevant delivery provider. Opening an Apple Music or Spotify link sends you to that service, which handles your activity under its own notice. We do not include your booking, guest list or FYEO social connections in an outbound music link. Optional FYEO listening analytics follow the choice described in section 1.6; essential content delivery is distinct from those analytics. The provider register identifies the actual playback and artwork sources.

3 Permission and lawful use

3.1 We give an appropriate notice at collection and obtain specific, informed consent where required. We may process information for an applicable lawful use, legal obligation, permitted emergency response, or the establishment or defence of legal claims where the law allows it. We do not rely on an unrestricted, imported "legitimate interests" exemption for all Indian processing.

3.2 Core account and booking information is necessary for the service you request. If you do not provide it, we may be unable to authenticate or fulfil that service. A photo, contact access, optional social sharing, promotional messages and optional analytics are separate choices. Withdrawing those choices does not cancel paid entitlements. We explain any service consequence before acting on a withdrawal of essential processing consent.

3.3 We do not sell personal data or permit venues to extract our guest data for unrestricted marketing. We do not use your private booking, contact or support information to train a general-purpose AI model under this notice. A materially different future use requires a fresh explanation and the applicable permission.

4 Who receives information

4.1 The Venue and its authorised door staff receive the event-specific information needed to manage your booking, assess entry and resolve a dispute: guest name, necessary contact information, category, party size, booking/pass references, status, admission count and relevant eligibility or issue information. They do not need your banking credentials, full social graph, unrelated venue history or full date of birth merely to scan a pass.

4.2 An authorised promoter may receive information for their own allocated list and attribution, limited to the permission and operational need. They cannot access every attendee or every venue through this role. We contractually prohibit personal use, onward sale, unapproved exports and marketing without a lawful separate basis. Venues are responsible for their own independent operations and notices; NOM remains responsible for its disclosures and service providers.

4.3 Our service providers support hosting, databases, authentication, file storage, payments, communications, analytics and security. The FYEO integrations include Supabase for backend services; Razorpay, including Razorpay Route, for payments, Linked Account allocations, refunds and settlement; Expo and the relevant Apple or Google notification services; Mixpanel for optional product analytics; and Apple/Shazam services for music identification and content. The OTP delivery provider and hosting details are listed at [SERVICE PROVIDER REGISTER URL] after configuration verification. We require appropriate confidentiality, purpose limits and security terms. Some payment and operating-system providers also act for their own regulatory or platform purposes under their notices.

4.4 We may disclose necessary information to professional advisers, auditors, insurers, courts, regulators or law enforcement where lawful and proportionate. We check the legal basis and scope rather than giving unrestricted database access. In an acquisition or restructuring, limited due-diligence access is protected, and any transfer of service records must preserve applicable privacy obligations and require notice or consent where necessary.

5 Processing locations and safeguards

Providers may process information in India and other countries depending on the service and configured region. We do not promise that all FYEO data stays in India. Our provider register states verified locations and material transfers. We apply the contractual and other safeguards required by applicable law, including restrictions on sensitive data and government-notified transfer limitations. Payment data and required security-log copies follow their applicable location requirements.

We use proportionate technical and organisational safeguards, including controlled access, protection of credentials, transport encryption, monitoring and limited staff access. No service can promise absolute security. We investigate incidents, take corrective action and notify affected people and authorities within applicable requirements. This notice is not a representation that NOM holds a particular certification.

6 Retention and deletion

6.1 We retain data only for its stated purpose, an applicable legal requirement or a documented dispute or security need. Account deletion stops ordinary profile use; it is not a promise to erase required invoices or pending refund records. Removing a user identifier from a payment record does not necessarily make the remaining record anonymous.

6.2 Our retention limits are: active account data for the life of the account; profile deletion from active service within 30 days of a verified deletion request unless a specific exception applies; optional identifiable analytics for up to 12 months; routine support cases for up to 24 months after closure; guest-list operational access until 30 days after the event; and restricted booking, payment, refund and commercial records for up to eight financial years where needed for accounting, tax, audit or claims. Shorter necessary periods apply to unnecessary fields. We do not keep every profile field for eight years simply because an invoice is retained.

6.3 Security logs are retained for at least the period applicable law requires, including a rolling 180-day period where the CERT-In directions apply. When the relevant DPDP retention provisions become applicable, records within their scope are retained for the prescribed minimum period, including the applicable one-year minimum, with restricted use. Intermediary-specific preservation duties may also apply to particular records. A legal hold is documented and released when no longer needed.

6.4 Backup copies are isolated from ordinary use and expire on a documented rotation, ordinarily within 90 days unless a required retention or incident hold applies. If a backup is restored, deletion and withdrawal instructions are re-applied. Public images, caches, local analytics queues and provider-held copies are included in deletion handling. We may retain a minimal suppression record to honour an opt-out and prevent accidental re-enrolment.

7 Your choices requests and complaints

You can ask to access information about our processing, correct inaccurate data, delete data no longer required, withdraw consent, manage marketing and social choices, complain, and exercise any additional right available under applicable law, including nomination when applicable. Contact [PRIVACY EMAIL] or [PRIVACY REQUEST URL]. You need not provide a full identity document for every request; we use verification proportionate to the risk of disclosing someone else's information.

We acknowledge privacy complaints within 48 hours and normally resolve requests within 30 calendar days, subject to any shorter binding period. If a lawful exception prevents full deletion or disclosure, we explain the category, reason and available review rather than simply refusing. Staff accounts with audit responsibilities can request removal of unnecessary personal details even when essential action records must remain.

We provide consent withdrawal with ease comparable to giving it. Contact permission can be withdrawn in device settings; other choices are available through the privacy controls or request channel identified above. You can escalate to our Grievance Officer, and to the competent authority or court under the law in force. Once applicable and operational for your complaint, the Data Protection Board route is available subject to statutory prerequisites; our grievance process does not waive other remedies. We provide legally required notices and language options, including the applicable Eighth Schedule language choice when required.

8 Venue music identification

At participating venues, a dedicated FYEO handset periodically captures short ambient audio samples in volatile device memory to identify music. It converts a sample into an acoustic signature and sends that signature to Apple/Shazam for matching. The original audio is not sent to NOM or Apple through this matching flow and is not saved as a recording by the FYEO Listener application. This still involves microphone capture; we do not describe the device as never listening.

NOM receives matched track information, such as title, artist and identifiers, associated venue and timestamps, and device health information such as battery and connectivity. Acoustic signatures are not reversible into the original audio. The service is for identifying music, not identifying speakers, transcribing conversations or tracking individual guests. It does not use a customer's phone microphone or link an ambient sample to an attendee's account.

The Venue must display a clear notice before the monitored area and place the handset away from private or sensitive spaces. Ask the Venue or [PRIVACY CONTACT] about the device or a concern. A Venue's CCTV, photographers or separate audio recordings are different systems and require their own disclosures and lawful basis. NOM's permitted music-identification activity does not authorise those uses.

9 Children and representatives

FYEO is intended for adults aged 18 or over. We do not knowingly offer membership to children. If we learn that a child has supplied information, we restrict the account and handle deletion or legally required retention with appropriate verification. Age-screening must occur before unnecessary child information is collected; an "18+" label alone is not our entire control.

For venue owners, employees, promoters and door operators, NOM also handles business contact details, role and venue association, login and device identifiers, access approvals, actions and audit logs, and necessary bank, tax and authority information for the contracting business. We use these for onboarding, access, payments, support and accountability. We may share role-relevant activity with the employing Venue and authorised administrators. Detailed partner information is in the Venue Data Sharing Schedule's partner notice. A Venue must separately explain its employment-related monitoring.

10 Changes

We publish a dated version and give appropriate notice of material changes. A new notice is not retroactive consent. Material new purposes, new sharing or a change requiring consent are presented for the required choice before the new processing starts. Contact the privacy team for a copy of the notice that applied to an earlier transaction.