Version 2026-07-22-beta · Pre-launch legal review required
Privacy Policy
How Eventloom handles creator, guest, security, and payment information.
Roles and purposes
For RSVP information, the event creator determines why the information is collected and Eventloom processes it on the creator’s behalf. Eventloom controls account, billing, fraud-prevention, support, and security information needed to operate the service.
Data we process
We process creator account details, event content, RSVP names and optional contact details, guests and answers, provider references, keyed network hashes, device class, and security events. Eventloom does not receive full card numbers from Stripe.
Use and sharing
Information is used to provide, secure, support, and bill for the service. Eventloom does not sell personal data, use RSVP data for marketing, or run behavioural advertising. Providers receive only data needed for their services.
Location and retention
The current database and several subprocessors operate in the United States, so information may be processed outside Canada. RSVP personal data is scheduled for deletion 90 days after the event unless a documented legal hold applies. Abuse data is kept 30 days, security logs 12 months, backups 30 days, and legally required payment records may be retained seven years.
Rights and contact
Creators and guests may request access, correction, deletion, or information about processing. Identity is verified before disclosure. Eventloom targets a response within 30 days, subject to lawful extensions and exceptions.
This pre-launch document records the intended product rules. It is not represented as lawyer-approved. Paid public launch remains disabled until Ontario/US legal review and the final business identity and contact details are published.