Where your data lives, and who can reach it
Written for the people who have to sign off on a platform before anyone uses it. Everything below is what the product does today — not a roadmap, and not a list of aspirations.
Where attendee data goes, and on what legal basis
EEA · UK · anywhere
The organizer decides which fields the form asks for. Consent is captured at the point of collection.
GCP · asia-southeast1
Organizer accounts, event records, and attendee registrations are all held in Singapore.
per request
Deletion is built in rather than bolted on, and the organizer stays the controller throughout.
Singapore has no EU adequacy decision, so transfers from the EEA and the UK run on the European Commission's Standard Contractual Clauses. A Data Processing Agreement is available to every organizer, and sub-processors are listed in full in the privacy policy.
Where your data lives
One region, one hosting provider, and a published list of everyone else who touches the data.
- Hosting
- Google Cloud Platform, Singapore (asia-southeast1). Organizer accounts, event records, and attendee registrations are all held there.
- EEA and UK transfers
- Singapore has no EU adequacy decision, so those transfers run on the European Commission's Standard Contractual Clauses.
- Singapore law
- The PDPA applies to our own processing, including the standard we require of any onward transfer.
- GDPR and PDPA
- For attendees in the EEA and the UK, GDPR applies and the organizer is the controller; BagEvent processes on their instructions. Consent is captured at each collection point, deletion is built in, a Data Processing Agreement is available to every organizer, and transfers run on Standard Contractual Clauses. Singapore's PDPA applies to our own processing.
- Sub-processors
- Published in full in the privacy policy — hosting, email, payments, analytics on this marketing site, and push notifications. Organizers are notified before a new one is added.
- Cookies on this website
- None until you choose. Analytics that set cookies are asked for once, default to off, and are never loaded if you decline; the page-view counter that runs either way sets nothing. Your choice can be changed from any page.
- In transit
- bagevent.io, account.bagevent.io, and app.bagevent.io are served over HTTPS, with HSTS, behind Cloudflare, which terminates TLS and is listed as a sub-processor.
Money never routes through us
The 0% platform fee is a consequence of the architecture: your ticket revenue is never in our custody to take a cut from.
- Ticket revenue
- Collected into your own Stripe or PayPal account. It does not pass through a BagEvent account on the way to you.
- Card details
- Handled by the payment provider. BagEvent does not store card numbers, for ticket sales or for your own subscription.
- Several entities
- Each currency or event can settle to a different legal entity, and each entity settles to its own bank account.
What runs on the devices at your event
An offline check-in pack is your attendee list on a machine that leaves the office. These are the controls around that, rather than a claim that it is not true.
- What is in a ticket QR
- An opaque token and nothing else. Scanning a ticket with any other app reveals nothing about the attendee.
- The attendee list on a phone
- Held in an encrypted database. Sign-in credentials go to the operating system's secure storage — Keychain on iOS, Keystore on Android. Signing out or leaving the event removes both.
- The camera
- Used for scanning QR codes only. Frames are processed on the device and are never uploaded or retained.
- Third-party code in the app
- One component: Firebase, for push notifications. No analytics SDK, no crash-reporting SDK, no advertising or attribution SDK, and no advertising identifier.
- An offline pack on a laptop
- Carries a lease — seven days by default — after which the machine has to reach the backend again, which re-checks the account in the same step. Winding the system clock back does not extend it.
- Signing in to a desk with no network
- The password is never stored on the machine, only a verifier, sealed by DPAPI on Windows and the Keychain on macOS. Five wrong attempts locks it for five minutes.
- Check-ins that have not uploaded
- Never discarded. Anything that fails to upload stays in the queue with the reason attached, and a duplicate created while two devices were offline is raised for a person to adjudicate rather than resolved silently.
Who can act in your account
Scanning staff, team members, and the assistant all operate inside permissions you set.
- Staff at the door
- Join a device with a short code you approve from your own account. They never get a login of their own, and one device can be revoked without touching the others.
- Your team
- Team members act within their own permissions. What a check-in point is allowed to do is set on the server, so a device is only ever offered the actions that point permits.
- The AI assistant
- Proposes; you confirm. Every change runs under your own account and permissions, so it can never do something your role could not do by hand.
- SSO and SAML
- Available on Enterprise plans, along with a custom DPA and onboarding training.
How long things are kept, and what deletion does
The same retention notice goes out with every personal data export.
- Closing an account
- A 30-day grace period, during which the closure can be reversed and the data stays exportable. After it passes the data is anonymised and cannot be recovered.
- Attendee data
- Kept while the organizer's account is active, or until an erasure request is actioned. Organizers can action a deletion request directly from the attendee record.
- What outlives an erasure request
- Invoices and payment records, for the period tax law requires — typically 7 to 10 years. And security logs, kept as an append-only record.
- Telling you about an incident
- If a security incident affects personal data we process for you, we notify you without undue delay after becoming aware of it — with what is known at the time, rather than waiting for a complete picture. The DPA sets out the mechanics.
- Uptime commitment
- A 99.9% uptime SLA is part of the Enterprise contract.
Questions security reviews ask
On Google Cloud Platform in Singapore (asia-southeast1). Organizer accounts, event records, and attendee registrations are all held in that one region. Singapore has no EU adequacy decision, so transfers from the EEA and the UK run on the European Commission's Standard Contractual Clauses.
The organizer is the controller and BagEvent is the processor, working on the organizer's instructions. Consent is captured at every collection point, deletion is built in, a Data Processing Agreement is available to every organizer, and sub-processors are published in full. For attendees in the EEA and the UK, transfers to Singapore run on the European Commission's Standard Contractual Clauses. BagEvent holds no certification and claims none.
No. Card details are handled by the payment provider, and BagEvent does not store card numbers — for ticket sales or for your own subscription. Ticket revenue is collected into your own Stripe or PayPal account and does not pass through a BagEvent account on the way.
None. The QR code holds an opaque token and nothing else, so scanning a ticket with any other app reveals nothing about the attendee.
On a phone, the attendee list is held in an encrypted database and sign-in credentials sit in the operating system's secure storage. Each door device joins with a code you approve and can be revoked on its own. An offline pack on a laptop carries a lease, seven days by default, after which it must reach the backend again.
Yes. A DPA is available to every organizer, and Enterprise contracts can have a custom one. Sub-processors are published in full in the privacy policy, and organizers are notified before a new one is added.
There is a 30-day grace period, during which the closure can be reversed and the data stays exportable. After that, BagEvent anonymises the data and it cannot be recovered. Invoices and payment records are kept for the period tax law requires, typically 7 to 10 years.
Documents, and how to reach us
Data Processing Agreement
Available to every organizer. Enterprise contracts can have a custom one.
Request the DPASub-processors and data flows
The current list, what each one does, and where the data goes.
Read the privacy policyReporting a vulnerability
Email us with the details and we will come back to you. Please do not disclose it publicly first.
[email protected]Filling in a security questionnaire? Send it over — it is quicker than guessing from this page, and anything it turns up that belongs here gets added.
Field guides
- What does GDPR actually require of an event organiser?You are the controller; your platform is the processor. The eight clauses a DPA must contain, why a dietary field is special-category data, and the deadlines.
- What should you look for in event registration software?A demo shows the happy path. What to check instead: the real cost at your volume, where the money sits, the checkout, the event day, and leaving.
Questions your security team needs answered?
Send them to us before you commit to anything — we would rather answer them now than at renewal.