EventSmart Privacy Policy
How EventSmart handles local business records, optional cloud tools and client sharing.
This policy explains EventSmart's local-first design, connected services, public links and practical privacy choices for event professionals and their clients.
Overview
Blue Sparrow is a solo developer based in India and operates EventSmart, a local-first workspace for event inquiries, customers, planning, quotes, invoices and event-day execution. This policy explains what the mobile app, EventSmart backend, public client pages and connected providers handle, why the information is used and the choices available to you.
EventSmart can be used locally without an account. Core records are written to an app-private Drift database and files on your device. Account, cloud sync, restore, team, hosted-file, public-link, email, notification and subscription features are separate connections used only when configured or requested.
EventSmart is designed around data minimisation, purpose limitation and transparency, including the protections of the EU General Data Protection Regulation where it applies. Compliance also depends on operators using EventSmart lawfully when entering information about their clients, venues, staff and event guests.
Data we handle
Depending on the features you use, EventSmart may handle:
- Local business profiles, including business and owner names, contact details, currency, tax labels, logos, service settings and payment-instruction profiles.
- Customer and inquiry information, such as names, organisation, email addresses, phone numbers, source, budgets, requested dates, preferences, follow-up details and private or client-visible notes.
- Event and venue information, including event type, dates and times, addresses, contacts, access and loading details, parking, power, dimensions, weather considerations, schedules, private notes and client-visible notes.
- Operational records such as tasks, timelines, checklists, materials, recipes, templates, activity history, team roles and assignments.
- Quote, invoice and payment records, including line items, amounts, tax labels, discounts, document status, manual payment entries, external payment instructions, bank or UPI details that you add, QR content and generated PDFs. EventSmart does not receive a client's full payment-card details and does not process client payments.
- Images and files deliberately imported through the platform file or image picker, together with filenames, types, sizes, captions, hashes, local paths, thumbnails, upload state and whether the operator marks an item client-visible.
- Optional account data from Google and Firebase Authentication, including Firebase identifier, email, display name and profile-image URL.
- Optional backend account, workspace and device information, including a generated device identifier, app version, platform, timezone, notification permission state, encrypted FCM token, sync cursors, changes, conflicts, idempotency records and entitlement state.
- Optional team invitations and membership data, including email address, display name, workspace role and status.
- Purchase information handled by Google Play and RevenueCat, including product, offering, transaction, receipt, subscription, renewal, expiry and entitlement state. Blue Sparrow does not receive your full store payment credentials.
- Public-link snapshots, link token hashes, permitted sections, creation, expiry, revocation and last-viewed times. A recipient may provide a name, response such as approve, decline or acknowledge, and a comment.
- Support or feedback content you submit, including request type, subject, message, rating and reply email. Invoice-email features may handle the recipient, an immutable invoice PDF, an optional payment QR image, a hosted link and delivery status.
- Technical and security records such as request identifiers, rate-limit events, audit events, delivery attempts and failures. EventSmart Crashlytics is enabled for non-debug builds and may receive crash, device, operating-system and app-state information needed to diagnose failures.
EventSmart removes Android advertising-ID permission and does not use information to build a cross-app advertising profile. The current app does not request direct location, contacts, microphone or camera permission. A system picker or another app you choose for importing, opening or sharing a file applies its own permission and privacy behavior.
How we use data
Information is used as reasonably necessary to:
- Save and present the event-business workflow, including inquiries, customers, venues, event briefs, quotes, invoices, schedules, files and event-day work.
- Generate PDFs, exports, summaries and external payment instructions requested by the operator.
- Authenticate an optional account, establish a workspace and provide requested sync, restore, attachment, team and entitlement features.
- Create selected public snapshots, record link activity and deliver recipient responses back to the operator's workspace.
- Register notification devices, deliver or present service and sync updates, and schedule local reminders chosen by the operator.
- Process and restore purchases, apply plan limits and keep subscription access associated with the correct account.
- Send support or feedback requests and operator-requested invoice emails.
- Protect accounts and infrastructure, limit abuse, investigate faults, maintain reliability and satisfy applicable privacy, security and record-keeping requirements.
Blue Sparrow does not sell or rent personal information and does not use operator or client records for targeted advertising. EventSmart does not include the Firebase Analytics Flutter SDK in the audited build and does not intentionally send event-business records as analytics events. Crashlytics collection is enabled in non-debug builds; operators should avoid putting unnecessary sensitive information into fields that might appear in an error context.
Cloud and backups
Local mode writes core records to the device first. Android backup is disabled in the EventSmart application manifest. An operating system, device manufacturer or user-selected file destination may still affect copies that the user independently exports or shares.
When a signed-in operator enables eligible cloud features, EventSmart sends selected local changes through its authenticated API to a PostgreSQL-backed workspace. Sync can include business profiles, customers, inquiries, events, venues, quotes, invoices, payment records and instructions, tasks, materials, templates, attachment metadata, share-link records and related operational data. Eligible files can be uploaded separately using time-limited signed URLs. Restore can download supported cloud records to a device.
Blue Sparrow-controlled synchronized content and backups are intended to remain in European Union infrastructure. Production datacentre, file-storage and backup-region evidence has not yet been completed, so this statement is an operational commitment rather than a claim that every copy is currently verified in a particular EU city or facility. Firebase, RevenueCat, Google Play, push and communication providers have separate global processing boundaries.
Cloud sync and restore are convenience features, not the sole copy to rely on for irreplaceable business records. Operators should review exports and retained source documents appropriate to their business. Local work can continue when a connected service is unavailable, but pending changes, public pages, email, team updates and cross-device restore require the relevant connection.
Public links
An eligible operator can create a token-bearing public link for a quote, invoice or event summary. The backend stores a fixed snapshot containing selected client-visible information. Depending on link type, this can include business and customer contact details, event dates and notes, venue name and address, visible tasks and attachment descriptions, quote or invoice lines and totals, payment instructions and QR content.
Anyone who obtains a working link can view its snapshot without signing in until the link expires or is revoked. A quote recipient may approve, decline or comment; an invoice recipient may acknowledge or comment. A name, action, comment and time may be stored, synchronized to the operator and visible to another holder of the same public token because the public response payload is returned with the snapshot.
Opening a valid link updates its last-viewed time, and a token-derived rate-limit key is stored to control repeated access. The audited frontend does not currently set an explicit no-index directive, so operators must not treat the link as guaranteed to be hidden from search systems. Share only the minimum necessary information, send the link through an appropriate channel, set an expiry where suitable and revoke it when access is no longer needed.
Retention
Local records and files remain until changed or deleted in EventSmart, cleared through device settings, or removed with the app. Generated exports and PDFs remain wherever the operator saved or shared them and must be managed there separately.
Cloud records are retained while needed to provide the connected workspace and until deleted, subject to short-lived operational copies, security records, delivery records, backups and any retention reasonably required for an applicable obligation. Public snapshots and recipient responses remain until their workspace data is deleted; expiry or revocation stops normal link access but is not described as immediate record erasure. Provider-held identity, purchase, notification and diagnostic information follows the relevant provider's retention controls.
The in-app account-data action first requests deletion of the signed-in EventSmart backend workspace, then signs out and clears supported local database records and app files only after the backend request succeeds. It does not delete the Firebase Authentication identity, a conditionally enabled Firestore mirror, RevenueCat or Google Play purchase records, store subscriptions, Crashlytics records, already delivered emails, recipient copies or exports saved elsewhere. The backend retains limited account-deletion audit information. Current production verification is still required for physical uploaded-file cleanup and the end-to-end backend deletion transaction. Contact [email protected] for a broader request and use provider controls where direct action is required.
Security
EventSmart uses proportionate safeguards including app-private local storage, HTTPS, Firebase authentication tokens, workspace membership checks, sync versioning, hashed public-link tokens, expiring signed file URLs, encrypted FCM tokens, request limits and restricted backend access. Public snapshots are assembled from selected fields, and private venue access notes are excluded from the current event-summary snapshot mapper.
The local Drift database and locally imported files are not described as independently encrypted by EventSmart. Device-lock and operating-system protections are therefore important. Public links are bearer-like credentials rather than private account sessions, and external payment details can be sensitive. No device, transmission or service can be guaranteed completely secure.
Operators should protect devices and accounts, keep the app updated, use client-visible controls carefully, verify recipients, avoid unnecessary sensitive notes and revoke links or team access when no longer required. Report a suspected account or privacy issue to [email protected].
Your rights
Depending on where you live and subject to applicable exceptions, you may have rights to know or access personal information, correct it, receive a portable copy, delete it, restrict or object to processing, and withdraw consent where consent is the basis. You may also contact your local privacy regulator. These protections include, where applicable, the EU GDPR and EEA rules, UK GDPR, India's Digital Personal Data Protection framework, California and other US state privacy laws, Brazil's LGPD, Canada's privacy laws and comparable regional rules.
Operators can view and edit many records in the app, export supported local data, change notification choices, revoke public links, sign out and use the account-data deletion action. Google Play controls subscription cancellation. A client, attendee or other person whose information was entered by an EventSmart operator should normally contact that business first; Blue Sparrow will assist the operator where required.
To exercise a privacy right concerning Blue Sparrow-controlled information, email [email protected] with EventSmart and enough detail to locate the relevant account or request. Blue Sparrow may request proportionate verification and will respond within the period required where you live. Ordinary requests are not charged, while clearly excessive or repeated requests may be handled as applicable rules permit.
Children
EventSmart is intended for event professionals and business operations, not for children to create accounts or operate workspaces. An operator may nevertheless record information about a family event, student event or attendee. The operator is responsible for limiting that information, having an appropriate basis and obtaining any permission required from a parent, guardian, venue or organisation.
Do not use public links to expose unnecessary information about a child. Contact the relevant event business first about information it entered, or [email protected] if you believe children's personal information is being handled inappropriately through the service.
International transfers
Local information remains on the operator's device unless a connected, export or sharing action is used. Blue Sparrow-controlled synced content is intended for EU infrastructure, subject to the production-evidence limitation explained above. Blue Sparrow is operated from India, and necessary operational access may occur from India.
Google, Firebase, RevenueCat, Google Play, push, communication and user-selected sharing providers may process limited information outside the operator's or client's country. Where transfer safeguards are required, Blue Sparrow and relevant providers rely on appropriate contractual, adequacy or other lawful mechanisms and apply data-minimisation and security measures.
Blue Sparrow does not claim that every item of EventSmart information always remains in the European Union. EU users retain the protections required by the EU GDPR while provider-controlled identity, purchase, notification, diagnostic and communication data follows each provider's disclosed infrastructure and safeguards.
Changes
This policy may change as EventSmart, its public pages, providers or applicable requirements evolve. Material changes will be explained through the app or https://bluesparrow.dev where appropriate, and the updated date will be revised. A new choice will be requested when required.
Contact
Blue Sparrow is the developer and privacy contact for EventSmart. For privacy questions, rights requests or account-data deletion, email [email protected]. For general questions, email [email protected]. Current product and policy information is available at https://bluesparrow.dev.