01 Introduction
Welcome to FestNest, operated by FestNest Technologies Pvt. Ltd. ("we", "us", or "our"). FestNest is India's centralized campus event discovery platform, connecting students with hackathons, cultural fests, workshops, sports events, and more across colleges and universities nationwide.
This Privacy Policy explains what personal data we collect when you use FestNest, why we collect it, how we use and protect it, and what rights you hold under the Digital Personal Data Protection Act, 2023 (DPDP Act) and other applicable Indian laws.
By creating an account or using FestNest in any way, you acknowledge that you have read, understood, and agreed to the practices described in this Policy. If you disagree with any part of it, please stop using FestNest and contact us to delete your account.
02 Information We Collect
We collect only the information necessary to provide and improve our services. Here is a plain-language breakdown:
2.1 Account & Profile Data
When you sign up, we collect:
Students
- First name and last name
- Email address (used to create your account)
- College or university name
- Course / branch (e.g., B.Tech CSE)
- Year of study (e.g., 2nd Year)
- Profile photo (if you choose to upload one)
- Phone number (optional)
Organizers
- Organization or college name
- Department or branch
- City of operation
- Contact email address
- Contact phone number
- Profile or organization photo (optional)
2.2 Event & Content Data
- Event details you submit: title, description, category, date, location, prizes, registration fee
- Event poster images and brochure PDFs uploaded when posting events
- Saved events list (events you bookmark on the platform)
- Registration actions (events you register your interest in)
2.3 Technical & Usage Data
We automatically collect certain data when you interact with FestNest:
- IP address and approximate geographic location (city/region level)
- Browser type, device type, and operating system
- Pages visited, features used, and time spent on the platform
- Search queries entered on FestNest
- Error logs and diagnostic data to help us fix problems
- Referring URLs (how you arrived at FestNest)
2.4 Cookies & Similar Technologies
FestNest uses cookies and similar local storage technologies to keep
you logged in (session token stored in localStorage),
remember your preferences, and improve page performance. We do
not use third-party advertising cookies or tracking
pixels. You can clear cookies at any time through your browser
settings; doing so will log you out of your account.
03 How We Use Your Data
We use the data we collect for these specific purposes:
We will never sell your personal data to third parties, use it for profiling unrelated to FestNest's core features, or share it with advertisers.
04 Legal Basis for Processing
Under the Digital Personal Data Protection Act, 2023 (DPDP Act), every organization that processes personal data must have a valid lawful basis. FestNest processes your data on the following grounds:
05 User Consent
FestNest collects your personal data only with your free, informed, and specific consent. Here is how consent works on our platform:
- When you create an account, you are shown this Privacy Policy and must accept it before proceeding. This constitutes your explicit consent.
- For any new type of data use that was not covered when you signed up, we will ask for fresh consent before proceeding.
- You can withdraw consent at any time by submitting an account deletion request to support@festnest.in. We will delete your personal data within 30 days of receiving a valid request.
- Withdrawing consent will not affect the legality of any processing we carried out before you withdrew it.
- Certain limited data (such as event submissions that were publicly listed) may be retained in anonymized or archived form as required by our legal obligations even after account deletion.
06 Data Sharing & Third Parties
We do not sell, trade, or rent your personal data. We share data only with the following trusted service providers who help us operate FestNest, and only to the extent necessary for those services:
All third-party providers are contractually required to keep your data confidential, use it only for the stated purpose, and maintain security standards consistent with applicable law.
We may disclose data to Indian government authorities or law enforcement agencies when required to do so by applicable law, court order, or to protect the safety of our users. We will, where legally permitted, notify affected users of such disclosures.
07 Data Retention
We keep your personal data only for as long as necessary to provide the service and meet our legal obligations. Here is our retention schedule in plain language:
08 Your Rights Under the DPDP Act
The Digital Personal Data Protection Act, 2023 grants every Indian data principal (that's you) a set of enforceable rights over your personal data. We are committed to honoring these rights promptly and without making the process unnecessarily difficult.
09 Data Security
Protecting your personal data is a core responsibility we take seriously. We implement the following security measures:
- All data in transit is encrypted using TLS/HTTPS โ your browser shows a padlock icon when connected to FestNest.
- Passwords are hashed using bcrypt with a strong salt factor. We never store plain-text passwords.
- Authentication uses industry-standard JSON Web Tokens (JWT) with defined expiry periods.
- Firebase Authentication handles sign-in sessions using Google's security infrastructure.
- Access to production databases is restricted to authorized personnel only, with role-based access control.
- We perform periodic security reviews and promptly apply security patches.
- File uploads (event posters, brochures) are stored on Cloudinary with access controls to prevent unauthorized retrieval.
Despite our best efforts, no system is completely invulnerable. We encourage you to use a strong, unique password for your FestNest account and to log out of shared devices.
10 Children's Privacy
FestNest is designed for college students and event organizers. Our platform is not intended for children under the age of 18. We do not knowingly collect personal data from anyone below the age of 18.
Under the DPDP Act, 2023, processing personal data of children requires verifiable parental consent. If we discover that a user under 18 has created an account without parental consent, we will delete that account and all associated data immediately.
If you are a parent or guardian and believe your child has created a FestNest account, please contact us at support@festnest.in and we will act promptly.
11 Changes to This Privacy Policy
We may update this Privacy Policy from time to time as our platform evolves, we add new features, or legal requirements change. Here is how we handle changes:
- We will update the "Last Updated" date at the top of this page whenever we make changes.
- For material changes (those that meaningfully affect how we use your data or your rights), we will notify you via email at the address associated with your account at least 14 days before the changes take effect.
- For minor changes (grammar corrections, clarifications, non-material updates), we will update the page and you will be notified on your next login.
- If you continue to use FestNest after a policy update takes effect, it means you accept the updated terms. If you do not agree, you can request account deletion before the effective date.
12 Contact & Grievance Redressal
We want to make it easy to reach us with privacy questions or concerns. Here are all the ways to get in touch:
Questions about this Policy, your data, or how we handle information.
Formal complaints about data rights violations under the DPDP Act.
Company: FestNest Technologies Pvt. Ltd.
Jurisdiction: India โ disputes arising from this
Privacy Policy are subject to the laws of India and the exclusive
jurisdiction of courts in India.
Response Time: We endeavour to respond to all privacy-related enquiries within 7 business days, and to formally acknowledge data rights requests within 30 days as required by the DPDP Act.
If you are dissatisfied with our response to a grievance, you have the right to escalate your complaint to the Data Protection Board of India once it is established under the DPDP Act, 2023.