Privacy Policy
Last updated: June 28, 2026
This notice is written for users, event organizers, exhibitors, sponsors, and dashboard administrators. It explains how IceBreaker by BoxHive processes personal data across the public website, event registration pages, organizer dashboard, Flutter mobile app, and related event tools. It is not a substitute for legal advice, and event organizers may provide additional privacy notices for their own events.
1. Who We Are And Scope
IceBreaker is a digital networking, event engagement, registration, check-in, analytics, and lead capture platform developed and operated by BoxHive Digital Solutions Co. In this policy, "IceBreaker," "BoxHive," "we," "us," and "our" refer to BoxHive Digital Solutions Co. and the IceBreaker platform.
This policy applies when you use the IceBreaker website, public registration pages, organizer/admin dashboard, QR tools, mobile application, Apple Watch companion features, email verification flows, support channels, and other services that link to this policy.
We process personal data in accordance with the Data Privacy Act of 2012 (Republic Act No. 10173), its Implementing Rules and Regulations, and applicable issuances of the National Privacy Commission.
2. Roles In Event Data Processing
IceBreaker is used by event organizers to operate their events. Depending on the feature, BoxHive may act as a personal information controller, a personal information processor, or a joint/independent controller with an event organizer.
- Event organizers decide who may attend, what attendee fields are needed, how registration and reporting are used, and which staff can access event data.
- BoxHive provides the platform, security, authentication, registration, check-in, networking, lead capture, messaging, and analytics systems.
- Exhibitors and sponsors may become independent controllers for leads they intentionally capture or export from the platform.
3. Information We Collect
Website and Public Registration Data
When you use our public website or register for an event, we may collect your email address, name, phone number, company, job title, selected event, registration status, verification status, event registration timestamps, and technical logs needed to protect the registration flow.
Dashboard and Organizer Data
For organizer, admin, exhibitor, and staff accounts, we may process account profile information, email address, role, organization, permissions, sign-in/session data, event configuration, uploaded event content, attendee management actions, scan/check-in actions, exports, audit/activity logs, and support requests.
Mobile App Profile and Event Data
In the Flutter mobile app, we may process account and attendee profile details such as name, email, profile picture, phone number, company, job title, industry, bio, social links, registration type, event assignments, QR identifier, selected event, agenda and session interactions, feedback, bookmarks, challenge progress, raffle/activity entries, badges, points, announcements, notifications, and support feedback.
QR, Check-In, Networking, and Lead Capture Data
We process QR scans, badge scans, booth scans, event and location check-ins, attendee-to-attendee connections, exhibitor leads, timestamps, scanner identity, location or booth context when configured by the event, and notes or follow-up data that users or exhibitors choose to add.
Device, App, and Usage Data
We may collect device type, operating system, app version, push notification tokens, crash logs, diagnostics, feature usage, performance data, IP-derived technical information, and security logs. We use Firebase Analytics and Firebase Crashlytics in the mobile app to understand usage patterns and diagnose crashes.
Local Device Storage
The mobile app may store authentication tokens, preferences, selected event context, notification read state, cached app data, chat or display cache, and encrypted local SQLite data on your device. Sensitive local database content is protected with an encryption key stored in platform secure storage, such as iOS Keychain or Android Keystore.
4. Cookies And Similar Technologies
We use cookies and local storage for necessary and functional platform purposes, not for third-party advertising on the public registration flow.
- Registration verification cookie: after you verify your email with a one-time code, we may set a secure, HTTP-only cookie named
ib_verified. It stores a signed verification payload for up to 30 days so you can register for another event without repeating OTP verification. You can clear it by using Log out on the registration page or clearing browser site data. - Dashboard session cookies: authenticated dashboard users rely on necessary session cookies to remain signed in, enforce authorization, and protect admin routes.
- Preferences and local storage: we may use local storage for UI preferences, event selector state, scanner helper state, and whether you have acknowledged the cookie notice.
5. How We Use Personal Data
We process personal data for legitimate, contractual, security, consent-based, and event-related purposes, including:
- Verifying email ownership and processing event registrations
- Creating, updating, and managing user and attendee profiles
- Operating event check-in, QR scanning, badge scanning, and venue/location workflows
- Enabling attendee networking, connection exchange, and contact export actions
- Supporting exhibitor and sponsor lead capture where a scan or intentional interaction occurs
- Delivering event announcements, reminders, push notifications, and transactional emails
- Providing organizer dashboards, attendee management, reporting, exports, and analytics
- Developing, testing, measuring, and improving IceBreaker and related BoxHive products, including product quality, reliability, recommendations, search, analytics, and integrations
- Maintaining platform security, fraud prevention, rate limiting, audit logging, and abuse detection
- Improving performance, usability, reliability, and crash diagnostics
- Complying with legal, regulatory, accounting, security, and dispute-resolution obligations
Cross-Product Use and Product Improvement
BoxHive may use personal data collected through IceBreaker to operate, support, secure, analyze, and improve IceBreaker and other BoxHive-owned products or services, provided the use is compatible with this policy, the event context, our contracts with organizers, and applicable law. Where a new use is materially different from the purposes described in this policy, we will provide additional notice, obtain consent where required, or limit the use to de-identified, anonymized, or aggregated data.
De-Identified and Aggregated Data
We may create and use non-identifiable data, including de-identified, anonymized, or aggregated data, for product analytics, benchmarking, industry insights, research, partner reporting, event performance reports, and business planning. These reports are intended to show trends, usage, attendance, engagement, product performance, and operational insights without identifying individual users. We will not use these datasets to identify you unless permitted or required by law, needed for security, or necessary to validate data quality.
6. When Data Is Shared
With Event Organizers
Event organizers and authorized staff may access attendee registration data, check-in status, attendance records, engagement activity, scan activity, feedback, and reports for their events.
With Other Attendees
When you connect with another attendee by scanning or exchanging QR codes, both parties may receive shared professional profile details such as name, company, position, email, profile picture, and social links, depending on the event configuration and profile fields available.
With Exhibitors and Sponsors
When you intentionally interact with an exhibitor or sponsor, such as by scanning a booth QR code or allowing your badge to be scanned, relevant professional profile and lead data may be shared with that exhibitor or sponsor. If they export leads, they are responsible for their own handling and follow-up use of that data.
With BoxHive Products, Integrations, and Business Partners
BoxHive may share or make data available across IceBreaker and related BoxHive products, integrations, and business partners when needed to deliver the service, support an event, provide requested features, prevent abuse, or support partner-enabled workflows. For analytics, reporting, benchmarking, product improvement, and partner insights, we use non-identifiable data where reasonably possible. We use contracts, access controls, and purpose limitations so partners may use personal data only for the authorized purpose. If a partner wants to use identifiable personal data for its own unrelated marketing or independent commercial purpose, we will require a lawful basis, additional notice, consent where required, or a separate relationship between you and that partner.
With Service Providers
We use service providers for hosting, authentication, database, storage, email, push notifications, analytics, crash reporting, search, file delivery, and infrastructure operations. They process data on our behalf under contractual, confidentiality, and security obligations.
Marketing, Promotions, and Sale of Personal Data
We may send BoxHive or IceBreaker product updates, event-related notices, and promotional communications where allowed by law or with your consent. You can opt out of non-essential marketing emails using the unsubscribe method provided or by contacting us. We do not sell personal data for money. If we ever participate in a data-sharing arrangement that applicable law treats as a sale, targeted advertising disclosure, or materially different commercial use, we will provide required notice and choices before doing so.
For Legal and Safety Reasons
We may disclose data when required by law, lawful request, dispute, security incident, protection of rights, prevention of fraud, or to protect users, organizers, BoxHive, or the public.
7. Third-Party Services
Depending on the event and platform configuration, IceBreaker may use:
- Supabase for authentication, database access, configuration, and storage-related services.
- Firebase for mobile analytics, crash reporting, cloud messaging, and related mobile infrastructure.
- Huawei Mobile Services for push delivery on supported Huawei devices.
- Resend or email providers for transactional email, OTP, invitations, and support communication.
- Algolia or search services for dashboard or in-app search where enabled.
- Cloud hosting, Redis/cache, object storage, and infrastructure providers for availability, speed, security, queueing, and file delivery.
8. Mobile Permissions
The mobile app asks for permissions only when needed for a feature:
- Camera: to scan attendee, event, booth, and badge QR codes.
- Notifications: to send event reminders, announcements, messages, and operational alerts.
- Contacts: to let you save exported connections to your phone contacts when you choose that action.
- Photo library or media picker: to select and crop a profile picture when you choose to upload one.
- Background fetch/processing: to support event data refresh, notification handling, and app reliability.
You can manage mobile permissions in iOS or Android settings. Some features may not work if the related permission is denied.
9. QR Codes, Offline Use, and Local Caches
Online QR codes use opaque identifiers where possible. Some offline QR features may include encrypted profile or event data so scanning can continue when network connectivity is unavailable. The app may cache event content, profiles, connections, announcements, session data, and scanner state locally to improve speed and offline resilience.
Local app data may remain on your device until you log out, clear app data, uninstall the app, or use an available deletion/reset feature.
10. Data Retention
We retain personal data only for as long as needed for the event, account, platform operations, organizer reporting, security, support, legal compliance, or legitimate business purposes.
- Public registration verification tokens are short-lived.
- The email verification cookie lasts up to 30 days unless cleared earlier.
- Account deletion requests may include a grace period, currently fourteen (14) days, before permanent deletion proceeds unless retention is legally required.
- Organizer exports and sponsor lead exports are controlled by the recipient after export.
- Security logs, audit logs, and backups may be retained for a limited period to protect the platform and comply with obligations.
11. Security Measures
We apply administrative, technical, and organizational safeguards, including:
- HTTPS/TLS for data in transit
- Authentication, role-based access control, and route authorization
- Secure, HTTP-only cookies for sensitive website verification/session flows
- Rate limiting, input validation, and abuse prevention on public registration endpoints
- Password hashing and secure token handling where passwords or tokens are used
- Encrypted local SQLite storage in the mobile app for selected cached user data
- Platform secure storage for sensitive mobile tokens and encryption keys
- Audit/activity logging for sensitive dashboard operations
- Access restrictions for event, organizer, exhibitor, and admin roles
- Dependency updates, monitoring, and incident response procedures
12. International Processing
Some service providers and infrastructure may process or store data outside the Philippines. Where this occurs, we rely on contractual, organizational, and technical safeguards, including processor agreements and security measures appropriate to the nature of the data and service.
13. Your Data Privacy Rights
Subject to applicable law and verification of your identity, you may request to exercise rights under RA 10173, including:
- Access to personal data we process about you
- Correction of inaccurate or incomplete data
- Deletion or blocking where legally available
- Objection to certain processing activities
- Withdrawal of consent where processing is based on consent
- Data portability where applicable
- Damages or complaint remedies as provided by law
To exercise these rights, contact [email protected]. We may need to verify your identity and coordinate with the event organizer before fulfilling requests involving event-controlled data.
14. Breach Notification
If a personal data breach occurs and notification is required by law, we will notify the National Privacy Commission and affected data subjects within the required period, including the nature of the incident, affected data, steps taken, and contact information for inquiries.
15. Children's Privacy
IceBreaker is intended for business, professional, school, organizer-approved, or event-authorized use. It is not intended for children under 16. If we learn that we collected personal data from a child without appropriate authorization, we will take reasonable steps to delete or restrict that data.
16. Changes To This Policy
We may update this policy as the product, laws, event requirements, or processors change. We will post the updated policy here and update the "Last updated" date. Material changes may also be communicated through the website, dashboard, app, or email.
17. Contact Us
Data Protection Officer / Privacy Contact: [email protected]
BoxHive Digital Solutions Co.
You may also contact or file a complaint with the National Privacy Commission at www.privacy.gov.ph.