Invy

Privacy Policy

Last updated: 2026-08-03

This Privacy Policy describes how Viral Engine ("we", "us", or "our") collects, uses, and shares information when you use Invy (the "Service") at invy.viralengine.in. By using the Service, you agree to this policy. Related terms are in our Terms of Service.

1. Who we are

The Service is operated by Viral Engine. For privacy requests, contact [email protected]. This policy is intended for use under the laws of India.

2. Roles: controller and processor

Organizers (accounts that create events) are typically the data controllers for attendee registration data they collect for their events. They decide why and how that data is used for their workshops and classes.

Viral Engine / Invy acts as a processor for attendee data processed on an organizer's behalf (for example, ingesting Google Form responses, sending confirmations and reminders, and hosting manage links). For organizer account data (email, password hash, connection metadata), Viral Engine is the controller.

3. Information we collect

Depending on how you use Invy, we may process:

  • Organizer account data: name (optional), email, password hash, session cookies, onboarding state, and settings.
  • Google connection metadata: connected Google account email, OAuth scopes granted, and connection status. We store encrypted refresh tokens to call Google APIs on your behalf; we do not use your Google data to advertise to you.
  • WhatsApp / Meta connection data: WhatsApp Business / Cloud API credentials and phone numbers needed to send template messages you configure.
  • Event and registration data: event details, Google Form / Calendar identifiers, registration fields (such as name, email, WhatsApp number, consent), reminder schedules, notification delivery status, and waitlist / feedback records.
  • Technical data: IP address and basic request logs for security, abuse prevention, and reliability; webhook payloads from Meta for delivery status.

4. Google APIs and Limited Use

When an organizer connects Google, Invy requests only the OAuth scopes required to run registration automation:

  • https://www.googleapis.com/auth/forms.body — create and update Google Forms for event registration and feedback
  • https://www.googleapis.com/auth/forms.responses.readonly — read form responses to create registrations
  • https://www.googleapis.com/auth/calendar.events — create and manage Calendar events / invites
  • https://www.googleapis.com/auth/gmail.send — send confirmation, reminder, and thank-you emails from the organizer's Gmail
  • https://www.googleapis.com/auth/userinfo.email — identify the connected Google account email

Invy's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, do not use it for advertising, and do not allow humans to read it except as needed for security, compliance, or with your explicit consent, or where required by law.

5. WhatsApp messaging and opt-out

If an organizer connects WhatsApp Cloud API (Meta), Invy may send event-related template messages (confirmations, reminders, thank-you notes) to attendees who provided a WhatsApp number and consent, or otherwise as permitted by Meta policies and applicable law.

Attendees can opt out of WhatsApp reminders from their private manage link at /r/{token}. Organizers remain responsible for obtaining any required consent and for complying with Meta's WhatsApp Business / Cloud API policies.

6. How we use information

We use information to:

  • Provide, operate, and improve the Service (registration ingest, confirmations, calendar invites, reminders, waitlist, feedback).
  • Authenticate organizers, maintain sessions, and secure accounts.
  • Troubleshoot delivery failures and show notification health to organizers.
  • Comply with legal obligations and respond to lawful requests.

7. No sale of personal information

We do not sell personal information or attendee contact lists. We do not share personal data with third parties for their independent marketing. We share data with subprocessors only as needed to run the Service (for example hosting, database, queue, and Meta/Google APIs when you connect those channels).

8. Cookies and sessions

Organizer sessions use an HTTP-only session cookie (for example sid) so you stay signed in. We do not currently run third-party advertising or analytics pixels on the marketing site. Attendee pages use tokenized URLs rather than login cookies.

9. Retention

We retain organizer and registration data while the account is active and as needed to provide the Service. A retention job exists to identify aged cancelled events, cancelled registrations, and webhook payloads, but automatic hard deletes are not yet enabled. Until deletes ship with legal/product sign-off, data may remain stored longer than published candidate thresholds. You may request deletion via [email protected]; we will process requests as required by applicable law and operational constraints.

10. Your rights

Depending on your role and applicable law, you may have rights to access, correct, or delete personal data, or to object to certain processing.

  • Organizers: authenticated export of account-scoped data via GET /privacy/export (JSON; excludes password hashes and encrypted OAuth secrets). Contact [email protected] for additional requests.
  • Attendees: use the private manage link /r/{token} to cancel, edit details where supported, or opt out of WhatsApp reminders. For broader requests, contact the event organizer or [email protected].

11. Security

We use industry-standard measures such as encrypted storage of OAuth refresh tokens, HTTPS in production, and access controls. No method of transmission or storage is completely secure; please use a strong password and protect manage links.

12. Children

The Service is directed to organizers running events. It is not intended for children under 16 to create accounts. If you believe we have collected personal data from a child inappropriately, contact [email protected].

13. Changes

We may update this Privacy Policy from time to time. The "Last updated" date at the top will change when we do. Material changes may be highlighted in the product or by email where appropriate.

14. Contact

Privacy questions and requests: [email protected]. Operator: Viral Engine. Jurisdiction: India. Public copy of this policy: https://invy.viralengine.in/privacy.