Privacy Policy
Last updated: August 8, 2026
1. Data Controller Information
EventHub is developed and operated by Denis Fedorovici, Republic of Moldova, who acts as the controller of personal data processed through the service. Privacy inquiries can be sent to privacy@geteventhub.app.
2. Scope and Legal Bases
This policy applies to the EventHub website and mobile application. We process data to perform our contract with users, based on consent for optional features such as push notifications, device permissions, the AI assistant, and marketing analytics, to comply with legal obligations, and for legitimate interests such as service security and fraud prevention. Where applicable, users in the European Economic Area and the United Kingdom have the rights provided by the GDPR and UK GDPR.
3. Data We Collect
We collect the minimum necessary amount of data required to provide our service:
- Account and authentication data: name, email address, password hash, and identifiers received from Google Sign-In or Sign in with Apple when those options are used.
- Event and planning data: event details, locations, schedules, tasks, budgets and expenses, seating plans, gift lists, polls, quizzes, invitations, and team information.
- Guest and communication data: names, contact details entered by organizers, attendance reply status, custom guest fields, comments, wishes, guestbook entries, and chat messages.
- Device contacts (mobile apps, only when you use “pick from contacts”): with your permission, EventHub can read a contact you select so you can fill a guest name and phone number. We do not upload your full address book.
- Media and device sensors: event covers, gallery images, invitation images, chat attachments, wishlist images, and photos or videos you capture or upload. On supported devices, camera access is used only when you take or attach media.
- Microphone and speech input (optional): when you use speech recognition or voice features, audio is processed to convert speech to text for the feature you requested. We do not use microphone audio for advertising.
- Approximate device location (optional): when you choose to use the map or “current location” controls, we may access approximate location to help place an event venue. Event addresses you type are also stored as event data.
- AI assistant inputs: messages you send to the EventHub AI assistant and the event context needed to answer (for example guest lists, tasks, schedule, or budget summaries for that event).
- Payment and entitlement data: transaction or purchase identifiers, product, price, currency, payment status, timestamps, and access rights received from Paddle, Google Play, or Apple when the applicable channel is used. EventHub does not receive or store full payment-card details.
- Technical and security data: IP address, browser and device information, app/device identifiers, push notification tokens, security logs, essential cookies, and local-storage values.
- Optional marketing analytics, after consent: campaign parameters (UTM), advertising click identifiers, visited page, interface language, and product activation events.
4. How We Use Data
We use data to create and secure accounts, provide event-planning and guest features, authenticate users, process purchases, send requested service and push notifications, operate the optional AI assistant, provide support, prevent abuse, comply with law, and improve EventHub. Optional marketing analytics and optional device permissions (contacts, camera, microphone, location) are used only after you grant them and can be revoked in system or in-app settings. Marketing analytics can also be disabled through the available privacy controls.
5. Service Providers and Data Sharing
- Google: optional Google Sign-In, Google Maps, Firebase services, Google Play distribution, Google Play Billing when offered, and Google Gemini / related AI models that process AI assistant prompts and the event context needed to respond.
- Apple: App Store distribution and, when offered, Sign in with Apple and Apple In-App Purchase.
- Firebase Cloud Messaging: delivery of push notifications to registered devices.
- Cloudflare R2 and infrastructure providers: hosting, storage, delivery, backup, and protection of service data and uploaded media.
- Paddle: merchant of record and payment processor for purchases made on the EventHub website, including checkout, tax, fraud-prevention, receipt, and refund processing.
- Analytics and support providers, when enabled and where required with consent.
- Authorities or professional advisers when disclosure is legally required or necessary to protect users, EventHub, or the public.
6. International Transfers and Security
Some providers may process data outside Moldova or the user’s country. Where required, we rely on contractual and other lawful transfer safeguards. We use HTTPS in transit, access controls, password hashing, restricted administrative access, secure token storage on supported mobile devices, and provider security measures. No system can guarantee absolute security.
7. Retention and Deletion
Account and event data are retained while the account is active and deleted when the user deletes the account, except for limited records retained where required by law, dispute resolution, fraud prevention, or security. Event photos and image attachments are scheduled for deletion 7 days after the event or 90 days after upload, whichever comes first, unless removed earlier or another displayed retention setting applies. Paddle and transaction records may be retained for legal, accounting, tax, refund, and fraud-prevention requirements. Backups and security logs are removed or overwritten according to operational retention cycles.
8. Your Choices and Rights
- Right to access personal data and obtain a copy.
- Right to rectify inaccurate personal information.
- Right to erasure ("Right to be forgotten") — request account deletion at any time.
- Right to restriction of processing and withdrawal of consent.
- Right to lodge a complaint with the National Centre for Personal Data Protection of Moldova (CNPDCP) or your local EU Data Protection Authority (DPA).
9. Children
EventHub is not directed to children. Organizers must not submit a child’s personal data without an appropriate legal basis and, where required, consent from a parent or legal guardian.
10. Account and Data Deletion
Users can permanently delete their account from the profile or event settings in the app. A request can also be initiated at geteventhub.app/delete-account or by emailing privacy@geteventhub.app. Deleting an account removes associated account and event data, subject only to limited retention required by law or for security and dispute resolution.
Open the account deletion page