EventBox Legal
Privacy Policy
This Policy explains what information EventBox processes, why it is used, when it is shared and the choices available to organizers, staff, guests and customers.
Effective September 16, 2026 · Version 2026-09-16
1. Scope and roles
This Policy applies to EventBox services operated by AXFusion Solutions. For organizer account and platform-administration data, AXFusion Solutions determines how the information is used. For guest and attendee information entered by an organizer, the organizer generally determines the event purpose and AXFusion Solutions processes that information to provide EventBox.
2. Information we collect
- Account information: name, email, organization, authentication status and team role.
- Event information: event details, tickets, seating, guest lists, guest admission source, media, sponsors, polls, merchandise and operational settings.
- Transaction information: order details, amounts, payment status, refunds, payout references, EventBox and processor fee records, receipt information and limited payment metadata. Complete card numbers are handled by Stripe or Square, not EventBox.
- Promotion information: ticket promotion codes, eligibility rules, quantity thresholds, EventBox event-specific commercial terms, applied discounts and redemption records.
- Connected payment information: Stripe or Square connected-account identifiers, merchant location, device, account-capability and verification status, payout-account display details and transaction references needed to operate EventBox Pay. Identity-verification documents and raw bank-account details are collected securely by the selected processor rather than stored by EventBox.
- Guest and auction activity: ticket identifiers, Event Pass delivery, check-in, purchases, votes, bidder registration details, event-specific bidder numbers, bids, winner records, payment and fulfillment status, Smart Pickup pass identifiers and collection audit events. Public auction registration may collect a bidder's name, email address and mobile number and process a time-limited verification challenge sent to that email address.
- Technical information: device, browser, network, request-rate, session, log, security and diagnostic information generated when the service is used. EventBox may derive non-public security keys from this information to enforce short-term abuse limits.
- Communications: the name, reply email, support category, event or order reference and message submitted through the EventBox contact form or otherwise sent about EventBox.
- Free Invitation information: invitation title, occasion, hosts, date, time, location, message, uploaded photo, expected guest count and the RSVP name, email address, response, party size, meal preference and optional message submitted by a recipient.
- Event Flyer information: event logo and banner, flyer category, design and text, public flyer link, selected guest journey, reservation capacity and the name, email address, response, party size, meal preference, attendee or exhibitor classification, business details and optional message submitted for a reservation, RSVP, pre-checkout registration or advance ticket interest form.
3. How information is used
We use information to:
- Provide accounts, events, tickets, payments, check-in, table assignments and other requested features, including seating notifications for guests added by an organizer.
- Authenticate users and enforce permissions and event isolation.
- Process transactions, payouts, refunds and financial reconciliation.
- Assign event-specific bidder numbers, operate live auctions, announce winners and produce organizer auction reports.
- Send operational emails such as account verification and password reset, organizer-initiated incomplete ticket-purchase reminders, ticket and QR delivery, payment, receipt, seating assignment, organizer-entered venue-change updates, event-date reminders and paid auction Smart Pickup messages. EventBox may automatically send a verification email after a successful password sign-in when an organizer's email address still requires verification.
- Prevent fraud, abuse, duplicate activity and security incidents.
- Maintain, troubleshoot and improve reliability and user experience.
- Receive, route, retain and respond to support requests, prevent contact-form abuse and maintain a record of delivery and resolution.
- Allow specifically authorized AXFusion Solutions support administrators to resolve organizer or customer requests, investigate payment status and maintain event-specific commercial terms. Event access and commercial-term changes are logged.
- Comply with law and enforce our agreements.
- Create and display Free Invitations, enforce their guest limits, record or update RSVPs and provide the creator with private RSVP management and export tools.
- Create and display organizer Event Flyers, direct paid-event guests to ticket checkout, collect an organizer-selected pre-checkout registration or advance ticket interest response, link a successful ticket purchase to that registration, enforce free-event reservation capacity, add ticketless attending parties to the applicable event guest list for seating, and provide authorized event organizers with private reservation tracking and operational follow-up tools.
4. How information is shared
We may share information with the organizer responsible for the event; authorized organizer team members; guests when necessary to provide an event experience; and service providers that operate EventBox. Key providers include Stripe and Square for payment and connected-account services, Google Firebase for authentication, database and storage, Vercel for application hosting, and communications providers used to deliver event messages.
During a live auction, EventBox may display an event-specific bidder number, bid amount, bid count and winner number to other participants or on a shared room display. The shared display does not show the bidder's name, email address or mobile number. The bidder can see their own registration details where applicable, and the organizer and authorized event team members can access bidder identity and auction history for administration, payment, fulfillment, safety and dispute resolution.
After an auction item is recorded as paid, EventBox may email the winner a unique QR code and short code for item collection. Authorized organizer staff can scan or enter that pass to view the associated winner, item and payment status and to record a one-time handoff. Pickup identifiers and collection audit details are shared only as needed to complete and document fulfillment.
Public donation displays use aggregate campaign information such as the contribution count, amount raised, goal and percentage reached. They do not display donor names, email addresses or individual donation records. Organizers may add guests whose admission was arranged outside EventBox and may use the guest's email address to send a table or seat assignment without issuing a second EventBox ticket.
A Free Invitation's event details, message and uploaded photo are visible to anyone with its public link. RSVP identities are not included in that public response. The invitation creator can access RSVP names, email addresses, party sizes, meal preferences and messages using the separate private management link. The creator is responsible for keeping that link confidential. EventBox does not send a Free Invitation or RSVP email as part of the initial free invitation service; creators choose how to share the public link or QR code.
A published Event Flyer's event details, logo, banner and organizer-supplied message are visible to anyone with its link or QR code. Reservation and registration identities are not returned by the public flyer API. They are available only to the event owner or an authorized event administrator through the authenticated event workspace. For ticketless events, attending party members may also appear in that event's private guest and seating tools. For paid events, a flyer may open checkout directly or collect guest details before checkout or a later sale; the flyer form does not itself collect or expose payment-card details.
We may also disclose information when required by law, to protect people or the platform, in connection with a business transaction, or with your direction or consent. We do not sell personal information for money.
5. Organizer obligations
Organizers must provide appropriate notices to their attendees and bidders, collect only information needed for the event, configure public displays responsibly, limit team access, respond to guest privacy requests and comply with applicable privacy, marketing and communications laws. Organizers must not publicly disclose a bidder's identity unless they have an appropriate legal basis or permission. Questions about an organizer's event-specific practices should first be directed to that organizer.
6. Browser storage and similar technologies
EventBox and its providers may use cookies, local browser storage and similar technologies that are necessary for authentication, security, checkout, preferences and service operation. Auction pages may store an event-specific Event Pass reference or random bidder-session token so the bidder can remain verified across auction items in the same browser. A bidder session expires after a limited period, and a different browser or device may require verification again. Public Live Vote uses a secure, server-signed, event-specific browser cookie to prevent that browser session from voting more than once in the same poll; client-side storage may be used to initialize or remember the public voting experience, but a value supplied by the browser is not accepted by itself as proof of voting identity. The voting-session cookie is not available to page scripts. Public voting does not require a voter name or email unless an organizer separately requires an Event Pass. Browser settings may allow you to remove stored information, but doing so can sign you out, require bidder verification again or create a new public voting session.
EventBox stores the English or French language preference in first-party browser storage and a preference cookie so the selected interface language persists across pages and future visits. EventBox performs interface translation from its own catalog and does not send page, guest or payment information to an external translation service for this feature.
The Free Invitation creator's browser may store the most recently issued private management URL so the creator can return to the RSVP dashboard. That URL contains a secret in its browser fragment, which is not sent in ordinary page requests; the invitation manager sends it to EventBox only in a protected request header. Clearing browser storage or losing that complete link can prevent the creator from returning to the invitation manager.
7. Retention and Media Vault
We retain information for as long as reasonably necessary to provide EventBox, maintain financial and audit records, resolve disputes, protect security and comply with legal obligations. Retention can vary by record type and organizer instructions. Information may remain in protected backups until those backups are replaced under standard retention cycles.
Event media retention depends on the organizer's displayed plan and event date. Unless a different date is shown, Standard event media is normally available through the event and for 30 days afterward, followed by a 7-day recovery period. Media protected by an active paid Media Vault is normally retained while the subscription remains active and within its allowance; after cancellation or expiration, a 30-day read-only recovery period normally applies. Premium recovery reminders may be sent approximately 30 days, 7 days and 24 hours before eligible permanent deletion, followed by a deletion confirmation. Media is not deleted while its event is actively taking place. Automated deletion is not activated for an account until EventBox can determine and display the applicable retention date.
EventBox records media usage information such as file type, byte size, image dimensions, organizer and event ownership, storage path, event references, creation and last-update timestamps, retention status and subscription entitlement. This information is used to enforce allowances, preserve organizer isolation, prevent deletion of referenced assets, calculate storage usage and operate recovery and deletion workflows. Removing an active-system file may not immediately remove encrypted or protected backup copies, which expire under normal backup cycles.
When an authorized organizer resets a vote, EventBox removes the poll's individual ballot records and live counter records from active systems and returns its displayed totals to zero. EventBox may retain a limited reset audit record containing the poll identifier and title, previous total ballot count, authorized organizer account and reset time for security, accountability and dispute resolution. That audit record does not retain each voter's selected candidate.
Unless a different date is displayed, a Free Invitation, its uploaded photo and its RSVP records become eligible for permanent deletion 30 days after the invitation's event date. Limited security, abuse-prevention or backup records may remain for their normal retention periods. Invitation creators should export RSVP information before the deletion date if they need to keep it.
8. Security
We use administrative, technical and organizational safeguards designed to protect information, including encrypted transport, authentication, access controls, token-revocation checks, server-side request validation, rate controls and service monitoring. Public display responses are limited to information needed for the display, while organizer controls require an authorized account. No system can guarantee absolute security. Users should protect their credentials and report suspected unauthorized access promptly.
9. Your choices and privacy requests
Depending on applicable law, you may have rights to request access, correction, deletion, portability or restriction of certain personal information, or to object to certain processing. We may need to verify your identity and may direct event-specific requests to the responsible organizer. Requests can be sent to info@axfusionsolutions.com.
10. Children
EventBox organizer accounts are not intended for children. Organizers are responsible for obtaining any consent required before submitting information about minors or operating events directed to children.
11. International processing
EventBox and its providers may process information in the United States and other countries where they operate. Those locations may have different data-protection rules than your location.
12. Policy updates and contact
We may update this Policy as EventBox changes. The effective date and version identify the current policy. For privacy questions or requests, contact info@axfusionsolutions.com.