Privacy Policy
Who We Are
Arctova Technologies Private Limited ("Arctova," "ShowUp," "we," "us," or "our") is the Data Fiduciary responsible for the personal data processed through the ShowUp platform (website at showup.group and associated mobile applications). ShowUp is a product of Arctova Technologies Private Limited, incorporated under the laws of India and headquartered in Hyderabad, Telangana.
This Policy applies to all personal data processed in connection with your use of ShowUp as a Host, Guest, or visitor. It should be read alongside our Terms of Service.
For any privacy-related enquiries, contact our Grievance Officer at the details provided in Section 17.
Data We Collect
| Category | Data Points | When Collected |
|---|---|---|
| Account Data | Full name, email address, mobile number, profile photo (optional) | Registration |
| Identity / KYC | Government ID type and number, date of birth, PAN (for payouts above applicable thresholds) | KYC verification |
| Event Data | Event title, description, location address, date/time, entry fee, guest list | Event creation (Hosts) |
| Payment Data | Masked card details, UPI ID, bank account details (for payouts), transaction IDs | Payments and payouts |
| Communications | Messages sent in event group chats, support tickets, feedback | In-app use |
| User Content | Photos, descriptions, or other content you upload | In-app use |
| Category | Data Points |
|---|---|
| Location Data | Precise GPS coordinates at the time of event check-in via the Attendance Verification System (AVS) |
| Device Data | Device model, OS version, unique device identifiers, app version, crash logs |
| Usage Data | Pages viewed, features used, clicks, session duration, search queries within the Platform |
| Log Data | IP address, browser type, referral URL, timestamps of actions |
| Cookies & Identifiers | Session cookies, analytics identifiers, push notification tokens |
We may receive data about you from:
- Razorpay - payment status, transaction metadata, and fraud signals;
- Social login providers (if you sign in via Google or similar) - your name, email, and profile photo as shared by that provider;
- Other Users - Hosts may provide Guest contact information when creating invite-only events.
How We Use Your Data
| Purpose | Data Used |
|---|---|
| Providing the Platform | Account data, event data, payment data |
| Attendance verification (AVS) | GPS location, QR scan data, device identifiers |
| Processing payments and payouts | Payment data, identity/KYC data, transaction history |
| Fraud detection and prevention | All categories, including device data, IP address, GPS history |
| Customer support | Account data, communications, transaction data |
| Legal compliance and dispute resolution | All categories as required by law or arbitration proceedings |
| Platform improvement and analytics | Usage data, device data, aggregated and anonymised event data |
| Safety and security | Log data, device data, usage patterns |
| Transactional communications | Email address, mobile number |
| Marketing (with consent) | Email address, mobile number, usage preferences |
We do not use your personal data to make solely automated decisions that have significant legal effects on you, without human review where required by applicable law.
Legal Basis for Processing
Under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), we process your personal data on the following bases:
- Consent - for location data collection during AVS check-in, marketing communications, and social login. You may withdraw consent at any time (see Section 10), though withdrawal may affect your ability to use certain features.
- Contractual necessity - to perform our obligations under the Terms of Service, including processing payments, verifying attendance, and distributing payouts.
- Legitimate interests - for fraud prevention, Platform security, and analytics, where these interests are not overridden by your rights.
- Legal obligation - to comply with Indian law, including tax regulations, anti-money laundering requirements, and court or regulatory orders.
Location Data and the Attendance Verification System
Location data is the most sensitive category of data we collect. We treat it accordingly.
The ShowUp AVS captures your device's precise GPS coordinates at the moment you scan the Host's QR code to check in to an Event. We do not collect background or continuous location data. Location access is requested only within the check-in window of an Event you have registered for.
GPS coordinates are used solely to verify that you are physically present at the Event venue at the time of check-in. This is essential to the integrity of the ShowUp commitment mechanism and the fairness of Redistribution Payouts.
Check-in GPS coordinates are retained for 24 months from the date of the Event, for the purposes of dispute resolution and fraud investigation. After this period, coordinates are permanently deleted or irreversibly anonymised.
Your precise GPS coordinates are not shared with Hosts, other Guests, or third parties except: (a) Razorpay, where required to process a related payout; (b) law enforcement or regulators, where required by law; or (c) in anonymised, aggregated form for analytics. Hosts see only whether attendance was confirmed - not your specific coordinates.
Payment Data
ShowUp uses Razorpay Software Private Limited to process all payments and payouts on the Platform. Razorpay is a PCI DSS-compliant payment processor regulated by the Reserve Bank of India.
- ShowUp does not store full card numbers, CVV codes, or net banking credentials.
- Payment tokenisation and encryption are handled entirely by Razorpay.
- ShowUp retains transaction records (amounts, timestamps, event references, payout status) for a minimum of 8 years for tax and legal compliance purposes.
- For payouts above thresholds prescribed under the Income Tax Act, 1961, we collect and retain your PAN and bank account details as required by law.
Razorpay's collection and handling of your payment data is governed by Razorpay's Privacy Policy. We encourage you to review it.
Communications and Group Chat
Guests who have paid an Entry Fee gain access to the Event's in-app group channel. Messages sent in group chats are:
- Visible to all current members of the group (Host and all registered Guests);
- Stored by ShowUp and may be reviewed by our Trust & Safety team in response to a report of abuse or a legal request;
- Retained for 12 months after the Event date, after which they are deleted.
Do not share sensitive personal information (financial details, government IDs, passwords) in group chats.
We send booking confirmations, payout notifications, attendance reminders, and other service communications via email and SMS. These are necessary for the provision of the service and cannot be opted out of while your account is active.
We will only send you marketing emails or SMS messages if you have explicitly opted in. You may withdraw this consent at any time by clicking "Unsubscribe" in any marketing email or adjusting notification preferences in your account settings. Withdrawal of marketing consent does not affect transactional communications.
Sharing Your Data
We do not sell your personal data. We share your data only in the following circumstances:
| Recipient | Data Shared | Purpose |
|---|---|---|
| Razorpay | Name, contact details, payment and payout data | Payment processing and payout disbursement |
| Cloud infrastructure providers (e.g., AWS, Google Cloud) | All data stored on the Platform | Hosting and data storage |
| Analytics providers | Anonymised/aggregated usage data | Platform improvement |
| Other Users (Hosts) | Name and attendance status only | Event management; Hosts see who has registered and who attended |
| Law enforcement / regulators | As required by applicable law or valid legal process | Legal compliance |
| Successor entity | All data | In the event of a merger, acquisition, or sale of ShowUp's business |
| Professional advisors | As required (under confidentiality) | Legal, audit, and tax advice |
All third-party data processors are bound by contractual data processing agreements requiring them to protect your data to standards consistent with this Policy and applicable law.
Data Retention
| Data Category | Retention Period |
|---|---|
| Account data | Duration of account + 3 years after deletion |
| GPS check-in coordinates | 24 months from Event date |
| Payment and transaction records | 8 years (Income Tax Act compliance) |
| KYC / identity documents | 5 years after last transaction (PMLA compliance) |
| Group chat messages | 12 months from Event date |
| Support communications | 3 years from resolution |
| Usage and log data | 18 months on a rolling basis |
| Marketing consent records | Duration of consent + 3 years |
Where we are required by law to retain data for longer periods, we will do so. At the end of a retention period, data is securely deleted or irreversibly anonymised.
Your Rights
Under the DPDP Act 2023 and applicable Indian law, you have the following rights as a Data Principal:
Request a summary of the personal data we hold about you and how it is being processed.
Request correction of inaccurate, incomplete, or outdated personal data.
Request deletion of your personal data, subject to our legal retention obligations.
Lodge a grievance with our Grievance Officer and receive a response within 30 days.
Withdraw consent for processing based on consent (e.g., marketing, location). Note: some withdrawals may impact service availability.
Nominate another individual to exercise your rights on your behalf in the event of death or incapacity.
If you are not satisfied with our response, you have the right to lodge a complaint with the Data Protection Board of India once constituted under the DPDP Act 2023.
Data Security
ShowUp implements industry-standard technical and organisational security measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include:
- Encryption of data in transit using TLS 1.2 or higher;
- Encryption of sensitive data at rest using AES-256;
- Role-based access controls limiting employee access to personal data on a need-to-know basis;
- Regular security audits and penetration testing;
- Incident response procedures with mandatory notification timelines.
In the event of a personal data breach that is likely to result in harm to you, we will notify you and, where required, the Data Protection Board of India, within the timeframes prescribed by applicable law.
No method of electronic transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. You are responsible for keeping your account credentials secure.
Cookies and Tracking Technologies
ShowUp uses cookies and similar tracking technologies on its website. We use:
| Type | Purpose | Can Be Disabled? |
|---|---|---|
| Essential cookies | Session management, security, authentication | No - required for Platform to function |
| Analytics cookies | Understanding how users navigate the Platform (e.g., Google Analytics) | Yes - via cookie preferences |
| Preference cookies | Remembering your settings and preferences | Yes - via cookie preferences |
| Marketing cookies | Delivering relevant advertisements (only with consent) | Yes - via cookie preferences |
You can manage cookie preferences via your browser settings or our cookie consent banner. Disabling non-essential cookies will not affect your ability to use the core features of the Platform.
Children's Privacy
The ShowUp Platform is not directed at, and we do not knowingly collect personal data from, individuals under the age of 18. If you are under 18, you must not use the Platform.
If we become aware that we have collected personal data from a person under 18 without appropriate consent, we will take prompt steps to delete that data. If you believe we have inadvertently collected data from a minor, please contact us immediately at hello@arctova.tech.
Cross-Border Data Transfers
ShowUp is an India-based platform and primarily stores and processes data within India. Some of our third-party service providers (including cloud infrastructure providers) may process or store data in other jurisdictions.
Where personal data is transferred outside India, we ensure adequate safeguards are in place in accordance with the DPDP Act 2023, including data processing agreements with recipients and transfer impact assessments where required. We will not transfer your data to jurisdictions that do not provide an adequate level of protection without implementing appropriate contractual safeguards.
Third-Party Links
The Platform may contain links to third-party websites or services, including Arctova Technologies (our parent company), Razorpay, and social media platforms. This Privacy Policy does not apply to those third-party sites. We encourage you to review the privacy policies of any third-party services you access through our Platform. ShowUp is not responsible for the privacy practices of third parties.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Update the "Last Updated" date at the top of this Policy;
- Send a notification to your registered email address; and/or
- Display a prominent notice on the Platform.
Your continued use of the Platform after the effective date of a revised Policy constitutes your acceptance of the changes. Where required by law, we will seek fresh consent for material changes to the basis of processing.
Contact and Grievance Officer
In accordance with the Information Technology Act, 2000, and the DPDP Act 2023, we have appointed a Grievance Officer to address privacy concerns:
| Role | Contact |
|---|---|
| Grievance Officer | hello@arctova.tech |
| General Privacy Queries | hello@arctova.tech |
| Data Deletion Requests | hello@arctova.tech |
| Security / Breach Reports | hello@arctova.tech |
Arctova Technologies Private Limited
Hyderabad, Telangana, India
We will acknowledge all privacy requests within 48 hours and aim to resolve them within 30 days. If you are not satisfied with our response, you may escalate to the Data Protection Board of India once it is constituted under the DPDP Act 2023.