Privacy notice.
Effective 10 August 2026. This notice explains how ExpoCollect processes personal data when operating ExpoCollect. It is designed for India’s Information Technology framework and the staged implementation of the Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025. We will update practices as further provisions become applicable.
1. Who decides how data is used
For account, billing, security, website and support data, ExpoCollect determines the purposes described below. For visitor and exhibition lead data, the exhibitor ordinarily determines why the data is collected and how it will be followed up; ExpoCollect processes that data to provide the contracted service. Visitors should also review the notice shown by the relevant exhibitor.
2. Data we process
We may process account names, business contact details, email OTP and session records, tenant and team roles, event and booth information, visitor lead fields, interests, notes, consent/source metadata, approved attachments, device/app information, security logs, payment references and subscription status, contact-form messages, and operational audit records. We do not ask for or store card PINs, CVVs, banking passwords or email OTP values in readable form.
3. Mobile OCR and card images
Business-card text recognition runs on the mobile device. The user reviews and can correct extracted fields before they are submitted. ExpoCollect’s server does not run Tesseract or generative AI for card extraction. Card images may be uploaded privately when the authorised user chooses to retain them with the lead. Lead data is not used to train generative-AI models.
4. Purposes and lawful use
We process data to authenticate users; provide capture, sync, reporting, export and billing functions; answer contact requests; prevent abuse and cross-tenant access; maintain audit trails; recover from failures; comply with law; and establish or defend legal claims. Exhibitors are responsible for having an appropriate lawful basis and giving the visitor a clear notice before collection and follow-up.
5. Service providers and disclosures
Data may be processed by vetted providers used for hosting, email delivery, payment processing, app distribution, storage, backup, diagnostics or professional support, subject to appropriate contracts and access controls. Razorpay receives payment information under its own privacy terms. We may disclose data when required by law, to protect rights and security, or during a lawful business reorganisation with appropriate safeguards. We do not sell visitor lead data.
6. Security
Controls include tenant-scoped authorisation, private attachment storage, encryption in transit, hashed OTPs and API tokens, session revocation, rate limits, audit records, bounded backups and production access controls. No system is risk-free. Customers must secure their email accounts, devices and authorised-user list and promptly report suspected misuse.
7. Retention and deletion
Customer lead data follows the exhibitor’s configured retention and deletion workflow. Expired operational records are pruned in bounded scheduled batches. Financial, fraud-prevention, security, dispute and backup records may be retained longer where reasonably necessary or legally required. Backups age out on their normal rotation and are not restored solely to recover a deleted individual record.
8. Your choices and rights
Subject to applicable law and verification, a person may request information about processing, correction, completion, erasure, grievance redressal, or withdrawal of consent where consent applies. If an exhibitor collected the lead, contact that exhibitor first; we will assist verified exhibitor requests. Requests may be limited where retention is required by law, needed for security or legal claims, or another lawful exception applies.
9. Children and international access
The service is for business exhibitions and authorised adult users, and is not designed to knowingly collect children’s data. Customers must not use it to collect children’s data without satisfying applicable requirements. Service providers or authorised users may access data from other locations, subject to contractual, security and legal safeguards and any transfer restrictions that apply.
10. Cookies and logs
The website uses necessary cookies and comparable storage for authentication, security, preferences and form protection. Where the platform owner enables optional analytics, the consent banner identifies that choice before Google Analytics, Google Tag Manager or Meta Pixel is loaded. Your accept/decline preference is stored locally in your browser and can be changed through “Cookie preferences” in the footer. We respect browser Do Not Track when that option is enabled. Advertising personalisation and Google signals remain disabled unless the published configuration and consent basis explicitly allow them. We do not require advertising cookies to operate the service. Server logs record limited technical information needed for security and reliability and are retained for bounded periods.
11. Grievance and privacy contact
Submit a verified request through Contact Us → Privacy or data request. We aim to acknowledge and handle grievances within 30 days, subject to identity verification and applicable law.
ExpoCollect