Your data
Privacy Policy
How we collect, use, and protect your personal data
Last updated: September 14, 2026 · Version 2026-09-14
This is Evorrah’s Privacy Policy. Our cookie policy is the Cookies & local storage section below, and how long we keep each kind of information is set out under Data retention. Our Terms & Conditions — which are also our service agreement, and which contain our cancellation and refund policies — are at evorrah.com/terms.
Who we are
Evorrah is a bespoke event design studio, operated by Innovatech Brazil LLC, a Delaware limited liability company with its principal office in Florida, doing business as Evorrah. Our website is evorrah.com. For all privacy-related enquiries contact hello@evorrah.com.
What data we collect and why
We collect only the data necessary to deliver your design suite and communicate with you about your project:
- Name & partner name — used to personalize your designs and address emails.
- Email address — used to create and access your private portal, and send order and delivery notifications.
- Phone number — collected optionally; used only if we need to contact you urgently about your project.
- Event details — event type, date, venue, and name used exclusively to produce your bespoke design suite.
- Design briefing data — colour palette preferences, style descriptions, moodboards, inspiration images, and notes submitted through your portal. This forms the creative brief for your project.
- RSVP guest list data — when you use the guest-list and RSVP features, we collect on your behalf the details you or your guests provide, which can include: guests’ names and plus-one names, household members (including children’s names, where you add them), email addresses and phone numbers, postal addresses (for mailed pieces), attendance status, accessibility needs, transport needs, and personal messages left in the guestbook. You are the data controller for your guests’ data and confirm you are authorised to share it; we process it solely to produce your guest list, personalized pieces, seating plan, and RSVP tracking — never for marketing to your guests.
- The “By Evorrah” mark. If you tap the small “By Evorrah” mark on an event page, we note the tap, which event it was on, and — if you came from the personal link we sent you — that it was you. Nothing else: no message, no device identifier, nothing passed to anyone else. We keep it for 90 days, only our own team can see it, your host never does, it is never a reason to contact you, and it is deleted whenever the rest of your guest details are.
- Payment data — all payments are processed by Stripe. We never see or store your full card number or banking credentials. We store only the Stripe customer ID and payment status.
- IP addresses — logged for security purposes (rate limiting, fraud prevention). Not used for profiling or marketing.
- Portal session token — a cryptographic token stored in your browser’s local storage to keep you logged in. Rotated on password reset.
How we use your data
- Deliver and personalize your design suite
- Send transactional emails (order confirmation, portal access, design delivery)
- Process and record payment via Stripe
- Maintain your private portal and project history
- Protect the platform from abuse and unauthorised access
- Comply with legal obligations
We never sell your personal data, and we do not share it for any purpose other than those listed above and the advertising measurement described next.
We do use advertising and analytics services to understand how people find us and whether our ads work: Google Analytics 4, Google Ads and the Meta (Facebook/Instagram) pixel. These set identifiers in your browser and, when you make a purchase, we may send Google and Meta a one-way cryptographic hash of your email address and phone number so they can confirm the sale came from an ad. Meta also receives your IP address and your browser’s user-agent, which it uses to recognise the same visit. A hash cannot be reversed back into your details, and we never send these companies your name, address, event details or design work. All of that is off by default and only runs if you accept cookies on the banner — decline, and no advertising or analytics identifier is set at all.
One thing does not depend on that choice, and we would rather say so than leave it out. If you arrive from a Google ad, the click identifier travels in the web address itself, so we still hold it whether or not you accepted cookies. When a purchase completes, a nightly job reports the amount to Google Ads against that click identifier. It carries no name, no email address and no phone number — a figure and a click. Nothing equivalent is sent to Meta or anyone else when you decline.
Text messages (SMS)
If you are a client, we may text you about your own commission — a design ready to review, a question that is holding up production, or a reminder about a deadline you set. If you are a guest at an event we are running the guest list for, the host may send you messages about that event: an invitation link, an RSVP reminder, a change of time or place, or travel and arrival details.
- How you come to receive them. Clients give a mobile number when they book or in their portal. Guests are added by their host, who is responsible for having a reason to contact them. We do not buy phone numbers and we never send marketing texts to a number we were given for an event.
- How often. There is no recurring campaign. Message frequency varies with your event — typically a handful of messages across the weeks around it, and none once it has passed.
- The full messaging disclosure — sender identity, what a guest receives, how consent is obtained and how to stop it — is set out on our Text Messages page.
- How to opt out. Reply STOP to any message to opt out. That number is opted out immediately; we will send one confirmation and nothing after it. Reply START to opt back in. Every message we send carries this instruction. You can also email us and we will remove the number by hand.
- Help. Reply HELP, or write to hello@evorrah.com.
- Cost. We do not charge for messages. Message and data rates may apply from your own mobile carrier, and delivery depends on your carrier — we cannot guarantee it.
- What we keep. The number, the message we sent, when it was sent, whether the carrier accepted it, and whether you opted out. We keep opt-outs indefinitely, because forgetting one would mean texting someone who asked us not to.
- Who sees it. Your number and the message pass through Twilio, our messaging carrier (listed below). Nobody else. We never sell or share phone numbers, and we never pass them to advertisers. Mobile phone numbers and SMS consent are never shared with third parties or affiliates for marketing or promotional purposes.
Third-party processors
- Twilio (twilio.com) — SMS delivery. Receives the recipient’s phone number and the message text in order to deliver it, and returns whether the carrier accepted it. Twilio’s privacy policy applies.
- Stripe (stripe.com) — payment processing under PCI-DSS compliance.
- Supabase (supabase.com) — secure database and file storage hosted on AWS in the US.
- Resend (resend.com) — transactional email delivery.
- Anthropic / Claude (anthropic.com) — AI assistance inside Evorrah’s workflow. Your briefing content is sent to this service: to check your brief for gaps before you submit it, to help Evorrah develop your creative direction, and to draft copy for Evorrah and its marketing. If we write to you about Evorrah, that draft is personalised with your first name, the occasion you asked us about, your event name and your plan — never your email address or phone number. Under Anthropic’s commercial terms, data sent through their API is not used to train their models. We never send your payment details, and every design that reaches you is reviewed by a person. Some details about your guests are sent to this service too, for two jobs. To suggest who should sit together, it receives the names on the event’s guest list along with the note being read — the seating notes, story and special requests in your brief, a seating note typed into the seating tool, or the note a guest leaves with their RSVP. To read a guest’s reply to one of our texts or emails — whether they are coming, not coming, or asking something — it receives that reply, the guest’s name and the names of the other guests on the same event; a short plain answer such as “yes”, “no” or “stop” is read without it. Guests’ phone numbers and email addresses are not attached to either.
- Image generation services — Recraft (recraft.ai), fal.ai and Google Gemini — used by Evorrah to originate artwork elements such as motifs, textures and backgrounds. They receive the design prompt and any wording that is to appear on the artwork itself (for example your names and event details). They never receive your contact details, payment information or guest list.
- Google reCAPTCHA v3 (google.com) — bot detection on public forms. Every form on this site is checked by it, so it receives your IP address and browser signals whenever you submit one, whether or not you accept cookies — it is what stops the forms being flooded. It receives nothing you typed. Google’s privacy policy applies.
- Google Fonts — typography. Google may log your IP when serving font files.
- Google Analytics 4 & Google Ads (google.com) — audience measurement and advertising performance. The identifiers set in your browser are only active if you accept cookies. Separately, and regardless of that choice, a completed purchase that began with a Google ad is reported to Google Ads as an amount against the click identifier that brought you here — no name, email address or phone number. Google’s privacy policy applies.
- Meta (Facebook/Instagram) (meta.com) — advertising performance measurement. Only active if you accept cookies. Receives a hashed (non-reversible) email address and phone number, your IP address, your browser’s user-agent and Meta’s own cookie identifiers — never your name, your event details or your design work. Meta has no partial mode: the pixel either sends real browser data or it does not run, which is why declining the banner switches it off entirely rather than limiting it.
- Vercel (vercel.com) — website and API hosting. Processes request metadata as part of normal hosting.
Data retention
- Client records & briefing data — 5 years from your last active project, then deleted or anonymised.
- Delivered design files — 1 year after your event date, then deleted. We email you 30 days beforehand, and you can ask us to extend the window.
- RSVP guest data — 5 years after your event date, then deleted. Held that long so a host who runs the same occasion year after year does not rebuild their list each time; you can ask us to delete it sooner at any point.
- Guest photographs — 90 days after your event date, then deleted, including the image files themselves. We email you 14 days beforehand so you can download anything you want to keep. These are your guests’ own pictures of themselves, so we hold them for as short a time as we sensibly can.
- Payment records — 7 years to comply with financial record-keeping obligations.
- IP address logs — 90 days for security purposes, then purged.
- Communication logs — the record of emails we sent you (recipient address, subject, delivery status): 5 years, then deleted. System health checks: 90 days.
- Website browsing records — which pages you looked at and how far you got in the booking flow: kept indefinitely, and only ever recorded if you accepted the cookie banner. Decline it, or withdraw your consent, and nothing is recorded.
- Backups — our backups are replaced on their own rolling schedule, so a copy of deleted information can survive in them for up to 6 months after the deletion. Backups are never used to serve the product; they exist only to restore it after a failure.
Your rights
Depending on your location (EU/EEA, UK, Brazil, California, Canada, etc.) you may have rights to access, correct, delete, export, or restrict processing of your personal data.
If you are a guest, four of these you can exercise yourself, straight away — from the personal link in any invitation or reminder we sent you. You can see what we hold about you, correct it, stop receiving messages (one tap on the unsubscribe link in the footer of every reminder, or reply STOP to a text), or ask not to be contacted about that event at all. Nothing has to reach us first and there is nothing to wait for.
Once an event has taken place, that self-service form closes. Write to us and we will make the correction for you.
To export or delete your data, write to hello@evorrah.com with the subject line “Privacy Request”. Those two need a person at our end, and we will respond within 7 days.
Two things deletion does not do, so you know before you ask. It does not remove the business records we must keep about an event that was paid for. And it does not remove records that belong to more than one person — a household, or a message sent to a whole guest list, where we take you out of the recipients and leave the message itself. Separately, if you have told us to stop contacting you, we deliberately keep your email address or phone number on a suppression list for that one purpose, so that a guest list uploaded later cannot reach you again.
Cookies & local storage
We use advertising and analytics cookies and identifiers — Google Analytics 4, Google Ads and the Meta pixel — but only if you accept them on the cookie banner. Until you accept, they are set to “denied” and no such identifier is stored; if you decline, they stay off. You can change your mind at any time: the Cookie choices link in this page’s footer reopens the banner, and your new answer replaces the old one. Nothing needs to be cleared. We keep a record of the choice itself and of any withdrawal — the answer, the wording you were shown, the time, and the page it was given on — and there is nothing in it that identifies you: no name, no email address, no IP address, and no link to your account or your event.
Separately from that choice, we use local storage and session storage to keep you signed in to your portal and to remember which version of a page you were shown. These are required for the site to work and are not used for advertising. Session cookies may also be set by Google Fonts and Vercel as part of normal web operation.
Security
We protect your data with HTTPS everywhere, encrypted passwords (scrypt), Stripe-side payment handling, Row Level Security on our database, rate limiting on all API endpoints, and access tokens rotated on password reset. To report a vulnerability: hello@evorrah.com.
Children
Our service is for adults: we do not offer accounts to under-16s, and we never market to or collect information directly from a child. We do, however, hold children’s names when a host includes them on a guest list — a family invited as a household, or a child’s birthday party. That information is provided by the adult organizing the event, never by the child, and is used only to produce and send their stationery.
It is covered by exactly the same protections as every other guest detail: it is never sold or shared, it is excluded from guest-list exports, and it is deleted on the schedule set out in Retention — 5 years after the event date. If you would like a child’s details removed sooner, or believe information about a child has been added without the organizer’s knowledge, write to hello@evorrah.com and we will remove it.
Changes
The “Last updated” date above reflects the current version. Continued use of the portal after an update constitutes acceptance of the revised policy.
Contact
Anything unclear
A contract you can
actually ask about.
If a clause here matters to your event and does not read plainly, write to us before you buy — a person replies.
Talk to us →