Privacy
Privacy Policy
Last updated: 14 July 2026
This policy explains what personal data we collect through the Elegance Events platform, why we collect it, how long we keep it, and what rights you have over it, in accordance with the General Data Protection Regulation (GDPR).
Who processes your data
Elegance Events ([Company name], Tax ID [To be completed], registered office [To be completed]) is the data controller for the information collected through this site and the event-planning app.
For any question about your personal data, you can reach us at the email address shown on the Contact page.
What data we collect
Account data: name, email address, encrypted password, role (planner or vendor).
Event data: event name, date, type, budget, and other details entered by the planner.
Guest data: name, email, phone, RSVP status, dietary preferences and restrictions, number of companions and children entered by the planner or submitted directly by guests through the public RSVP link.
Payment data: we never store your card number. Payments are processed entirely by Stripe, which only provides us with transaction confirmation.
Technical data: your IP address, used temporarily to rate-limit requests and prevent abuse of public forms.
Why we collect this data
To provide the platform's features: guest management, seating plan, budget, checklist, and your event's RSVP page.
To process subscription payments through Stripe.
To prevent abuse (spam, automated requests) of public forms (RSVP, contact, collaborator invites).
To communicate with you about your account or your event.
How long we keep your data
Account and event data is kept for as long as your account is active.
If you delete your account, associated data is deleted or anonymized within a reasonable timeframe, except where the law requires us to keep it (e.g. invoices).
Technical data used for rate limiting is automatically kept for only a few tens of seconds/minutes and deleted automatically afterward.
Who else has access to your data (sub-processors)
Supabase database hosting and user authentication.
Stripe payment processing for paid plans.
Upstash technical caching and rate limiting, so the platform responds quickly and is protected from abuse.
All these providers act as processors and handle data strictly according to our instructions, under their own privacy policies and security measures.
Your rights
You have the right to access your personal data, the right to rectify inaccurate data, the right to erasure ("the right to be forgotten"), the right to data portability, the right to restrict processing, and the right to object.
You can exercise these rights at any time by contacting us at the email address on the Contact page.
You also have the right to lodge a complaint with your national data protection authority (in Romania: ANSPDCP) if you believe your rights have not been respected.
Data security
We apply technical and organizational measures to protect data: row-level access restrictions (Row Level Security) in the database, encrypted connections (HTTPS), and encrypted password storage.
No system is 100% infallible, but we make reasonable efforts to prevent unauthorized access.
Cookies
We use a minimal number of cookies, strictly necessary for your account to function. Full details are in our Cookie Policy.
Changes to this policy
We may update this policy periodically. Any significant change will be reflected by updating the date above.