Privacy Policy
Last updated: 20 July 2026
1. Introduction
EventLink is event planning and operations software for teams. This policy explains what personal data we collect, why we collect it, who we share it with, and what you can do about it. We have tried to write it in plain language rather than legalese.
The company responsible for your data (the “data controller”) is:
EventLink Co., Ltd. 102 Soi Yasoob 1, Vibhavadi-Rangsit Road,Chomphon, Chatuchak, Bangkok 10900, Thailand
hello@eventlink.dev
This policy covers both our website at eventlink.dev and the EventLink application at app.eventlink.dev. We are based in Thailand and comply with the Personal Data Protection Act (PDPA). If you are in the European Economic Area or the United Kingdom, the GDPR gives you additional rights; if you are in California, the CCPA/CPRA does. Those rights are set out in section 6.
EventLink is not intended for children. See section 7.
2. Information We Collect
Account information
When you create an account we collect your name (and any nickname or username you choose), email address, and a password, which we store only as a salted hash; we never store it in a readable form. You can optionally add a phone number, profile photo, gender, date of birth, job title, employer, location and country, and links to your other profiles. The optional fields are exactly that: optional, and you can remove them at any time.
If you sign in with Google, Microsoft, LinkedIn, Facebook or LINE, we receive your basic profile information and email address from that provider so we can create or match your account. We never receive your password for those services.
Content you put into EventLink
We store what you create in the product: your organisations and teams, your events (including descriptions, target audience, and event addresses, which include map coordinates), tasks and their descriptions, comments, approvals, files and documents you upload, your conversations with the AI assistant (both the one inside an event's workspace and the one that creates an event for you), and post-event reflections and reports.
About “anonymous” reflections: post-event reflections are presented to your team without your name attached, but they are still stored linked to your account. They are not technically anonymous, and we would rather tell you that than let you assume otherwise. Please keep it in mind when writing them.
Technical information
We automatically collect your IP address, browser type, device information, and pages or features you use. Specifically, we store your IP address with your active session (alongside your browser user-agent) so you can stay signed in and so we can spot suspicious activity, and we use it to enforce rate limits; this is how we stop brute-force login attempts and abuse. Your IP address is also seen by the providers who deliver the service to you (our hosting platform and our network provider) and appears in their access logs, as it would for any website you visit.
We also record the IP address each AI generation was requested from, and keep it with that generation's usage record. AI costs us real money per request, so we use it to cap AI spending per origin; that is how we stop someone creating account after account to get a fresh AI allowance each time, which a per-account limit cannot catch. We clear these IP addresses after 90 days; the usage record itself (which model, how many tokens, what it cost) is kept.
Information you send us directly
If you fill in our contact form or join a waitlist, we collect the name, email address, phone number, company and message you provide, along with your IP address.
What we do not collect
We do not currently process payments, so we do not collect or store card or billing details. We do not sell your personal data, and we do not use it for advertising or share it for cross-context behavioural advertising.
3. How We Use Your Information
We use the data described above to:
- Provide, maintain and improve EventLink, and keep your account working.
- Let you collaborate, showing your name and avatar to other members of your organisation and events.
- Power our AI features (see below).
- Send you service messages: invitations, password resets, security and technical notices. You cannot opt out of these while you have an account, because they are part of the service.
- Send you product or marketing email, only if you have opted in. You can withdraw that at any time.
- Understand how the product is used, so we can improve it.
- Keep EventLink secure, detecting abuse, enforcing rate limits, and investigating incidents.
- Comply with our legal obligations.
AI features
EventLink uses Claude, an AI model provided by Anthropic, to generate starter task lists, write event descriptions, power the in-app assistant, produce post-event debrief reports, draft an event from a description you type, and, if you choose it, set up a new event by talking to you. To do that, we send Anthropic the relevant content: your event details, task descriptions, team names and descriptions, anything recorded in the event's memory (see below), the first name or username of the person using the assistant, any documents you deliberately upload, and, for debrief reports, the free text of your team's reflections.
If you describe an event in the box on our marketing site ("a wedding for 200 guests"), we keep that sentence in your browser session and carry it into the app. When you reach the create-event form, we send it to Anthropic to draft the form's contents for you. We hold the draft briefly against your account so refreshing the page does not re-run it, and it is discarded once you create the event. If the AI is unavailable, the form simply opens empty; nothing is lost.
When you create an event by talking to the AI, everything you type in that conversation is sent to Anthropic, along with the event it is building for you. If you ask it to find your venue, we send what you typed to Google Maps to look the place up, exactly as the venue picker in the form does. The live conversation is held against your account so you can pick it back up, and it expires by itself once you have not touched it for 24 hours. You can leave the conversation at any point and finish in the ordinary form instead.
You can also attach documents to that conversation — a brief, a run sheet, a budget, a slide deck — or paste in a long piece of text. We read the text out of what you attach and send that text to Anthropic so the assistant can use it to fill in your event. We never show your attachments to anyone outside your organisation, and there is no way for a stranger to download them.
What happens to those documents depends on whether you go on to create the event. If you do, we keep them with it: the file is moved into that event's own storage and the text we read out of it is stored alongside, so the assistants can refer back to your brief while you actually run the event rather than forgetting it the moment the conversation ends. They are not currently listed anywhere in the interface — they are held for the assistants to read — and deleting the event deletes both the file and the text. If you do not create the event — you start over, switch to the ordinary form, or simply walk away — we delete the file and the text as soon as the conversation ends, and a daily clean-up removes anything left from an abandoned conversation within 48 hours of your last activity.
A document kept with an event stays readable by the assistants for as long as the event does. Until recently the text of something you attached reached the AI once, on the message you attached it to. Now an assistant can look at it again at any point while you run the event — and so can other people working on that event, through their own assistant, because a kept document belongs to the event rather than to the conversation it arrived in. If a file should not be that widely readable, it can be limited to a single team, and then only that team, your organisation's owners and admins, and the event's approver can see it or ask the AI about it.
We ask Anthropic to write one line describing each document we keep. When a document joins an event we send its opening pages to Anthropic once, and store the sentence it writes back — "a catering contract covering the budget ceiling and the headcount deadline", say. That sentence is what lets the assistant tell which file is worth opening instead of reading all of them, so it means less of your document is sent to the model as you work, not more. It happens once per document, not on every request.
We keep a copy of that conversation for 90 days. We read them to find out where the assistant is getting in your way (asking you the same thing twice, misunderstanding a date, taking ten replies to do something that should take three) and then we fix it. It is deleted after 90 days, and immediately if you delete your account. It is not used to train anyone's AI model, and it is not shown to your organisation. That copy does not include your attachments. It records only that you attached something, its name and how long it was — never what was inside it.
Your conversations with the in-app assistant (the one inside an event's workspace) are stored in your account so you can come back to them, and you can delete them. You can attach documents there too — a brief, a run sheet, a budget, a slide deck — or paste in a long piece of text. As with the create-an-event chat, we read the text out of what you attach and send that text to Anthropic. We do not keep the file itself. We keep only the text we read out of it, stored alongside that conversation for as long as the conversation lasts, so the assistant can look at it again later. Clearing the conversation deletes those documents, and so does deleting the event or your account.
An event can also have a memory. These are the durable things about an event that do not fit anywhere else — who your caterer is, a budget ceiling, a decision you have already taken, something that went wrong last time. Everything in it is sent to Anthropic as background whenever you use either assistant on that event, so you stop having to re-explain the same context every time you ask for help.
Some of it is written by the assistant rather than by you. Three things can put an entry there: anyone who can edit the event writing one by hand; the assistant noting something down as you mention it while creating the event; and, once your event is created, a one-off background pass that re-reads that conversation and any documents you attached, and records the durable facts nobody wrote down as they went. That pass is another request to Anthropic, and it is the only time we send a whole conversation for a purpose other than replying to you. Anything the assistant recorded is marked as unconfirmed until a person checks it, and all of it is listed in event settings for you to correct or remove.
Two things about it are worth being plain about. First, a memory can describe a person — a supplier's contact, a sponsor, someone you are dealing with — and that person may well not have an EventLink account, so they have no way of knowing we hold it or of asking us themselves. We ask you to record only what you need in order to run the event: who someone is, what they do, and how to reach them about it. Please do not record opinions about a person, their performance or conduct, anything about their health or beliefs, or payment and identity details. Second, unlike your AI conversations, an event's memory is not on a 90-day clock — it lasts as long as the event does, which is the whole reason it is useful. It is all visible in one place in event settings, and anyone who can edit the event can change it, remove it from the assistants, or delete it outright at any time. Deleting the event deletes it too.
We do not send your email address to the AI model. Documents you upload for task generation are used for that generation and then deleted. Anthropic processes this content to return a response to us; their handling of it is governed by their commercial terms, which do not permit training their models on it.
Legal bases (GDPR / PDPA)
Where the GDPR or Thailand's PDPA applies, we rely on: performance of a contract (running the service you signed up for); legitimate interests (securing the platform, preventing abuse, and improving the product); consent (optional analytics cookies, session replay, and marketing email, each of which you can refuse or withdraw); and legal obligation where the law requires us to keep or disclose something.
4. How We Share Your Information
With people you work with
EventLink is collaboration software, so content you create is visible to other members of the organisations and events you belong to, according to their role and permissions. Organisation owners and admins can see the content of their organisation.
Your public profile
Please read this one. EventLink profiles are public by default. If your profile is public, your name, nickname, photo, username, job title, employer, location, country, public contact links, and your event and connection counts can be viewed by anyone on the internet (no EventLink account required) at a public profile address based on your username. You can turn this off in your settings, and we will honour that. We are telling you plainly because the default is “on”.
With service providers
We share data with companies that run parts of EventLink for us. They may only use it to provide their service to us, not for their own purposes.
| Provider | What they do | Where |
|---|---|---|
| Anthropic (Claude) | Powers our AI features. Receives the event content you send it; see “AI features” below. | United States |
| PostHog | Product analytics and, where you allow it, session replay of your use of the app. | United States |
| Sentry | Error and performance monitoring, so we can diagnose crashes. | United States |
| MailerSend | Sends transactional email (invitations, password resets, notices). | United States / EU |
| Amazon Web Services (S3) | Stores files you upload: avatars, documents, event assets. | Singapore (ap-southeast-1) |
| Laravel Cloud & Cloudflare | Application hosting, delivery and abuse protection. | United States / global edge |
| Pusher | Delivers real-time updates inside the app. | United States / EU |
| Google Maps Platform | Address search and geocoding when you add a location to an event. | United States |
| Vercel & Sanity | Host and serve this marketing site and its blog. | United States |
Our website and app also load fonts and icons from third-party networks (Bunny Fonts and Iconify). Doing so reveals your IP address to them, as it would to any website you visit.
International transfers
We are based in Thailand, and the providers above are mostly outside Thailand, principally in the United States, the EU and Singapore. That means your personal data is transferred across borders. Where the law requires it, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, and we only work with providers that commit to protecting the data they handle for us.
Other disclosures
We may disclose personal data if we are legally required to, if we need to protect our rights or someone's safety, or as part of a merger or acquisition, in which case we will tell you before your data becomes subject to a different policy. We do not sell your personal data.
5. Cookies, Analytics and Tracking
We use a small number of essential cookies to keep you signed in and to remember your language preference. These are required for the service to work and cannot be turned off.
We use PostHog for product analytics. In the app, analytics and session replay are off until you agree to them; you will see a banner asking, you can reject it, and you can change your mind at any time in your privacy preferences. Session replay records how you interact with the app so we can find usability problems; passwords and sensitive tokens are stripped before anything is sent.
Two honest caveats. First, on this marketing site (eventlink.dev), our analytics currently load as soon as you arrive, before we ask you; we are fixing that, and you can block it in the meantime with your browser or an ad blocker. Second, we record a small number of core business events server-side (for example: an account was created, an event was created) so we can count how the product is doing. These are tied to your account rather than to a cookie, and they are recorded regardless of your cookie choice. If you would rather we did not, contact us and we will remove you.
Our analytics cookie is set on .eventlink.dev,
which means the same visitor is recognised across the marketing site and
the app. We do not use advertising cookies, and we do not track you
across other companies' websites.
6. Data Security and Retention
We protect your data with encryption in transit (HTTPS everywhere), encrypted session storage, strong password hashing (bcrypt), strict role and permission checks on every request, and rate limiting against brute-force attacks. Photos you upload are re-encoded on upload, which strips embedded metadata such as GPS coordinates before we store them. Access to production data is limited to the people who need it.
No system is perfectly secure, and we will not pretend otherwise. If we ever suffer a breach affecting your personal data, we will notify you and the relevant regulator as the law requires.
We keep your personal data for as long as your account exists. When you delete your account, we delete your profile and personal records immediately; this is a real deletion, not a hidden flag. Content you contributed to an organisation (such as events and tasks) may remain with that organisation so your colleagues' records stay intact, but it is unlinked from you. We may keep the minimum necessary to meet legal obligations or resolve disputes.
Two things we deliberately keep for less than that: the conversations you have with the AI when creating an event, which we delete after 90 days, and the IP addresses recorded against AI generations, which we clear after 90 days.
Server logs and backups. Our application logs are held by our hosting platform (Laravel Cloud) and our error-monitoring provider (Sentry), and are deleted automatically once they pass those providers' retention windows; we do not keep our own indefinite archive of them. Database backups are taken automatically by our hosting platform, which encrypts every database and backup at rest and in transit by default, and they expire on that platform's retention schedule.
7. Your Data Protection Rights
Wherever you live, you can ask us to: access the personal data we hold about you; correct it if it is wrong; delete it; export it in a portable format; object to or restrict how we use it; and withdraw consent you previously gave. You will never be treated differently for exercising these rights.
How to actually do it
- Delete your account: in the app, under Settings → Account. If you own an organisation, you will need to transfer or delete it first.
- Make your profile private: in your profile settings.
- Change your cookie and analytics choices: via privacy preferences in the app.
- Opt out of marketing email: the unsubscribe link in any such email, or your notification settings.
- Get a copy of your data: we do not yet have a self-service export button. Email us and we will put your data together for you.
- Anything else: email hello@eventlink.dev.
We will respond within 30 days. We may need to verify who you are first, so that we do not hand your data to someone else.
If you are in the EEA or UK
You have the right to lodge a complaint with your local data protection authority. We would appreciate the chance to put things right first.
If you are in Thailand
The PDPA gives you the rights above, and you may complain to the Personal Data Protection Committee.
If you are in California
You have the right to know what we collect, to delete it, to correct it, and to opt out of sale or sharing. We do not sell or share your personal information, and we have not done so in the past 12 months. We do not knowingly sell the personal information of anyone under 16.
8. Children's Privacy
EventLink is business software for event teams. It is not directed to children, and we do not knowingly collect personal data from anyone under 13. If you believe a child under 13 has given us personal data, email us at hello@eventlink.dev and we will delete it promptly.
If you are between 13 and 20 and Thai law requires a parent or guardian's consent for you to use a service like ours, please get it before creating an account.
9. Changes to This Privacy Policy
We will update this policy when what we do changes. When we do, we will revise the “last updated” date at the top. If the change is significant (new categories of data, a new purpose, a new kind of sharing), we will tell you directly, by email or in the app, before it takes effect. We will not quietly broaden what we do with your data and hope you do not notice.
10. Contact Us
Questions about this policy, or about your data? We would rather hear from you than have you wonder.
EventLink Co., Ltd. 102 Soi Yasoob 1, Vibhavadi-Rangsit Road,Chomphon, Chatuchak, Bangkok 10900, Thailand
hello@eventlink.dev