Privacy Policy
This Privacy Policy explains how Crahooli s.r.o. collects, uses, stores, shares, and protects personal data when you use Ceremo.
Introduction
This Privacy Policy explains how Crahooli s.r.o. ("Crahooli", "we", "us", or "our") collects, uses, stores, shares, and protects personal data when you use Ceremo, including the Ceremo website, web portal, iOS application, event pages, RSVP tools, media upload tools, voice memo tools, and related services (together, the "Service").
Ceremo is a wedding-focused platform that allows event owners and organizers to create wedding events, invite guests, collect RSVP responses, receive photos, videos, and voice memos, and manage event-related content.
This Privacy Policy applies to event owners and organizers, invited guests, uploaders and visitors using an event link or QR code, wedding professionals or planners using Ceremo where applicable, and people who contact us for support or other communications.
If you do not agree with this Privacy Policy, you should not use the Service.
1. Controller information
The controller of your personal data is Crahooli s.r.o., registered in Slovakia.
- Address: Doležalova 3424/15C, Bratislava - Ružinov, 82104
- Company ID: 57 684 456
- Email: support@crahooli.com
- Website: https://ceremoapp.com
2. What Ceremo does
Ceremo provides digital tools for wedding events. Event owners control many event settings, including whether guests can view uploaded content, whether guests can download uploaded content, and whether an event is accessible to people with a link or QR code.
- Event creation and event management
- Guest list and RSVP management
- Invitation and RSVP emails
- Photo and video uploads
- Voice memo uploads
- QR code and event link sharing
- Media gallery access, if enabled by the event owner
- Subscriptions, event passes, and payment-related features
- Support and account management
3.1 Account and profile data
When an event owner, organizer, or other account user creates or uses an account, we may collect account and profile data.
- Name
- Email address
- Apple private relay email address, if the user signs in with Apple Hide My Email
- Firebase user ID
- Authentication provider information, such as Google Sign-In or Apple Sign-In
- Account settings
- Subscription and payment status
- Support messages and communications with us
We do not collect or store profile photos from Google or Apple Sign-In.
3.2 Event data
When an event is created or managed, we may collect event data.
- Event name
- Event date and time
- Event cover photo
- Event settings
- Event links and QR codes
- Upload link identifiers
- Guest list information
- RSVP settings
- Gallery and download settings
- Event pass or subscription status
3.3 Guest and RSVP data
Event owners may manually create guests, import guests, or invite guests through Ceremo. Guests may RSVP without creating a Ceremo account. Depending on the event settings and RSVP form, we may process guest and RSVP data.
- Guest name
- Guest email address
- Attendance status
- Invitation status, such as created, invited, accepted, or declined
- RSVP response timestamp
- Meal preference
- Allergies
- Dietary restrictions
- Accessibility needs
- Accommodation needs
- Transport needs
- Personal notes or messages to the event owner
- Children count
Some RSVP fields, such as allergies, dietary restrictions, accessibility needs, accommodation needs, or personal notes, may reveal sensitive information. Guests should only provide information they are comfortable sharing with the event owner and that is necessary for the event.
If an event owner imports or manually enters guest information, the event owner is responsible for having the necessary rights or permissions to provide that information to Ceremo.
3.4 Photos, videos, voice memos, and uploaded content
Ceremo allows users and guests to upload event content. Guests may upload content without creating a Ceremo account. Depending on the event settings, we may collect and store uploaded content and related metadata.
- Photos
- Videos
- Voice memos or audio recordings
- Captions, messages, or descriptions added to uploads
- Optional uploader name
- File metadata
- Upload timestamp
- Event ID, upload link ID, or guest ID
- Device and browser information related to the upload
- Technical log data, which may include IP address
3.5 Payment and subscription data
For web payments, Ceremo uses Stripe. For iOS in-app purchases and subscriptions, Ceremo uses Apple In-App Purchases. We may store payment and entitlement data needed to operate paid features.
- Stripe customer ID
- Stripe subscription ID
- Payment status
- Subscription status
- VAT or tax ID, where applicable
- Refund-related records
- Event pass or subscription entitlement information
We do not store full payment card numbers, full card details, card security codes, Stripe invoices, billing addresses, or last four card digits. Payment providers may process payment and billing information according to their own privacy policies and legal obligations.
3.6 Technical, analytics, and diagnostic data
We may collect technical and usage data to operate, secure, debug, and improve the Service.
- Device type
- Operating system
- App version
- Browser type
- Approximate technical region or locale
- Crash logs
- Error logs
- Performance data
- Usage events
- Security logs
- Timestamps
- IP address in server, security, or infrastructure logs
We use analytics, crash reporting, performance monitoring, and diagnostic tools, including Firebase Analytics, Firebase Crashlytics, Google Analytics, Vercel Analytics, and Sentry.
We do not use Meta Pixel, TikTok Pixel, or third-party advertising tracking tools.
3.7 Cookies and local technologies
The Ceremo web experience may use cookies, local storage, session storage, or similar technologies where necessary for authentication, security, session management, preferences, analytics, or service functionality.
Strictly necessary technologies may be used to provide the Service. Analytics or non-essential cookies will be handled through a consent mechanism where required by law.
4. How we use personal data
We use personal data for the following purposes.
- To create and manage user accounts
- To authenticate users through Google Sign-In, Apple Sign-In, and Firebase Authentication
- To create and manage events
- To generate and manage event links and QR codes
- To allow guests to RSVP
- To send RSVP invitations and RSVP reminders
- To collect and display event uploads, where enabled
- To allow event owners to manage uploaded photos, videos, and voice memos
- To process subscriptions, event passes, payments, refunds, and entitlements
- To send account, payment, subscription, event expiration, and system emails
- To send marketing or newsletter emails, where permitted by law
- To send push notifications, where enabled by the user
- To provide customer support
- To detect, prevent, and investigate abuse, illegal content, security incidents, and fraud
- To debug, monitor, analyze, and improve the Service
- To comply with legal, accounting, tax, and regulatory obligations
- To enforce our Terms of Service and other policies
5. Legal bases for processing under GDPR
Where the GDPR applies, we rely on contract where processing is necessary to provide the Service, including account creation, event management, RSVP features, uploads, subscriptions, event passes, and customer support.
We rely on legitimate interests for security, abuse prevention, debugging, analytics, service improvement, fraud prevention, and maintaining reliable infrastructure, provided those interests are not overridden by your rights and freedoms.
We rely on consent where required, including for certain marketing communications, non-essential analytics or cookies, or optional device permissions such as push notifications.
We may process or retain data where necessary to comply with tax, accounting, legal, regulatory, or law enforcement obligations.
6. Event owner responsibility and event sharing
Ceremo is a tool used by event owners and organizers. Event owners control many privacy and sharing settings for their events. Depending on the settings chosen by the event owner, event content and event pages may be visible, downloadable, private, or accessible to people with an event link or QR code.
Event owners are responsible for configuring event settings and for sharing event links and QR codes only with people they want to access the event.
Ceremo cannot control how event owners, guests, uploaders, or other people copy, download, screenshot, screen record, forward, publish, or otherwise disclose event content outside the Service.
7. User-generated content
Users are responsible for the content they upload or submit through Ceremo, including photos, videos, voice memos, captions, RSVP responses, guest information, and messages.
Users should not upload or submit content unless they have the necessary rights, consents, or permissions to do so. This is especially important where content includes other people, children, private moments, personal data, sensitive information, or copyrighted material.
We may remove content or restrict access to content if we believe it is abusive, illegal, harmful, violates our policies, or may expose Ceremo, users, or others to legal or security risk.
8. Emails and communications
We may send emails through our email provider, Resend.
- Account emails
- Security or login-related emails
- RSVP invitation emails
- RSVP reminder emails
- Payment and subscription emails
- Event expiration emails
- Support emails
- Service or system messages
- Marketing or newsletter emails, where permitted
Transactional and service emails are necessary for the Service and may still be sent even if a user opts out of marketing.
Marketing emails should include an unsubscribe or opt-out mechanism. Users may also contact us at support@crahooli.com to opt out of marketing communications.
9. Push notifications
If users enable push notifications in the iOS app, Ceremo may send notifications about new uploads, RSVP changes, event reminders, subscription or payment events, system messages, and other event-related activity.
Push notifications may be delivered through Firebase Cloud Messaging and Apple Push Notification service. Users can manage push notification permissions in their device settings.
10. Service providers and processors
We use third-party providers to operate the Service. These providers may process personal data on our behalf or as independent controllers, depending on the service and context.
- Firebase Authentication, Firebase Analytics, Firebase Crashlytics, and Firebase Cloud Messaging
- Supabase for database services
- Amazon Web Services, including App Runner, Secrets Manager, WAF, and S3
- Vercel for frontend hosting and deployment
- Resend for email communication
- Stripe for web payments and subscriptions
- Apple for Sign in with Apple, Apple Push Notification service, and Apple In-App Purchases
- Google for Google Sign-In and Google Analytics
- Sentry for error monitoring and diagnostics
We only share personal data with service providers where necessary to provide, secure, analyze, support, or improve the Service, process payments, communicate with users, comply with law, or enforce our rights.
11. International transfers
Ceremo primarily stores and processes data in the European Union or European Economic Area. Current infrastructure regions include Supabase in Ireland, AWS App Runner and S3 in Frankfurt, Germany, Vercel in Europe, Firebase/Auth in Europe, Stripe account region in Europe, and Resend in Europe.
Some service providers may process limited data outside the EEA depending on their infrastructure, support, security, or operational requirements. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses, adequacy decisions, or other legally recognized transfer mechanisms.
12. Security
We use technical and organizational measures designed to protect personal data.
- HTTPS/TLS for data transmission
- Private S3 storage by default
- Signed URLs for controlled access to stored media
- Role-based access controls for event owners and administrators
- AWS WAF and infrastructure security controls
- Secrets management
- Admin and audit logs
- Access restrictions for internal systems
- Provider-level encryption at rest for core infrastructure where provided by our hosting, database, storage, authentication, analytics, and payment providers
No online service can guarantee absolute security. Users are responsible for keeping their account credentials secure and for controlling who receives access to event links, QR codes, guest links, and downloadable content.
13. Data retention
We keep personal data only for as long as necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
- Event uploads are stored for a maximum of 2 years, depending on the selected plan or product
- When a subscription or event pass expires, related event content may be deleted after 1 month
- When an account owner requests account deletion, a 30-day grace period applies
- After the grace period expires, we delete the account and associated events, uploads, RSVP data, guest data, voice memos, and related content, except where retention is required or permitted by law
- Backups are deleted or overwritten within 90 days after deletion
- Technical and security logs are retained for up to 12 months unless needed for security, debugging, fraud prevention, legal reasons, or dispute resolution
- Support emails are retained for up to 24 months after the last interaction
- Analytics records are retained for up to 26 months, depending on provider configuration
- Payment, tax, accounting, refund, dispute, and legal records are retained as long as necessary to comply with legal obligations or protect our rights
Some records, such as payment, tax, accounting, security, and legal records, may be retained longer where required or permitted by law.
14. Account deletion and guest deletion requests
Account owners can request account deletion through the iOS app, through the web portal, or by contacting support@crahooli.com.
When an account owner requests deletion, Ceremo starts a 30-day grace period. During this period, the account remains usable and the deletion request can be cancelled. After the grace period expires, Ceremo deletes the account and associated events, uploads, RSVP data, guest data, voice memos, and related content, except for information that must be retained for legal, tax, accounting, security, fraud prevention, or dispute-resolution purposes.
Guests and uploaders who do not have a Ceremo account may request deletion of their RSVP response or uploaded content by contacting support@crahooli.com. We may need information sufficient to identify the relevant event, RSVP response, upload, or content.
15. Your rights
Depending on your location and applicable law, you may have privacy rights.
- Access your personal data
- Correct inaccurate personal data
- Request deletion of your personal data
- Restrict processing of your personal data
- Object to processing of your personal data
- Receive a copy of your personal data in a portable format
- Withdraw consent where processing is based on consent
- Opt out of marketing communications
- Lodge a complaint with a data protection authority
To exercise your rights, contact us at support@crahooli.com.
If you are in Slovakia or the EEA, you may also contact your local data protection authority. In Slovakia, the supervisory authority is the Office for Personal Data Protection of the Slovak Republic.
16. Children and minors
Ceremo is not directed to children, and we do not knowingly allow children to create accounts.
Wedding events may include photos, videos, voice memos, or RSVP information relating to children or minors, for example where children attend a wedding or appear in uploaded content. Event owners and uploaders are responsible for ensuring they have the necessary rights, consents, or permissions before uploading or submitting content involving children.
If you believe a child has provided personal data to Ceremo or appears in content that should be removed, contact us at support@crahooli.com.
17. Marketing
We may send marketing or newsletter emails where permitted by law. Users may opt out of marketing communications at any time by using the unsubscribe mechanism provided in the email or by contacting support@crahooli.com.
Opting out of marketing does not stop transactional or service-related communications, such as account, payment, subscription, security, RSVP, event expiration, or support emails.
18. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we may notify users through the Service, by email, or by other appropriate means.
The updated version will be posted on https://ceremoapp.com/privacy-policy with a new "Last updated" date.
19. Contact
For privacy questions, data requests, deletion requests, or complaints, contact Crahooli s.r.o. at support@crahooli.com.
- Address: Doležalova 3424/15C, Bratislava - Ružinov, 82104
- Company ID: 57 684 456
Apple App Privacy Disclosure Summary
This section is provided to help keep Ceremo’s App Store Connect privacy disclosures consistent with this Privacy Policy. It is not a substitute for completing Apple’s App Privacy questionnaire accurately in App Store Connect.
Data types Ceremo may collect
Ceremo may collect contact information such as name and email address for account management, event ownership, RSVP, invitations, support, and communication.
Ceremo may collect user content such as photos, videos, audio data, voice memos, captions, messages, RSVP notes, and event cover photos to provide event upload, gallery, voice memo, RSVP, and event management features.
Ceremo may collect identifiers such as Firebase UID, Stripe customer ID, Stripe subscription ID, event IDs, guest IDs, upload link IDs, and device or installation identifiers where used by Firebase, analytics, diagnostics, or push notification systems.
Ceremo may collect purchase data such as subscription status, payment status, event pass status, Stripe subscription ID, and Apple In-App Purchase subscription status for payments, subscriptions, refunds, and entitlement management.
Ceremo may collect usage data and diagnostics such as app interactions, feature usage, event activity, analytics events, crash logs, performance data, error logs, and technical logs for analytics, product improvement, debugging, service reliability, crash reporting, diagnostics, and security.
Depending on what guests voluntarily submit in RSVP forms, Ceremo may process allergies, dietary restrictions, accessibility needs, accommodation needs, transport needs, and personal notes to the event owner. These are collected to support event organization and are shared with the relevant event owner.
Tracking and App Store disclosure notes
Ceremo does not use third-party advertising tracking tools such as Meta Pixel or TikTok Pixel.
Ceremo uses analytics and diagnostics tools such as Firebase Analytics, Firebase Crashlytics, Google Analytics, Vercel Analytics, and Sentry. These should be disclosed in App Store Connect according to their actual configuration and Apple’s definitions of tracking, data linked to the user, and data used for analytics or diagnostics.
Some collected data may be linked to the user, including account information, event ownership, subscription status, uploaded content, RSVP data, and diagnostics associated with an account or device. Some analytics or diagnostic data may be aggregated or not directly linked to a user, depending on provider configuration.
App Store purposes
Ceremo may use collected data for the following purposes.
- App functionality
- Account management
- Event management
- RSVP and invitations
- Media uploads and galleries
- Payments and subscriptions
- Push notifications
- Analytics
- Diagnostics
- Security and fraud prevention
- Customer support
- Marketing communications, where permitted