Privacy policy

Effective September 25, 2026

Eventela is an event management service for organizations. This policy explains what information we collect, how we use it, and the choices you have. If you have a question, email us at hello@eventela.app.

Who this policy covers

Eventela is used by organizations, such as nonprofits, cultural centers and associations, to run their events. There are two groups of people whose information we handle:

  • Users: people who sign in to Eventela as staff or volunteers of an organization.
  • Contacts and guests: people an organization adds to Eventela or invites to its events, and people who reply to an invitation or register through a public link.

For contacts and guests, the organization decides what information to collect and why. We process that information on the organization’s behalf and only to provide the service to them.

Information we collect

  • Account information: name, email address and password for users, and the organizations and roles they belong to.
  • Contact information uploaded by organizations: names, email addresses, phone numbers, contact type, lists and other details an organization chooses to store.
  • Event and RSVP information: events, replies, party sizes, guest names, table assignments and check-in times.
  • Email delivery information: which emails were sent to whom and when, delivery status, and whether a recipient opened an email or clicked a link in it. Opens are measured with a small image in the email, and clicks with links that pass through Eventela.
  • Email sender settings: the sender addresses an organization configures, including mailbox server settings and credentials. See the next section for Google accounts.
  • Technical information: basic logs such as IP address, browser type and timestamps, used to keep the service secure and working.

Google user data

Organizations can connect a Google account so that invitations and event emails are sent from their own Gmail or Google Workspace address.

  • What we request: only permission to send email on the account’s behalf (the Gmail gmail.send permission), plus the account’s basic profile: its email address and name.
  • How we use it: to send the emails the organization writes and chooses to send in Eventela, from that Google account, and to show which address is connected. We use the name as the default sender name.
  • What we do not do: Eventela does not read, store or scan the contents of your mailbox. We do not use Google user data for advertising, and we do not sell it or use it to train AI models.
  • How it is stored: the refresh token Google gives us, which lets Eventela keep sending until you disconnect, is stored encrypted and is never shown in the app.
  • How to disconnect: you can remove access at any time at myaccount.google.com/permissions, or by removing the sender in Eventela. When a sender is removed, we delete its stored token.

Eventela’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

How we use information

  • To provide the service: run events, send invitations and event emails, collect replies, and manage check-in and seating.
  • To keep accounts and data secure, prevent abuse and fix problems.
  • To contact users about their account, the service and changes to it.

We do not sell personal information, and we do not use contact or guest information for our own marketing.

Sharing and service providers

We share information only with the organization it belongs to and with service providers that help us run Eventela:

  • Supabase for database hosting, authentication, file storage and server functions.
  • Cloudflare for our website and network delivery.
  • Google when an organization connects a Google account to send email.
  • Email servers configured by an organization, which deliver the emails that organization sends.

We may also disclose information if the law requires it, or to protect the rights and safety of our users and the public.

Security

Each organization’s data is separated from other organizations by database access rules. Email credentials and Google tokens are stored encrypted. Data travels over encrypted connections. No system is perfectly secure, and we will notify affected organizations if we learn of a breach that affects their data.

Retention and deletion

We keep information for as long as the organization’s account is active. Organizations can edit or delete contacts, events and senders in the app at any time. When an organization closes its account, we delete its data within 30 days, except where we must keep limited records to meet legal obligations. Backups are overwritten on a rolling schedule.

If you are a guest or contact, the organization that invited you controls your information. Please ask them first. You can also email hello@eventela.app and we will pass your request to the organization and help them act on it.

Your choices

  • Users can update their account details and ask us to delete their account.
  • Guests can change or withdraw an RSVP from their personal link.
  • Anyone can ask what information we hold about them, or ask us to correct or delete it, by emailing hello@eventela.app.

Children

Eventela is meant for organizations and is not directed at children under 13. We do not knowingly collect information from children under 13 through user accounts. If you believe a child has created an account, contact us and we will delete it.

Changes to this policy

If we change this policy, we will update the effective date above. If a change is significant, we will tell users by email or in the app before it takes effect.

Contact

Eventela
Email: hello@eventela.app