Security & guest data
Is my guest list safe with you?
Your guest data is stored encrypted on Supabase (hosted on AWS in the US), protected by row-level security so one client’s event can never read another’s, and it is never used to market to your guests — not by us, and not by anyone we work with. It is deleted five years after your event date, sooner if you ask.
The one promise that matters.
You are handing a young company several hundred people’s names, addresses and phone numbers. The reasonable fear is not that we will be hacked — it is that we will use them. We do not.
Guest details are processed for exactly one purpose: producing your guest list, your personalized pieces, your seating plan and your RSVP tracking. Your guests never receive marketing from Evorrah. They receive what you send them, from your event, and nothing else. We do not sell personal data and we do not pass guest details to advertisers.
Every message a guest receives carries a one-click way out, and an opt-out is kept indefinitely — because forgetting one would mean contacting somebody who asked us not to.
Where each kind of data actually lives.
How long we keep it — and the clock that deletes it.
Nothing is kept indefinitely because deleting it is harder. Each kind of data has a window, and the window is enforced rather than intended.
Guest & RSVP data
Five years after your event date, then deleted. Five and not one, because a host who repeats an occasion should not rebuild their guest list every year. Ask and we delete it sooner. The single exception is a guest’s opt-out, kept so it can never be forgotten.
Delivered design files
One year after your event — and we email you 30 days before, so you can download them or ask us to extend.
Client & Your Vision records
Five years from your last active project, then deleted or anonymized — the same window as the guest data attached to them, so a record never outlives its own client file.
Guest photographs
90 days after your event — and we email you 14 days before, so you can download anything you want to keep.
You can ask for your data earlier than any of those dates and we will do it. Write to hello@evorrah.com.
The controls, named.
HTTPS everywhere
Every page and every API call, with no plaintext fallback.
Row Level Security
Enforced in the database itself, not in application code — one event cannot read another’s guests even if a query is wrong.
Passwords hashed with scrypt
We cannot read your password. Nobody here can.
Cards never touch us
Payments go straight to Stripe under PCI-DSS. No card number is stored on our side.
The short version
Your guests are your guests.
We just help you host them.
Questions a page can’t answer? Write to us — a person replies.
Talk to us →