Privacy Policy

Last updated: 7 August 2026

Version: privacy_v3

1. Who we are

This ticketing platform is operated by Christ (Deemed to be University) (Christ University Arts & Events), Christ University Campus, Hosur Road, DRC Post, Bengaluru – 560 029, Karnataka, India. This policy explains what personal data we collect when you use booking.christuniversity.in, why we use it, and the rights you have over it.

2. Data we collect

  • Booking details — your name and email address (and phone number, if you provide one).
  • Order information — the events, shows, seats/tickets you select and your order history.
  • Payment status — confirmation of success/failure and a payment reference from our payment provider. We do not receive or store your card number, UPI PIN, or bank credentials.
  • Entry / scan logs — the time and gate at which your ticket QR code is scanned, for access control and fraud prevention.
  • Technical & usage data — device/browser information, and analytics/session identifiers (including cookies) used to run and improve the site.

3. Why we use your data (purposes)

  • To process your order and deliver your ticket.
  • To validate entry at the venue and prevent duplicate or fraudulent scans.
  • To provide customer support and send transactional messages (order and ticket emails).
  • To understand site usage through analytics and to keep the platform secure.
  • To meet legal, accounting and tax obligations.

4. Payment data

Payments are processed by Razorpay, a third-party payment provider. Your card/UPI/bank credentials are entered on and handled by the payment provider and are not stored as raw credentials by Christ University Arts & Events. Please also review Razorpay's own privacy policy.

5. Cookies & analytics

We use necessary cookies/session identifiers to operate checkout, and analytics tools (such as Google Analytics / Tag Manager) to measure usage. Analytics data is used in aggregate to improve the service.

We also use the Meta Pixel in your browser, and Meta's Conversions API on our server, to measure how our advertising performs. The pixel loads only if you have given marketing consent. Separately, when an order is completed, our server reports that purchase to Meta together with a one-way (SHA-256) hashed form of your email address and phone number and your IP address, so that the purchase can be matched to an advert without disclosing your contact details in readable form. Hashing is irreversible — your email address and phone number cannot be recovered from it.

6. Who we share data with

We share the minimum necessary data with: our payment provider (Razorpay) to take payment; our email delivery provider to send tickets and confirmations; venue / event staff for entry validation; and our analytics and advertising measurement providers(Google, Meta) as described in section 5 — with Meta this is limited to hashed identifiers and your IP address, never your name or your seat. We do not sell your personal data. We may disclose data where required by law.

7. How long we keep it

We keep personal data only for as long as the purpose it was collected for is still being served, or for as long as Indian law requires us to keep it — whichever is longer. Where a statute sets the period, the statute governs and we cannot delete the record earlier, even on request.

  • Order, payment and ticket records — retained as accounting records for the period required of books of account under the Companies Act, 2013, and of tax records under the GST and income-tax legislation. This is a legal obligation, not a choice.
  • Consent records — the record of what you agreed to, and when, is kept for as long as the data it authorises, and afterwards for the period in which a claim relating to the transaction can still be brought under the Limitation Act, 1963. Consent records are append-only: a withdrawal is added as a new entry and never erases the earlier agreement.
  • Technical and security logs — retained for at least 180 days within India, as directed by CERT-In under section 70B(6) of the Information Technology Act, 2000.
  • Marketing contact data — kept until you withdraw consent, and erased or anonymised once the purpose is no longer being served, in line with the Digital Personal Data Protection Act, 2023.

Withdrawing consent stops further use of your data for that purpose. It does not delete records we are legally required to keep, such as the accounting record of a completed purchase.

8. Your rights

Subject to applicable law (including India's Digital Personal Data Protection Act), you may request to access, correct, or erase your personal data, withdraw consent, and raise a grievance. To exercise any of these, contact us using the details below and we will respond within the timelines stated in our grievance process.

9. Data-privacy & grievance contact

Grievance Officer – Booking Support musicstudiobookings@christuniversity.in. We acknowledge requests within 48 hours and aim to resolve them within 30 days.