Privacy Policy
Last change: 5 October 2026
What pavoot.events and the Pavoot Events app collect, why, who sees it, and how you stay in control. For pavoot.com, see its own policy.
Contents
1.Who we are
pavoot.events and the Pavoot Events app are run by Pavoot Inc., San Francisco. For the GDPR, the UK GDPR and the Swiss FADP, we are the controller of the data described here.
When you register for an event, the host of that event also receives your registration and is responsible for how they use it. Where the host runs the event on the Pavoot platform, we process that registration on the host's behalf under our Data Processing Agreement.
2.What we collect
You give us
- Account: your email address, verified with a one time code. If you sign in with another account, such as Google, we receive the name, email and picture it shares.
- Profile, all optional: name, company, LinkedIn, city, interests, the roles you are open to, days you are free, social handles and a profile photo.
- Registrations: your answers to the host's questions, and your status (going, waitlisted, checked in).
- Interest in ideas: the role you offer, preferred city, time and format, sponsor amounts, photographer prices, conditions and messages.
- Ideas you pitch, and messages you send us.
- Saved searches and alert signups, including your email if you sign up without an account.
We collect automatically
- Log data: IP address, browser and device type, pages requested, times and errors. We use it to run and secure the Service.
- Whether our emails were delivered.
We do not use Google Analytics, advertising pixels or tracking across other sites and apps, and we do not collect precise location, health data or payment card numbers.
3.How we use it
- To provide the Service (contract, Art. 6(1)(b) GDPR): your account, registrations, tickets, ideas you back, saved searches and the emails you asked for.
- To match you with events (contract, and legitimate interest, Art. 6(1)(f)): ranking events and ideas by your profile and preferences.
- To build events people want (legitimate interest): deciding which ideas to schedule, and inviting people whose profile fits.
- To keep it safe (legitimate interest): preventing abuse, fraud and spam, and fixing errors.
- With your consent (Art. 6(1)(a), and Art. 9(2)(a) for face matching): alerts about new rooms and finding you in event photos. You can withdraw consent at any time.
- To meet legal duties (Art. 6(1)(c)): tax, accounting, and lawful requests from authorities.
5.Service providers
- Amazon Web Services: hosting and database (United States)
- Supabase: file storage, such as profile photos (United States)
- Clerk: sign in and account security
- OpenAI: ranking events for personalized search
- Resend: sending emails
- Stripe: ticket payments
- Apple: distributing the iOS app
Events run on the Pavoot platform also use the providers in our Data Processing Agreement.
6.AI
Personalized search sends what you searched for (role, cities, dates, formats, topics) and a short list of events to OpenAI, which ranks them and writes one line on why each fits. Nothing that identifies you is sent, and it is not used to train AI models. AI only suggests: it never decides on its own whether you get into an event.
7.Photos and face matching
A profile photo is optional. Hosts of events you engage with see it next to your name.
“Find me in event photos” lets us compare your profile photo with photos from events you attend, so we can send you yours. That comparison uses biometric data, so we only do it with your consent, only for events where Pavoot handles the photos, and you can turn it off at any time in your profile. Removing your photo or turning the switch off stops matching and deletes the face data derived from your photo.
8.Emails
We send emails you need, such as sign in codes, registration confirmations and changes to events you joined. Alerts about new rooms and matches for saved searches are optional: switch them off in My rooms or with the link in any alert.
10.Security
Data is encrypted in transit and at rest, access is limited to people who need it, and payments go through Stripe. No system is perfectly secure, so we cannot guarantee absolute security. Details on our Security page.
11.How long we keep it
- Account and profile: until you delete your account. We then delete it from live systems within 30 days and from backups within 90 days.
- Registrations: as long as the host keeps the event, under their own retention rules.
- Interest you withdrew: kept as withdrawn, so we do not contact you again for it, until you delete your account.
- Alert signups: until you unsubscribe.
- Logs: as long as needed for security and abuse prevention.
- Payment and tax records: as long as the law requires.
12.International transfers
Pavoot is based in the United States, where your data is stored. When data leaves the EU, the EEA, the UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses, with the UK addendum and Swiss amendments where they apply, and assess each transfer.
13.Your rights
Depending on where you live, you can:
- see the data we hold about you, and get a copy in a portable format;
- correct it (most of it you can edit yourself in My rooms);
- delete it, or your whole account;
- restrict or object to how we use it;
- withdraw consent you gave, without affecting earlier use;
- not be subject to decisions made only by automated means;
- under California law, know what we collect and not be discriminated against for using these rights. We do not sell or share data for cross context behavioral advertising.
Write to hello@pavoot.com. We answer within the time the law requires, usually one month. To delete data a host holds, contact the host, or ask us and we pass it on. You may also complain to your data protection authority (in Switzerland, the FDPIC).
14.Other websites
Events listed from other platforms, such as Luma or Partiful, open on their sites. What you give them is covered by their privacy policies, not this one. The same applies to maps, videos and any links we show.
15.Google data
If you sign in with Google, our use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to train AI models.
16.Children
The Service is not for anyone under 16, and we do not knowingly collect their data. If you believe a child gave us data, contact us and we will delete it.
17.Changes
We may update this policy. The date at the top shows the latest version. If a change is material, we tell you by email or in the Service before it takes effect.
18.Contact
2261 Market Street STE 76439
San Francisco, CA 94114
United States of America