Privacy Policy
Last updated: 2 September 2026
1. Introduction
EventLink is event planning and operations software for teams. This policy explains what personal data we collect, why we collect it, who we share it with, and what you can do about it. We have tried to write it in plain language rather than legalese.
The company responsible for your data (the “data controller”) is:
EventLink Co., Ltd. 102 Soi Yasoob 1, Vibhavadi-Rangsit Road,Chomphon, Chatuchak, Bangkok 10900, Thailand
hello@eventlink.dev
This policy covers both our website at eventlink.dev and the EventLink application at app.eventlink.dev. We are based in Thailand and comply with the Personal Data Protection Act (PDPA). If you are in the European Economic Area or the United Kingdom, the GDPR gives you additional rights; if you are in California, the CCPA/CPRA does. Those rights are set out in section 6.
EventLink is not intended for children. See section 7.
2. Information We Collect
Account information
When you create an account we collect your name (and any nickname or username you choose) and your email address. There is no password: we sign you in with a single-use link or code sent to that address. You can optionally add a phone number, profile photo, gender, date of birth, job title, employer, location and country, and links to your other profiles. The optional fields are exactly that: optional, and you can remove them at any time.
If you sign in with Google, Microsoft, LinkedIn, Facebook or LINE, we receive your basic profile information and email address from that provider so we can create or match your account. We never receive your password for those services.
If you sign up through a referral link or code, we record which code you used, and we link your new account — and the first organisation you create — to the person that code belongs to. We keep this as our record of how people found EventLink. No discount or other benefit is attached to a referral today; if that changes, this policy will change with it.
Content you put into EventLink
We store what you create in the product: your organisations and teams, your events (including descriptions, target audience, and event addresses, which include map coordinates), tasks and their descriptions, comments, approvals, files and documents you upload, your conversations with the AI assistant (both the one inside an event's workspace and the one that creates an event for you), and post-event reflections and reports.
About “anonymous” reflections: post-event reflections are presented to your team without your name attached, but they are still stored linked to your account. They are not technically anonymous, and we would rather tell you that than let you assume otherwise. Please keep it in mind when writing them.
Technical information
We automatically collect your IP address, browser type, device information, and pages or features you use. Specifically, we store your IP address with your active session (alongside your browser user-agent) so you can stay signed in and so we can spot suspicious activity, and we use it to enforce rate limits; this is how we stop brute-force login attempts and abuse. Your IP address is also seen by the providers who deliver the service to you (our hosting platform and our network provider) and appears in their access logs, as it would for any website you visit.
We also record the IP address each AI generation was requested from, and keep it with that generation's usage record. AI costs us real money per request, so we use it to cap AI spending per origin; that is how we stop someone creating account after account to get a fresh AI allowance each time, which a per-account limit cannot catch. We clear these IP addresses after 90 days; the usage record itself (which model, how many tokens, what it cost) is kept.
Information you send us directly
If you fill in our contact form, ask us about a pricing plan, or join a waitlist, we collect the name, email address, phone number, organisation and message you provide, along with your IP address, your language preference and the page you submitted the form from. We use this only to reply to you and to tell you when a plan you asked about becomes available; we do not add you to a marketing list without asking.
What we do not collect
We do not currently process payments, so we do not collect or store card or billing details. We do not sell your personal data, and we do not use it for advertising or share it for cross-context behavioural advertising.
3. How We Use Your Information
We use the data described above to:
- Provide, maintain and improve EventLink, and keep your account working.
- Let you collaborate, showing your name and avatar to other members of your organisation and events.
- Power our AI features (see below).
- Send you service messages: sign-in links, invitations, security and technical notices. You cannot opt out of these while you have an account, because they are part of the service.
- Send you product or marketing email, only if you have opted in. You can withdraw that at any time.
- Understand how the product is used, so we can improve it.
- Keep EventLink secure, detecting abuse, enforcing rate limits, and investigating incidents.
- Comply with our legal obligations.
AI features
EventLink uses Claude, an AI model provided by Anthropic, to generate starter task lists, write event descriptions, power the in-app assistant, produce post-event debrief reports, draft an event from a description you type, add to your plan when you answer one of its questions, and, if you choose it, set up a new event by talking to you. To do that, we send Anthropic the relevant content: your event details, task descriptions, team names and descriptions, the outcomes your plan is built around and which approach you chose for each, the comments your team leaves on tasks, the record of what changed on a task and when, anything recorded in the event's memory (see below), the first name or username of the person using the assistant, any documents you deliberately upload, and, for debrief reports, the free text of your team's reflections.
Your plan is built around outcomes — the things that have to become true for your event to work, like "Venue secured". Where we cannot know how you are handling one, the AI asks instead of guessing, and you answer by tapping one of the options it offers or by replying in your own words. When you answer, we send Anthropic that outcome, the approach you picked, and the descriptions of the tasks already on the event, so that what it adds fits your situation and does not repeat work you already have.
You can also answer in your own words instead of picking one of the options, using "Something else" on the question or by telling the assistant in the chat. When you do, we keep exactly what you wrote and send it to Anthropic as part of building the plan for that outcome — that is the point of answering this way, since the detail in your own sentence is what stops the plan assuming work you have already done. We store it with the question you answered and with the outcome itself, for as long as the event exists, and it can later be read by the assistants like anything else recorded on the event.
Replying to the question as an ordinary comment works differently: we match what you typed on our own servers, not by asking the AI to interpret it, and if it plainly means one of the options we record that option. Your reply is an ordinary comment on the task, visible to your team as any comment is, and like any other comment it can later be read by the AI as described below.
Some events are ceremonies, and a plan that treats one as an ordinary party can be wrong in ways that matter. So when we build your plan we check what you wrote about your event against a list of ceremony names we maintain ourselves, in English, Thai and Chinese. That check runs on our own servers and involves no AI. If it matches, we store which ceremony your event appears to be, and the word that matched, alongside the event; we send Anthropic our own reference material about that ceremony so the plan covers what it actually needs. Be aware that a ceremony can imply a religious or cultural context, and this is the one place we record something of that kind. It is our inference about an event from the words you chose, not a statement about you or anyone else: we never ask for, and never store, any person's religion, and we do not use it to profile you, target you, or decide anything about your account. It is deleted when the event is. If it guesses wrong, or you would rather it did not guess at all, describing your event in different words changes what it finds, and you can ask us to remove it.
If you describe an event in the box on our marketing site ("a wedding for 200 guests"), we keep that sentence in your browser session and carry it into the app. When you reach the create-event form, we send it to Anthropic to draft the form's contents for you. We hold the draft briefly against your account so refreshing the page does not re-run it, and it is discarded once you create the event. If the AI is unavailable, the form simply opens empty; nothing is lost.
When you create an event by talking to the AI, everything you type in that conversation is sent to Anthropic, along with the event it is building for you. If you ask it to find your venue, we send what you typed to Google Maps to look the place up, exactly as the venue picker in the form does. The live conversation is held against your account so you can pick it back up, and it expires by itself once you have not touched it for 24 hours. You can leave the conversation at any point and finish in the ordinary form instead.
You can also attach documents to that conversation — a brief, a run sheet, a budget, a slide deck — or paste in a long piece of text. We read the text out of what you attach and send that text to Anthropic so the assistant can use it to fill in your event. We never show your attachments to anyone outside your organisation, and there is no way for a stranger to download them.
What happens to those documents depends on whether you go on to create the event. If you do, we keep them with it: the file is moved into that event's own storage and the text we read out of it is stored alongside, so the assistants can refer back to your brief while you actually run the event rather than forgetting it the moment the conversation ends. They are not currently listed anywhere in the interface — they are held for the assistants to read — and deleting the event deletes both the file and the text. If you do not create the event — you start over, switch to the ordinary form, or simply walk away — we delete the file and the text as soon as the conversation ends, and a daily clean-up removes anything left from an abandoned conversation within 48 hours of your last activity.
A document kept with an event stays readable by the assistants for as long as the event does. Until recently the text of something you attached reached the AI once, on the message you attached it to. Now an assistant can look at it again at any point while you run the event — and so can other people working on that event, through their own assistant, because a kept document belongs to the event rather than to the conversation it arrived in. If a file should not be that widely readable, it can be limited to a single team, and then only that team, your organisation's owners and admins, and the event's approver can see it or ask the AI about it.
We ask Anthropic to write one line describing each document we keep. When a document joins an event we send its opening pages to Anthropic once, and store the sentence it writes back — "a catering contract covering the budget ceiling and the headcount deadline", say. That sentence is what lets the assistant tell which file is worth opening instead of reading all of them, so it means less of your document is sent to the model as you work, not more. It happens once per document, not on every request.
We keep a copy of that conversation for 90 days. We read them to find out where the assistant is getting in your way (asking you the same thing twice, misunderstanding a date, taking ten replies to do something that should take three) and then we fix it. It is deleted after 90 days, and immediately if you delete your account. It is not used to train anyone's AI model, and it is not shown to your organisation. That copy does not include your attachments. It records only that you attached something, its name and how long it was — never what was inside it.
Two things outlive that 90 days, and we want to be exact about them. The first is a set of figures with no words in them: how the conversation ended, how many replies it took, how long it ran, what kind of event it was about, and which problems we spotted in it (that it asked you the same thing twice, say). They carry nothing you typed. Once the conversation itself is deleted they carry nothing that identifies you or your organisation either, and we keep them indefinitely from that point, so we can tell whether the assistant is getting better or worse over time.
The second is short excerpts of the exchange that went wrong — both what it said and what you said, word for word. We keep these because a count on its own cannot be acted on: knowing that it repeated a question does not tell us which question, and often it is your own wording that confused it. These excerpts are short, we keep at most a few from any one conversation, and we delete them after 12 months — or immediately if you delete your account. They are not anonymous, and we do not describe them as such.
Your conversations with the in-app assistant (the one inside an event's workspace) are stored in your account so you can come back to them, and you can delete them. You can attach documents there too — a brief, a run sheet, a budget, a slide deck — or paste in a long piece of text. As with the create-an-event chat, we read the text out of what you attach and send that text to Anthropic. We do not keep the file itself. We keep only the text we read out of it, stored alongside that conversation for as long as the conversation lasts, so the assistant can look at it again later. Clearing the conversation deletes those documents, and so does deleting the event or your account. Clearing a conversation does not remove anything the assistant already saved to the event's memory from it — those entries are listed in event settings, where you can change or delete them.
We do not read those in-app conversations to improve the product. What we look at instead is what happened to the assistant's suggestions — how many it made, of what kind, and whether you took them or turned them down. That tells us which kinds of suggestion are worth making without anyone reading your thread. The one exception is an exchange you flag yourself, below.
You can tell us when it did badly. Each of the assistant's replies can be marked helpful or unhelpful, and now and then we will ask you outright. If you mark a reply unhelpful, we keep that exchange — your message and its reply — so we can read it and fix what went wrong, on the same 12-month window as above. Marking a reply helpful keeps no text at all. If you would rather we did not keep any of it, simply do not use the thumbs.
You can also attach a picture — a photo or a screenshot. Here the assistant looks at the image itself rather than at text we have read out of it, so the picture is sent to Anthropic. It is shown to the assistant once, on the message you attach it to. At the same time we ask Anthropic to write down what the picture shows, including any words in it, and it is that written description we keep, on exactly the same terms as a document's text above. The picture itself is not kept. It is held only for the moments between you uploading it and your message being sent, and is deleted as soon as the message goes; a daily clean-up removes anything a failure left behind.
The assistant can also open files attached to your tasks. If you ask it about a contract, a quote or a floor plan somebody uploaded to a task, we read that file at that moment and send its contents to Anthropic so it can answer. It only ever opens files on tasks you are already allowed to see. We do not store what it reads — the text is used to answer you and held briefly in a temporary cache so a follow-up question does not have to re-read the same file, and nothing is written into your event's records. A picture attached to a task is handled the same way as one attached to the chat: it is described, and the description is what the assistant reads.
An event can also have a memory. These are the durable things about an event that do not fit anywhere else — who your caterer is, a budget ceiling, a decision you have already taken, something that went wrong last time. Everything in it is sent to Anthropic as background whenever you use either assistant on that event, so you stop having to re-explain the same context every time you ask for help.
Some of it is written by the assistant rather than by you. Five things can put an entry there: anyone who can edit the event writing one by hand; the brief you write when creating an event, which is kept as memories so the assistants can read it later; the assistant noting something down as you mention it while creating the event; a one-off background pass, once your event is created, that re-reads that conversation and any documents you attached and records the durable facts nobody wrote down as they went; and the assistant inside your event's workspace, which saves a durable fact to the event's memory as you mention it while you work. That background pass is another request to Anthropic, and it is the only time we send a whole conversation for a purpose other than replying to you. Anything the assistant recorded is marked as unconfirmed until a person checks it, and all of it is listed in event settings for you to correct or remove. Only people who can edit the event can record a memory, by hand or through an assistant — nobody else, and no one outside your organisation.
Your task board is also read overnight. Once a day, for each event where something meaningful happened, we send Anthropic what changed on the board that day — the tasks your team finished, the comments left on them, and edits to their descriptions and checklists — and keep the durable facts worth remembering, such as a supplier you picked or a quote you were given. Most days this records nothing at all. It is told to record facts about the event and never about how a person is doing their job, and never to record anyone's health, beliefs, political opinions, background, payment details or identity numbers.
The in-app assistant can read those comments too, when you ask it something. The conversation on the task you have open is sent with your question, it can search the comments on any task you are allowed to see, and it can read a task's history of changes. It only ever reaches what you could open yourself: if your event limits members to their own team's tasks, the assistant is limited the same way. Unlike the overnight pass above, which strips names out, this one includes who said what and who changed what, because answering "what did we decide" usually depends on it. Comments are written by your teammates to each other, so this is worth knowing even though nothing here is shown to anyone who could not already see it.
Two things about it are worth being plain about. First, a memory can describe a person — a supplier's contact, a sponsor, someone you are dealing with — and that person may well not have an EventLink account, so they have no way of knowing we hold it or of asking us themselves. We ask you to record only what you need in order to run the event: who someone is, what they do, and how to reach them about it. Please do not record opinions about a person, their performance or conduct, anything about their health or beliefs, or payment and identity details. Second, unlike your AI conversations, an event's memory is not on a 90-day clock — it lasts as long as the event does, which is the whole reason it is useful. It is all visible in one place in event settings, and anyone who can edit the event can change it, remove it from the assistants, or delete it outright at any time. Deleting the event deletes it too.
You can talk to the assistant instead of typing. If you record a voice note, we send the recording to OpenAI — a different company from Anthropic, used for this and nothing else — because the model that powers the rest of our AI features cannot listen to audio. Along with it we send a short list of your event's own names: the event, its teams, and the people on them. That is so the words come back spelled the way you have them rather than as something that merely sounds similar. We send nothing else with it — not your tasks, not your comments, not your email address.
We do not keep the recording. It is turned into text and discarded straight away; we never store the audio, and there is nowhere in EventLink to play it back. What survives is the text, and only where you left it — in the message box, for you to read, correct or delete. Nothing is sent to the assistant until you send it. We do keep a record of what each recording cost us, so we can measure what the feature costs to run; that record holds no audio and no words. OpenAI processes the recording to return the text to us and their terms do not permit training their models on it, though they may hold it for up to 30 days to detect misuse before deleting it.
We do not send your email address to the AI model. Anthropic processes this content to return a response to us; their handling of it is governed by their commercial terms, which do not permit training their models on it.
Legal bases (GDPR / PDPA)
Where the GDPR or Thailand's PDPA applies, we rely on: performance of a contract (running the service you signed up for); legitimate interests (securing the platform, preventing abuse, and improving the product); consent (optional analytics cookies, session replay, and marketing email, each of which you can refuse or withdraw); and legal obligation where the law requires us to keep or disclose something.
4. How We Share Your Information
With people you work with
EventLink is collaboration software, so content you create is visible to other members of the organisations and events you belong to, according to their role and permissions. Organisation owners and admins can see the content of their organisation.
Your public profile
Please read this one. EventLink profiles are public. Your name, nickname, photo, username, job title, employer, location, country, contact links, and your event and connection counts can be viewed by anyone on the internet (no EventLink account required) at a public profile address based on your username. There is currently no setting that makes a profile private. What you control is what the profile contains: those fields are optional, you can edit or clear them at any time, and you can delete your account. We are telling you plainly because there is no way to opt out of this while holding an account.
With service providers
We share data with companies that run parts of EventLink for us. They may only use it to provide their service to us, not for their own purposes.
| Provider | What they do | Where |
|---|---|---|
| Anthropic (Claude) | Powers our AI features except voice input. Receives the event content, documents and images you send it; see “AI features” below. | United States |
| OpenAI | Turns a voice note you record in the app into text. Receives the recording and a short list of your event's own names; see “AI features” below. Used for nothing else. | United States |
| PostHog | Product analytics and, where you allow it, session replay of your use of the app. | United States |
| Sentry | Error and performance monitoring, so we can diagnose crashes. | United States |
| MailerSend | Sends transactional email (sign-in links, invitations, notices). | United States / EU |
| Amazon Web Services (S3) | Stores files you upload: avatars, documents, event assets. | Singapore (ap-southeast-1) |
| Laravel Cloud & Cloudflare | Application hosting, delivery and abuse protection. | United States / global edge |
| Pusher | Delivers real-time updates inside the app. | United States / EU |
| Google Maps Platform | Address search and geocoding when you add a location to an event. | United States |
| Vercel & Sanity | Host and serve this marketing site and its blog. | United States |
Our website and app also load fonts and icons from third-party networks (Bunny Fonts and Iconify). Doing so reveals your IP address to them, as it would to any website you visit.
International transfers
We are based in Thailand, and the providers above are mostly outside Thailand, principally in the United States, the EU and Singapore. That means your personal data is transferred across borders. Where the law requires it, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, and we only work with providers that commit to protecting the data they handle for us.
Other disclosures
We may disclose personal data if we are legally required to, if we need to protect our rights or someone's safety, or as part of a merger or acquisition, in which case we will tell you before your data becomes subject to a different policy. We do not sell your personal data.
5. Cookies, Analytics and Tracking
We use a small number of essential cookies to keep you signed in and to remember your language preference. These are required for the service to work and cannot be turned off.
We use PostHog for product analytics. In the app, analytics and session replay are off until you agree to them; you will see a banner asking, you can reject it, and you can change your mind at any time in your privacy preferences. Session replay records how you interact with the app so we can find usability problems. Replay is switched off entirely on the pages that carry a sign-in link, an invitation, or an email-verification link, and the sign-in code you type is never recorded.
Two honest caveats. First, on this marketing site (eventlink.dev), our analytics currently load as soon as you arrive, before we ask you; we are fixing that, and you can block it in the meantime with your browser or an ad blocker. Second, we record a small number of core business events server-side (for example: an account was created, an event was created) so we can count how the product is doing. These are tied to your account rather than to a cookie, and they are recorded regardless of your cookie choice. If you would rather we did not, contact us and we will remove you.
Our analytics cookie is set on .eventlink.dev,
which means the same visitor is recognised across the marketing site and
the app. We do not use advertising cookies, and we do not track you
across other companies' websites.
6. Data Security and Retention
We protect your data with encryption in transit (HTTPS everywhere), encrypted session storage, sign-in links and codes that are single-use, short-lived, tied to the browser that asked for them, and stored only as SHA-256 hashes, strict role and permission checks on every request, and rate limiting against brute-force attacks. Photos you upload are re-encoded on upload, which strips embedded metadata such as GPS coordinates before we store them. Access to production data is limited to the people who need it.
No system is perfectly secure, and we will not pretend otherwise. If we ever suffer a breach affecting your personal data, we will notify you and the relevant regulator as the law requires.
We keep your personal data for as long as your account exists. When you delete your account, we delete your profile and personal records immediately; this is a real deletion, not a hidden flag. Content you contributed to an organisation (such as events and tasks) may remain with that organisation so your colleagues' records stay intact, but it is unlinked from you. We may keep the minimum necessary to meet legal obligations or resolve disputes.
A referral record outlives the account it came from. If you signed up through a referral link and later delete your account, we sever the link to you and to your organisation; what remains is the code that was used and the date, which identifies nobody. We keep that indefinitely.
Some things we deliberately keep for less than that: the conversations you have with the AI when creating an event, which we delete after 90 days, and the IP addresses recorded against AI generations, which we clear after 90 days.
When you ask for a sign-in link, we store the address we sent it to — even if you never go on to create an account — together with the hashes of the link and the code, and the times they were issued and used. We keep that for seven days after the link expires, so we can tell you whether a link was actually sent; a nightly job deletes it after that.
And one thing we keep for longer than the conversation it came from: the short excerpts described in section 2, taken from an exchange that went wrong or that you marked unhelpful. We delete those after 12 months, or immediately if you delete your account. The figures we derive alongside them contain no text and nothing that identifies anyone, and we keep those indefinitely.
Server logs and backups. Our application logs are held by our hosting platform (Laravel Cloud) and our error-monitoring provider (Sentry), and are deleted automatically once they pass those providers' retention windows; we do not keep our own indefinite archive of them. Database backups are taken automatically by our hosting platform, which encrypts every database and backup at rest and in transit by default, and they expire on that platform's retention schedule.
7. Your Data Protection Rights
Wherever you live, you can ask us to: access the personal data we hold about you; correct it if it is wrong; delete it; export it in a portable format; object to or restrict how we use it; and withdraw consent you previously gave. You will never be treated differently for exercising these rights.
How to actually do it
- Delete your account: in the app, under Settings → Security. If you own an organisation, you will need to transfer or delete it first.
- Limit what your public profile shows: edit or clear the optional fields in your profile settings. The profile itself cannot be hidden while the account exists.
- Change your cookie and analytics choices: via privacy preferences in the app.
- Opt out of marketing email: the unsubscribe link in any such email, or your notification settings.
- Get a copy of your data: we do not yet have a self-service export button. Email us and we will put your data together for you.
- Anything else: email hello@eventlink.dev.
We will respond within 30 days. We may need to verify who you are first, so that we do not hand your data to someone else.
If you are in the EEA or UK
You have the right to lodge a complaint with your local data protection authority. We would appreciate the chance to put things right first.
If you are in Thailand
The PDPA gives you the rights above, and you may complain to the Personal Data Protection Committee.
If you are in California
You have the right to know what we collect, to delete it, to correct it, and to opt out of sale or sharing. We do not sell or share your personal information, and we have not done so in the past 12 months. We do not knowingly sell the personal information of anyone under 16.
8. Children's Privacy
EventLink is business software for event teams. It is not directed to children, and we do not knowingly collect personal data from anyone under 13. If you believe a child under 13 has given us personal data, email us at hello@eventlink.dev and we will delete it promptly.
If you are between 13 and 20 and Thai law requires a parent or guardian's consent for you to use a service like ours, please get it before creating an account.
9. Changes to This Privacy Policy
We will update this policy when what we do changes. When we do, we will revise the “last updated” date at the top. If the change is significant (new categories of data, a new purpose, a new kind of sharing), we will tell you directly, by email or in the app, before it takes effect. We will not quietly broaden what we do with your data and hope you do not notice.
10. Contact Us
Questions about this policy, or about your data? We would rather hear from you than have you wonder.
EventLink Co., Ltd. 102 Soi Yasoob 1, Vibhavadi-Rangsit Road,Chomphon, Chatuchak, Bangkok 10900, Thailand
hello@eventlink.dev