Privacy, in plain language.
What happens when you register a booth visit, and how to ask about your details.
Updated 15 September 2026
What we collect
A visitor form collects your name, mobile number, booth and registration time. You can optionally provide a city or village and a product or service interest. We store your follow-up choice and the consent wording shown. The current forms support Indian mobile numbers. Formatting checks do not verify that a number belongs to you.
For business users and administrators, managed email sign-in provides an account identifier and verified email. Booth setup stores the company name, event, booth number and contact email. The hosting service processes technical request information. We use request counters and hashed phone identifiers to limit abuse; expired counters require operational cleanup.
When you request a pilot
The Get started form collects your business name, verified account email and optional exhibition details, along with the request time and notice version. We use them to review and respond to your request. You and the platform administrator can view your application. Approval creates a business account and makes you its owner. This does not authorise unrelated marketing. Request records are currently retained for manual review; automatic expiry is not configured. You can request correction or removal through the privacy contact below.
Why your details are used
Submitting the visitor form asks us to record your visit and share the submitted details with the exhibitor named on that form. The separate, optional follow-up checkbox allows that exhibitor to contact you about its products by phone or WhatsApp. You can register without selecting it.
We use account information to restrict dashboard access and technical information to operate and protect the service. We do not sell visitor lists to unrelated businesses.
Who can access the record
Other visitors cannot browse your details. The named business owner can see its booth records, manage assigned staff and export data. Staff can view and update records only for booths assigned to them. Platform administrators review businesses and audit events; their role does not grant access to visitor registers. Netlify and Supabase process hosting, database and authentication data when this deployment is configured. Resend delivers account emails, and Zoho hosts our contact mailboxes. Information may also need to be disclosed where required by applicable law.
The exhibitor is responsible for how it uses a copy it receives, including any follow-up it sends. Opening a WhatsApp link takes the sender to a separate service with its own privacy terms. Boothmilo does not automatically send visitor follow-up or marketing messages.
Your choices and requests
You can decline marketing, ask to stop future contact, and ask to see, correct or remove your record. Use the contact email on the original booth form or submit a request at /privacy/request. The business owner must verify your identity before fulfilling a request. Include the event and booth so the right record can be found. We may need proportionate verification to protect you from someone changing your information.
Submitting the same mobile number again does not replace the original details or contact preference. To change them, make a correction request. Do not send passwords, identity documents or payment details with a request unless a necessary and secure verification process has been agreed.
Storage and deletion
Records are stored in the configured Supabase database. Retention and deletion are currently managed by the business owner and operator; automatic expiry is not yet configured. Completed privacy requests have their phone number and message removed. Consent and audit records have separate retention needs. Ask the booth contact for removal when your record is no longer needed. Any information that must be retained for a legal obligation must be handled separately from ordinary marketing use.
Copies already exported to an exhibitor also need to be addressed with that exhibitor. Detailed retention periods, backup deletion procedures and infrastructure locations will be published before wider business onboarding.
Children and assisted registration
This pilot is intended for adults. Do not submit a child’s personal details; a verified parental-consent flow is not available. When helping another adult, explain what will be shared, read the phone number back and let that person choose whether to receive follow-up.
Service notices and updates
We use the authentication necessary to run the business dashboard and do not add advertising trackers to these pages. Providers may process necessary operational logs. We will update this notice when the operator details, authentication or data-handling arrangements change. New purposes require an appropriate notice and permission; a notice update alone does not grant permission for unrelated marketing.