Privacy policy
Last updated 4 September 2026
EventSetu holds a community's financial records, which is a serious thing to be trusted with. This page describes exactly what is stored, who can see it, and what we do not do.
Who this is between
EventSetu is operated from India by the individual reachable at hello@event-setu.com. “We” below means that operator. “You” means the person using the product, and “your community” means the organization, society, committee or trust whose records you keep here.
What we collect
Your account. Sign-in is through Google. We receive your name, email address and profile picture from Google. We never receive or store your Google password.
What your community records. Events, budgets, donations, expenses, accounts, tasks, meetings and their minutes, and any images or bills uploaded. This includes information about other people — donor names, amounts, flat numbers, phone numbers and vendor details — entered by your committee.
Technical records. Ordinary server logs, and an audit trail recording who changed what and when. The audit trail is deliberate and is a feature: it is how a community can show that a figure was not quietly altered.
We do not use advertising trackers, and we do not sell anything to anybody.
Money: what we never touch
No payment ever passes through EventSetu. Donations go directly into your community’s own bank or UPI account. We record what was collected and spent; we never receive, hold, route or settle funds, and we never see card or bank credentials.
Where the product helps automate collection, it does so by generating a payment reference for your own account and matching the credits that appear on your own statement. The money still goes straight to you.
What is public, and what is not
An event page is only reachable by anyone once your committee marks the event public. Even then, your committee chooses what appears: contributor list, itemised expenses, budget breakdown and meetings are each switchable.
Donor privacy is enforced in the database, not the page. A donor marked anonymous has their real name filtered out inside the database, so it never reaches the browser at all — not in a hidden field, not in a page source. Phone numbers, email addresses and internal notes are never published under any setting.
Bills and receipts are private. They are stored in a bucket with no public access and are readable only through short-lived signed links issued to signed-in members of your community. They are never shown on a public page.
Who can see your community’s data
Only members of your community, according to their role, plus anything your committee has deliberately published. Access is enforced by row-level security in the database rather than by the interface, so a member of one community cannot read another’s records even through a direct request.
We access your data only when you ask us to help with a problem, or where the law requires it.
Where it is stored
Data is held on Supabase infrastructure, currently in the Asia-Pacific (Singapore) region, and the application is served through a hosting provider. These providers process data on our behalf under their own security obligations.
We keep records for as long as your community uses EventSetu, and for a reasonable period afterwards — financial records are often needed later, and deleting a past year’s accounts on request could destroy something a community is answerable for.
Your choices
You can edit or correct anything your role permits, ask us for a copy of your community’s data, or ask us to delete your account. An Admin can remove a member at any time.
Deleting an organization deletes its records. Because financial history is the point of the product, this is deliberate and cannot be undone — ask us if you are unsure.
Requests go to hello@event-setu.com.
Children
EventSetu is meant for adults running a community’s affairs. It is not directed at children, and we do not knowingly create accounts for them.
Changes
If this policy changes in a way that matters, we will update the date at the top and, for a significant change, tell the Admins of active communities.