Privacy
policy.

How CKR Technology Group Ltd, the operator of Vowly Event, collects, processes, and protects your personal data in accordance with the UK Data Protection Act 2018, UK GDPR, and EU GDPR.

Effective: 29 July 2026 · v2.0
01

Data controller & our roles

CKR Technology Group Ltd ("we," "us," or "Vowly Event"), a private limited company registered in England and Wales (company no. 17218156) with its registered office at Unit A, 82 James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom, operates the Vowly Event platform. Our role depends on the data: for your account, subscription, billing, support, platform security and our own consent-based analytics, we act as the data controller. For the guest data an event host uploads or collects — guest lists, RSVP responses, dietary notes, photos — the host decides why and how that data is used: the host is the data controller and we process it on their behalf as processor, under our Data Processing Addendum (vowly.co/data-processing).

Our privacy team can be contacted at support@vowly.co for all data protection matters, including access requests, complaints, and corrections.
02

Scope of this policy

This policy applies to all personal data we collect when you use our website (vowly.co), web application (web.vowly.co), mobile applications, or interact with us through email, customer support, or marketing channels. It covers both hosts (organisers) and guests who interact with events created on our platform.

  • Website visitors and prospective customers
  • Registered hosts (event organisers) using paid or trial subscriptions
  • Guests who receive invitations and submit RSVPs via our platform
  • Partners listed in our partner directory and their representatives
  • Job applicants and business contacts
03

Personal data we collect

We collect only the personal data that is necessary to deliver and improve the Vowly Event service. The categories of data we process depend on your role and how you interact with the platform.

  • Identity data: name, email address, phone number, profile photograph
  • Account data: encrypted password hash, account preferences, language settings
  • Event data: event title, date, venue, theme selection, cover imagery
  • Guest data: names, RSVP status, plus-one details supplied by hosts or guests, and optional dietary or allergen notes guests choose to share
  • Payment data: processed by Stripe Inc. — we never store full card numbers; we retain only the last four digits, billing country, and Stripe customer reference
  • Technical data: IP address, browser type, device identifiers, time zone, operating system
  • Usage data: pages visited, features used, click events, error logs, performance metrics
  • Communication data: support tickets, in-app messages, marketing preferences
04

Legal basis for processing

We process your personal data under specific lawful bases as defined in Article 6 of the UK GDPR and EU GDPR. Different processing activities rely on different legal grounds.

  • Contractual necessity — to provide the platform, manage your subscription, and deliver invitations and RSVP tracking
  • Legitimate interests — to improve our services, prevent fraud, ensure platform security, and conduct anonymised analytics
  • Consent — for marketing communications, optional cookies and analytics, and the dietary details guests choose to share (explicit consent under Article 9(2)(a))
  • Legal obligation — to comply with tax, accounting, anti-money-laundering, and cybersecurity regulations applicable to UK companies
05

Special category data

The only special category data the platform is designed to handle is the optional dietary information guests can share on an event's Menu page — allergies and dietary choices, which can reveal health information or religious beliefs (for example halal or kosher). Guests provide this voluntarily, with a separate, explicit consent tick, and it is used solely so the event host can plan catering. It is never used for profiling, analytics or marketing. Guests can withdraw consent and have this information removed at any time by contacting the event host or support@vowly.co. This processing relies on explicit consent under Article 9(2)(a) UK/EU GDPR.

06

Data retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including any legal, accounting, or reporting requirements. Retention periods vary based on data type.

  • Account, event and guest data: retained while your account exists, so your events and memories stay available to you; you can delete individual events, guests or photos at any time
  • Account deletion: removes your account, all events, guest lists, photos and planning data immediately from our production systems; residual copies on Google Cloud infrastructure are purged in line with Google's documented deletion timelines (up to 180 days)
  • Anti-abuse record: after account deletion we keep a minimal record (name and email address only) to prevent fraudulent re-use of deleted accounts — it is used for nothing else
  • Payment and transaction records: retained for the period required by UK tax law (at least 6 years)
  • Security and abuse logs: up to 90 days
  • Support correspondence: as long as needed to resolve your request and for up to 3 years afterwards
  • Marketing preferences: until consent is withdrawn
  • Analytics: collected only with your consent, with analytics cookies capped at 13 months
07

How we share data

We do not sell your personal data. We share data only with carefully selected service providers (processors) who help us deliver the Vowly Event platform under strict data processing agreements (DPAs).

  • Google Cloud / Firebase (Google Ireland Ltd) — hosting, database and file storage (both in the EU), sign-in (operated from Google's US data centres), and automated-abuse protection (reCAPTCHA / App Check)
  • Google Analytics 4 (Google Ireland Ltd) — usage statistics, and only if you consent
  • Stripe Payments Europe Ltd (Ireland) — subscription billing and payment processing
  • Resend Inc. (US) — transactional email delivery, under EU Standard Contractual Clauses
  • Crisp IM SARL (France, data hosted in the EU) — live chat support, loaded only when you choose to use it
  • Functional Software, Inc. (Sentry, US) — error monitoring on our web surfaces, with personal identifiers switched off
  • Cloudflare, Inc. — DNS for our domains
  • Apple Inc. & Google LLC — app store distribution and in-app purchase processing
  • The full, always-current list is published at vowly.co/subprocessors
All processors are bound by GDPR-compliant data processing terms. International transfers outside the UK/EEA rely on adequacy decisions, the EU Standard Contractual Clauses and the UK Addendum/IDTA, with supplementary safeguards.
08

Your rights

Under the UK GDPR and EU GDPR, you have extensive rights regarding your personal data. We honour all rights requests within one calendar month at no charge.

  • Right of access — request a copy of all personal data we hold about you
  • Right to rectification — correct inaccurate or incomplete personal data
  • Right to erasure ("right to be forgotten") — request deletion of your data subject to legal exceptions
  • Right to restrict processing — limit how we use your data in specific circumstances
  • Right to data portability — receive your data in a machine-readable format
  • Right to object — to direct marketing or processing based on legitimate interests
  • Right to withdraw consent — for any processing based on consent
  • Right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk
09

International transfers

Vowly Event primarily processes data within the European Economic Area (EEA) and the United Kingdom: our database and file storage run in Google Cloud's EU multi-region infrastructure. Some providers process data in other jurisdictions — for example, our sign-in service (Firebase Authentication) is operated by Google from data centres in the United States, and our email provider (Resend) is US-based. In those cases we ensure equivalent protection through legal safeguards.

  • EU Standard Contractual Clauses and, for UK transfers, the UK Addendum or International Data Transfer Agreement
  • Adequacy decisions where available (including the EU–UK adequacy decisions, renewed in December 2025)
  • Technical safeguards including encryption in transit (TLS) and at rest (AES-256)
10

Children's data

Vowly Event is not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you become aware that a minor has provided us with personal data without parental consent, please contact support@vowly.co and we will promptly delete it.

11

Security measures

We implement a layered security programme to protect personal data against unauthorised access, alteration, disclosure, or destruction. See our dedicated Security page for full details.

  • Encryption in transit (HTTPS/TLS) for all connections
  • AES-256 encryption at rest for our database and file storage (Google Cloud managed encryption)
  • Server-side access rules on every read and write — only you, and teammates you explicitly invite, can access your events
  • Sign-in and passwords handled by Firebase Authentication; we never see or store your password
  • Abuse protection with rate limiting, request attestation (App Check / reCAPTCHA) and audit logging
  • Incident response procedures with breach notification within 72 hours
12

Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in law, regulation, or our service. Material changes will be communicated to registered users by email at least 30 days before they take effect. The latest version is always available at vowly.co/privacy.

13

Complaints

If you believe we have not handled your personal data properly, contact us at support@vowly.co with "complaint" in the subject line — this is our data-protection complaints channel under section 164A of the UK Data Protection Act 2018. We will acknowledge your complaint within 30 days (usually much sooner), investigate it, and tell you the outcome without undue delay. You can also complain to the UK Information Commissioner's Office (ico.org.uk) — ideally after giving us the chance to put things right — or to your local EU supervisory authority.

14

Contact & complaints

For any privacy-related questions, complaints, or to exercise your data rights, please contact our privacy team at support@vowly.co or write to: Privacy Team, CKR Technology Group Ltd, Unit A, 82 James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) — ico.org.uk — or your local EU supervisory authority.

Questions about your data?

Contact our privacy team for any privacy-related inquiries, subject access requests, or to exercise your data rights.

support@vowly.co