Privacy Policy
Last updated: August 13, 2026
Event Capsule (“Event Capsule,” “we,” “our,” or “us”) provides a private event service that lets hosts create event photo capsules, invite guests by QR code or link, optionally collect RSVPs, collect photos during an upload window, and reveal the gallery at a selected reveal time.
This Privacy Policy explains what information we collect, how we use it, how we protect it, and the choices available to hosts and guests.
1. Information we collect
We collect information needed to provide Event Capsule.
Information provided by hosts may include:
- Event name
- Event upload start and end times
- Reveal time
- Photo limits
- Host name
- Host email address
- Host mobile number, if provided
- Optional event cover image
- Event settings and event code
- RSVP settings, event start time, location details, and optional host message when RSVP is enabled
Information provided by guests may include:
- Guest display name
- Guest email address when submitting an RSVP
- RSVP status, number attending, and response timestamps
- Optional dietary requirements and message to the host when those fields are enabled or provided
- Photos uploaded to an event
- Upload activity related to the event
Photo and event information may include:
- Uploaded photos
- Photo file metadata, such as file name, file type, file size, upload time, storage path, and contributor information where available
- Event code
- Event link
- Contributor counts and photo counts
- Gallery and download activity needed to provide the service
Verification and email information may include:
- Email verification codes
- Verification code expiry and usage status
- Host verification and access status
- Email delivery records for transactional emails
- Event recovery, gallery link, invite, RSVP confirmation and change, and photo-expiry reminder activity
- Private RSVP-management link status and RSVP activity needed to provide and secure the service
Support information may include:
- Name and reply email address
- Support category, optional event code, and message content
- Hashed rate-limit identifiers used to prevent abuse; Event Capsule does not store the raw IP address in its contact rate-limit table
Payment information may include:
- Checkout and payment status when a paid plan or add-on is used
- Plan, price, promotion, and purchase details needed to complete and support an order
Stripe handles payment card details. Event Capsule does not directly store full payment card numbers.
Technical information may include:
- Browser and device information
- Basic logs needed for debugging, reliability, fraud prevention, abuse prevention, and security
- IP address or similar technical data processed by our hosting, storage, database, domain, and email service providers
2. How we use information
We use information to:
- Create and manage event capsules
- Display digital invitations, collect RSVPs, let guests manage their responses, and show responses to the verified event host
- Allow guests to join events by QR code, event code, or link
- Allow guests to upload photos during the upload window
- Keep the gallery sealed until the selected reveal time
- Display galleries after reveal
- Let hosts verify access and manage their events
- Send verification, invite, RSVP confirmation and change, gallery, retention reminder, and other service emails
- Allow hosts to download event photos
- Process payments through Stripe when paid plans or add-ons are used
- Track and enforce photo, guest, and service limits
- Maintain security, prevent abuse, and prevent unauthorized access
- Respond to support, privacy, and deletion requests
- Troubleshoot issues and improve Event Capsule
3. Who can access event photos and RSVP information
Event Capsule is designed for private event sharing, but event links and event codes can be forwarded or shared by others.
Guests can upload photos to an event they join. Photos remain sealed from the shared gallery before reveal. After reveal, people with the event or gallery link may be able to view the gallery, depending on the event access design.
Hosts can manage, download, and delete event photos after reveal. Event photo files are not made publicly browsable, but hosts and guests can share event links or copies they have downloaded, so absolute confidentiality cannot be guaranteed.
When RSVP is enabled, the verified host can view and export RSVP responses for that event, including guest names, email addresses, attendance status, attendee count, optional dietary requirements, optional messages, and recent response activity. RSVP information is not displayed in the public gallery.
Each RSVP guest receives a private management link by email. Anyone who obtains that link may be able to view or change that guest’s response until changes close, so recipients should keep it private and use the most recent link provided.
4. Photos and uploaded content
Guests should only upload photos they have the right to share.
New guest photos are stored in a private storage bucket and are shown through temporary signed URLs when access is allowed. This helps prevent new guest photos from being available through permanent public file URLs.
5. Reveal timing
Photos are intended to remain hidden from the shared gallery until the event reveal time. Before reveal, guests should not see the full gallery. After reveal, people with the event gallery link or event code may be able to view the gallery.
6. Host verification
Hosts access host-only features through email verification. Guest upload sessions are also checked before uploads are accepted.
Host-only actions may include:
- Viewing host dashboard details
- Sending gallery links
- Sending invite details
- Downloading event photos
- Deleting selected photos or all event photos
- Accessing host-only previews where available
- Viewing and exporting RSVP responses for their event
7. Reminder and service emails
Event Capsule may send service emails needed to provide the event, including:
- Verification codes
- Event recovery emails
- Gallery links
- Invite details
- Calendar invite attachments
- Photo-expiry reminders around 7 days, 48 hours, and 24 hours before deletion
- RSVP confirmations and private management links for guests
- RSVP activity notifications for eligible verified hosts when enabled
Expiry reminders help hosts download or delete photos before the retention period ends. These are service messages related to the event and photo retention, not marketing emails.
8. Calendar invites
Hosts may email invite details that include a calendar invite attachment. Calendar invites may include the event name, upload window, join link, event code, and reveal time.
9. Third-party services
We use trusted service providers to operate Event Capsule, including:
- Supabase for database and file storage
- Resend for transactional email delivery
- Stripe for payment processing
- Lovable and related hosting infrastructure for the web application
- Cloudflare for domain, DNS, and related infrastructure
- Google Search Console for search visibility and indexing monitoring
These providers may process information as needed to provide their services to us. Stripe handles payment card details, and Event Capsule does not directly store full payment card numbers.
10. Retention and deletion
Event photos are available for 30 days after the reveal time. After that period, Event Capsule automatically deletes the photos.
Hosts may delete selected photos or all event photos earlier from the host dashboard after reveal. Once photos are deleted, they are no longer available in the gallery or downloads.
Downloading photos does not stop automatic deletion, so hosts should save copies before the expiry date if they want to keep them.
RSVP responses, associated private-link records, and response activity remain associated with the event while needed to provide RSVP management, host reporting, security, and support. They are deleted if the parent event is deleted. A guest or host may contact us to request deletion or correction, subject to identity or event-access verification and any limited records we must retain for security, legal, or operational reasons.
Contact Us messages are delivered to our support inbox through Resend and are not stored in Event Capsule application tables. Support correspondence is retained only as needed to respond and maintain necessary operational, security, or legal records. Hashed contact rate-limit events expire from active use after no more than 24 hours and are periodically deleted.
11. Your choices and requests
You may contact us to request:
- Access to information associated with your event
- Correction of host contact information
- Correction or deletion of RSVP information associated with an event
- Deletion of an event or uploaded photos, where reasonably possible
- Help with host access or event recovery
We may need to verify your identity or host access before completing certain requests.
Contact:
12. Security
We use reasonable technical and organizational measures to protect information. These include private storage for new event photos, temporary signed photo links where appropriate, host verification for host-only actions, private time-limited RSVP-management links, rate limiting and identifier hashing for RSVP abuse prevention, guest session checks for uploads, and server-side access controls for sensitive actions.
No online service can guarantee complete security. Hosts and guests should share event links carefully and avoid uploading highly sensitive content.
13. Children
Event Capsule is not intended for children under 13. If you believe a child has provided personal information without appropriate permission, contact us through the Contact Us form.
14. International processing
Event Capsule may be accessed from different countries. Information may be processed and stored in countries where our service providers operate.
15. Changes to this Privacy Policy
We may update this Privacy Policy as Event Capsule evolves. If we make material changes, we will update the “Last updated” date above.
16. Contact
For privacy questions or requests, contact:
Event Capsule
Use the Contact Us form