Privacy Policy
Last updated: 2026-08-03
This Privacy Policy describes how Viral Engine ("we", "us", or "our") collects, uses, and shares information when you use Invy (the "Service") at invy.viralengine.in. By using the Service, you agree to this policy. Related terms are in our Terms of Service.
1. Who we are
The Service is operated by Viral Engine. For privacy requests, contact [email protected]. This policy is intended for use under the laws of India.
2. Roles: controller and processor
Organizers (accounts that create events) are typically the data controllers for attendee registration data they collect for their events. They decide why and how that data is used for their workshops and classes.
Viral Engine / Invy acts as a processor for attendee data processed on an organizer's behalf (for example, ingesting Google Form responses, sending confirmations and reminders, and hosting manage links). For organizer account data (email, password hash, connection metadata), Viral Engine is the controller.
3. Information we collect
Depending on how you use Invy, we may process:
- Organizer account data: name (optional), email, password hash, session cookies, onboarding state, and settings.
- Google connection metadata: connected Google account email, OAuth scopes granted, and connection status. We store encrypted refresh tokens to call Google APIs on your behalf; we do not use your Google data to advertise to you.
- WhatsApp / Meta connection data: WhatsApp Business / Cloud API credentials and phone numbers needed to send template messages you configure.
- Event and registration data: event details, Google Form / Calendar identifiers, registration fields (such as name, email, WhatsApp number, consent), reminder schedules, notification delivery status, and waitlist / feedback records.
- Technical data: IP address and basic request logs for security, abuse prevention, and reliability; webhook payloads from Meta for delivery status.
4. Google APIs and Limited Use
When an organizer connects Google, Invy requests only the OAuth scopes required to run registration automation:
https://www.googleapis.com/auth/forms.body— create and update Google Forms for event registration and feedbackhttps://www.googleapis.com/auth/forms.responses.readonly— read form responses to create registrationshttps://www.googleapis.com/auth/calendar.events— create and manage Calendar events / inviteshttps://www.googleapis.com/auth/gmail.send— send confirmation, reminder, and thank-you emails from the organizer's Gmailhttps://www.googleapis.com/auth/userinfo.email— identify the connected Google account email
Invy's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, do not use it for advertising, and do not allow humans to read it except as needed for security, compliance, or with your explicit consent, or where required by law.
5. WhatsApp messaging and opt-out
If an organizer connects WhatsApp Cloud API (Meta), Invy may send event-related template messages (confirmations, reminders, thank-you notes) to attendees who provided a WhatsApp number and consent, or otherwise as permitted by Meta policies and applicable law.
Attendees can opt out of WhatsApp reminders from their private manage link at /r/{token}. Organizers remain responsible for obtaining any required consent and for complying with Meta's WhatsApp Business / Cloud API policies.
6. How we use information
We use information to:
- Provide, operate, and improve the Service (registration ingest, confirmations, calendar invites, reminders, waitlist, feedback).
- Authenticate organizers, maintain sessions, and secure accounts.
- Troubleshoot delivery failures and show notification health to organizers.
- Comply with legal obligations and respond to lawful requests.
7. No sale of personal information
We do not sell personal information or attendee contact lists. We do not share personal data with third parties for their independent marketing. We share data with subprocessors only as needed to run the Service (for example hosting, database, queue, and Meta/Google APIs when you connect those channels).
8. Cookies and sessions
Organizer sessions use an HTTP-only session cookie (for example sid) so you stay signed in. We do not currently run third-party advertising or analytics pixels on the marketing site. Attendee pages use tokenized URLs rather than login cookies.
9. Retention
We retain organizer and registration data while the account is active and as needed to provide the Service. A retention job exists to identify aged cancelled events, cancelled registrations, and webhook payloads, but automatic hard deletes are not yet enabled. Until deletes ship with legal/product sign-off, data may remain stored longer than published candidate thresholds. You may request deletion via [email protected]; we will process requests as required by applicable law and operational constraints.
10. Your rights
Depending on your role and applicable law, you may have rights to access, correct, or delete personal data, or to object to certain processing.
- Organizers: authenticated export of account-scoped data via
GET /privacy/export(JSON; excludes password hashes and encrypted OAuth secrets). Contact [email protected] for additional requests. - Attendees: use the private manage link
/r/{token}to cancel, edit details where supported, or opt out of WhatsApp reminders. For broader requests, contact the event organizer or [email protected].
11. Security
We use industry-standard measures such as encrypted storage of OAuth refresh tokens, HTTPS in production, and access controls. No method of transmission or storage is completely secure; please use a strong password and protect manage links.
12. Children
The Service is directed to organizers running events. It is not intended for children under 16 to create accounts. If you believe we have collected personal data from a child inappropriately, contact [email protected].
13. Changes
We may update this Privacy Policy from time to time. The "Last updated" date at the top will change when we do. Material changes may be highlighted in the product or by email where appropriate.
14. Contact
Privacy questions and requests: [email protected]. Operator: Viral Engine. Jurisdiction: India. Public copy of this policy: https://invy.viralengine.in/privacy.