All legal documents

Privacy Policy

How we collect, use, share and protect personal information when you use Perical.

Last updated: October 2026

01Introduction

This Privacy Policy explains how Perical ("we", "us", or "our") collects, uses, discloses, and protects personal information when you use the Perical platform, including our website, applications, and related services (collectively, the "Platform").

02Who We Are

Perical is an event-management platform that helps organizers run events and helps guests find and attend them. We provide tools for publishing events, selling tickets, checking guests in, tracking attendance, and following up afterwards. The Platform is operated by Blear and related entities ("we"). If you have questions about how your data is handled, you can reach us at support@perical.in.

03Scope

This Policy applies to personal information we process when you:

  • create or use an account on the Platform;
  • host or manage an event;
  • create, register for, or attend events;
  • check guests in;
  • communicate through the Platform; or
  • otherwise interact with the Platform or its administrators.

This Policy does not apply to third-party services you access through the Platform, unless we say otherwise.

04Information We Collect

We collect information that is necessary to operate the Platform and to provide the features you use. We aim to collect only what is needed for a legitimate purpose (data minimization).

05Information You Provide

  • Account and profile information - such as your name, email address, and profile image, as well as any organization/event details you choose to add.
  • Event information - event names and descriptions, dates and venues, guest lists you manage, announcements, and similar content you submit.
  • Communications - messages you send through the Platform, email communications, and responses to event forms.
  • Tickets, check-ins and files - ticket and check-in data, guest lists, and files you upload to the Platform.

Most users are not required to provide government-issued identity documents. To create a normal account, or to RSVP, register for, or attend an event as a guest, you are not asked to provide an Aadhaar number, PAN, passport, driving licence, voter ID, or similar identity document. The exception is event organizers: before creating or publishing an event, an organizer must verify their identity through DigiLocker (see "Organizer Identity Verification" below), which may involve sharing verified details from a government-issued identity document.

06Account and Authentication Information

Account authentication is handled by our authentication provider, Clerk. When you sign up or sign in, Clerk processes the credentials you provide (such as email and password, or a social login) on our behalf and supplies us with an authenticated user identifier and basic profile information (such as your name and email). We do not store your password, and account ownership verification relies on the authenticated session established with our authentication provider - not on identity documents. The exception is organizer verification: to help prevent abuse, organizers must separately complete DigiLocker identity verification before creating an event, as described below.

07Organizer Identity Verification (DigiLocker)

To prevent fraud, impersonation, and abuse, users who create or publish an event must verify their identity through DigiLocker, the Government of India's digital document service, before the event can be created. This verification is not required to create a normal account or to attend an event as a guest.

During verification, DigiLocker confirms your identity to us - for example, your name and a verified identity reference. We use this information solely to confirm your identity and eligibility to host events, and to detect and prevent abuse. We do not use it for advertising, and we do not sell it. Where you use DigiLocker, the documents you hold remain under your control in DigiLocker, and DigiLocker's own terms and privacy practices apply to that service.

08Usage and Technical Information

When you use the Platform, we may collect limited technical information about how you use it, including:

  • the pages or sections you visit;
  • the date and time of visits;
  • browser type, operating system, and device type;
  • coarse location data (such as country, region, or city) derived from your network connection, where we are able to derive it; and
  • referrer information.

This information is used for product analytics and to understand how the Platform is used so we can improve it.

09IP Address Handling

As part of handling network requests, the servers that operate the Platform receive the IP address of the device connecting to them. This is ordinary network processing and is not unique to Perical.

We do not store your raw IP address in our product-analytics records. For analytics purposes, we may store a privacy-preserving identifier derived from your IP using a server-side keyed hash (an HMAC). This means the identifier cannot be reversed to recover your IP address, and it is used only for limited correlation purposes. The key used to derive this identifier is kept secret and is never exposed to browsers or users.

We may use network-origin signals (including the connecting IP address) on a transient basis to detect the use of VPNs, proxies, or other location-concealment services for security and abuse prevention, as described in the Acceptable Use Policy.

10Approximate Location / Country / Region / City

Where the Platform records location information (for example, in analytics), it stores only coarse location data such as country, region, or city. We do not collect precise real-time geolocation (such as GPS coordinates) unless a specific feature you are using requires it and you have chosen to provide it.

11Cookies and Similar Technologies

We and our service providers use cookies and similar technologies to keep you signed in, remember preferences, and understand how the Platform is used. The authentication provider and hosting providers may set their own cookies necessary for their services. You can usually control cookies through your browser settings, though some Platform features may not work if you disable them.

12How We Use Personal Data

We use personal information to:

  • provide, operate, and maintain the Platform;
  • authenticate users and protect accounts;
  • manage events, ticket tiers, guest lists, and check-ins;
  • send notifications, event updates, and service communications;
  • process privacy requests (access, correction, export, deletion, grievances);
  • improve and analyze the Platform;
  • detect, prevent, and respond to abuse, fraud, and security incidents, including detecting the use of VPNs, proxies, and other location-concealment services; and
  • comply with applicable legal obligations.

We do not sell your personal information, and we do not use your data for unrelated purposes without an appropriate basis or notice.

13Data Minimization

We design the Platform to collect only the personal information reasonably needed for the purposes described in this Policy. We do not collect unnecessary personal data, and we do not require identity documents, date of birth, or other sensitive identifiers for general use of the Platform. The one exception is organizer identity verification: to prevent abuse, organizers must verify their identity through DigiLocker before creating an event (see "Organizer Identity Verification" above).

15Data Sharing

We do not sell your personal information. We share personal information only as needed to operate the Platform, including with service providers who process data on our behalf, with event organizers who administer the events you join, or where required by law. Sharing with an event organizer is limited to the information needed to run that event (for example, your name and email so organizers can manage their guest list and admit you at the door).

16Service Providers / Processors

The Platform relies on third-party service providers for core operations. These providers process data on our behalf subject to appropriate arrangements. The principal providers include:

17Authentication Provider

Clerk provides authentication and account management. Clerk processes sign-in credentials, sessions, and basic profile information on our behalf. Account deletion is coordinated with Clerk as part of our deletion workflow. You can review Clerk's privacy practices at clerk.com/privacy.

18Database / Hosting Providers

Turso / LibSQL provides our primary database. Our database is hosted in the ap-south-1 (Mumbai) region. Data stored in the database includes account records, event and guest-list data, messages, analytics, audit records, and privacy-request records.

Cloudflare provides edge hosting and infrastructure. Cloudflare may process data as part of serving and protecting the Platform, in accordance with its own terms and privacy practices.

19File Storage

Cloudflare R2 provides object storage for files you upload to the Platform, such as avatars, banners, event assets, and check-in-related files. During an approved account deletion, files owned by your account are deleted where they can be identified as yours. Host-owned or shared files are not deleted when one guest leaves.

20Email / Communication Providers

Resend is used to send transactional and notification emails, such as event invitations, attendance confirmations, event updates, and ticket and check-in emails. We provide Resend only the information needed to deliver the message (such as the recipient email address and relevant message content).

21Analytics / Observability

Grafana Cloud is used for observability, including operational metrics, traces, and logs used to keep the Platform reliable and secure. We configure this so that sensitive content - such as passwords, tokens, cookies, and personal message contents - is not included in telemetry.

22International Processing

Some of the third-party services we use may process or store data outside India as part of providing their services, in accordance with their service terms and applicable contractual arrangements. For example, our authentication provider, email provider, and observability provider operate global infrastructure. We do not represent that all data remains within India at all times. Where processing occurs outside India, it is subject to the provider's applicable safeguards and our arrangements with them.

23Data Retention

We retain personal information only as long as necessary for the purposes described in this Policy or as required by law. Retention differs by category:

  • Account data - retained while your account is active and processed for deletion when you submit an approved account-deletion request.
  • Product / navigation activity - page-visit analytics are retained for approximately 90 days.
  • Security / ICT logs - security-relevant events are retained for approximately 365 days.
  • Admin audit records - privileged administrative actions are retained for approximately 730 days for accountability.
  • Temporary data exports - generated exports and download links expire within approximately 7 days.
  • Check-ins and attendance - retained for verification and operational purposes in accordance with applicable requirements.
  • Backups - backup copies may persist for the backup lifecycle and expire according to the backup retention schedule; data is not instantaneously removed from every backup copy when you delete it from the live Platform.

24Account Deletion

You can request deletion of your account from the Privacy area of your Settings. Account deletion is a request/approval workflow:

  • you submit an account-deletion request while signed in;
  • the request is reviewed by a platform administrator; a Super Admin is responsible for approving or rejecting deletion requests;
  • once approved, our deletion service removes or anonymizes your records in stages - including database records, your authentication account with our authentication provider, OAuth/integration credentials, and user-owned files stored with our file provider.

Some records may be retained where necessary for security, fraud prevention, legal obligations, dispute resolution, or audit accountability. Certain shared records (such as events, check-ins, attendance history, and audit logs) are retained - where appropriate, personal identifiers are anonymized. Backups may expire according to the backup retention lifecycle rather than disappearing instantaneously.

25Data Export

You can request an export of your personal information from the Privacy area of your Settings. Generated exports are temporary and expire after a short period.

Exports include your relevant personal information held by the Platform and never include passwords, authentication secrets, access or refresh tokens, API keys, internal security information, or other users' personal data.

26Data Correction

You can update your profile and account information directly in your settings. Where you identify information that is inaccurate, you may request a correction through the Platform's privacy request mechanism, and we will review and process eligible correction requests.

27Privacy Requests

You may use the Platform's privacy request mechanism to raise supported requests, including access, correction, export, deletion, and privacy grievances. Requests are processed through the Platform's privacy workflow and, where applicable, reviewed by platform administrators. You can track the status of your request from the Privacy area of your Settings.

28Grievance Mechanism

If you have a privacy concern or grievance, you can raise it through the Platform's privacy request mechanism or contact us at support@perical.in. We will review your concern and respond in a reasonable time. For security-related concerns, you may contact us at security@perical.in.

29Security

We implement reasonable technical and organizational measures to protect personal information against unauthorized access, disclosure, alteration, and loss, including:

  • encryption in transit;
  • authenticated access and role-based authorization;
  • audit logging of privileged administrative actions;
  • security logging and monitoring;
  • rate limiting and abuse controls; and
  • regular backups and an incident-response process.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

30Security Incidents

In the event of a security incident affecting personal data, we will follow our internal incident-response process, take reasonable steps to contain and remediate the incident, and - where required by applicable law or our obligations - notify affected users and relevant authorities. Where Indian regulations (such as CERT-In directions) require specific reporting, we will follow those requirements as applicable.

31Children's Data

The Platform is not designed for children. Users are required to be at least 18 years old. We do not knowingly collect personal information from children, and we do not build profiles of or target children for behavioral advertising. If you believe a child has provided us personal information, please contact us so we can take appropriate action.

32Age Requirement

Perical is intended for users who are at least 18 years old. During onboarding, users are asked to confirm they are 18 or older. We do not collect your date of birth and do not use government-issued identity documents to verify age.

33Changes to this Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date and, where appropriate, notify users. Continued use of the Platform after changes take effect constitutes acceptance of the updated Policy.

34Contact Information

If you have questions about this Privacy Policy or how your data is handled, please contact us:

If additional details such as a registered business address or a designated grievance officer are required, these will be published here once confirmed by the operating entity.

Questions about this document? Contact us at support@perical.in.