Privacy policy
Last updated August 30, 2026
Ovante LLC (“Ovante”, “we”) runs an event platform: organizations use it to publish event pages, sell tickets, collect donations, and keep a record of their attendees. This page says what information passes through us when they do, and what we do with it.
Two kinds of people use Ovante
Organizers create an account and run events. Attendees register for those events, usually without an account. The distinction matters: attendee information belongs to the organizer whose event you registered for. We store and process it on that organizer’s behalf, and they control how it is used. If you registered for an event and want your information changed or removed, the event’s organizer is the right first call, and we will act on their instruction or on your direct request.
What we collect
- Organizer accounts: name, email address, password (stored as a hash by our authentication provider), organization name and branding, and payment account identifiers from Stripe or PayArc.
- Registrations: the name, email address, and phone number an attendee enters at checkout, their ticket selections, answers to any questions the organizer added, donation amounts, and check-in status.
- Payments: card charges are processed by Stripe or PayArc on the organizer’s own merchant account. Card numbers never touch our servers. We store the transaction record: amounts, fees, refunds, and processor identifiers.
- Email activity: whether emails we send for an organizer (confirmations, receipts, blasts) were delivered, opened, or bounced.
- Basic usage data: the session cookie that keeps you signed in, and standard server logs. We do not run third-party ad trackers.
What we use it for
To run the product: process registrations, send tickets and receipts, show organizers who is coming, and settle payments to the organizer’s own account. We also use aggregate, non-identifying figures (for example, average donation size across the platform) to understand and describe the product. We do not sell personal information, and we do not use attendee lists for our own marketing.
Who else touches the data
We run on a small set of infrastructure providers, each processing data only to provide their service to us: Supabase (database and authentication), Vercel (hosting), Stripe and PayArc (payments), Resend (email delivery), Google Maps (venue address lookup), and Sanity (marketing site content, no customer data). Beyond these, information is shared only with the organizer who collected it, or when the law requires it.
Who at Ovante can see it
Platform administrators can access customer records for support, debugging, and safety. Administrative access requires two-factor authentication, payment credentials are stored so that even administrators cannot read them, and our internal rule is that customer data is opened for a support reason, not browsed.
Retention and deletion
We keep records for as long as the organizer’s account is active, because their transaction history is theirs. Organizers can export everything to CSV at any time and can ask us to close and delete their account. Attendees can ask the organizer, or us directly at support@ovante.app, to delete their personal information; we honor these requests except where a transaction record must be retained for financial or legal reasons.
Security
Data is encrypted in transit and at rest. Access is controlled row-by-row in the database, organizer accounts support two-factor authentication, and payments are handled by processors that are PCI certified. No system is beyond failure; if a breach affects your personal information, we will tell the affected organizers and users promptly.
Children
Ovante accounts are for adults. Organizers may sell tickets for family events, but we do not knowingly collect information from children under 13.
Changes and contact
When this policy changes, the date above changes with it, and material changes will be announced to organizers by email. Questions go to support@ovante.app.