Skip to content
bagevent.io
SECURITY

Where your data lives, and who can reach it

Written for the people who have to sign off on a platform before anyone uses it. Everything below is what the product does today — not a roadmap, and not a list of aspirations.

Where attendee data goes, and on what legal basis

Attendee registers

EEA · UK · anywhere

The organizer decides which fields the form asks for. Consent is captured at the point of collection.

Stored in one region

GCP · asia-southeast1

Organizer accounts, event records, and attendee registrations are all held in Singapore.

Deleted or exported

per request

Deletion is built in rather than bolted on, and the organizer stays the controller throughout.

Singapore has no EU adequacy decision, so transfers from the EEA and the UK run on the European Commission's Standard Contractual Clauses. A Data Processing Agreement is available to every organizer, and sub-processors are listed in full in the privacy policy.

Where your data lives

One region, one hosting provider, and a published list of everyone else who touches the data.

Hosting
Google Cloud Platform, Singapore (asia-southeast1). Organizer accounts, event records, and attendee registrations are all held there.
EEA and UK transfers
Singapore has no EU adequacy decision, so those transfers run on the European Commission's Standard Contractual Clauses.
Singapore law
The PDPA applies to our own processing, including the standard we require of any onward transfer.
GDPR and PDPA
For attendees in the EEA and the UK, GDPR applies and the organizer is the controller; BagEvent processes on their instructions. Consent is captured at each collection point, deletion is built in, a Data Processing Agreement is available to every organizer, and transfers run on Standard Contractual Clauses. Singapore's PDPA applies to our own processing.
Sub-processors
Published in full in the privacy policy — hosting, email, payments, analytics on this marketing site, and push notifications. Organizers are notified before a new one is added.
Cookies on this website
None until you choose. Analytics that set cookies are asked for once, default to off, and are never loaded if you decline; the page-view counter that runs either way sets nothing. Your choice can be changed from any page.
In transit
bagevent.io, account.bagevent.io, and app.bagevent.io are served over HTTPS, with HSTS, behind Cloudflare, which terminates TLS and is listed as a sub-processor.

Money never routes through us

The 0% platform fee is a consequence of the architecture: your ticket revenue is never in our custody to take a cut from.

Ticket revenue
Collected into your own Stripe or PayPal account. It does not pass through a BagEvent account on the way to you.
Card details
Handled by the payment provider. BagEvent does not store card numbers, for ticket sales or for your own subscription.
Several entities
Each currency or event can settle to a different legal entity, and each entity settles to its own bank account.

What runs on the devices at your event

An offline check-in pack is your attendee list on a machine that leaves the office. These are the controls around that, rather than a claim that it is not true.

What is in a ticket QR
An opaque token and nothing else. Scanning a ticket with any other app reveals nothing about the attendee.
The attendee list on a phone
Held in an encrypted database. Sign-in credentials go to the operating system's secure storage — Keychain on iOS, Keystore on Android. Signing out or leaving the event removes both.
The camera
Used for scanning QR codes only. Frames are processed on the device and are never uploaded or retained.
Third-party code in the app
One component: Firebase, for push notifications. No analytics SDK, no crash-reporting SDK, no advertising or attribution SDK, and no advertising identifier.
An offline pack on a laptop
Carries a lease — seven days by default — after which the machine has to reach the backend again, which re-checks the account in the same step. Winding the system clock back does not extend it.
Signing in to a desk with no network
The password is never stored on the machine, only a verifier, sealed by DPAPI on Windows and the Keychain on macOS. Five wrong attempts locks it for five minutes.
Check-ins that have not uploaded
Never discarded. Anything that fails to upload stays in the queue with the reason attached, and a duplicate created while two devices were offline is raised for a person to adjudicate rather than resolved silently.

Who can act in your account

Scanning staff, team members, and the assistant all operate inside permissions you set.

Staff at the door
Join a device with a short code you approve from your own account. They never get a login of their own, and one device can be revoked without touching the others.
Your team
Team members act within their own permissions. What a check-in point is allowed to do is set on the server, so a device is only ever offered the actions that point permits.
The AI assistant
Proposes; you confirm. Every change runs under your own account and permissions, so it can never do something your role could not do by hand.
SSO and SAML
Available on Enterprise plans, along with a custom DPA and onboarding training.

How long things are kept, and what deletion does

The same retention notice goes out with every personal data export.

Closing an account
A 30-day grace period, during which the closure can be reversed and the data stays exportable. After it passes the data is anonymised and cannot be recovered.
Attendee data
Kept while the organizer's account is active, or until an erasure request is actioned. Organizers can action a deletion request directly from the attendee record.
What outlives an erasure request
Invoices and payment records, for the period tax law requires — typically 7 to 10 years. And security logs, kept as an append-only record.
Telling you about an incident
If a security incident affects personal data we process for you, we notify you without undue delay after becoming aware of it — with what is known at the time, rather than waiting for a complete picture. The DPA sets out the mechanics.
Uptime commitment
A 99.9% uptime SLA is part of the Enterprise contract.

Questions security reviews ask

On Google Cloud Platform in Singapore (asia-southeast1). Organizer accounts, event records, and attendee registrations are all held in that one region. Singapore has no EU adequacy decision, so transfers from the EEA and the UK run on the European Commission's Standard Contractual Clauses.

Documents, and how to reach us

Data Processing Agreement

Available to every organizer. Enterprise contracts can have a custom one.

Request the DPA

Sub-processors and data flows

The current list, what each one does, and where the data goes.

Read the privacy policy

Reporting a vulnerability

Email us with the details and we will come back to you. Please do not disclose it publicly first.

[email protected]

Filling in a security questionnaire? Send it over — it is quicker than guessing from this page, and anything it turns up that belongs here gets added.

Questions your security team needs answered?

Send them to us before you commit to anything — we would rather answer them now than at renewal.