1. Two roles, one principle
Everlage processes personal data in two roles. For operator accounts (you and your team) we are the data controller. For guest data collected through your branded storefront, your organization is the controller and Everlage is the processor acting on your instructions. In both roles the principle is the same: data is collected for a purpose, not for resale.
2. What we collect
Operator data: name, work email, role, login and billing records. Guest data (on your behalf): registration details you request through your forms, ticket and order records, check-in timestamps and communication logs. We do not sell personal data, and we never market to your guests.
3. Why we process it
To run the service you bought: issuing tickets, validating QR codes at the door, sending reminders you configure, generating badges, producing your reports and preventing fraud and duplicate entry.
4. Where it lives
Data is stored on hardened cloud infrastructure with encryption in transit and at rest. Access inside Everlage is role-based and logged. Sub-processors (hosting, email delivery) are bound by data-processing agreements.
5. Your guests' rights
Guests can request access, correction or deletion of their personal data. Requests arriving to Everlage are routed to the operator who controls that data, and we provide the tooling to honor them within statutory windows (GDPR and equivalent regimes where applicable).
6. Retention
Operator account data is kept for the life of the account plus statutory retention for billing records. Guest data is retained per your configuration and deleted or anonymized on your instruction or account wind-down.
7. Contact
Privacy questions and data-subject requests: contact@everlage.com. We answer within one business day.