Privacy Policy

Last updated: 16 August 2026

FESTOOO ("we", "us", "our") respects your privacy. This Privacy Policy describes — in plain language and item by item — exactly what we collect, why, how it's stored, who it's shared with, and the choices you have. It covers our website, mobile experience and related services (the "Service").

1. Data we store about you

We only collect what we actually need to run FESTOOO. Concretely, the personal data we save in our database is:

a. Account & profile

  • From Google sign-in: your Google account ID, email, name and profile photo URL. We never see your Google password.
  • Profile you fill in: full name, avatar URL, college, city, state.

b. Organizer applications

If you apply to become a verified organizer, we save: full name, email, phone, college, your role at the organization, organization name, website, description, Instagram & LinkedIn handles, and a summary of past events.

c. Event registrations

When you register through FESTOOO's in-app form (not a third-party organizer link), we store: your name, email, phone, optional team name and team members, the custom fields the organizer asks for, and your payment status. This data is shared with the organizer running the event.

d. Saved events & activity

We store the events you save or bookmark, and a record of which events you view (your user ID linked to the event ID and timestamp). This is what powers your saved list and event-view counts for organizers.

e. Notifications & push

If you turn on browser push notifications, we store your push endpoint URL and the two keys your browser issues (p256dh, auth) plus your user-agent. We use them only to deliver the notifications you opted into.

f. Experiences (reviews) & photos

If you post a fest experience, we store your college, event name, rating, written story and (optionally) a photo you upload. Photos are kept in a private storage bucket; experiences only appear publicly after an admin approves them.

g. Feedback & reports

When you send feedback or report a listing, we save: your user ID (if signed in), email, category, rating, message, the page URL you were on, and your browser user-agent string.

h. Technical & security data

Like every web service, our servers log basic request data — IP address, browser/device, referrer, timestamps — to keep the Service available, prevent abuse, and debug issues. Cookies and local storage are used to keep you signed in and remember UI preferences.

2. Publicly scraped event data

FESTOOO continuously discovers new fests by crawling publicly available pages from college and organizer websites — using the Firecrawl API and our own link-checker. What we save from that crawl is event-level information, not personal data about individuals:

  • Event title, description, category, dates and venue.
  • Host college / organization, city and state.
  • The original registration / event URL (so we can send traffic back to you).
  • Cover image URL (we link or proxy; we do not re-host branded artwork).
  • Link health status (alive, expired, broken) so we can auto-remove dead listings.

We only index pages that are publicly accessible (no login, no paywall, no bypass of access controls), we respect robots.txt, and we rate-limit our requests with an identifying User-Agent. If you're a rights holder and want a listing removed, see our disclaimer or the report-a-listing form.

3. What we don't collect

  • We don't sell or rent your data.
  • We don't run third-party advertising or behavioural-ad trackers.
  • We don't store your Google password or any OAuth secret.
  • We don't take payments on FESTOOO, so we don't store card numbers, UPI IDs or bank details.
  • We don't track your exact GPS location.

4. How we use the data

  • Run your account, save fests, and personalise recommendations.
  • Send transactional messages (sign-in, event reminders, listing updates) and — if you opted in — push notifications.
  • Show organizers anonymised counts (views, registrations) for their own events only.
  • Keep the Service safe: detect abuse, spam and fraud; enforce our Terms of Use.
  • Measure usage and improve features, performance and reliability.
  • Respond to your support requests, feedback and legal notices.

5. Legal basis

We process personal data on the basis of your consent (e.g. account creation, push notifications), our contract with you (operating the Service), our legitimate interests (safety, analytics, improvement) and to comply with legal obligations.

6. Who we share data with

  • Event organizers — when you register through our in-app form, your registration details (name, email, phone, team info, custom-field answers) are shared with the organizer of that event so they can run it. Their use of your data is governed by their own privacy policy.
  • Infrastructure providers — hosting and CDN (Cloudflare / Lovable), database & authentication (Supabase), email delivery, web-push gateways (your browser's push service, e.g. Google FCM / Apple APNs / Mozilla autopush), and the Firecrawl API for crawling public event pages. They process data on our behalf under confidentiality and data-protection terms.
  • Authorities — when required by law, court order, or to protect the rights, property or safety of FESTOOO, our users or the public.
  • Successors — in the event of a merger, acquisition or reorganisation, with notice to you.

7. Cookies and similar tech

We use cookies and local storage to keep you signed in, remember UI preferences, measure traffic and prevent abuse. You can clear cookies in your browser settings — note this will sign you out. We do not run third-party advertising trackers.

8. Data retention

  • Account, profile and saved-event data: kept while your account is active.
  • Event registrations: kept for as long as the organizer needs them to run the event and any follow-ups (e.g. certificates), then deleted on request.
  • Push subscriptions: removed when they expire or you turn off notifications.
  • Feedback and reports: kept as long as needed to act on them and to keep audit trails.
  • Scraped event data: live events stay listed; expired/closed/broken events are auto-removed by our link sweeper.
  • When you delete your account, we delete or anonymise your personal data within a reasonable period, except where retention is required by law.

9. Security

We use industry-standard safeguards — TLS encryption in transit, row-level security on our database so users can only see what they're allowed to, least-privilege server-side keys, and signed/short-lived OAuth flows for Google sign-in. No internet service is 100% secure; please use a strong, unique password (for non-Google logins) and tell us immediately if you suspect unauthorised access to your account.

10. Your rights

Subject to applicable law, you have the right to:

  • Access the personal information we hold about you.
  • Correct inaccurate or incomplete data.
  • Delete your account and personal data ("right to be forgotten").
  • Object to or restrict certain processing.
  • Withdraw consent for push notifications or marketing communications at any time.
  • Lodge a complaint with the relevant data protection authority.

To exercise these rights, email festooo274@gmail.com from the address linked to your account.

11. Children

The Service is not directed to children under 13. If you believe a child under 13 has provided us personal information, contact us and we will delete it.

12. International transfers

FESTOOO is operated from India. Some of our infrastructure providers may store or process data outside India. Where this happens, we put in place appropriate safeguards as required by law.

13. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we'll change the "Last updated" date above and, for material changes, notify you in-app or by email.

14. Contact

For privacy queries, data requests, takedowns or anything else: festooo274@gmail.com.

See also: Terms of Use · Disclaimer