Privacy Policy
Last updated: 2026-07-12
1. Data controller
The party responsible for data processing in connection with operating Venuva is:
Yannick Zinner
Dilshofer Str. 14, 64354 Reinheim, Deutschland
Email: E-Mail-Adresse wird geladen…
Phone: Telefonnummer wird geladen…
2. Roles in data processing
Hosts: When you create an event and invite guests, you are generally the controller of your guests' personal data (e.g. names, RSVP details). You must inform your guests about the processing.
Venuva operator: We are the controller for operating the platform (hosting, security, technical logs) and also process event data as a processor on behalf of hosts to provide the service.
3. What data is processed?
Venuva only processes data that you, hosts, or guests enter during use or that arises technically:
- Event information (title, date, location, description, settings)
- RSVP details (name, attendance status, optional plus-ones, message, dietary notes, custom responses)
- Bring-list and task/poll entries including names
- Cover images (optional, publicly accessible via the event link)
- Host credentials (password stored as a hash, not in plain text)
- RSVP secret codes (hashed on the server; stored in plain text locally on the device for re-authentication)
- Optional host accounts (email address, authentication provider, and technically necessary session data; managed through Supabase Auth)
- Geocoding requests (search terms or coordinates when selecting a location)
- Server log data during hosting (e.g. IP address, timestamp, requested URL — by the hoster)
- Anonymous usage data: event type (e.g. page view, RSVP, event creation), page visited, platform (web/Android), and language (from Accept-Language header) for analytics purposes. Hosts are identified by a cryptographic hash of the event slug — this hash cannot be reversed and does not identify the person.
Host accounts are optional and only provide cross-device management of a host's own events. Guests still do not need an account. No advertising profiles are created.
4. Purpose and legal bases
Processing takes place to provide the service (event organisation, RSVP, bring lists, tasks) on the basis of Art. 6 (1) lit. b GDPR (use of the offered service) or lit. f GDPR (operation, security, abuse prevention).
Optional information (e.g. dietary notes) may concern special categories of personal data under Art. 9 GDPR. Hosts should only enable these fields when necessary and inform guests accordingly. The legal basis depends on guests' consent or the host's legitimate interest in organising the event.
5. Visibility and sharing within an event
The event link acts as an invitation secret. Anyone with this link can view event information and — depending on settings — guest names, RSVP status, bring-list entries, and poll results. Therefore, only share the link with trusted people.
Data is not shared for marketing purposes.
6. Processors
We use the following service providers that process data on our behalf:
- Vercel Inc. — hosting of the website and API (including server logs)
- Supabase Inc. — database (PostgreSQL, EU Central region)
- Vercel Blob — storage of processed cover images (public URLs)
Data processing agreements or corresponding standard contractual clauses are in place with these providers. Further information can be found in their privacy policies.
7. Other third-party services
Depending on use, data may be transmitted to the following services:
- Photon (Komoot) / Nominatim (OpenStreetMap) — address search and reverse geocoding (web: via our API; Android app: sometimes directly from the device)
- OpenStreetMap — map tiles when displaying maps
- Google Fonts — fonts are downloaded at build time and self-hosted (no tracking by Google when visiting pages)
- Google Maps — only when you actively click a navigation link
- WhatsApp (Meta) — only when you actively use a share function
When requests are sent directly from your device to external services (e.g. in the Android app), your IP address may be processed by the respective provider.
8. Storage technologies on your device
Venuva does not use marketing cookies or user-based tracking. Technically necessary data is stored on your device:
- localStorage / sessionStorage (web): host token, RSVP PINs and names, party lists, display hints
- DataStore / encrypted preferences (Android): same purposes as above
- Map cache (Android osmdroid): cached map tiles
A separate cookie banner is not required because no non-essential cookies are set. Technically necessary httpOnly cookies are used only for optional host accounts (Supabase Auth sessions) and the internal analytics dashboard (24 hours, no tracking function). You can remove local data at any time by deleting browser or app data.
9. Retention period
Event data is automatically deleted if the host shows no activity on the event for one year (e.g. login, editing, export). Hosts can manually delete their event at any time in the host area.
Optional account data is retained until the account is deleted. Anonymous usage analytics are automatically deleted after 180 days.
Local data on your device remains until you delete it or remove app/browser data.
Server log data at the hoster is rotated according to their policies (typically a few weeks to months).
10. Usage analytics / no advertising
Venuva collects anonymous usage data (page views, feature interactions) to understand how the app is used and to improve it. This data is stored in our database on Supabase (EU).
No cookies, no IP addresses, no personal data is collected for analytics. Returning hosts are recognized by a cryptographic hash of the event slug — this hash cannot be reversed and does not identify the person. The platform (web/Android) and language (from the Accept-Language header) are stored in anonymized form.
Venuva does not use advertising trackers, Google Analytics, user profiling, or sale of data to third parties for marketing purposes. You can opt out by disabling JavaScript or using a browser extension.
11. Android app
The native Android app uses the same API as the website. In addition:
- INTERNET permission (and network status) for API access
- Geocoding requests may go directly from the device to Photon/Nominatim
- Device backup may include local app data (depending on Android settings)
- No access to location, camera, contacts, or microphone
12. Your rights
Under the GDPR, you have the right to access, rectification, erasure, restriction of processing, data portability, and objection. As a host, you can delete your event. Guests can ask the host or us to delete their RSVP data.
To exercise your rights, contact E-Mail-Adresse wird geladen…. You also have the right to lodge a complaint with a data protection supervisory authority.
13. Further information
14. Bot protection and abuse prevention
To protect against automated data retrieval (scraping), spam and abuse, Venuva employs the following measures:
- Contact details (email, phone) are decoded client-side and only become visible after the page loads — they are not present in plain text in the HTML source.
- Automated access to the API is not permitted and may be blocked by technical measures (e.g. rate limiting).
- In case of repeated, manifestly abusive access we reserve the right to temporarily block IP addresses and take legal action.
- The website uses no advertising cookies, no trackers and no cross-user profiling. Anonymous usage data (event types, pages, hashed event slugs, platform and language) is collected for analytical purposes only — no personal data is involved.
If you encounter malfunctions or security vulnerabilities, please report them by email. We take data protection and security seriously.