Privacy policy
This policy explains what personal data BagEvent collects, why we collect it, and the rights you have over it. It covers both event organizers who hold a BagEvent account and attendees who register for an event run on the platform.
Who is responsible for your data
For organizer account data, the controller is BAGEVENT PTE. LTD. (UEN 202600799E), a company incorporated in Singapore and registered at 68 Circular Road, #02-01, Singapore 049422.
For attendee data collected through an event's registration form, the event organizer is the controller and BagEvent acts as processor on their instructions. A Data Processing Agreement is available to every organizer. The same applies to what attendees do in the app at an event — their networking profile, connections, meetings, questions, and survey answers — which belongs to the organizer's event.
One exception: when you report someone or something in the app, BagEvent also reviews the report, to keep people safe on the platform. For that review BagEvent is a controller in its own right, relying on its legitimate interest in preventing harassment and abuse.
Data protection contact: [email protected].
What we collect
Organizer account data. Name, work email, organization name, and billing details. Payment card details are handled by our payment provider and never stored by BagEvent.
Attendee data. Whatever the organizer's registration form asks for. This typically includes name and email, and may include job title, dietary requirements, or other fields the organizer configures. Organizers decide which fields are required.
Networking at an event. If the organizer turns on networking, the app shows attendees and exhibitors to each other. You choose, in the app under Me → Privacy & blocked people, what exhibitors can see about you, in three levels: your name, company and job title; your email and phone; and what you are at the event for. You can change those choices, or stop sharing everything at that event, at any time. When an exhibitor scans your badge or you scan their stand code, they receive the levels you have agreed to share; if you allow it, they can also export them. What an exhibitor has already exported stays with that exhibitor, who then handles it under their own privacy policy.
What you send through the app. Connection requests and the note you add to them, meeting requests and replies, questions you ask in sessions, survey answers, and prize draw entries. Organizers and exhibitors also add their own content: stand descriptions, logos, prize names and pictures, and the extra terms of a draw. Images are uploaded only when someone picks one to upload.
Reports and blocks. If you report a person, a question, a request, or a stand, we keep the report — who sent it, what it is about, the reason, and anything you wrote — and show it to the event's organizer and to our team. If you block someone, we keep the fact that you did, so the two of you stay hidden from each other at that event. The person you block or report is not told.
Enquiry data. If you request a walkthrough, download a resource such as the check-in manual, start a chat with us on this website, email us, or message us on WhatsApp, we keep what you send — typically your name, work email, organization, and whatever you tell us about the events you run. We use it to answer you, to prepare the walkthrough, and to see who uses what we publish, on the basis of our legitimate interest in replying to people who contact us. Walkthrough requests and website chat are held in a support system we run ourselves, on the same infrastructure listed under sub-processors below. WhatsApp is different: messages you send us there are carried by WhatsApp, a Meta service, under WhatsApp's own terms and privacy policy, and are kept in the WhatsApp account we reply from. If you would rather your enquiry did not pass through Meta, email us instead. We do not add you to a marketing list from any of these, and you can ask us to delete the exchange at any time.
Usage data. Pages visited, features used, and error diagnostics, used to operate and improve the service. See our cookie policy for what is set in your browser.
Apps on your device
BagEvent publishes a mobile app — used by organizers and their staff to run events and check people in, by exhibitors to run their stands, and by attendees for their tickets, agenda, and networking — and a desktop check-in app for Windows and macOS. Alongside the data described above, these apps handle the following on the device itself.
Device identifier for notifications. The app collects a device identifier — the push notification token issued by Firebase Cloud Messaging, which delivers to Android directly and to iOS by way of Apple Push Notification service — so that we can send you notifications about your events, such as a registration awaiting approval, a check-in desk dropping offline, or a meeting request waiting for your answer. The token identifies the device rather than you personally. It is discarded when you sign out or uninstall the app, and you can turn notifications off at any time in your device settings without losing any other functionality.
Camera. The app requests camera access only to scan codes: tickets and badges at check-in, an attendee's badge at a stand, and a stand's code or another attendee's card at the event. Frames are processed on the device; only the code that was read is sent to us, and no picture is uploaded or kept.
Photos. Exhibitors and organizers can pick an image from their photo library — a stand logo or a prize picture. Only the image picked is uploaded. The app does not read the rest of the library.
Calendar. Adding your ticket or your agenda to your calendar hands a calendar file to your calendar app. The app does not ask for access to your calendar and cannot read it.
Event data stored locally. So that the app keeps working when the venue network does not, it keeps a copy of what you need on the device — for staff, the event's attendee list; for attendees, your tickets and their codes, the agenda, and your card — in an encrypted database. Sign-in credentials are kept in the operating system's secure storage — Keychain on iOS, Keystore on Android. All of it is removed when you sign out or uninstall the app. Sign out on all devices, in the Me tab (Account for organizers), also ends your sessions everywhere else.
Third-party components. The mobile app embeds two third-party services, both from Google: Firebase, used only for push notifications, which issues an installation identifier and the messaging token described above; and, on Android only, Sign in with Google, used only if you choose it, which gives us your name, email address, and Google account identifier to sign you in. The app contains no analytics SDK, no crash-reporting SDK, and no advertising or attribution SDK.
Desktop app updates. The desktop app checks our update server for a newer version. That request carries your IP address, operating system, and the version you are running — the minimum needed to serve the right update. It is not used to build a profile of you.
We do not collect an advertising identifier (Apple's IDFA or Android's AAID), we do not track you across other companies' apps or websites, and nothing these apps collect is shared with advertising networks or data brokers.
Deleting app data. Signing out removes the locally stored event data and the notification token from the device. To delete your account and the data held in it, use Delete account at the bottom of the Me tab in the app (Account for organizers), or email [email protected] and we will action it. See deleting your account for what is removed and what is kept.
What we do not do
QR codes on tickets contain only an opaque token. No attendee personal data is encoded in the scan code.
We do not sell personal data, and we do not share it with advertising networks.
Legal bases
We process personal data on the basis of contract performance (running the event you registered for), legitimate interests (operating and securing the service), and consent where the organizer's form asks for it — for example marketing opt-ins.
Children
BagEvent is not intended for use by children, and the platform does not support registering attendees below the age of digital consent in their country. We do not knowingly collect personal data from children, and organizers must not use the platform to collect it.
If you believe a child has registered through an event on BagEvent, tell the event organizer — who is the controller for that data — or contact us and we will route the request. We will action deletion.
How long we keep it
Organizer account data is retained for the life of the account. When an account is closed there is a 30-day grace period, during which the closure can still be reversed and the data remains exportable. After it passes, the data is anonymised and cannot be recovered.
Attendee registration and attendance data is kept while the organizer's account is active, or until an erasure request is actioned. There is no fixed expiry date — the organizer decides when an event's data is no longer needed. Networking data, prize draw entries, blocks, and reports are part of the event's data and follow the same rule.
Two categories outlive an erasure request:
- Invoices and payment records, kept for the period tax law requires — typically 7 to 10 years. An erasure request does not remove them.
- Security logs, kept as an append-only record.
This is the same retention notice included in every personal data export.
Your rights
Under GDPR you may request access to your data, correction of inaccurate data, deletion, restriction of processing, portability, and you may object to processing based on legitimate interests.
Because BagEvent is a Singapore company, Singapore's Personal Data Protection Act also applies to our own processing. Under the PDPA you may request access to and correction of your personal data, and withdraw consent where consent is the basis we rely on.
Attendees should direct requests to the event organizer, who controls that data. If you are unsure who that is, contact us and we will route the request. Organizers can action deletion requests directly from the attendee record.
You also have the right to lodge a complaint with your local supervisory authority.
How we protect it
The controls around hosting, payments, the check-in apps, and who can act in an account are set out on the security page.
If a security incident affects personal data we process, we notify affected organizers without undue delay after becoming aware of it, with what is known at the time rather than waiting until the picture is complete. Where we act as processor, that notification is what lets you meet your own obligation to your supervisory authority and to your attendees. The Data Processing Agreement sets out the mechanics.
Sub-processors
We use third-party services to run the platform. The current list is:
- Google Cloud Platform (Google) — hosting and infrastructure
- Cloudflare — CDN, DNS, and TLS termination for bagevent.io and its subdomains; it sees the IP address of every request
- Mailgun — transactional and campaign email delivery
- Stripe and PayPal — payment processing for subscriptions and ticket sales
- Plausible — cookieless usage analytics on our marketing site only, not on event sites
- Google Analytics — usage analytics on our marketing site only, loaded only if you consent on your first visit and never on event sites
- Firebase Cloud Messaging (Google) — delivering notifications to the mobile app; on iOS it hands off to Apple Push Notification service for the final delivery step
We notify organizers before adding a new sub-processor.
Where your data is stored, and international transfers
BagEvent runs on Google Cloud Platform in Singapore (region asia-southeast1). That is where organizer accounts, event records, and attendee registrations are held.
If you are in the EEA or the UK, registering for an event therefore transfers your data out of that area. Singapore is not covered by a European Commission adequacy decision, so for those transfers we rely on the European Commission's Standard Contractual Clauses.
Some of the sub-processors listed above operate outside Singapore — payment and email providers in particular. Where they receive personal data, we require a standard of protection comparable to the PDPA, as that Act requires of any transfer out of Singapore.
Changes
We will post any change to this policy on this page and update the date below. Material changes will be notified to account holders by email.
Contact
Questions about this policy: [email protected].
Last updated: 24 September 2026