Updated at : 6 August 2026
Organiser Privacy Policy
This Organiser Privacy Policy applies to personal data processed in connection with Organiser accounts, Event listings, KYC and bank verification, sales, settlements, support, compliance, and use of Spotlyte's organiser tools. It is separate from Spotlyte's attendee-facing privacy policy.
1. Who is responsible for your data
1.1Spotlyte, operated as a sole proprietorship from the registered business address in Section 14, is responsible for personal data it processes for operating the organiser relationship and Platform services.
1.2When you receive Attendee data for running an Event, you are independently responsible for using that data lawfully and only for permitted Event purposes, as described in the Organiser Terms & Conditions.
2. Personal data we may collect
•Account and identity data, such as name, business or entity details, date of birth where required, username, role, profile information, identity document details, and verification status.
•Contact data, such as email address, phone number, postal address, registered business address, and communication preferences.
•Tax and compliance data, such as PAN, GST registration information, tax status, declarations, permits, licences, and records required for legal or payment compliance.
•Bank and payout data, such as account holder name, bank account details, IFSC, cancelled cheque or bank proof, payout status, and settlement history.
•Event and content data, including listings, Ticket categories, prices, images, videos, artist or venue information, schedules, terms, and Event performance data.
•Transaction and financial data, including Gross Sales, fees, refunds, chargebacks, statutory deductions, invoices, balances, and payout requests.
•Support and communication data, including emails, calls, complaints, dispute records, and responses to verification or risk-review requests.
•Technical and usage data, such as IP address, device or browser information, account activity, login history, dashboard use, and security logs.
•Risk and compliance data generated from fraud prevention, identity checks, payment partner feedback, chargebacks, complaints, or legal requests.
3. How we collect data
3.1We collect data directly from you when you register, complete verification, create a listing, connect a bank account, request a payout, contact support, or use organiser features.
3.2We may receive data from payment gateways, KYC or identity verification providers, banks, tax or regulatory systems, Attendees, service providers, public sources, and authorities, where permitted by law.
3.3We may automatically collect technical and usage information when you access the Platform.
4. Why we use personal data
•To create, administer, secure, and support Organiser accounts.
•To verify identity, business, tax, bank, and eligibility information.
•To publish and manage Event listings, sell Tickets, communicate with Attendees, and provide check-in or dashboard features.
•To collect payments, calculate fees, issue invoices, process up to two eligible payouts per Event, complete final settlement, and reconcile balances.
•To process refunds, cancellations, disputes, chargebacks, complaints, and support requests.
•To detect, prevent, and investigate fraud, abuse, money laundering, security incidents, and policy breaches.
•To comply with legal, tax, accounting, payment, regulatory, court, and law-enforcement requirements.
•To improve and troubleshoot the Platform, develop features, analyse performance, and maintain service reliability.
•To send service messages, policy updates, Event or payout notifications, and other communications necessary for the organiser relationship.
•To send marketing communications where permitted and subject to any consent or opt-out required by law.
5. Basis for processing and consent
5.1Depending on the context, Spotlyte processes personal data to perform the organiser agreement, take steps requested by you, comply with law, prevent fraud and secure the Platform, and for other legitimate Platform purposes permitted by applicable law.
5.2Where consent is required, Spotlyte will seek it in an appropriate form. You may withdraw consent for optional processing, but withdrawal will not affect earlier lawful processing and may limit optional features.
5.3Certain data is required to create an account, complete KYC, receive payments, or meet legal obligations. If you do not provide it, Spotlyte may be unable to activate or continue the relevant service.
6. How we share personal data
6.1We may share personal data with payment gateways, banks, KYC and verification providers, cloud hosting and technology providers, customer support vendors, analytics and security providers, professional advisers, auditors, and other vendors that help operate the Platform.
6.2We may share data with Attendees where reasonably necessary to identify the Organiser, provide Event support, communicate changes, handle complaints, or satisfy consumer protection obligations.
6.3We may disclose data to regulators, tax authorities, courts, law enforcement, payment networks, or other competent authorities where required or permitted by law.
6.4We may share data in connection with a merger, financing, restructuring, sale, or transfer of all or part of the Platform or business, subject to appropriate safeguards.
6.5Spotlyte does not sell Organiser personal data as a standalone commercial product.
7. Payment and KYC providers
7.1Payment, bank, and KYC providers may process personal data under their own terms and privacy practices. Spotlyte shares only data reasonably necessary for verification, payment collection, payout, fraud prevention, or compliance.
7.2A provider may reject or delay verification or payment processing. Spotlyte may rely on the provider's status and risk signals when deciding whether to activate features or release funds.
8. Attendee data available to Organisers
8.1Spotlyte may make limited Attendee data available through the dashboard for Event fulfilment, support, communication, or check-in.
8.2Organisers must not use Attendee data for unrelated marketing, sale, profiling, or disclosure. Marketing use requires separate valid consent from the Attendee.
8.3Organisers must restrict access to authorised personnel, apply reasonable security measures, and delete or anonymise Attendee data when no longer required for the Event or legal compliance.
9. Data retention
9.1Spotlyte retains Organiser personal data for as long as reasonably required to operate the account, provide services, complete Events and settlements, resolve refunds or chargebacks, meet tax and accounting requirements, enforce agreements, prevent fraud, and comply with law.
9.2Some records may be retained after account closure where required for legal, tax, dispute, audit, fraud prevention, or payment network purposes.
9.3When data is no longer required, Spotlyte may delete, anonymise, or securely archive it, subject to legal and technical constraints.
10. Security
10.1Spotlyte uses reasonable administrative, technical, and organisational safeguards designed to protect personal data against unauthorised access, alteration, loss, misuse, or disclosure.
10.2No online service is completely secure. You must protect account credentials, use authorised devices, and promptly report suspected compromise to support@spotlyte.app.
10.3Where Spotlyte becomes aware of a personal data breach, it will take reasonable steps to contain, assess, and notify affected persons or authorities where required by applicable law.
11. Your choices and rights
11.1You may request access to or correction of certain account information through the dashboard or by contacting Spotlyte.
11.2Subject to applicable law and verification, you may request information about processing, correction, completion, updating, erasure, withdrawal of consent, or grievance redressal.
11.3Spotlyte may retain or continue processing information where required or permitted by law, including for tax, payment, fraud prevention, dispute, or legal claim purposes.
11.4You may opt out of optional promotional messages using the method provided in the message. Service, security, Event, policy, and payout communications cannot be disabled while the account is active.
12. Children
12.1Organiser accounts are intended only for persons aged 18 or older. Spotlyte does not knowingly permit a child to create an Organiser account.
13. Policy changes
13.1Spotlyte may update this policy to reflect changes in law, services, providers, or data practices. Material changes will be notified through the Platform, dashboard, or registered email where appropriate.
14. Contact and grievance redressal
Spotlyte
993/44A1, South Weavers Colony, Nesamony Nagar, Nagercoil - 629003, Kanyakumari, Tamil Nadu, India
Privacy and support queries: support@spotlyte.app | +91 75300 99945
Grievance Officer: Vikram | complaints@spotlyte.app