Privacy Policy
Last updated: 13 September 2026
1. Who we are
Mi Karchi (www.mikarchi.com) is an event registration, ticketing and check-in platform. It is operated by D&I Business Support Services N.V., doing business as Reshapers, in Willemstad, Curaçao ("Mi Karchi", "we", "us").
This policy explains what personal data Mi Karchi handles, why, who we share it with, how long we keep it, and what rights you have. It covers the website, the event pages, the ticket emails, the organizer dashboard and the door check-in app.
We wrote this policy to address the Curaçao data protection law (Landsverordening bescherming persoonsgegevens) and the EU General Data Protection Regulation (GDPR).
In plain words: Mi Karchi is run by Reshapers in Curaçao. This page tells you what we do with your information.
2. Our role: organizer or Mi Karchi
Mi Karchi is used by companies and organizations that run events (the "organizer"). The organizer decides who is invited, which questions the registration form asks, and what the guest list is used for.
- If you register for or attend an event, the organizer is responsible for your data (the controller). Mi Karchi processes it on the organizer's behalf and on their instructions (the processor). The organizer's name is shown on the event page and in your ticket email.
- If you visit our website, request a demo, or use an organizer account, Mi Karchi is responsible for that data (the controller).
In plain words: When you sign up for an event, the company hosting the event owns your registration. We run the system for them. When you talk to us directly, we're responsible.
3. What we collect
If you register for an event
- Your name and email address.
- Your answers to the questions the organizer added to the form (for example department, dietary needs, or whether you're bringing a guest). The organizer chooses these questions.
- Your ticket: ticket number, QR code, and whether it's confirmed, waitlisted, cancelled or void.
- Check-in details: the time you were scanned in, the door station, the name the door staff entered, and whether you were scanned by QR, looked up by hand, or registered as a walk-in.
- Whether your ticket email was sent, delivered, delayed, bounced or marked as spam. We do not track whether you open the email or click its links.
If you request a demo or email us
Your name, email, organization, event date, expected headcount and your message. If you email any @mikarchi.com address, we receive your message, including any attachments, and pass it on to our team's inbox so a person can answer.
If you have an organizer account
Your name, email, role (owner, organizer or viewer), organization, a scrambled (hashed) version of your password, when you last signed in, and a record of your active sign-in sessions. We also record who changed certain event settings, such as the door code.
If you work at the door
The name or label you enter at your door station is saved with each check-in you make. Your device's camera is used to read QR codes. Camera images are processed on the device and are never recorded or sent to us.
When anyone visits the site
- IP address, used briefly in memory to stop automated abuse of our forms (rate limiting). It isn't stored in our database. Our hosting provider keeps short-lived server logs that include IP addresses, for security and troubleshooting.
- Page counts for event pages: we count how many times an event page was opened and how many times the form was started, per day. These are plain totals, with no cookie and no link to any person.
We don't use analytics tools, advertising pixels or tracking cookies. See our Cookie Policy.
In plain words: For events, we keep what you type into the form, your ticket, and when you walked in. We don't track you around the web or watch whether you open your emails.
4. Why we use it, and on what legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Registering you, sending your ticket, checking you in, waitlist and cancellations | Registration, ticket and check-in data | On the organizer's instructions. The organizer's basis is usually their contract with you, their legitimate interest in running a safe and well-organized event, or your consent. |
| Showing the organizer who registered and who attended, and giving them reports | Registration and check-in data | On the organizer's instructions |
| Checking that ticket emails arrive and resending them | Email address and delivery status | On the organizer's instructions |
| Answering your demo request or email, and following up | Demo request details, emails you send us | Our legitimate interest in replying to people who contact us, and taking steps toward a contract |
| Running organizer accounts, access and security | Account and session data | Our contract with the organizer |
| Preventing abuse, fraud and attacks | IP address, server logs | Our legitimate interest in keeping the service safe |
| Meeting legal and bookkeeping duties | Business records | Legal obligation |
We don't sell personal data, and we don't use it for advertising. We don't use attendee data for our own marketing.
In plain words: We use your details to run the event and keep the system safe. Nothing else.
5. Who we share it with
- The organizer of the event you registered for, and the people they give access to in their dashboard (including read-only viewers). Organizers can export guest lists. What they do with an export is their responsibility.
- Door staff working that event. Door devices keep a copy of the guest list (names, emails, answers, ticket status) so check-in keeps working without internet.
- Service providers we use to run Mi Karchi, under agreements that limit how they can use the data:
| Provider | What they do | Where |
|---|---|---|
| Vercel Inc. | Hosts the website and app, server logs | United States |
| Supabase Inc. | Database | United States (US East) |
| Resend (Plus Five Five, Inc.) | Sends ticket emails and demo requests, reports delivery status, receives email sent to @mikarchi.com | United States |
- Authorities, if the law requires it, or to protect the rights and safety of people at an event.
- A buyer or successor, if Mi Karchi or Reshapers is reorganized or sold. This policy would continue to apply.
In plain words: The event organizer sees your registration. Three technical providers help us run the system. We don't hand your details to anyone else.
6. International transfers
Our providers store and process data in the United States. For transfers from the EU, we rely on the safeguards our providers offer, such as the European Commission's Standard Contractual Clauses. Where Curaçao law requires it, we take equivalent steps.
In plain words: Our servers are in the US. We use the standard legal agreements to protect data sent there.
7. How long we keep it
| Data | How long |
|---|---|
| Registrations, answers, tickets, check-ins, email delivery status | 12 months after the event date, then deleted or anonymised. An organizer can ask us to delete an event's data sooner. |
| Guest list copies on door devices | Until the device is cleared. Organizers should clear door devices after the event. |
| Demo requests and emails you send us | Up to 24 months after our last contact, unless you become a client |
| Organizer accounts | While the account is active, then deleted within 90 days of closing it |
| Sign-in sessions | 30 days, or until you sign out |
| Server logs | Short-lived, as set by our hosting provider |
| Invoices and business records | As long as Curaçao law requires |
In plain words: Event data is gone a year after the event. Account data goes when the account does.
8. How we protect it
- All traffic to Mi Karchi is encrypted (HTTPS), and our database provider encrypts data at rest.
- Passwords are stored only as a scrypt hash. Sign-in cookies can't be read by scripts on the page.
- Every organization only sees its own events. Access is limited by role.
- Each event has its own ticket signing key, so a ticket from one event can't be forged for another.
- Forms are protected against automated abuse.
No system is completely secure. If a breach affects your data, we'll inform the organizer without undue delay so they can meet their obligations, and we'll inform you and the authorities where the law requires us to.
In plain words: We protect your data with encryption, hashed passwords and strict access. If something goes wrong, we'll tell the people who need to know.
9. Your rights
Under the Curaçao data protection law and, where it applies, the GDPR, you can ask to:
- see the personal data we hold about you, and get a copy
- correct data that's wrong
- delete your data
- restrict or object to how it's used
- receive your data in a portable format
- withdraw consent where processing is based on consent
For event registrations, send your request to the event organizer. If you contact us, we'll pass it on to them and help them respond. For everything else, email privacy@mikarchi.com. We'll respond within one month and may ask you to confirm your identity first.
You can also complain to the data protection authority in Curaçao or, if you're in the EU, to the authority in your country.
In plain words: You can ask to see, fix or delete your data. For event sign-ups, ask the organizer first. Otherwise, email us.
10. Children
Mi Karchi isn't meant for children to use on their own. Organizer accounts are for adults. If an event is open to people under 16, the organizer is responsible for getting consent from a parent or guardian. If you think a child has given us data without that consent, email privacy@mikarchi.com and we'll delete it.
In plain words: Kids shouldn't sign up without a parent. If one did, tell us and we'll remove it.
11. Changes to this policy
We may update this policy when Mi Karchi changes. The date at the top shows the latest version. If a change is significant, we'll email organizer account holders at least 30 days before it takes effect.
In plain words: If we change this page, the date changes. For big changes, organizers hear from us first.
12. Contact
D&I Business Support Services N.V. (Reshapers)
Willemstad, Curaçao
privacy@mikarchi.com