Privacy & Data Protection

Event Capsule is built for private events, so privacy is part of the product design—not an afterthought.

This page summarizes, in plain English, how we handle event photos and personal information. It does not replace our formal Privacy Policy, which remains the governing document.

The Canadian privacy framework

PIPEDA (the Personal Information Protection and Electronic Documents Act) is Canada's federal privacy law for how private-sector organizations collect, use and disclose personal information in commercial activities. Alberta, British Columbia and Quebec also have their own private-sector privacy laws that may apply depending on the circumstances.

Event Capsule is designed with PIPEDA's principles in mind. This is a description of our approach, not a certification or regulatory approval, and it isn't legal advice.

Our privacy principles

How our current practices map to the ten fair information principles behind PIPEDA.

Principle 1

Accountability

Event Capsule is responsible for the personal information it handles. Privacy questions can be sent through our Contact form.

Principle 2

Identifying purposes

We collect information only to run the service:

  • Host email — verification, event access and service emails
  • Event details — to set up the capsule and its schedule
  • Guest names — to attribute uploads within the event
  • RSVP details, where the host enables RSVP
  • Event photos — to build the gallery and slideshow
  • Payment transaction details — to apply paid plans

Principle 3

Consent

Hosts choose to create events, and guests choose whether to join and upload. Hosts remain responsible for appropriate consent practices at their event. Event Capsule does not obtain consent on behalf of everyone who appears in a photo.

Principle 4

Limiting collection

We aim to collect only what's needed to operate the service. Guests don't create accounts — a name is enough to upload.

Principle 5

Limiting use, disclosure & retention

Uploaded photos are used to provide the event experience. They remain available for 30 days after reveal and are then automatically deleted. Hosts can delete photos earlier from the host dashboard. Files are not kept indefinitely.

Principle 6

Accuracy

Hosts can update event details from the host dashboard, and guests with RSVP enabled can update their response through their private RSVP link. Other corrections are handled through support.

Principle 7

Safeguards

  • New guest photos are kept in private storage
  • Temporary signed links are used where appropriate
  • Host-only controls require email verification
  • Access checks run on our servers
  • Administrative functions are protected
  • Stripe handles payment-card data; we don't directly store full card numbers

Principle 8

Openness

Our practices are described in our Privacy Policy and Terms. Questions are welcome via Contact.

Principle 9

Individual access

There is currently no self-service export tool. Requests to access, correct or delete personal information are handled through our Contact form, subject to reasonable identity or event-access verification.

Principle 10

Challenging compliance

If you have a concern or complaint about how we handle your information, contact us and we'll review it. You may also contact the Office of the Privacy Commissioner of Canada.

Event photo privacy

  • Galleries are not intended to be publicly browsable or listed.
  • Access is through the event link or event code.
  • Host-only controls require verification.
  • Host moderation controls what appears in the gallery after reveal.

Because event links and downloaded photos can be forwarded by the people who have them, we can't promise absolute confidentiality. Share your event link only with people you want to include.

Retention

  • Photos remain available for 30 days after the reveal time.
  • Verified hosts receive expiry reminders around 7 days, 48 hours and 24 hours before deletion.
  • Hosts should download any photos they want to keep — downloading doesn't pause deletion.
  • Hosts can delete selected or all photos earlier from the host dashboard after reveal.
  • A scheduled cleanup process removes expired photos after the retention period ends.

Service providers

We rely on trusted providers to run Event Capsule. Each processes information only as needed to provide its service to us.

Supabase

Database and private file storage for event data and photos.

Stripe

Payment processing. Stripe handles payment-card details.

Resend

Delivery of transactional emails such as verification codes, reminders and confirmations.

Cloudflare

Domain, DNS and related network infrastructure.

Lovable and hosting infrastructure

Hosting and running the Event Capsule web application.

Cross-border processing

Some of our service providers may process or store information outside Canada, including in the United States. Information processed in another country may be subject to that country's laws.

Children & family events

Event Capsule is often used for birthdays, school events and family gatherings, where children may appear in photos.

  • Hosts should follow appropriate consent and privacy practices for children's photos.
  • Hosts decide whether Event Capsule is appropriate for their event.
  • Event Capsule provides the tool; it doesn't replace an organizer's own consent obligations.

Event Capsule itself is not intended for use by children under 13.

Data requests

Use our Contact form for any of the following. Include your event code where relevant so we can find the right records:

  • Privacy questions
  • Access requests
  • Correction requests
  • Deletion requests
  • Complaints

Canadian privacy and GDPR

Canadian privacy laws and the EU's GDPR are different frameworks. Event Capsule's approach is built around Canadian principles, and we don't claim GDPR compliance. If Event Capsule is used by people in the EU/EEA, GDPR obligations may apply depending on how the service is offered and how personal data is processed.

Formal policies