Privacy policy
Last updated: July 2026
Draft written against how the product actually works, pending legal review. Items marked [TO COMPLETE] must be filled in before publication.
This policy explains what personal data we process when you use Togevent or visit an event site built with Togevent, why we do it and what rights you have. It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).
Data controller
The controller is Nebula S.r.l., [TO COMPLETE: registered office address], VAT [TO COMPLETE: VAT number]. To exercise your rights or ask anything, write to [TO COMPLETE: privacy request email address].
[TO COMPLETE: state whether a Data Protection Officer has been appointed and give their contact details.]
Who decides about guests' data
For your account data and for running the platform, we are the controller.
For the data your guests submit to your site — RSVPs, messages, photographs — it is you, as the event organiser, who decides what to collect and what to publish: for that data we act as processor on your behalf and handle it only to provide you the service.
What data we process
Account data: email address, authentication identifiers, preferred language and — if you sign in with Google — the identifier Google returns to us.
Event data: the couple's names, the date, the venue, the text and images you upload, the theme you pick and your site address.
Guest data: RSVP answers (the name of the person replying and of anyone they bring), messages left on the board and photographs uploaded, together with a random device identifier — which lets a guest find their own contributions again — and a hashed form of the IP address, used only to limit abuse.
Payment data: the amount, what was bought and the transaction identifiers. Card details are handled directly by Stripe. If you order printed postcards we also process the recipient's name, postal address and any phone number.
Technical data: IP address, browser and device type, pages visited and — only if you consent — the usage events, heatmaps and session recordings described below.
Why we process data, and on what legal basis
To provide the service you asked for — creating your account, publishing the site, collecting RSVPs, running the gallery: performance of the contract (Art. 6(1)(b) GDPR).
To handle payments, invoicing and tax obligations: legal obligation (Art. 6(1)(c)) and performance of the contract.
For platform security — anti-bot protection on guest uploads, rate limits, abuse prevention: our legitimate interest in keeping the service sound (Art. 6(1)(f)).
To measure and improve product usage through analytics, heatmaps and session recordings: your consent (Art. 6(1)(a)), which you can withdraw at any time.
To answer your requests and handle disputes: legitimate interest.
Cookies and similar technologies
We use technical cookies needed to keep you signed in, remember your language, carry a referral code and record your choice about this policy. These require no consent.
The analytics described in the next section use non-essential cookies and local storage: they are switched on only after you consent, and nothing is written to your device before that.
Usage analytics, heatmaps and session recordings
If you consent, we use PostHog to understand how the product is used: which pages are visited, which features are used, where people get stuck. The service is configured on PostHog's European infrastructure and the data stays in the European Union.
This includes heatmaps (where people click and how far they scroll) and session recordings: a reconstruction of the navigation from the page structure, not a video of your screen. Recordings redact the contents of every input field by default, plus any text we mark as sensitive; we do not record passwords or payment details, which are entered directly with Stripe.
We link events to your user identifier only if you have an account, and we do not send your email address to PostHog. Visitors to couples' sites stay anonymous and get no profile.
You can give or withdraw this consent at the bottom of this page, at any time and with no effect on your use of the service.
Who we share data with
We rely on providers who process data on our behalf, each bound by an agreement under Art. 28 GDPR:
Supabase — database, authentication and file storage. Vercel — application hosting and delivery. Stripe — payments and invoicing. Resend — transactional email, including sign-in codes. OpenAI — AI-assisted setup chat and voice transcription, limited to what you type or dictate at that stage. PostHog — usage analytics, heatmaps and session recordings, only with consent. Cloudflare — anti-bot protection on guest uploads. Google — Google account sign-in and, if you give a venue, retrieval of one public photograph of the place. [TO COMPLETE: the supplier that prints and ships the QR postcards.]
We do not sell your data and do not pass it to third parties for their own marketing.
Transfers outside the European Union
We prefer providers that host data in the European Union. Some services — Stripe and OpenAI in particular — may also process it in the United States: in those cases the transfer relies on the standard contractual clauses approved by the European Commission and on the additional safeguards the provider offers.
[TO COMPLETE: verify and state each provider's actual hosting region as at the publication date.]
How long we keep data
Account data stays for as long as the account exists. Event content and guest contributions stay for the period the purchased plan provides, or beyond it if you bought the "Keep forever" add-on.
Accounting records are kept for the period tax law requires. The hashed IP addresses used against abuse are kept only as long as that purpose needs.
Session recordings and analytics events follow the retention period configured in PostHog. [TO COMPLETE: state the actual period.]
When you delete an event or your account, the data is removed from live systems; residual copies in backups are overwritten on the backup rotation cycle.
Security
Data is protected in transit and at rest, database access is governed by row-level security rules, and operations needing elevated privileges run only on the server. You sign in with a one-time code or a Google account: we store no passwords.
Your rights
You can ask us for access to your data, and for rectification, erasure, restriction or portability, and you can object to processing based on legitimate interest. Where processing rests on consent you can withdraw it at any time, without affecting the lawfulness of what came before.
Write to [TO COMPLETE: privacy request email address]: we reply within one month.
If you are a guest and want a message, photograph or RSVP of yours removed, you can ask the couple who created the site directly, or ask us and we will pass the request on.
Children
The service is not aimed at children under sixteen and we do not knowingly collect their data. If you believe a child has given us personal data, tell us and we will remove it.
Changes to this policy
If we change how we handle data we will update this page and the date at the top; for material changes we will also tell you by email or in the product.
Complaints
If you believe the processing of your data breaches the GDPR you can lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it), or with the supervisory authority of the country where you live.