Este documento es un borrador pendiente de revisión legal y aún no constituye los términos legales definitivos de Eventyno. Versión del borrador: 2026-09-25-v3-draft
Eventyno Privacy Policy
Document version: 2026-09-25-v3-draft (see §2d for what changed) Status: DRAFT — LEGAL REVIEW REQUIRED BEFORE COMMERCIAL LAUNCH Operator: Twilight Media Design Corp. ("Eventyno," "we," "us," "our") Privacy contact: [PRIVACY EMAIL] Mailing address: [COMPANY MAILING ADDRESS]
This Privacy Policy explains what information Eventyno collects, why, how it is used and shared, and the choices and rights available to you.
1. Who we are
Eventyno is operated by Twilight Media Design Corp. This Policy applies to the Eventyno website and application (the "Service").
2. Information we collect
Account data. Email address, password (stored in hashed form by our authentication provider), and account status information.
Profile data. Display name, username, optional profile photo, optional short bio, preferred language, optional country, timezone, and your privacy choices (for example, whether your public profile is visible).
Event data. Event details you create: title, description, type, date, time, location fields, visibility setting, and status.
Story content. The text and structured content blocks you write to tell your event's story.
Photographs and videos. Media you upload for your event's cover, gallery, story, or gift list, along with related metadata (file type, size, and, for video, duration).
Gift-list data. Gift titles, descriptions, external product links, and optional prices you add to your event's Gift List.
Printable invitation, RSVP, and gift-reservation data (event guests). See §2a below — this category is collected from your event's guests, not from your own account.
Age-assurance, guardian-relationship, and event-subject data. See §2c below.
Support communications. Messages you send us, including reports and privacy or copyright requests.
Basic technical and device data. Information such as IP address (used transiently for security and abuse prevention, and not retained longer than reasonably necessary for that purpose), browser type, and general usage information needed to operate and secure the Service.
Security logs. Records of authentication events and similar security- relevant activity, used for fraud and abuse prevention.
Essential cookies and local storage. Used for authentication, security, and essential preferences (such as your selected interface language). We do not use non-essential tracking cookies in this phase.
Page and event usage. Aggregate view counts for events, and first-party funnel metrics (for example, that a "Create Your Event" button was clicked from a specific event page) used to understand and improve the product. We do not use invasive fingerprinting, and referral attribution uses a privacy-conscious, randomly generated session identifier rather than device fingerprinting; we do not permanently retain IP addresses for this purpose.
2a. Guest data for printable QR invitations, RSVP, and gift reservations
Event creators can generate printable invitations carrying a QR code. When someone scans that code or opens the linked invitation page, and when they respond to an RSVP or reserve a gift, we collect the following — from the guest, not from the event creator's account, and without requiring the guest to create an account:
maybe), and, only if the event creator has enabled the corresponding setting for that event, a child count, child first names, an adult count, dietary notes, and/or allergy notes. Child names are never collected unless the event creator has explicitly turned that setting on for the specific event, and we do not collect any other child-identifying information (no birthdates, no photos, no contact details) — only what a parent chooses to enter in the fields the event creator has enabled, kept to the minimum needed to plan for that event.
an event's Gift List, associated with that reservation only. This name is visible only to the event's creator (to coordinate gifts) and is never shown publicly — other guests see only that an item is reserved, not by whom.
or its page is viewed, we log the event type (for example, "invitation scanned" or "RSVP started") and which distribution batch it came from (for example, "school" or "workplace" — a label the event creator chooses, not guest-specific). These records are tied to a randomly generated, non- identifying session identifier stored in a short-lived (24-hour) first- party cookie on the guest's device, never to an IP address or device fingerprint, and exist to give the event creator aggregate counts (for example, "42 scans from the school flyer"), not to track individual guests across visits.
RSVP and gift-reservation submission (while not interfering with the normal case of many guests scanning the same shared invitation), we keep a short-lived counter keyed to that same random session cookie. This counter is not linked to a guest's identity and is not retained beyond what is needed for abuse prevention.
- RSVP responses. The responsible adult's name, the response (yes/no/
- Gift reservations. The name a guest enters when reserving an item from
- Invitation scan and view analytics. When an invitation link is scanned
- Abuse-prevention rate limiting. To prevent automated abuse of public
A guest submitting an RSVP is shown a concise notice, at the point of submission, summarizing what is collected and why, before they submit.
RSVP and gift-reservation data is visible only to the event's creator (and Eventyno administrators, for safety/legal purposes) — it is never public and is not shared with other guests.
2b. What's new in this version
This version adds §2a above to describe the data collected through the printable QR invitation, RSVP, and gift-reservation features introduced after the initial launch of the Service. No other data-collection practice described in this Policy changed. Signed-in users are asked to acknowledge this update the next time they visit their dashboard; viewing a public event page never requires acknowledging it.
2c. Age assurance, guardian relationships, dependents, and event subjects
Birthdate and age tier. Account creation requires a real birthdate. We use it only to place your account into one of three age tiers — under-13 (no independent account offered at all; see below), 13–17 ("teen"), or 18-and-over ("adult") — and to enforce the resulting capability differences described in our Terms of Service Section 14 and our [Guardian Consent for Teen Accounts](/guardian-consent) document. This data is used only for age-tiering and safety purposes. It is never used for advertising, analytics, profiling, or any recommendation system, and it is never joined into any such system. If no birthdate is on file (for example, immediately after signup, before it is confirmed), the account is treated at least as restrictively as a teen account until a birthdate is provided — never treated as an adult account by default.
Guardian relationships. If you are 13–17, you (or a parent/guardian) can initiate a guardian relationship. We collect: which guardian account is linked to which teen account, the stated relationship (for example, "parent"), its status (pending, active, or revoked), the specific capabilities the guardian has enabled (for example, permission to publish a public event), and, separately, the guardian's own record of reviewing and agreeing to the Guardian Consent document (which version, and when), plus a revocation record and optional reason if the relationship is later ended. This data is visible to the specific teen and guardian who are party to the relationship (for the relationship and its controls) and to Eventyno administrators; the guardian's consent/verification record itself is visible only to Eventyno administrators. We do not use any external identity-verification provider in this version of the product, and we do not collect or store a government ID or other identity document as part of this flow.
Dependents (children under 13). A parent or guardian may list a child under 13 as a "dependent" on their own account — a display name, relationship, and optional birthdate, for identification purposes only (for example, naming a child as an event's honoree). This never creates a login, an account, or a public profile for the child, and is visible only to the guardian who added it (and Eventyno administrators). We do not collect a photo as part of a dependent record.
Event subjects. An event may name a "subject" — the person the event honors — separately from the event's creator, with a display name, the subject's relationship to the creator, and an optional photo the creator explicitly uploads and confirms they have the rights and authorization to use (mirroring our existing family-event-media authorization requirement). Like every photo you upload to Eventyno, an event-subject photo has its metadata — including any embedded GPS location — stripped before it is stored, and is only ever re-encoded and served, never stored in its original form. An event-subject photo, and the subject's name, are hidden by default on both the event page and any printed invitation — the event's creator must explicitly turn each of those two visibility settings on, independently, before either is shown to anyone else. There is no general public or search API access to event-subject data at any time, regardless of those visibility settings; only trusted, server-rendered pages read it, and only the minimum fields either setting allows.
2d. What's new in this version
This version adds §2c above (age assurance, guardian relationships, dependents, and event subjects), updates §11 (Children) to reflect the new 13-and-over minimum age with a guardian model for 13–17, and adds a California-specific minor-privacy note to §10. No other data-collection practice described in this Policy changed. Signed-in users are asked to acknowledge this update the next time they visit their dashboard; viewing a public event page never requires acknowledging it.
3. Why we process this information
store and display your content, and deliver your event to the guests you share it with.
abuse.
conversion patterns (for example, how many guests who view an event go on to create their own), and to fix problems.
requests, and enforce our Terms of Service.
- To provide the Service: create and host your account and event pages,
- For security: authenticate you, protect accounts, and prevent fraud and
- To operate and improve the product: understand aggregate usage and
- For legal compliance: to comply with applicable law, respond to lawful
4. How information is shared
We do not sell your personal information.
We share information with:
contractual confidentiality and security obligations, currently including infrastructure/hosting (Vercel), database and authentication (Supabase), object storage for photos and video (Cloudflare), and, once payments are enabled, payment processing (Stripe). A future transactional email provider may also process your email address solely to deliver account and product emails.
event content visible to them, and, if you choose "Public" visibility, more broadly as described in Section 6.
rights, property, or safety of Eventyno, our users, or the public, or in connection with a merger, acquisition, or sale of assets (subject to continued privacy protections).
- Service providers who host, store, or process data on our behalf under
- Guests you share your event with, to the extent you choose to make
- Legal and safety purposes, where required by law, to protect the
We do not engage in cross-context behavioral advertising, and we do not use third-party advertising trackers in this phase of the product.
5. Where your information is stored
database (via Supabase).
about your media (file type, size, and similar) is stored in the database — not the files themselves.
details. If payments are enabled in the future, card data is handled directly by our payment processor (planned: Stripe) and never touches Eventyno's own servers.
- User accounts: Supabase Auth.
- Profile, event, story, gift-list, follow, and referral data: PostgreSQL
- Photographs and videos: Cloudflare R2 object storage. Only metadata
- Payment card information: Eventyno never stores your payment card
- Source code: a Git repository controlled by Twilight Media Design Corp.
6. Event visibility and discoverability
Every event you create has a visibility setting:
direct link. Not listed on your public profile, not included in Eventyno's sitemap, and marked so search engines are asked not to index it.
indexed by search engines.
- Anyone with the link (default): visible only to people who have the
- Public: may appear on your public profile (if enabled) and may be
You choose this setting when you publish an event and can review it at any time.
7. Data retention
We retain your information for as long as your account is active, and for a limited period afterward as described in our account-deletion process (see Section 9) or as needed to comply with legal obligations, resolve disputes, and enforce our agreements. Aggregate or de-identified information may be retained longer for product-improvement purposes. Age-assurance, guardian- relationship, dependent, and event-subject data (§2c) follow this same retention approach — they are not retained on any separate or extended schedule — and are subject to the same backup-expiration limitations described in Section 9.
8. Security
We use technical and organizational measures designed to protect your information, including database-level access controls (row-level security), encrypted connections (HTTPS), secure secret management, and server-side authorization checks. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
9. Your choices and rights
Download your data. From Account Settings, you can request a machine-readable export (JSON) of your profile, events, story content, gift lists, follow relationships, media metadata, and legal acceptance records.
Delete your account. From Account Settings, you can request account deletion. This revokes your active sessions, deactivates your account, and queues your content and media for deletion. We do not promise instantaneous removal from backups, which are retained for a limited period and expire according to our standard backup rotation (see /docs/BACKUP_AND_RECOVERY.md); we retain only information legitimately required for legal, safety, or accounting purposes during that period.
Access, correction, deletion, and other privacy requests. You can submit a request at `/privacy-request`, or contact us at [PRIVACY EMAIL]. We will verify your request and respond within the time required by applicable law. This includes a request to access, correct, or delete age-assurance, guardian-relationship, dependent, or event-subject data (§2c) — a guardian can also end an active guardian relationship directly, at any time, from Account Settings, as described in our Guardian Consent document.
Opt out of non-essential communications. Where we send non-essential communications, you may opt out via the link provided or in Account Settings.
10. California privacy rights
We intend for our privacy practices to support applicable California privacy law, including the California Online Privacy Protection Act (CalOPPA) and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), to the extent Eventyno is or becomes subject to them. We do not sell or share (as defined under CCPA/CPRA) personal information, and we do not engage in cross-context behavioral advertising. California residents may submit access, deletion, correction, or "opt-out" requests via `/privacy-request` or [PRIVACY EMAIL]. [LEGAL REVIEW REQUIRED: confirm applicability thresholds and finalize the required CCPA/CPRA-specific disclosures, including any "Do Not Sell or Share My Personal Information" mechanism, before commercial launch.]
Minors (California-specific). For a California resident aged 13–17 using a teen account (see §2c and §11), we do not sell or share their personal information, consistent with CCPA/CPRA's opt-in requirement for a known minor under 16, and we do not use their age-assurance or guardian-relationship data for advertising or profiling of any kind (§2c). [LEGAL REVIEW REQUIRED: confirm this satisfies CCPA/CPRA's specific minor-consent and opt-in mechanics, and any additional California minor-privacy statute (for example, coordination with an "eraser button"- style deletion right), before commercial launch.]
11. Children
Eventyno account creation requires a real birthdate and a minimum age of 13.
13–17 ("teen accounts"). A user in this range has a real, independently-usable account, with a defined set of capabilities (publicly visible content and profile settings — see §2c and our Terms of Service Section 14) gated behind an active, guardian-approved relationship. The full terms of that relationship are in our separate [Guardian Consent for Teen Accounts](/guardian-consent) document.
Under 13. Eventyno does not offer any independent account to anyone under 13, and does not knowingly collect personal information directly from a child under 13 in connection with an account of their own. A parent or guardian may instead list a child under 13 as a "dependent" on their own account, for identification purposes only (§2c) — this is not an account for the child and does not involve collecting information from the child directly.
If we learn that we have collected personal information from a child under 13 in a manner inconsistent with applicable law (including, without limitation, the U.S. Children's Online Privacy Protection Act, "COPPA"), we will take steps to delete it. [LEGAL REVIEW REQUIRED: confirm this architecture's COPPA posture — including whether the teen-account tier or any other feature requires additional COPPA-specific process — before commercial launch; this document does not itself certify COPPA compliance.]
12. International users and data transfers
Eventyno is intended to become a global product. If you access the Service from outside the country where our servers or service providers are located, your information may be transferred to, stored, and processed in other countries. [LEGAL REVIEW REQUIRED: confirm appropriate international transfer mechanisms — for example GDPR adequacy or standard contractual clauses — once specific launch jurisdictions and vendor data-processing agreements are finalized.]
13. Third-party links
Event pages, including Gift List entries, may link to third-party websites. This Privacy Policy does not apply to those third-party sites, and we encourage you to review their privacy practices independently.
14. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the updated Policy with a new "Last Updated" date and version identifier and, where required by law or where changes are material, provide additional notice.
15. Contact us
Privacy questions or requests: [PRIVACY EMAIL] General/legal contact: [LEGAL EMAIL] Mailing address: [COMPANY MAILING ADDRESS]
---
Last Updated: 2026-09-25 (draft) Operator: Twilight Media Design Corp.
