Legal
Privacy policy
What we collect, why, who we share it with, and what you can ask us to do about it.
Last updated August 6, 2026
1. About this policy
Exhibitio is operated by Wiktis Pty Ltd. This policy explains how we handle personal information, whether you are an organizer running events, a buyer purchasing a ticket or a booth, or a member of an organizer's team.
We are bound by the Australian Privacy Principles under the Privacy Act 1988 (Cth). Where the GDPR, UK GDPR, or a United States state privacy law applies to you, we honor the rights those laws give you as well.
2. Our role, and the organizer’s
This is the most important thing to understand, because it decides who you ask for what.
We are the controller for information about our own account holders: organizers, their team members, and people who contact us. We decide how that information is used.
We are the processor for information an organizer collects about their own buyers, applicants, exhibitors, and suppliers. The organizer decides what to collect and why. We hold it and act on their instructions.
So if you bought a ticket and want your details corrected or deleted, the organizer is the right first stop. Tell us and we will help, and we will pass the request on, but the decision is theirs.
3. Information you give us
- Account details: name, email address, password (stored hashed, never in readable form), and the workspace and role you belong to.
- Event content: event names, descriptions, images, venue and date details, ticket and booth types, prices, and floor plans.
- Contact records: the suppliers, exhibitors, sponsors, and payees an organizer adds to their address book, including business names, emails, and phone numbers.
- Documents: supplier invoices emailed into a workspace, and anything else uploaded.
- Support messages: what you write to us, and what we write back.
4. Information about buyers
When someone buys through Exhibitio we hold what the purchase requires: name, email address, phone number where the organizer asks for it, the order and its contents, the amount, the currency, and the time. Where tickets carry attendee names, we hold those too.
We never see or store card numbers. Payment details are entered directly with Stripe and stay with Stripe. What comes back to us is a reference, the outcome, and the last four digits.
Where an organizer runs applications, we hold the answers applicants give, which are whatever that organizer chose to ask.
5. Information collected automatically
Our own analytics is deliberately narrow. When someone views an event page or moves through a checkout we record the event, the page path, the type of interaction, a randomly generated session identifier, and the referring site.
We do not record IP addresses, names, or device fingerprints in our analytics. The session identifier is not linked to a person and cannot be used to identify one.
Separately, our hosting and security providers process technical information, including IP addresses, in order to serve the site and block abuse.
6. Information from connected accounts
An organizer may connect their own Meta Ads, Google Ads, Xero, ExpoFP, or AI assistant account. Connecting is optional and always started by the organizer.
From advertising accounts we read campaign level data: campaign names, spend, impressions, clicks, and conversions. That is business data, not personal information about the people who saw the ads, and we do not receive audience lists or individual level ad data.
Access tokens are stored encrypted and are deleted when the connection is removed. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
7. How we use information
- To run the platform: create accounts, list events, take orders, issue tickets and badges, and check people in at the door.
- To deliver purchases: send order confirmations, tickets, receipts, approval and payment links, and reminders about installments.
- To show organizers their own numbers: revenue, budgets, applications, and return on ad spend.
- To read supplier invoices an organizer emails in, and propose where the cost belongs.
- To keep the platform safe: detect fraud, abuse, and unauthorized access.
- To support you when you ask for help.
- To meet legal, tax, and accounting obligations.
- To improve the platform, using aggregated or de-identified information wherever that is sufficient.
We do not sell personal information, and we do not share it for cross context behavioral advertising. We do not use one organizer's data to benefit another, and we do not use your content to train AI models.
8. Why we are allowed to
Where the GDPR applies, we rely on: performing our contract with you, for running accounts and delivering purchases; our legitimate interests, for security, fraud prevention, and improving the platform; legal obligation, for tax and accounting records; and consent, where we ask for it, such as optional marketing.
Under Australian law we collect only what is reasonably necessary for the functions described above.
9. AI features
Three features use AI, and each is under the organizer's control:
- Drafting event copy: the event details an organizer has entered are sent to our AI provider to draft a headline and description. The organizer reviews it before anything is published.
- The buyer-facing agent: when an organizer turns it on, a buyer’s question and the event information the organizer has published are sent for processing to generate an answer. It answers only from that content.
- Reading supplier invoices: a document emailed into a workspace is sent for processing to extract the supplier, amounts, and payment details. Extraction only proposes; a person confirms before anything is filed or paid.
Content sent for these purposes is not used to train the provider's models. AI output can be wrong, and it is presented as a suggestion rather than a decision.
An organizer may also connect an AI assistant to their own workspace. That connection is read only, scoped to their workspace, and revocable at any time in settings.
11. Our sub-processors
These are the providers who process personal information on our behalf:
- Stripe, for payment processing and payouts. Card data is handled by Stripe directly and never reaches us.
- Supabase, for the database, file storage, and authentication.
- Vercel, for hosting and serving the application.
- SendGrid (Twilio), for transactional email such as tickets, receipts, approvals, and reminders.
- Anthropic, for the AI features described in section 9.
- Google, where an organizer connects Google Ads, and for the advertising measurement on our own marketing site.
- Meta, where an organizer connects Meta Ads.
- Xero, where an organizer connects their ledger.
- ExpoFP, where an organizer connects an interactive floor plan.
We require each of them to protect the information and use it only to provide their service to us. We will update this list when it changes.
12. Marketing and communications
Transactional messages are part of the service: order confirmations, tickets, approvals, payment reminders, and important account notices. You cannot opt out of these while you hold an account or an order, because they are how the thing you bought is delivered.
Marketing email is separate, is sent only where we are permitted to, and carries an unsubscribe link in every message. Unsubscribing stops marketing and leaves transactional messages untouched.
Where an organizer emails their own buyers through Exhibitio, the organizer is the sender and is responsible for complying with the Spam Act and equivalent laws.
14. How long we keep it
- Account records: while the account is open, and up to 12 months after it closes.
- Order, ticket, and payment records: at least 7 years, because tax and corporations law require it. This applies even if an account is closed.
- Supplier invoices and documents: while the workspace holds them, and deleted on request unless a tax record obligation applies.
- Analytics events: 24 months.
- Access tokens for connected accounts: deleted immediately on disconnect.
- Support correspondence: 3 years.
- Backups: purged on a rolling cycle, normally within 90 days.
Where we no longer need something and no obligation requires it, we delete it or de-identify it.
15. Security
- Everything is served over HTTPS, and data is encrypted in transit and at rest.
- Passwords are hashed. We never store them in readable form and cannot tell you what yours is.
- Connected account tokens are stored encrypted, and API keys are stored hashed and shown once.
- Workspaces are isolated at the database level, so one organization cannot read another’s data.
- Money surfaces require an admin role, and admin sessions require an additional verification step.
- Access to production systems is limited to those who need it.
No system is perfectly secure, and we will not claim otherwise. If you find a vulnerability, tell us and we will act on it.
16. If something goes wrong
If a data breach occurs that is likely to result in serious harm, we will notify the affected people and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires, and any other regulator we are required to inform.
Where the breach concerns data we hold as processor for an organizer, we will notify that organizer without undue delay so they can meet their own obligations.
17. Overseas transfers
Our providers operate internationally, so personal information may be stored or processed outside Australia, including in the United States and the European Union.
Before disclosing information overseas we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, including through contractual protections such as standard contractual clauses where they apply.
18. Your rights and choices
Subject to the law that applies to you, you can ask us to:
- Give you a copy of the personal information we hold about you.
- Correct anything that is wrong.
- Delete it, where no legal obligation requires us to keep it.
- Export it in a portable format.
- Stop or limit a particular use, or object to it.
- Withdraw consent you previously gave, without affecting what was done beforehand.
Contact us and we will respond within 30 days. We may need to verify who you are first. See our data deletion policy for how deletion works in practice.
If you are unhappy with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au, or to your local supervisory authority.
19. If you are an organizer
You are the controller of your buyers' personal information, and the law places obligations on you directly. In particular you must:
- Have a lawful basis for what you collect, and collect only what you need.
- Tell your buyers what you are doing with their information, in your own privacy notice.
- Honor requests from your buyers to access, correct, or delete their information.
- Keep application answers confidential and use them only to assess the application.
- Not use buyer data for marketing without a lawful basis, and honor unsubscribes.
- Tell us promptly if you become aware of a breach affecting data held in your workspace.
We act on your instructions, keep the data confidential, and will help you meet these obligations, including by providing exports and deleting data when you ask.
20. Children
Exhibitio is not intended for children. Accounts require you to be at least 18. Where a child attends an event, the ticket is bought by an adult, and we do not knowingly collect information directly from children. If you believe we hold information about a child, contact us and we will delete it.
21. Changes and contact
We will update this policy as the platform changes. If a change is material we will give reasonable notice before it takes effect, and the date at the top always shows the current version.
For any privacy question or request, contact us through the details on our company page. Privacy requests are handled by Wiktis Pty Ltd as operator of Exhibitio.