Privacy Policy — XPay Events
Last updated: 31 August 2026
1. Who we are
XPay Events (xpay.events) is an event-ticketing service operated by XPay ("XPay", "we"), an Egyptian company. XPay is the data controller for the personal data described in this policy. Contact: info@xpay.app. This policy covers the XPay Events product; XPay's payment services are covered by the privacy notice at xpay.app/legal-privacy.
2. The law this policy follows
We process personal data in accordance with the Egyptian Personal Data Protection Law No. 151 of 2020 ("PDPL") and its Executive Regulations issued by Prime Ministerial Decree No. 816 of 2025, under the supervision of the Egyptian Personal Data Protection Center. Where guests or organizers are located outside Egypt, we apply the same standards.
3. Data we collect
Organizer accounts: name, email address, password (stored as a cryptographic hash — we never see it), organization name and logo, and sign-in metadata.
Guest data entered by organizers: guest name, email address and/or phone number, optional company name, ticket type, and ticket status. Organizers are responsible for having a lawful basis to share their guests' contact details with us.
Ticket and delivery data: ticket QR codes, scan events at event gates, and message-delivery metadata (whether a ticket email or WhatsApp message was sent, delivered, or read — including message identifiers from our providers).
Technical data: authentication cookies for signed-in sessions. The application itself uses no advertising or cross-site tracking cookies. Our public marketing pages may in future use advertising or analytics pixels from ad platforms; if introduced, they will be disclosed here and consent obtained where the law requires it.
4. Why we process it
To operate the service: creating events, registering guests, generating tickets, delivering tickets by email or — where the organizer selects it and the guest has a phone number — by WhatsApp using pre-approved message templates, verifying tickets at the gate, and showing organizers whether each ticket was delivered. We send transactional messages only; we do not use guest data for marketing.
5. Processors we use
Data is processed by these providers under their own safeguards, acting on our instructions:
- Supabase (database and authentication — hosted in the European Union)
- Vercel (application hosting and delivery infrastructure)
- Resend (transactional email delivery)
- Meta Platforms — WhatsApp Business Platform (WhatsApp ticket delivery and delivery receipts)
This involves transferring data outside Egypt to the providers above; we limit what is shared to what each provider needs (e.g. WhatsApp receives the guest's phone number and the ticket message content).
6. Retention
Event and ticket records are kept for as long as the organizer's account is active. Raw message-provider webhook events are deleted after 30 days. Opt-out (suppression) records are kept so that we keep honoring the opt-out.
7. Your rights under the PDPL
Organizers and guests may: know what personal data we hold about them; access and obtain a copy; correct or update it; object to or restrict processing; withdraw consent; and request erasure. To exercise any right, email info@xpay.app from the address concerned (or, for phone-only guests, include the phone number and an event reference). We respond within the periods set by the PDPL and will notify you of any data breach affecting you as the law requires.
8. Data deletion instructions
Guests: ask the event organizer who registered you, or email info@xpay.app with your name and the event; we will delete your guest record, contact details, and tickets unless a legal retention duty applies. Organizers: email the same address from your account email to delete your account and its data.
WhatsApp opt-out: reply STOP to any WhatsApp message from us and you will no longer receive WhatsApp messages from us; the opt-out takes effect immediately and automatically.
9. Security
Access to guest data is scoped per organization; tickets are verified by unguessable tokens; transport is encrypted (HTTPS); message webhooks are cryptographically verified; logs mask phone numbers and tokens.
10. Changes
We will update this page when our practices change; the "Last updated" date above reflects the current version.