Takits · Privacy
Privacy notice
Version v2 · effective 10 September 2026
Takits is an AI Assisted Event Ecosystem operated by Sandbox Digital Consulting (SDC). This notice explains what information Takits handles when you create an account, host an event, register, check in, or receive a certificate. The event host is responsible for the event-specific purpose and instructions shown on its event page.
The short version
We use the minimum information needed to run the event: identity and contact details, registration answers, ticket and check-in records, and certificate information. We do not sell participant data. Optional photo consent is separate from the operational registration record.
What we collect
- Account information: email, first and last name, display name, timezone, mobile number, bio, and optional profile photo.
- Event information: name, email, mobile, custom answers requested by the host, ticket code, consent version and timestamp.
- Attendance information: ticket status, check-in time, admission method, certificate code, issue/reissue and revocation history.
- Optional city-update subscriptions: email, selected city, consent version and timestamp, plus a random unsubscribe token.
- Technical information needed to keep the service secure and available, such as request logs and error records.
Do not put passwords, payment-card details, government IDs or unrelated sensitive information into a custom answer.
Why we use it
- To create and manage accounts, event pages, tickets, calendars, check-in and certificates.
- To send a ticket, waitlist, invitation or certificate message when email delivery is configured.
- To keep an optional city-update list; you can unsubscribe from that list at any time using its link.
- To produce the private attendee ledger and organiser CSV export for the stated event purpose.
- To prevent duplicate or fraudulent registrations, protect the door scanner and keep an audit trail.
We do not use an optional photo/video permission as a condition of registering.
Who receives it
The event host receives the information needed to run its event. Takits uses service providers such as Supabase for database/authentication/storage, Vercel for hosting, and Resend for transactional email when configured. They act as processors or service providers for the relevant operation and may process information outside the Philippines under their own security and transfer terms. A Google Calendar link is a user-initiated template: clicking it sends the event details to Google through the guest's browser; Takits does not silently add anything to a calendar.
Cookies and automated decisions
Takits uses necessary authentication/session cookies so sign-in and protected organiser pages work. The prototype does not use advertising cookies or sell browsing activity. No admission, approval or certificate decision is made by an AI model: the host or authorised event operator makes those decisions. “AI Assisted Event Ecosystem” describes the product direction, not an automated decision about a guest.
Retention
Event records are kept for the host's legitimate event, audit and certificate needs, then deleted or anonymised under the host's documented retention schedule. Account records remain while the account is active. A certificate's public verification record may need to remain for its stated authenticity period; a revoked certificate is marked revoked rather than silently rewritten. Hosts should not collect a sensitive field unless it is necessary and should set a shorter retention period for it.
Your choices and rights
Subject to applicable law and the event host's role as controller, you may ask for access, correction, deletion, portability, restriction or withdrawal of optional consent. To start, use Data requests and include the event name, the email used to register, and what you want changed. Do not send a password or ticket QR in the request.
The platform contact address will be configured before the public business launch. Until then, use the contact channel provided by the host or the channel through which you received the event invitation; the prototype does not publish a platform privacy inbox. You may also raise a concern with the National Privacy Commission.
Security and updates
Takits uses authenticated access for accounts and organiser tools, role checks for attendee data, server-side validation, protected ticket codes, revocation-aware certificates and no-store responses for CSV exports. No online service is risk-free; report a suspected security issue to the event host promptly. We will version this notice when its purposes or material processing changes.
This notice is an implementation baseline, not a legal opinion. SDC should appoint the responsible privacy contact/DPO and obtain a Philippine legal review before commercial launch. Current site: https://takits.online.