Skip to main content

Privacy & Data Security Policy

At UniTix (unitix.aarx.online), safeguarding student identity and organizer financial records is our highest priority. This Privacy Policy details the exact mechanisms by which we collect, store, process, and protect your data in compliance with international privacy standards and local data protection regulations (PDPA / GDPR).

1. Information We Collect

A. From Student Attendees

To verify academic status and issue forgery-proof digital passes, we collect:
  • Core Identity: Full Legal Name, Primary Email Address, and Phone Number (SMS OTP validation).
  • Academic Verification: University Name, Degree Program, and Official University Roll/Registration Number (e.g., 2022-CS-101).
  • Profile Headshot: A clear facial photograph uploaded during onboarding. This photo is displayed to on-site Gate Scanners exclusively for facial verification against ticket transfers or QR fraud.
  • Transaction Proofs: Screenshots of manual bank transfers (JazzCash, EasyPaisa, IBFT) and transaction reference IDs (TxID) submitted during paid checkouts.

B. From Society Organizers & Presidents

To comply with Anti-Money Laundering (AML) and Know-Your-Customer (KYC) financial regulations:
  • Official Identifiers: Society Name, Campus Slug, and Faculty Advisor verification credentials (Email & Contact).
  • President KYC Documents: National ID Card (CNIC) Front and Back photographs submitted during society registration.
  • Banking Credentials: Official Bank Account Title, Bank Name, and International Bank Account Number (IBAN) for ticket sales payout transfers.

2. How Your Data Is Used & Processed

We process your personal information strictly for core platform functionality:
  1. Cryptographic Ticket Issuance: Generating dynamic JSON Web Tokens (JWT) and QR codes (qrToken) tied directly to your roll number and identity.
  2. Gate Check-in & Security: Displaying your name, roll number, and profile headshot to authorized volunteer Gate Scanners during on-site entry to prevent screenshot sharing.
  3. Financial Reconciliation: Verifying payment screenshots against society ledger statements and executing payout wire transfers (IBFT).
  4. Automated Waitlists & Notifications: Dispatches SMS (OTP/Alerts) and transaction emails when tickets are approved, transferred, or reallocated from waitlists.

3. Data Sharing & Disclosure Boundaries

UniTix never sells, rents, or monetizes your personal data to third-party advertisers. Data access is strictly compartmentalized:
  • Society Visibility: When you reserve a ticket, the organizing society gains access to your Name, Roll Number, Email, and Check-in Status for event management and .CSV attendee manifest generation.
  • Role-Based Access Control (RBAC): Volunteer Gate Scanners only see your Name, Roll Number, and Photo during the split-second scan. They cannot download attendee spreadsheets or view financial details.
  • Legal Compliance: We reserve the right to disclose KYC identity records to university administration or law enforcement if required by lawful subpoena in cases of financial fraud, ticket forgery, or campus safety violations.

4. Encryption & Data Storage

  • In-Transit Encryption: All communication between mobile browsers, gate scanners, and our server platform is encrypted using industry-standard TLS 1.3 / HTTPS.
  • At-Rest Storage: User records, event data, and cryptographic tickets are stored securely inside Enterprise Multi-Region Cloud Databases protected by strict Identity & Access Management (IAM) security boundaries.
  • KYC & Receipt Storage: Sensitive CNIC identity images and bank receipts are stored inside isolated, encrypted cloud object storage governed by short-lived, signed cryptographic access tokens.

5. Your Data Rights & Deletion Requests

As a registered student or organizer, you retain absolute sovereignty over your profile data:
  • Access & Corrections: You can update your profile name, roll number, and password anytime inside My Profile.
  • Account Deletion (Right to be Forgotten): You may request permanent deletion of your account and personal identifiers by contacting support@unitix.aarx.online. Note that financial audit logs, completed payout records, and used ticket transaction IDs must be retained for 7 years to comply with tax and AML regulations.