Home / Security
Security
Eventnet is built to keep your account, payments, and personal data safe. Here's how we protect the platform, and how to reach us if you spot a problem.
Last updated: August 2026
1. Account Security
- Login is OTP-based — we never store or ask for account passwords over chat, email, or phone
- Every OTP is time-limited and single-use, with rate limits to block brute-force attempts
- Sessions are scoped per device; you can be logged in on multiple devices, and each session is independently revocable
- Role-based permissions restrict what admin and executive staff can see and do — no single login has unrestricted access to customer or vendor data
2. Payment Security
- All payments are processed by Razorpay, a RBI-authorised payment aggregator — Eventnet never sees or stores your card, UPI PIN, or net-banking credentials
- Card and bank details are handled entirely within Razorpay's PCI-DSS compliant infrastructure
- Eventnet only stores payment status, amount, and a transaction reference — never raw payment instrument data
- Refunds are issued back to the original payment method through Razorpay's refund APIs
3. Vendor Verification
- Vendors submit business and identity documents (such as Gumasta, GST, MSME, PAN, FSSAI, or address proof) during onboarding, reviewed manually by our operations team
- Verified vendors are marked accordingly on their public profile; unverified listings are clearly distinguishable
- We monitor vendor performance — cancellation rate, response time, and customer complaints — and can suspend accounts that violate platform guidelines
4. Data Protection
All traffic to Eventnet is encrypted in transit over HTTPS. Data is stored on Supabase (hosted on AWS infrastructure) with row-level access controls, private storage buckets for sensitive documents, and audit logging on administrative actions. For a full breakdown of what we collect and how we use it, see our Privacy Policy.
5. Fraud & Abuse Prevention
- Automated checks flag unusual booking, payment, or messaging patterns for manual review
- Contact details between customers and vendors are only shared once an enquiry is unlocked or a booking is confirmed, reducing spam and scraping
- We act on reports of fake listings, impersonation, or off-platform payment requests that bypass our booking protections
6. Reporting a Security Issue
If you discover a vulnerability, suspicious activity, or a security concern involving Eventnet, please report it to security@eventnet.in. Include as much detail as you can (steps to reproduce, screenshots, affected account) so we can investigate quickly. Please do not publicly disclose a vulnerability before we've had a chance to address it.
7. Changes to This Page
We may update this page as our security practices evolve. Material changes will be reflected here with an updated "Last updated" date.