Privacy Policy & Data Security
Compliant with international privacy standards (GDPR, CCPA, NDPR). We protect your event data, guest privacy, and communication records.
Table of Contents
At Event Owner App, your privacy and event data integrity are non-negotiable. We do not sell your personal data or guest lists to third-party advertisers. While we maintain technical and administrative safeguards, in the unlikely event of data disruption or security incidents, we guarantee immediate disclosure and active technical remediation.
Information We Collect
To deliver event orchestration, guest RSVPs, QR ticketing, and cash registries across web and mobile platforms, we collect the following categories of information:
- Account Data: Name, email address, phone number, password hash, profile avatar, and account preferences.
- Event & Guest Data: Event titles, venues, schedules, guest names, RSVP statuses, dietary requirements, coat check records, and guestbook messages.
- Payment Meta-Data: Transaction IDs, gift amounts, payout account reference numbers. (Note: We never store card PINs, CVVs, or bank login credentials).
- Device & Notification Data: Device push tokens (Expo Push Token, FCM Token, VAPID WebPush Subscriptions), browser type, IP address, and locale.
How Data Is Used
Collected data is strictly used for core platform functionality:
- Generating invitation landing pages and issuing unique QR access passes for guest entry.
- Sending real-time push notifications and email/SMS alerts for RSVP changes, broadcast messages, and schedule updates.
- Processing cash registry gifts, spray money transactions, and vendor payouts.
- Providing aggregated event analytics to event hosts and organizers.
Payment Security & Financial Isolation
All monetary transactions on Event Owner App are processed directly through PCI-DSS Level 1 certified payment partners, including Paystack, Flutterwave, Stripe, OPay, and Monnify.
Payment options are dynamically auto-hidden whenever a payment gateway is unconfigured or under maintenance, ensuring zero failed financial submissions.
Third-Party Integrations & Infrastructure
We integrate with trusted infrastructure providers to deliver services globally:
- Google Single Sign-On (SSO): Used for secure OAuth 2.0 authentication.
- Firebase & Expo Cloud Services: Used for push notification routing to Android and iOS devices.
- AWS S3 & Cloud Storage: Used for secure media backup (event photos, gallery assets).
Push Tokens & Notification Preferences
Users and guests retain full control over push notifications. You can toggle notification preferences (RSVPs, updates, reminders, broadcasts) at any time in your Account Settings or disable push permissions directly in your browser or device settings.
Your Data Rights (GDPR & CCPA Compliance)
Under global data protection frameworks, you have the right to:
- Access & Export: Request a complete copy of your personal data and event history in JSON/CSV format.
- Rectification: Correct inaccurate or incomplete account details.
- Right to be Forgotten: Request full account and data deletion by contacting our privacy team.
Technical Security & Incident Policy
We employ TLS 1.3 encryption, database tokenization, strict access controls, and continuous vulnerability monitoring. In the event of a technical data incident, we will notify affected users within 72 hours and publish remediation status reports.
Data Protection Officer (DPO) & Contact
If you have questions regarding this Privacy Policy or wish to exercise your data rights, please contact our Data Protection Officer: