Privacy Policy
Last updated: August 1, 2026
Convivo is an event and celebration platform that connects hosts and organizers — people planning a wedding, a party, or a corporate event — with the vendors who help bring it to life (DJs, planners, photographers, videographers, caterers, florists, and venues). This policy explains what information we collect on joinconvivo.com and in the Convivo app, why we collect it, who we share it with, and the choices and rights you have.
This document is a working draft prepared to support our Google OAuth verification and to give you an honest, plain-language account of our data practices ahead of a full legal review — it is not a substitute for advice from a lawyer, and placeholders below are marked FOUNDER-CONFIRM until the founder finalizes them.
Information we collect
We collect information you give us directly, information generated by using the product, and a small amount of information from the services we rely on to run it.
- Account information — when you create an account, we collect the email address and name your identity provider (Amazon Cognito, our authentication service) shares with us, including your name, email address, and profile photo when you sign in with Google.
- Event and guest data you enter — as a host or organizer, the event details, schedule, and guest list you build, including guest names, email addresses, and any dietary or meal preferences, seating choices, RSVP responses, messages, and photos you or your guests add.
- Vendor business data — as a vendor account (DJs, planners, photographers, videographers, caterers, florists, and venues), the client records, bookings and projects, quotes, invoices, signable agreements (electronic-signature records), questionnaire answers, and files you create or exchange with your clients through your Convivo portal.
- Payment information — handled entirely by Stripe, our payment processor. We never collect or store your full card number, expiry date, or CVC; Stripe returns us only what we need to display a receipt or invoice status (e.g. the last four digits, a payment amount, a status). See "How we share information" for how vendor payments work.
- Files you upload — photos, documents, and other files you upload are stored in Amazon S3 (part of AWS, our hosting provider).
- Push notification subscriptions — if you turn on push notifications, we store the delivery endpoint and encryption keys your browser assigns to your device, solely to deliver the notifications you opted into. You can remove any device at any time from your notification settings.
- Communications — when we send you a transactional email (a receipt, an RSVP confirmation, a notification) through Amazon SES, we rewrite the links in it so we can record its delivery status, including whether it was delivered, opened, and clicked, so you and we can tell whether a message got through and was acted on.
- Cookies and similar technologies — strictly-necessary cookies only: for signing you in, remembering which workspace you are acting in, and remembering that you unlocked a password-protected event site. No advertising, cross-site tracking, or third-party cookies. See "Cookies and tracking" below for the full list, including the ordinary browser storage we use for display preferences like theme.
How we use information
We use the information above to operate and provide the service you signed up for: to authenticate you, run the event-planning and vendor-collaboration tools you use, send the transactional emails those tools depend on, process payments, provide customer support, keep the product secure and free of abuse, and meet our legal obligations.
We do not sell your personal information, and we do not use your event, guest, or vendor data to serve you or anyone else third-party advertising. If that ever changes, we will update this policy first.
Support and platform-staff access
In rare cases — helping with a support request, investigating abuse, or handling a trust-and-safety issue — an authorized member of the Convivo team may access or act within your account through a time-limited, audited internal tool. Every use is logged and scoped to what the request requires; it is never used to browse accounts without a reason.
Google Calendar sync (planned feature)
We are building an optional Google Calendar integration for vendor accounts, so a vendor's bookings on Convivo can stay in sync with their own calendar's availability. This section describes how that feature will handle data once it ships, so reviewers and users can evaluate our commitment ahead of launch.
- We will only request access to a vendor's Google Calendar after that vendor explicitly connects their Google account through Google's own consent screen — never on their behalf, and never for host/organizer accounts.
- We will create and update calendar events only for bookings made through Convivo, and we will read only your calendar's free/busy times to prevent double-bookings — we will never read the titles, attendees, locations, descriptions, or any other contents of your other calendar events.
- We will never sell Google Calendar data, never use it to serve advertising, and never share it with any other user, vendor, or third party.
- A vendor will be able to disconnect Google Calendar at any time from their portal settings, which immediately revokes our access to their calendar.
- Convivo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
And similar technologies: local storage
We also use ordinary browser local storage — which never leaves your device and is never sent to our servers — to remember display preferences like light/dark theme and layout state.
We do not run third-party advertising trackers, social-media pixels, or cross-site analytics cookies on the app or on our marketing site. If we ever add optional, consent-gated analytics, this policy — and a cookie-consent control — will be updated before that happens.
Data retention
We keep your account, event, and vendor data for as long as your account is active, so the product keeps working the way you expect. When you delete an event, a guest, or a file inside the product, we remove it from active use promptly, subject to a short backup-retention window we use for disaster recovery.
If you close your account (see "Your rights" below), we delete your personal data within a reasonable period, except where we must keep certain records to meet a legal, tax, or accounting obligation, or to resolve disputes.
Your rights: access, export, and delete
You control your data. Hosts and vendors already have self-serve export tools inside the Convivo dashboard — CSV export is available today for your guest list, invoices, expenses, client (CRM) records, and payment history — so you can take a copy of your data whenever you like without waiting on us.
If you are a workspace owner, you can also delete your own workspace yourself, self-serve, at any time: Dashboard → Settings → Danger Zone → Delete workspace. This immediately and permanently removes the workspace, every member and vendor's access to it, and your own Cognito sign-in account — it cannot be undone.
For anything self-serve deletion doesn't cover — a request from someone other than the workspace owner, a partial deletion, a full copy of your account data outside the CSV exports above, or any other question about your data — contact us at hello@joinconvivo.com (FOUNDER-CONFIRM: confirm this is the address the founder wants published before this ships to production) and we will process your request.
Wherever you live, we honor requests to access, correct, export, or delete your personal data, and to object to or restrict certain processing, consistent with applicable law (including GDPR and CCPA-style rights) — you do not need to be an EU or California resident to ask.
Children's privacy
Convivo is not directed at children, and we do not knowingly collect personal information from anyone under 13 (or under 16 in jurisdictions where that is the relevant age, such as the EU). If we learn we have collected personal information from a child below the applicable age without the consent required by law, we will delete it.
A guest RSVPing to an event may be a minor whose name, meal choice, or dietary note a parent or the event host enters on their behalf — that data is provided and controlled by the adult host, not collected directly from a child.
Security
We encrypt data in transit (TLS) and at rest, isolate every customer's data by a tenant identifier enforced at the application layer, and apply least-privilege access controls to the systems that can reach it. No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security, but we design and operate the product to industry-standard practice for a company our size.
Where your data is stored
Convivo is hosted on Amazon Web Services in the United States (us-east-1). If you access the service from outside the United States, you understand that your information will be transferred to, stored, and processed in the United States, which may have data protection laws different from those of your country.
Changes to this policy
We may update this Privacy Policy from time to time. If we make a material change, we will update the "Last updated" date above and, where appropriate, notify you by email or an in-app notice before the change takes effect.
Contact us
Questions about this Privacy Policy or a request to access, export, or delete your data can be sent to hello@joinconvivo.com (FOUNDER-CONFIRM before production).