This Privacy Policy outlines how Thrillathon Innovation (“Thrillathon Innovation”, "Thrillathon", “Whooppe”, “TI”, "we", "our", "us") collects, processes, uses, stores, shares, and protects personal data through its digital facial-recognition-based ticketing ecosystem, applications, and related services. Thrillathon Innovation is committed to maintaining the highest standards of privacy, security, and user control over personal information.
Thrillathon Innovation is a technology startup focused on developing a secure, seamless, and privacy-preserving ticketing and access management system using face recognition and digital identity technologies. Our platform uses Self-Sovereign Identity (SSI) principles, enabling users to maintain full control of their personal data.
Thrillathon’s digital identity ecosystem is built on Self-Sovereign Identity (SSI), an identity framework that incorporates selective centralization. While Thrillathon uses certain SSI concepts for user‑controlled credentials, it also relies on a centralized database for operational, security, and event‑management purposes. This means:
We develop: a facial-recognition-enabled mobile application, a centralized identity ecosystem for generating Verifiable Credentials (VCs), and tools that allow users to authenticate seamlessly at venues using a "single face token." We maintain a centralized database for operational and security purposes; however, sensitive identity information—such as Government-ID details, biometric data, and Verifiable Credentials (VCs)—is stored only until our services are in use.
Thrillathon Innovation (“Thrillathon Innovation”, “Thrillathon”, “Whooppe”, “TI”, “our”, “we”, or “us”) respects your privacy and is committed to protecting the Personal Data we process about you. This Privacy Policy (“Policy”) explains our practices regarding the Personal Data processed when users create and store their Verified Credentials (VCs) on their devices through the Thrillathon Application (Whooppe). This Policy also describes how Verified Credentials and event-entry information may be shared with authorized event verifiers to enable seamless, contactless entry using facial recognition and/or digital event passes. Additionally, this Policy outlines the legal basis for processing Personal Data, the rights of individuals, and our overall approach to safeguarding your information.
This Privacy Policy applies to: The Thrillathon mobile application, Thrillathon’s backend systems, any (“If”) third-party partners who assist us in providing our services. All third parties follow the same standards outlined in this policy.
The objectives of TI’s Privacy Policy are to:
âś” Account & Profile Creation: To use the Thrillathon Innovation (Whooppe) service, a user profile is created on our backend systems. This profile includes your Name, Email Address, Phone Number, State, and a unique User ID. We do not claim to be "profile-less" or "anonymous" at an account level.
âś” Personally Identifiable Information (PII) Storage: Thrillathon Innovation does store the PII listed above (Name, Email, Phone, State, User ID) on our secure backend servers to manage your account, issue verifiable credentials, and facilitate event ticketing. This statement corrects any previous claims of "no PII storage."
âś” User Control: You remain in control of your Verifiable Credentials (VCs) stored locally on your device. You can choose to share event-entry details with event organizers after providing explicit consent before each entry.
âś” Support Interactions: When you interact with our team for support, Thrillathon Innovation will never request sensitive personal details such as Government-ID numbers or copies via unsecured channels. If a user voluntarily shares any personally identifiable information while seeking support, they consent to its use in accordance with this Privacy Policy.
In accordance with data protection principles and the Digital Personal Data Protection Act, 2023, you have the right to request permanent deletion of your account and all associated personal data from Thrillathon Innovation’s systems. We respect your control over your digital identity. Below is the official procedure to delete your Whooppe account and associated credentials.
To initiate the deletion of your Thrillathon Innovation (Whooppe) account and all related personal data (including Verifiable Credentials, event tickets, and any backend references), you must send a deletion request email from the registered email address associated with your account. Please use the following draft or compose a clear request.
đź“§ Email to: contact@thrillathon.co.in
📌 Subject line: Request for Account Deletion – Whooppe / Thrillathon Innovation
âś… What happens after you send the email?
Our support team will verify your ownership of the account (by matching the registered mobile number). Once verified, we will initiate the deletion process. You will receive a confirmation notification via WhatsApp and email within 7 business days from the date of receipt of a valid request. In most cases, deletion is completed within 3–5 business days. You will be notified through both channels to ensure you are fully informed.
⏳ Business days & communication:
Thrillathon Innovation operates on standard business days (Monday–Friday, excluding public holidays). After submitting the deletion email, you will receive an acknowledgement within 48 hours. Once the account and associated data are permanently erased from our centralized systems (including any stored biometric references and logs older than required retention), we will send a final confirmation via WhatsApp (to your registered number) and an email copy. No residual data will be retained unless required by law (e.g., transaction records for statutory audit, which will be anonymized).
⚠️ Note: Deleting your account will revoke all Verifiable Credentials stored on your device. Event entry passes will become invalid. You will need to onboard again if you wish to reuse Thrillathon services in the future. The deletion request is irreversible.
| Information | Stage | Purpose | Storage Location | Retention | Sharing |
|---|---|---|---|---|---|
| Mobile Number | Login / Registration | Authentication via OTP, account recovery | Backend Server | Until account deletion | With service providers for OTP delivery |
| Full Name | User Onboarding | Profile creation, ticket personalization | Backend Server | Until account deletion | With event organizers upon consent |
| Email Address | User Onboarding | Account verification, communication, password recovery | Backend Server | Until account deletion | With email service providers |
| State | User Onboarding | Location-based compliance, event suggestions | Backend Server | Until account deletion | Not shared externally |
| User ID (Internal) | Account creation | Unique identifier for account management | Backend Server | Until account deletion | With event verifiers for validation |
| Government ID / Virtual ID | Onboarding (eKYC) | Create Verifiable Credential (VC), age verification | Encrypted Backend & Device | Until user deletes VC or account | Shared with venue on explicit consent |
| Selfie (Face Image) | Onboarding | Biometric matching, identity binding | Encrypted Backend & Device VC | Until VC or account deletion | Shared with venue on consent for entry |
| Event Ticket / QR Code | Ticket Upload | Validate ticket and generate event-pass credential | Backend Server & Device | Until event concludes or deleted | Shared with venue on consent |
| Information | Stage | Purpose | Storage Location | Retention | Notes |
|---|---|---|---|---|---|
| Device ID (Android ID) | App installation / Push notification setup | Sending push notifications, fraud prevention | Backend Server (Firebase) | Until app uninstall or account deletion | Used by Firebase Cloud Messaging |
| Crash Logs & Diagnostics | When app crashes or encounters error | Debugging, app stability improvements | Firebase Crashlytics | 90 days | May include stack traces, device model, OS version. No PII by design but could contain contextual data. |
| IP Address | During API requests | Security, fraud analysis, rate limiting | Temporary backend logs | Few hours to 30 days | Anonymized after processing |
| Information | Purpose | Storage | Retention | Sharing |
|---|---|---|---|---|
| Email or unsolicited PII shared by user | Issue resolution | Support inbox (Zendesk or similar) | 30 days after ticket closure | Yes – Our Partners for Tech Support, and Customer support teams can have access |
| Information | Stage | Purpose | Storage | Retention | Sharing |
|---|---|---|---|---|---|
| Device Types and OS Version | Feedback, Crash Analytics reports | Optimize app performance, compatibility | Firebase reports, App stores dashboards | As per platform policy | Yes – Tech support partners |
| Anonymous App Data (downloads, usage, geo availability) | From download till uninstall | Track app popularity, engagement, usage patterns | Anonymous & aggregated data as per platform policy | Per platform policy | Yes – Tech support partners |
Thrillathon Innovation application does not allow creation of a VC for Minors (Any individual who is less than 18 years of age), and thus they cannot use the Thrillathon Application (Whooppe) without Guardian/Adult’s consent. This is enabled by a business rule that allows Minor profile creation only on those mobile devices where 1 Adult profile is available. This business rule is implemented by doing an age check with the Date of Birth available in the Government-ID eKYC data. Thus, TI does not collect, store, process, or transfer personal information of a child without consent from the parent or guardian.
Clarification on Central Storage: Thrillathon uses a hybrid storage model. While we utilize Self-Sovereign Identity (SSI) principles to keep Verifiable Credentials (VCs) and biometric templates on the user’s device, our backend systems do centrally store certain data for operational, security, and legal compliance purposes.
All processing of sensitive data (e.g., identity verification) takes place on secure, isolated servers within India. We comply with applicable Indian data protection laws.
| Personal Right and Controls | Description |
|---|---|
| Data Modification | Users have the right to review, access, and modify their Verifiable Credential and Entry Pass. Users can delete current entry pass and upload new one; for Government ID updates, delete credentials and re-authenticate. Updates in original Government ID must be done via Government Seva Kendra. |
| Withdrawal/Revocation or Transfer of Consent | Opt out by deleting VC and Ticket Credentials data or uninstalling the app. All data stored locally is permanently erased and cannot be retrieved. Backend data will be deleted upon account deletion request. |
| Grievance Redressal | For any questions or concerns, contact Thrillathon Innovation at contact@thrillathon.co.in. |
In accordance with this privacy policy, TI may share personal information with TI employees, advisers, agents and third parties who provide services on TI’s behalf insofar as reasonably necessary and in relation to the fulfilment of the purpose. Service providers who assist in protecting and securing TI systems. Successors or assigns to whom TI may assign or transfer functions. TI stores necessary user data in a central repository as described in Section 8. Information from the TI App present on the user’s device is only shared with explicit consent and does not disclose any personal information to others.
TI ensures security by adopting reasonable data protection practices, internal policies, periodic security audits, data privacy by design, and encryption. Employees follow ethical code of conduct. TI implements physical and cyber safeguards, encrypted transmission channels, and restricted access on a need-to-know basis. TI performs a yearly comprehensive audit and two non-comprehensive audits in a fiscal year.
Limited to the TI will only keep any personal data for a minimal amount of time and in the manner specified by relevant law and/or regulatory requirements. Account data is retained until deletion request. Logs and diagnostic data are retained as specified in Section 6.
Links to additional third-party websites and/or applications may be found on the TI public website. The content and privacy policies of those third-party websites are not TI’s responsibility. TI is not liable for the security and privacy of the data shared via those third-party programs.
TI retains the right, at any time, to update, modify, add, or change any provisions in this privacy statement. The TI website and application will be updated with any changes. The modifications will be incorporated into this policy and take effect on the date of the amendment, alteration, change, modification, addition, or update.
If you choose to use the TI Platform, your visit and any dispute over privacy is subject to this privacy policy. In addition to the foregoing, any disputes arising under this privacy policy shall be governed by the laws of India and the courts of Kota, Rajasthan, India shall have exclusive jurisdiction in case of disputes.
End of Policy — Thrillathon Innovation x Whooppe. Privacy by design, security at core.