Data and privacy
GDPR and registration data for Model A embeds vs Model B webhooks.
Model A — features on your site
Public embeds expose only published event marketing / schedule surfaces for your slug or company catalog — not private attendee lists. Registration and payment PII stay in Eventyvo unless you add Model B.
Model B — related Eventyvo data in your stack
When you receive webhook payloads or Connect REST responses with attendee data:
- Process only for stated event purposes
- Honor deletion requests via your organizer dashboard workflows
- Do not log full PII in plaintext application logs
- Verify webhook signatures before persisting — Verification
- Keep Connect keys and webhook secrets out of client-side code, analytics, and support tickets
See Two website models and Security checklist.
Eventyvo retention
Registration data retention follows platform policy. See your organizer agreement for export and deletion timelines.