Privacy Policy

Last updated 1 August 2026

This is how [COMPANY LEGAL NAME] ("Eventinary", "we", "us") handles personal data on eventinary.com — a host's, a guest's, and a vendor's.

The description of what we collect and why is written against the actual product rather than a template, so it should stay accurate as the product changes. What it cannot supply on its own are the facts only the business decides — those are marked in brackets and need a real answer, and a lawyer's review, before this page means anything.

1. Who this covers

Three kinds of person appear in the product, and this policy covers all three differently: a host, who has an account; a guest, who does not; and a vendor, whose profile is a business listing rather than a personal one.

2. What we collect

What we hold depends on which of those three you are.

  • Host: your email address and name, through sign-in (Amazon Cognito). We do not see or store your password.
  • Guest: whatever a host enters or you reply with — your name, and an email address or phone number, plus anything you type into an RSVP: a party size, dietary or access notes, a message. You never create an account, and a guest link is the only credential involved.
  • Vendor: the business profile you fill in — name, category, city, portfolio photos, pricing — plus the enquiries and bookings that pass through it.
  • Payments: card details never reach us. Ticket sales and cash gifts are processed by Stripe directly, and we hold only what Stripe returns — an amount, a status, and a reference.
  • Everyone: standard web request data (IP address, browser) that reaches our infrastructure as a side effect of serving the page, and analytics data — see section 5.

3. Why we collect it

To do the thing you asked: run the event a host is organising, deliver an invitation or reminder to a guest, process a payment, or list a vendor and route enquiries to them.

We do not collect data to build a profile of you for our own purposes, and a guest list a host uploads is used to run that host's event and nothing else — see the equivalent commitment in the Terms.

4. Marketing communications

We do not run our own marketing list. The messages a guest receives — an invitation, a reminder, an update — are the host's own messages, sent on the host's behalf and addressed by the host, not marketing from us.

A host may receive an occasional email from us about their own event (a status digest they requested, or a service notice about their account). [STATE WHETHER THE BUSINESS EVER EMAILS HOSTS OR VENDORS DIRECTLY ABOUT THE PRODUCT ITSELF — E.G. FEATURE ANNOUNCEMENTS — AND IF SO, LINK THE UNSUBSCRIBE MECHANISM HERE.]

5. Cookies and analytics

We use Google Analytics to understand which pages are read and which are not — page views and a small number of named interactions (for example, clicking through to create an event). It runs on the marketing and account pages generally, and is set up not to reduce to a personal identity on our side.

It sets cookies through Google to do that measurement. See Google's own privacy policy for how Google itself handles that data.

[STATE WHETHER A COOKIE BANNER / CONSENT MECHANISM IS REQUIRED IN THE JURISDICTIONS YOU OPERATE IN, AND LINK IT HERE IF SO.]

6. Who we share it with

We do not sell personal data. It is shared only with the processors that make the product work, each doing one job:

  • Amazon Web Services — hosting, storage, and the database everything above lives in.
  • Amazon Cognito — host sign-in.
  • SendGrid — delivering invitations, reminders and updates by email.
  • Twilio — delivering invitations and reminders by text message.
  • Mailjet — sending a host their own status digest, when they ask for one.
  • Stripe — processing ticket payments and cash gifts.
  • Google Analytics — the usage measurement described in section 5.

7. How long we keep it

There is no automatic expiry on an event, a guest list, or a vendor profile — it is kept for as long as the account that owns it exists, because a host may return to an event long after it happened.

Deleting an event deletes its guest list, replies, posts, tasks, seating plan and uploaded design immediately, and that cannot be undone from within the product. The database that held it keeps point-in-time backups for a rolling 35 days afterward, which is an operational safeguard against our own mistakes, not a way to recover a deletion you asked for.

[STATE HOW LONG AN ACCOUNT ITSELF IS KEPT AFTER A HOST STOPS USING IT, AND WHETHER YOU RUN ANY ADDITIONAL DELETION ON REQUEST BEYOND WHAT THE PRODUCT ALREADY DOES.]

8. Guests specifically

A guest's data is entered by the host who invited them, or by the guest replying to that invitation — we do not collect it independently. The host controls that guest list: adding, editing or removing a guest, and revoking their link, are all things only the host can do.

If you are a guest and want your details corrected or removed, the fastest route is asking your host, since they hold the list. Contact us directly if that is not possible.

9. Your rights

[SET OUT THE RIGHTS THAT APPLY IN YOUR USERS' JURISDICTIONS — E.G. GDPR ACCESS, CORRECTION, ERASURE, PORTABILITY AND OBJECTION RIGHTS FOR THE UK/EU, OR CCPA/CPRA RIGHTS FOR CALIFORNIA — AND HOW TO EXERCISE THEM.]

Questions or requests about your data go to [SUPPORT EMAIL].

10. Children

Eventinary is not directed at children, and a host must be old enough to hold an account under the Terms. A guest list may include a child's name where a host is inviting a family — that is the host's data to hold, on the same basis as the rest of their guest list.

11. Where data is processed

[STATE THE AWS REGION(S) DATA IS PROCESSED IN, AND WHETHER ANY TRANSFER MECHANISM (E.G. STANDARD CONTRACTUAL CLAUSES) IS NEEDED FOR USERS OUTSIDE THAT REGION.]

12. Changes to this policy

We may update this policy as the product changes. Where a change is material we will give notice before it takes effect, and the date at the top of this page always says when it last changed.

13. Contact

Questions about this policy go to [SUPPORT EMAIL].