Effective date: 7 July 2026 · Prepared with reference to the Digital Personal Data Protection Act, 2023 (“DPDP Act”).
1. Who We Are
Baatasari is operated by Simha Karthik Reddy, a sole proprietor trading as BAATASARI (GSTIN 37HRGPR8105H1ZD), with its principal place of business at 28/1A-4-145/41, Sathyamjee Layout, Navalak Gardens, Nellore, Andhra Pradesh – 524002. For the purposes of the DPDP Act, Baatasari is the data fiduciary for the personal data described in this policy.
2. Scope of this Policy
This policy covers personal data processed when you browse the Platform, create an account, book tickets (with or without an account), register as an Organizer or Talent, contact support, or otherwise interact with Baatasari. It does not cover what an Organizer does with your data outside the Platform once an event is fulfilled — Organizers are independently responsible for their own compliance, and we contractually restrict their use of your booking data to event fulfilment (see Section 6).
3. Data We Collect
Account data: name, email address, password (stored as a secure hash), and — if you sign in with Google — the name, email, and profile identifiers Google shares with us.
Profile & onboarding data: phone number, date of birth, gender, location (area/city/state/pincode), profession, interests and preferences, and any avatar image you upload.
Booking data: events booked, ticket quantity and tier, attendee name, email and phone provided at checkout, order and invoice records, and check-in status.
Payment data: order amount, payment status, and gateway transaction references. We do not collect or store your card, UPI, or bank credentials — payments are handled by our payment gateway (Razorpay).
Organizer verification data: legal/business name, PAN, GSTIN, bank account details (account number, IFSC), contact details, address, and the KYC documents and signed agreement you upload.
Talent data: the talent profile details you submit and the registration payment record.
Support & grievance data: messages you send us, including the phone number and issue description submitted via the contact form.
Technical data: authentication cookies, device/browser information, and event-page view counts (de-duplicated per visitor per day) used for organizer analytics.
4. How We Use Your Data
To create and secure your account and authenticate your sessions.
To process bookings and payments, issue tickets and tax invoices, operate venue check-in, and process refunds where due.
To verify Organizers (KYC), enable payouts, and meet our tax obligations.
To send transactional communications — booking confirmations, tickets, payment/refund updates, verification emails, and account or security notices.
To personalise event discovery based on your stated preferences and location.
To produce aggregate analytics for Organizers (for example, daily views vs purchases of their event page) — reported in aggregate, not as your individual browsing history.
To respond to support requests and grievances, and to keep records of them.
To detect and prevent fraud, abuse, and violations of our Terms.
To comply with law, including tax, accounting, and record-keeping obligations.
5. Consent & Legal Basis
We process your personal data on the basis of the consent you give when you sign up (recorded with a timestamp and the version of the terms you accepted) and when you book, and for certain legitimate uses permitted by the DPDP Act (such as compliance with law). You may withdraw consent at any time by deleting your account (Section 10). Withdrawal does not affect processing already carried out, or data we are legally required to retain.
6. Who We Share Data With
We do not sell your personal data. We share it only as follows:
Event Organizers: when you book an event, the booking details needed to fulfil it (attendee name, contact details, ticket details, check-in status) are shared with that event’s Organizer. Organizers may use this data only to fulfil and manage that event.
Payment gateway (Razorpay): to process payments and refunds. Your payment instrument details are provided by you directly to the gateway.
Infrastructure providers: our cloud hosting, storage (for uploaded images and documents), email delivery, and database/caching providers, who process data on our behalf under their service agreements.
Google: if you choose “Sign in with Google”, authentication is handled by Google under its own privacy policy.
Authorities: where disclosure is required by law, legal process, or to protect the rights and safety of users or the public.
7. Cookies & Analytics
Essential cookies: we use secure, httpOnly cookies to keep you signed in. These are necessary for the Platform to function and are not used for advertising.
Usage analytics: we measure page performance and aggregate usage (via our hosting provider’s analytics) and de-duplicated event-page view counts. We do not run third-party advertising trackers.
8. Data Retention
Account and profile data: for as long as your account exists.
Financial records (orders, invoices, refunds, payout and tax records): retained for the statutory retention period under Indian tax and accounting law, even after account deletion — anonymised where possible.
Organizer KYC records: retained while the Organizer account is active and thereafter as required by law.
Support and grievance records: retained as required to demonstrate compliance.
9. Security
We apply reasonable security safeguards appropriate to the data we hold: passwords are stored hashed, authentication uses short-lived signed tokens in httpOnly cookies, tickets carry cryptographically signed QR codes, access to production systems is restricted, and traffic is encrypted in transit (HTTPS). No system is perfectly secure; if we become aware of a personal data breach we will notify affected users and the Data Protection Board as required by the DPDP Act.
10. Your Rights & How to Exercise Them
Access & correction: view and edit your details any time under Profile.
Erasure / withdrawal of consent: delete your account via Profile → Security → Delete account (confirmed by OTP). Your account is removed after a short grace window; records we must keep by law are retained and anonymised where possible.
Grievance: raise any data-protection concern with our Grievance Officer (Section 14). We acknowledge within 48 hours and resolve within the timelines required by law.
Nomination: as provided by the DPDP Act, you may nominate a person to exercise your rights in the event of death or incapacity — contact the Grievance Officer to record a nomination.
11. Guest Bookings
If you book without an account, we collect the name, email, and phone number you provide at checkout to issue and deliver your ticket and invoice. Since there is no account to delete, you can request access to or erasure of your guest data by emailing grievance@baatasari.com (records we must retain by law are excluded).
12. Children
The Platform is intended for users aged 18 and above. We do not knowingly collect personal data from minors, and account creation requires confirming you meet the age requirement. If you believe a minor has provided us data, contact the Grievance Officer and we will delete it.
13. Where Your Data is Stored
Our primary infrastructure and storage are hosted with reputable cloud providers, with media and document storage located in India (AWS Asia Pacific — Mumbai). Where any provider processes data outside India, we ensure it is permitted under applicable law.
14. Grievance Officer
Grievance Officer: Simha Karthik Reddy · grievance@baatasari.com. Full contact details, acknowledgement (48 hours) and resolution (30 days) commitments are on the Grievance Redressal page.
15. Changes to this Policy
We may update this policy from time to time; the effective date above reflects the latest version. Material changes will be notified on the Platform.