Data controller & our roles
CKR Technology Group Ltd ("we," "us," or "Vowly Event"), a private limited company registered in England and Wales (company no. 17218156) with its registered office at Unit A, 82 James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom, operates the Vowly Event platform. Our role depends on the data: for your account, subscription, billing, support, platform security and our own consent-based analytics, we act as the data controller. For the guest data an event host uploads or collects — guest lists, RSVP responses, dietary notes, photos — the host decides why and how that data is used: the host is the data controller and we process it on their behalf as processor, under our Data Processing Addendum (vowly.co/data-processing).
Scope of this policy
This policy applies to all personal data we collect when you use our website (vowly.co), web application (web.vowly.co), mobile applications, or interact with us through email, customer support, or marketing channels. It covers both hosts (organisers) and guests who interact with events created on our platform.
- Website visitors and prospective customers
- Registered hosts (event organisers) using paid or trial subscriptions
- Guests who receive invitations and submit RSVPs via our platform
- Partners listed in our partner directory and their representatives
- Job applicants and business contacts
Personal data we collect
We collect only the personal data that is necessary to deliver and improve the Vowly Event service. The categories of data we process depend on your role and how you interact with the platform.
- Identity data: name, email address, phone number, profile photograph
- Account data: encrypted password hash, account preferences, language settings
- Event data: event title, date, venue, theme selection, cover imagery
- Guest data: names, RSVP status, plus-one details supplied by hosts or guests, and optional dietary or allergen notes guests choose to share
- Payment data: processed by Stripe Inc. — we never store full card numbers; we retain only the last four digits, billing country, and Stripe customer reference
- Technical data: IP address, browser type, device identifiers, time zone, operating system
- Usage data: pages visited, features used, click events, error logs, performance metrics
- Communication data: support tickets, in-app messages, marketing preferences
Legal basis for processing
We process your personal data under specific lawful bases as defined in Article 6 of the UK GDPR and EU GDPR. Different processing activities rely on different legal grounds.
- Contractual necessity — to provide the platform, manage your subscription, and deliver invitations and RSVP tracking
- Legitimate interests — to improve our services, prevent fraud, ensure platform security, and conduct anonymised analytics
- Consent — for marketing communications, optional cookies and analytics, and the dietary details guests choose to share (explicit consent under Article 9(2)(a))
- Legal obligation — to comply with tax, accounting, anti-money-laundering, and cybersecurity regulations applicable to UK companies
Special category data
The only special category data the platform is designed to handle is the optional dietary information guests can share on an event's Menu page — allergies and dietary choices, which can reveal health information or religious beliefs (for example halal or kosher). Guests provide this voluntarily, with a separate, explicit consent tick, and it is used solely so the event host can plan catering. It is never used for profiling, analytics or marketing. Guests can withdraw consent and have this information removed at any time by contacting the event host or support@vowly.co. This processing relies on explicit consent under Article 9(2)(a) UK/EU GDPR.
Data retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including any legal, accounting, or reporting requirements. Retention periods vary based on data type.
- Account, event and guest data: retained while your account exists, so your events and memories stay available to you; you can delete individual events, guests or photos at any time
- Account deletion: removes your account, all events, guest lists, photos and planning data immediately from our production systems; residual copies on Google Cloud infrastructure are purged in line with Google's documented deletion timelines (up to 180 days)
- Anti-abuse record: after account deletion we keep a minimal record (name and email address only) to prevent fraudulent re-use of deleted accounts — it is used for nothing else
- Payment and transaction records: retained for the period required by UK tax law (at least 6 years)
- Security and abuse logs: up to 90 days
- Support correspondence: as long as needed to resolve your request and for up to 3 years afterwards
- Marketing preferences: until consent is withdrawn
- Analytics: collected only with your consent, with analytics cookies capped at 13 months
Your rights
Under the UK GDPR and EU GDPR, you have extensive rights regarding your personal data. We honour all rights requests within one calendar month at no charge.
- Right of access — request a copy of all personal data we hold about you
- Right to rectification — correct inaccurate or incomplete personal data
- Right to erasure ("right to be forgotten") — request deletion of your data subject to legal exceptions
- Right to restrict processing — limit how we use your data in specific circumstances
- Right to data portability — receive your data in a machine-readable format
- Right to object — to direct marketing or processing based on legitimate interests
- Right to withdraw consent — for any processing based on consent
- Right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk
International transfers
Vowly Event primarily processes data within the European Economic Area (EEA) and the United Kingdom: our database and file storage run in Google Cloud's EU multi-region infrastructure. Some providers process data in other jurisdictions — for example, our sign-in service (Firebase Authentication) is operated by Google from data centres in the United States, and our email provider (Resend) is US-based. In those cases we ensure equivalent protection through legal safeguards.
- EU Standard Contractual Clauses and, for UK transfers, the UK Addendum or International Data Transfer Agreement
- Adequacy decisions where available (including the EU–UK adequacy decisions, renewed in December 2025)
- Technical safeguards including encryption in transit (TLS) and at rest (AES-256)
Children's data
Vowly Event is not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you become aware that a minor has provided us with personal data without parental consent, please contact support@vowly.co and we will promptly delete it.
Security measures
We implement a layered security programme to protect personal data against unauthorised access, alteration, disclosure, or destruction. See our dedicated Security page for full details.
- Encryption in transit (HTTPS/TLS) for all connections
- AES-256 encryption at rest for our database and file storage (Google Cloud managed encryption)
- Server-side access rules on every read and write — only you, and teammates you explicitly invite, can access your events
- Sign-in and passwords handled by Firebase Authentication; we never see or store your password
- Abuse protection with rate limiting, request attestation (App Check / reCAPTCHA) and audit logging
- Incident response procedures with breach notification within 72 hours
Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in law, regulation, or our service. Material changes will be communicated to registered users by email at least 30 days before they take effect. The latest version is always available at vowly.co/privacy.
Complaints
If you believe we have not handled your personal data properly, contact us at support@vowly.co with "complaint" in the subject line — this is our data-protection complaints channel under section 164A of the UK Data Protection Act 2018. We will acknowledge your complaint within 30 days (usually much sooner), investigate it, and tell you the outcome without undue delay. You can also complain to the UK Information Commissioner's Office (ico.org.uk) — ideally after giving us the chance to put things right — or to your local EU supervisory authority.
Contact & complaints
For any privacy-related questions, complaints, or to exercise your data rights, please contact our privacy team at support@vowly.co or write to: Privacy Team, CKR Technology Group Ltd, Unit A, 82 James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) — ico.org.uk — or your local EU supervisory authority.
Questions about your data?
Contact our privacy team for any privacy-related inquiries, subject access requests, or to exercise your data rights.
support@vowly.co