Frequently asked questions

Before you open the door.

Straight answers about guest access, vendors, programmes, payments, privacy and what the MVP does not yet do.

Sotto pauses scanning within three seconds and clearly enters manual mode. No guest is silently rejected. Door staff can use the minimal last-synced handle and invitation-source list, record the admission on the venue fallback sheet, and retry when connectivity returns.

No. Guests claim through a private mobile link and present a time-limited browser-based door pass.

A link can be copied, but a direct invitation can only be claimed once. Distribution links can also be capped, paused and attributed to a source.

Yes. An organiser can add an optional event passcode on top of a valid invitation and verified phone. Sotto stores only a salted hash, and replacing the passcode immediately affects unclaimed invitations without invalidating passes already claimed.

Not in the MVP. One invitation represents one person and one door credential. The host should issue a separate invitation for every guest.

The organiser chooses a reveal time. Sotto checks that boundary on the server before returning the decrypted venue.

Yes. The event owner can export claimed handle, status, invitation source and check-in time. Exports are audited and become unavailable after the event is wiped.

Claimed handles, invitation lineage, approvals, distribution performance, reveal delivery and check-in state. Phone numbers and decrypted venues are kept out of list views.

Access is restricted to authorised operational support and infrastructure administrators when necessary to run, secure or support the service. Sotto does not sell the data or use it for cross-event profiling.

Sotto automatically runs the configured event wipe after the arrival window, and the organiser can trigger it early. It removes event-scoped guest details, tokens, lineage, delivery records and venue ciphertext while retaining anonymous totals.

Yes. Stripe Connect handles the payment. Organisers can agree a flat fee or deposit, collect it through their connected account, issue controlled refunds and retain a commercial record. Any Sotto percentage is disclosed before the vendor accepts.

Yes. Each programme entry can have its own time, capacity, eligibility, approval flow, partner link and encrypted venue reveal.

Yes. Create expiring, revocable links for producers, guest-list staff and door devices. Each person sees only their part of the event.

Private-beta capacity is agreed during application so the door, messaging and support plan match the room. Sotto does not make a universal public capacity promise for the MVP.

Recurring series are not native in the MVP; create a separate event for each edition. One event can include after-parties, partner sessions and other programme entries across multiple dates.

Private-beta pricing is invite-only. There is no automatic renewal: scope and price are agreed before a second event.

New organisers accepted into the private beta receive one Sotto platform event without a platform fee. SMS is charged only at cost and disclosed before anything is sent.