
Loading

Loading
Legal
Last updated 13 August 2026
When you use ScanMyPass, you are trusting us with your information. This page explains what we collect, why we collect it, who else gets to see it — organisers especially — and how you can review, correct or delete it. Written to be read, not to be impenetrable.
ScanMyPass lets organisations and clubs publish events, issue tickets, and check attendees in at the door. We understand that handing over your name, your number and your payment is a big responsibility, and we work to protect that information and keep you in control of it. What we collect, and how it gets used, depends on how you use the service — as someone buying a ticket, or as someone running an event.
For anything in this policy, including a request to see or delete your data, write to info@scanmypass.com.
For the personal data you give to ScanMyPass itself, we are the Data Fiduciary under India's Digital Personal Data Protection Act, 2023 (“DPDP Act”), and the body corporate responsible under the Information Technology Act, 2000 and its rules.
For the data an organiser receives about you when you register for their event, that organiser is responsible in their own right. Section 4 explains exactly what they get and what that means for you. It is the most important section on this page — please read it before you register for anything.
Information you create or give us. When you create an account, register for an event, or list one:
Information we collect as you use ScanMyPass.
We never collect or store your card number, CVV, UPI PIN, or bank credentials. Those are entered on Razorpay's own checkout and never reach our servers.
Under the DPDP Act we rely on your consent, given when you create an account or register for an event; on the legitimate uses the Act permits, including data you voluntarily gave us for a purpose you would reasonably expect; and on legal obligation for tax and financial records. You can withdraw consent at any time, as easily as you gave it, by writing to info@scanmypass.com. Withdrawing it does not undo processing already carried out lawfully, and we may still have to keep records the law requires us to keep.
Registering for an event means handing your details to whoever is running that event. That is not a side effect; it is the point. An organiser cannot admit you at the door, seat you, cater for you, or contact you about a change of venue without knowing who you are. So when you register, understand that you are choosing to give your information to that organiser, and that the decision to register is yours.
For every event you register for, that organiser can see and use:
Once this data reaches an organiser it is on their systems and outside our technical control.
This means, in plain terms: the organiser holds their own copy of your data and is responsible for it. They decide independently what they do with it. Our terms of use require them to handle it lawfully, to use it only for running their event, and forbid them from selling it — but their internal privacy practices are theirs, not ours.
What an organiser cannot see: your card, UPI or bank credentials; your account password; anything about events you registered for with a differentorganiser. Each organisation is separated at the database access layer, so one organiser cannot read another's attendees, orders or revenue.
If you want an organiser to delete what they hold about you, contact that organiser directly. If you cannot reach them, write to us and we will help.
ScanMyPass has no public user profiles. There is no username, no avatar and no follower list for anyone to find, and search engines cannot index you as an attendee.
We never sell your personal data. We share it only in these cases:
Some providers process data outside India. Where that happens we rely on the DPDP Act's permission to transfer personal data outside India, except to countries the Central Government has restricted.
We protect your information with strong, industry-standard encryption — in transit between your device and our servers, and at rest for the most sensitive things we hold. Passwords are never stored in a form anyone can read back, and organiser bank details stay encrypted until the moment a payout is actually being executed.
Alongside encryption:
We keep these measures under review and strengthen them as standards move, including as guidance on post-quantum cryptography matures.
No system is perfectly secure. If a breach affects your personal data we will notify affected users and the Data Protection Board as the DPDP Rules require, including a detailed report to the Board within 72 hours.
When data is no longer needed for any of these purposes we delete it or irreversibly anonymise it. Deleting your ScanMyPass account does not reach copies an organiser already holds — for those, contact the organiser.
Under the DPDP Act you have the right to:
To exercise any of these, write to info@scanmypass.com. We will respond within 30 days, and in any case within the 90 days the DPDP Rules allow. We may ask you to verify your identity first, so we do not hand your data to someone else. If you are unhappy with our response you may complain to the Data Protection Board of India.
We use a small number of cookies that are necessary for the service to work, principally to keep you signed in. We also use Google Analytics to understand overall traffic and how the site is used, which sets its own cookies. We do not use advertising cookies and we do not build advertising profiles of individual visitors. Blocking essential cookies will stop you being able to sign in.
We send transactional email — sign-in links, tickets, receipts, and messages about events you registered for. We do not add you to marketing lists without asking, and any marketing email we do send has a way to unsubscribe.
An organiser may contact you about their own event using the details they received under section 4. If you would rather they did not, tell them, or tell us and we will pass it on.
We do not knowingly collect data from children under 18. If you believe a child has given us data, write to info@scanmypass.com and we will delete it.
If we change this policy the “last updated” date at the top changes, and we will give notice of material changes by email or in the product.
Questions, requests or complaints about privacy: info@scanmypass.com. For anything about a specific event, the organiser who published it is the faster route — see contact.