Privacy Policy
- Effective date:
- August 8, 2026
- Version:
- 1.0
At eventi we take user privacy seriously. This policy explains what data we collect through the eventi application ("the App"), how we use it, who we share it with, and the rights you have to control it. It is drafted to comply with the Saudi Personal Data Protection Law (PDPL), issued by Royal Decree M/19 of 1443H.
1. Who we are
eventi is a product of SymbolAI, based in the Kingdom of Saudi Arabia.
Data-protection contact: info@symbolai.net.
2. Data we collect
- Account data: email, username, display name, age, gender (optional).
- Trip data: chosen interests, traveler type, party size, day count, budget, restaurants/activities/hotels added to your plan, scheduled times, and geographic coordinates of picked items.
- Chat data: messages you send to the AI guide and its replies, plus your interactive-bubble selections.
- Booking and payment data: last 4 digits of your card only (we never store the full number or CVV), confirmation code, total amount, booking date, discount details if applicable.
- Review data: ratings (1–5) and comments you post on places and activities.
- Technical data: IP address, browser type, language preference, strictly-necessary cookies (session), error logs.
3. Purposes
- Operate the service and deliver personalized recommendations.
- Improve AI quality via anonymized pattern analysis.
- Fraud prevention and platform integrity.
- Send transactional notifications (booking confirmation, password reset, support-ticket replies).
- Respond to your requests through support channels.
4. Legal basis
We process your data on the basis of:
- Consent (Art. 6 PDPL): when you register and use the service.
- Contract performance: to deliver what you requested (plan building, booking).
- Legitimate interest: to improve the service and prevent abuse.
5. Third-party sharing
- Resend (email): used only for password-reset and support-ticket confirmation emails.
- Manus / Vercel (hosting): store the database and files on managed infrastructure.
- Google Maps (map deep-links): we open place URLs; identity is not shared through the URL.
- OpenStreetMap (interactive tiles): only map tiles are loaded.
We do not sell your data or share it for advertising.
6. Data retention
- Active accounts: for the duration of your use of the service.
- Chat messages: retained for 12 months, then automatically deleted.
- Error logs: 90 days.
- Booking records: retained for accounting/audit obligations under Saudi regulations.
- Support tickets: retained for 12 months after resolution.
7. Your rights (Art. 4 PDPL)
You have the right to:
- Access your data — contact
info@symbolai.net. - Correct your data — via the Settings page.
- Delete your account — via the "Delete account" button in Settings, or by direct request.
- Object to specific processing.
- Portability — request an exportable copy of your data.
We respond to requests within 30 days.
8. Security
- Passwords stored as bcrypt hashes with cost factor 12.
- All traffic encrypted with HTTPS/TLS.
- Database encryption in transit via SSL.
- Strict ownership guards on every API endpoint.
- Rate limiting to protect against automated abuse.
9. Cookies
We use only strictly-necessary cookies to preserve your login session. No advertising or external analytics trackers.
10. Children
The service is not directed to individuals under 13. If we learn we have collected data from a child under that age, we will delete it promptly.
11. Policy updates
We may update this policy from time to time. For material changes we will notify you via email and/or an in-app banner at least 30 days before the change takes effect.
12. Contact
For privacy questions or to exercise your rights:
📧 info@symbolai.net