Thrillathon Innovation x Whooppe
Privacy Policy

đź“… Last Updated: 17th April, 2026
Self-Sovereign Identity · Privacy-first facial recognition ticketing · User controlled credentials

This Privacy Policy outlines how Thrillathon Innovation (“Thrillathon Innovation”, "Thrillathon", “Whooppe”, “TI”, "we", "our", "us") collects, processes, uses, stores, shares, and protects personal data through its digital facial-recognition-based ticketing ecosystem, applications, and related services. Thrillathon Innovation is committed to maintaining the highest standards of privacy, security, and user control over personal information.

1. About Thrillathon Innovation

Thrillathon Innovation is a technology startup focused on developing a secure, seamless, and privacy-preserving ticketing and access management system using face recognition and digital identity technologies. Our platform uses Self-Sovereign Identity (SSI) principles, enabling users to maintain full control of their personal data.

Thrillathon’s digital identity ecosystem is built on Self-Sovereign Identity (SSI), an identity framework that incorporates selective centralization. While Thrillathon uses certain SSI concepts for user‑controlled credentials, it also relies on a centralized database for operational, security, and event‑management purposes. This means:

We develop: a facial-recognition-enabled mobile application, a centralized identity ecosystem for generating Verifiable Credentials (VCs), and tools that allow users to authenticate seamlessly at venues using a "single face token." We maintain a centralized database for operational and security purposes; however, sensitive identity information—such as Government-ID details, biometric data, and Verifiable Credentials (VCs)—is stored only until our services are in use.

2. Introduction

Thrillathon Innovation (“Thrillathon Innovation”, “Thrillathon”, “Whooppe”, “TI”, “our”, “we”, or “us”) respects your privacy and is committed to protecting the Personal Data we process about you. This Privacy Policy (“Policy”) explains our practices regarding the Personal Data processed when users create and store their Verified Credentials (VCs) on their devices through the Thrillathon Application (Whooppe). This Policy also describes how Verified Credentials and event-entry information may be shared with authorized event verifiers to enable seamless, contactless entry using facial recognition and/or digital event passes. Additionally, this Policy outlines the legal basis for processing Personal Data, the rights of individuals, and our overall approach to safeguarding your information.

3. Scope

This Privacy Policy applies to: The Thrillathon mobile application, Thrillathon’s backend systems, any (“If”) third-party partners who assist us in providing our services. All third parties follow the same standards outlined in this policy.

4. Objective

The objectives of TI’s Privacy Policy are to:

5. Key Points

âś” Account & Profile Creation: To use the Thrillathon Innovation (Whooppe) service, a user profile is created on our backend systems. This profile includes your Name, Email Address, Phone Number, State, and a unique User ID. We do not claim to be "profile-less" or "anonymous" at an account level.

âś” Personally Identifiable Information (PII) Storage: Thrillathon Innovation does store the PII listed above (Name, Email, Phone, State, User ID) on our secure backend servers to manage your account, issue verifiable credentials, and facilitate event ticketing. This statement corrects any previous claims of "no PII storage."

âś” User Control: You remain in control of your Verifiable Credentials (VCs) stored locally on your device. You can choose to share event-entry details with event organizers after providing explicit consent before each entry.

âś” Support Interactions: When you interact with our team for support, Thrillathon Innovation will never request sensitive personal details such as Government-ID numbers or copies via unsecured channels. If a user voluntarily shares any personally identifiable information while seeking support, they consent to its use in accordance with this Privacy Policy.

Account Deletion Policy & Right to Erasure

In accordance with data protection principles and the Digital Personal Data Protection Act, 2023, you have the right to request permanent deletion of your account and all associated personal data from Thrillathon Innovation’s systems. We respect your control over your digital identity. Below is the official procedure to delete your Whooppe account and associated credentials.

🗑️ How to request account deletion

To initiate the deletion of your Thrillathon Innovation (Whooppe) account and all related personal data (including Verifiable Credentials, event tickets, and any backend references), you must send a deletion request email from the registered email address associated with your account. Please use the following draft or compose a clear request.

đź“§ Email to: contact@thrillathon.co.in
📌 Subject line: Request for Account Deletion – Whooppe / Thrillathon Innovation

✉️ Suggested email draft (copy & paste):

To the Thrillathon Innovation Privacy Team,

I hereby request the permanent deletion of my Whooppe account and all personal data associated with it, including but not limited to my Verifiable Credentials, Government-ID linked data, selfie biometric references, event tickets, and any backend logs tied to my identity.

Registered Mobile Number: [Enter your Whooppe registered mobile number]
Full Name (as displayed in app): [Optional but helpful]
Reason for deletion (optional): [Withdraw consent / no longer using services]

I understand that once deletion is processed, all my Verifiable Credentials and locally stored data will be permanently removed from Thrillathon’s systems (centralized operational databases) and cannot be recovered. Kindly confirm via email and WhatsApp once the deletion is completed.

Thank you,
[Your Full Name]
[Registered Mobile Number]

âś… What happens after you send the email?
Our support team will verify your ownership of the account (by matching the registered mobile number). Once verified, we will initiate the deletion process. You will receive a confirmation notification via WhatsApp and email within 7 business days from the date of receipt of a valid request. In most cases, deletion is completed within 3–5 business days. You will be notified through both channels to ensure you are fully informed.

⏳ Business days & communication:
Thrillathon Innovation operates on standard business days (Monday–Friday, excluding public holidays). After submitting the deletion email, you will receive an acknowledgement within 48 hours. Once the account and associated data are permanently erased from our centralized systems (including any stored biometric references and logs older than required retention), we will send a final confirmation via WhatsApp (to your registered number) and an email copy. No residual data will be retained unless required by law (e.g., transaction records for statutory audit, which will be anonymized).

⚠️ Note: Deleting your account will revoke all Verifiable Credentials stored on your device. Event entry passes will become invalid. You will need to onboard again if you wish to reuse Thrillathon services in the future. The deletion request is irreversible.

6. Information Collected and Processed

a) Personal / Account Information

InformationStagePurposeStorage LocationRetentionSharing
Mobile NumberLogin / RegistrationAuthentication via OTP, account recoveryBackend ServerUntil account deletionWith service providers for OTP delivery
Full NameUser OnboardingProfile creation, ticket personalizationBackend ServerUntil account deletionWith event organizers upon consent
Email AddressUser OnboardingAccount verification, communication, password recoveryBackend ServerUntil account deletionWith email service providers
StateUser OnboardingLocation-based compliance, event suggestionsBackend ServerUntil account deletionNot shared externally
User ID (Internal)Account creationUnique identifier for account managementBackend ServerUntil account deletionWith event verifiers for validation
Government ID / Virtual IDOnboarding (eKYC)Create Verifiable Credential (VC), age verificationEncrypted Backend & DeviceUntil user deletes VC or accountShared with venue on explicit consent
Selfie (Face Image)OnboardingBiometric matching, identity bindingEncrypted Backend & Device VCUntil VC or account deletionShared with venue on consent for entry
Event Ticket / QR CodeTicket UploadValidate ticket and generate event-pass credentialBackend Server & DeviceUntil event concludes or deletedShared with venue on consent

b) Device & Technical Data (Previously Missing)

InformationStagePurposeStorage LocationRetentionNotes
Device ID (Android ID)App installation / Push notification setupSending push notifications, fraud preventionBackend Server (Firebase)Until app uninstall or account deletionUsed by Firebase Cloud Messaging
Crash Logs & DiagnosticsWhen app crashes or encounters errorDebugging, app stability improvementsFirebase Crashlytics90 daysMay include stack traces, device model, OS version. No PII by design but could contain contextual data.
IP AddressDuring API requestsSecurity, fraud analysis, rate limitingTemporary backend logsFew hours to 30 daysAnonymized after processing

c) Grievances / Support Information

InformationPurposeStorageRetentionSharing
Email or unsolicited PII shared by userIssue resolutionSupport inbox (Zendesk or similar)30 days after ticket closureYes – Our Partners for Tech Support, and Customer support teams can have access

d) Non-Identifiable / Aggregated Data

InformationStagePurposeStorageRetentionSharing
Device Types and OS VersionFeedback, Crash Analytics reportsOptimize app performance, compatibilityFirebase reports, App stores dashboardsAs per platform policyYes – Tech support partners
Anonymous App Data (downloads, usage, geo availability)From download till uninstallTrack app popularity, engagement, usage patternsAnonymous & aggregated data as per platform policyPer platform policyYes – Tech support partners

7. Data Processing for a Minor (less than 18 years of age)

Thrillathon Innovation application does not allow creation of a VC for Minors (Any individual who is less than 18 years of age), and thus they cannot use the Thrillathon Application (Whooppe) without Guardian/Adult’s consent. This is enabled by a business rule that allows Minor profile creation only on those mobile devices where 1 Adult profile is available. This business rule is implemented by doing an age check with the Date of Birth available in the Government-ID eKYC data. Thus, TI does not collect, store, process, or transfer personal information of a child without consent from the parent or guardian.

8. Data Storage & Processing

Clarification on Central Storage: Thrillathon uses a hybrid storage model. While we utilize Self-Sovereign Identity (SSI) principles to keep Verifiable Credentials (VCs) and biometric templates on the user’s device, our backend systems do centrally store certain data for operational, security, and legal compliance purposes.

All processing of sensitive data (e.g., identity verification) takes place on secure, isolated servers within India. We comply with applicable Indian data protection laws.

9. Your Rights

Personal Right and ControlsDescription
Data ModificationUsers have the right to review, access, and modify their Verifiable Credential and Entry Pass. Users can delete current entry pass and upload new one; for Government ID updates, delete credentials and re-authenticate. Updates in original Government ID must be done via Government Seva Kendra.
Withdrawal/Revocation or Transfer of ConsentOpt out by deleting VC and Ticket Credentials data or uninstalling the app. All data stored locally is permanently erased and cannot be retrieved. Backend data will be deleted upon account deletion request.
Grievance RedressalFor any questions or concerns, contact Thrillathon Innovation at contact@thrillathon.co.in.

10. Data Sharing

In accordance with this privacy policy, TI may share personal information with TI employees, advisers, agents and third parties who provide services on TI’s behalf insofar as reasonably necessary and in relation to the fulfilment of the purpose. Service providers who assist in protecting and securing TI systems. Successors or assigns to whom TI may assign or transfer functions. TI stores necessary user data in a central repository as described in Section 8. Information from the TI App present on the user’s device is only shared with explicit consent and does not disclose any personal information to others.

11. Security Measures

TI ensures security by adopting reasonable data protection practices, internal policies, periodic security audits, data privacy by design, and encryption. Employees follow ethical code of conduct. TI implements physical and cyber safeguards, encrypted transmission channels, and restricted access on a need-to-know basis. TI performs a yearly comprehensive audit and two non-comprehensive audits in a fiscal year.

12. Personal Data Retention

Limited to the TI will only keep any personal data for a minimal amount of time and in the manner specified by relevant law and/or regulatory requirements. Account data is retained until deletion request. Logs and diagnostic data are retained as specified in Section 6.

13. Third-Party Links

Links to additional third-party websites and/or applications may be found on the TI public website. The content and privacy policies of those third-party websites are not TI’s responsibility. TI is not liable for the security and privacy of the data shared via those third-party programs.

14. Policy Changes

TI retains the right, at any time, to update, modify, add, or change any provisions in this privacy statement. The TI website and application will be updated with any changes. The modifications will be incorporated into this policy and take effect on the date of the amendment, alteration, change, modification, addition, or update.

15. Jurisdiction

If you choose to use the TI Platform, your visit and any dispute over privacy is subject to this privacy policy. In addition to the foregoing, any disputes arising under this privacy policy shall be governed by the laws of India and the courts of Kota, Rajasthan, India shall have exclusive jurisdiction in case of disputes.


End of Policy — Thrillathon Innovation x Whooppe. Privacy by design, security at core.

```