Privacy Policy
Effective 29 September 2026 · Last updated 29 September 2026 · Version 1.0
This Privacy Policy explains how Cosmoura Marketing Private Limited ("Cosmoura", "we", "us", "our") — the operator of the MyShowPage platform available at myshowpage.com — collects, uses, discloses and protects personal data of visitors, subscribers, tenants and their end-users.
This policy is drafted to comply with the Digital Personal Data Protection Act, 2023 (India) and the DPDP Rules, 2025, and — for users in the European Economic Area, United Kingdom and other jurisdictions — the General Data Protection Regulation (EU) 2016/679, the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA) and comparable laws.
1. Who we are & how to contact us
Data Fiduciary / Data Controller: Cosmoura Marketing Private Limited (CIN U52609HR2019PTC080335, GSTIN 06AAICC1768L1ZC), a company incorporated under the Companies Act, 2013, with head office at 295, Block C, Sushant Lok III, Sector 57, Gurugram, Haryana — 122003, India. Website: https://cosmoura.com.
- Grievance Officer (India, DPDP Act §8(9)) & Data Protection Officer: Subesh Kumar — [email protected]
- Website / product support: [email protected]
- Postal: Cosmoura Marketing Private Limited, 295, Block C, Sushant Lok III, Sector 57, Gurugram, Haryana — 122003, India
2. Scope of this policy
This policy covers:
- The public marketing website at myshowpage.com and cosmoura.com.
- The MyShowPage SaaS dashboard used by artists, agencies and their team members ("Tenants").
- Public artist / agency profile pages hosted on myshowpage.com/@handle.
For personal data of end-users (event enquirers, clients, booking contacts) submitted through a Tenant's profile page, the Tenant is the Data Fiduciary / Controller and Cosmoura is the Data Processor under our Data Processing Agreement. Please read the Tenant's own /privacy page for their processing.
3. Personal data we collect
3.1 When you visit myshowpage.com
- Technical data — IP address, browser type, device type, referrer, pages viewed, timestamps.
- Cookies — strictly necessary cookies (session, CSRF), and, with your consent, analytics cookies. See our Cookie Policy.
3.2 When you register a Tenant account
- Identity — full name, stage name, handle, profile photo.
- Contact — email, mobile phone.
- Authentication — password (stored only as a bcrypt hash), MFA seed if enabled, login timestamps and IPs.
- Billing — plan tier, billing address, GSTIN (India) or VAT number (EU) where applicable, invoices we raise on you, tokenised payment instruments (never full card numbers — we never see or store PAN, CVV or full card details).
- KYC (agencies only, on request) — PAN, company registration proof, bank statement — encrypted at rest.
3.3 When you use the dashboard
- Content you enter — event details, client contacts, quotes, invoices, notes, tasks, uploaded media, messages.
- Usage telemetry — features clicked, errors encountered, session duration — for reliability, security and product improvement.
3.4 What we do NOT collect ourselves
- Ticket-buyer personal data — this stays with SignupDesk.
- Payment card numbers, CVV, UPI PIN — handled entirely by Razorpay (India) or Dodo Payments (international).
- Sensitive personal data (health, biometrics, sexual orientation, religion) — please do not submit these; if inadvertently submitted, we will delete on notice.
4. Purposes & legal bases for processing
| Purpose | Legal basis (India / DPDP) | Legal basis (EU / GDPR) |
|---|---|---|
| Provide the service you signed up for | Certain legitimate use §7 | Contract, Art. 6(1)(b) |
| Charge and invoice subscription fees | Legal obligation §7(b) | Contract & legal obligation, Art. 6(1)(b),(c) |
| Comply with tax / anti-money-laundering / statutory record-keeping | Legal obligation §7(b) | Legal obligation, Art. 6(1)(c) |
| Fraud prevention, security, abuse detection | Certain legitimate use §7 | Legitimate interest, Art. 6(1)(f) |
| Product analytics & improvement | Consent §6 | Consent / legitimate interest, Art. 6(1)(a),(f) |
| Marketing communications (email, WhatsApp) | Consent §6 (unticked opt-in) | Consent, Art. 6(1)(a) / PECR |
| Respond to your rights requests, support, disputes | Certain legitimate use §7 | Legal obligation, Art. 6(1)(c) |
5. Sharing & sub-processors
We share personal data only with vetted sub-processors bound by written agreements. Current list (updated periodically):
- Cloudflare, Inc. — CDN, DDoS protection, R2 object storage.
- Contabo GmbH — primary application & database hosting (India region).
- OVHcloud — disaster-recovery replication (Singapore).
- Razorpay Software Private Limited — subscription payments for India (INR).
- Dodo Payments — subscription payments for international customers (USD/EUR).
- Meta Platforms (WhatsApp Business Cloud API) via BookMySMS — outbound messaging you initiate.
- Anthropic PBC (Claude API) — generative-AI features you invoke (redacted prompts only).
- SignupDesk — ticketing for public events (only aggregate readback stored here).
- Google LLC — one-way calendar push (with your Google account consent).
- Postmark / Amazon SES — transactional email.
We do not sell personal data. We do not share personal data with advertisers.
6. Cross-border transfers
India (DPDP Act §16): primary storage is in India. Disaster-recovery replication is to Singapore. Certain named sub-processors may process outside India. We monitor the Central Government's "restricted country" notifications and will reconfigure if a currently-permitted country becomes restricted.
EU/UK (GDPR Chapter V): where personal data of EEA/UK residents is transferred to India or to a third country without an adequacy decision, we rely on Standard Contractual Clauses (2021/914) or the UK IDTA, plus a transfer impact assessment. A copy is available on request from [email protected].
7. Retention
- Account & profile data — for the life of the account plus 90 days after cancellation (grace period) unless you request erasure sooner.
- Financial records (invoices, tax records) — 8 years, per Section 128 of the Companies Act, 2013 and Rule 6F of the Income-tax Rules.
- Communication logs — 12 months.
- Backups — 35 days rolling.
- Marketing consent records — until withdrawal plus 3 years, per the DPDP Rules audit obligation.
On erasure, we anonymise personal data across CRM, messages and consents, but retain financial records with PII replaced by a token to satisfy tax laws.
8. Your rights
8.1 Under the DPDP Act, 2023 (India)
- Right to access your personal data (§11).
- Right to correction & erasure (§12).
- Right to grievance redressal (§13) — contact the Grievance Officer first; escalate to the Data Protection Board of India if unresolved.
- Right to nominate another individual to exercise your rights in the event of death or incapacity (§14).
- Right to withdraw consent at any time — as easily as it was given (§6(4)).
8.2 Under GDPR / UK GDPR
- Access (Art. 15), rectification (Art. 16), erasure "right to be forgotten" (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21), automated-decision-making rights (Art. 22).
- Right to lodge a complaint with your national supervisory authority (Art. 77) — e.g. the Irish DPC, ICO (UK), or CNIL (France).
8.3 Under CCPA/CPRA (California)
Right to know, right to delete, right to correct, right to opt-out of "sale/sharing" (we do not sell), right to limit use of sensitive personal information, and non-discrimination. Submit requests to [email protected].
8.4 How to exercise your rights
Email the address above from the account address on file, or use the in-app "Data & privacy" screen. We verify identity, respond within 30 days (extendable by 60 days for complex requests under GDPR; 90 days under DPDP Rules), and never charge a fee for the first request in any 12-month period.
9. Children
MyShowPage is not directed to children below 18 years. Where a Tenant manages an artist who is a minor, verifiable parental / guardian consent must be captured (feature provided). We do not conduct behavioural tracking or targeted advertising on any profile of a person we know to be a minor (DPDP Act §9).
10. Security
Reasonable safeguards under DPDP Act §8(5) and GDPR Art. 32 include: TLS 1.2+ in transit, AES-256 at rest for KYC/financial fields, bcrypt password hashing, role-based access control, multi-factor authentication for privileged roles, tamper-evident audit logs, annual third-party penetration testing, documented incident-response and backup/restore procedures, and least-privilege access.
11. Personal-data breach notification
If a personal-data breach occurs, we notify the Data Protection Board of India and affected Data Principals without undue delay, as required by DPDP Act §8(6). For EU/UK residents we notify the lead supervisory authority within 72 hours under GDPR Art. 33, and affected data subjects without undue delay under Art. 34 where high risk is likely.
12. Cookies & tracking
We use only strictly necessary cookies by default. Analytics and preference cookies load only after your opt-in. Full details in the Cookie Policy.
13. Changes to this policy
We will announce material changes via in-app banner and email at least 15 days before they take effect. Historical versions are archived and available on request.
14. Grievance redressal & regulators
Please write first to our Grievance Officer / DPO. If unresolved:
- India: Data Protection Board of India (once operational) — meity.gov.in.
- EU: the supervisory authority in your Member State.
- UK: Information Commissioner's Office — ico.org.uk.