Legal publication
- Controller
- Kadirhan Bal
- Legal entity
- Kadirhan Bal
- Postal address
- Çiftlikköy Mah. 32225 Sok. Bina No: 9, İç Kapı No: 1, Yenişehir/Mersin 33110, Türkiye
- Policy version
- 2026-07-18
- Effective date
1. Privacy
EVENTY provides private QR event albums for weddings, parties, venues, planners, agencies, and other invite-based events. Organizers create and manage albums in the mobile app; guests add photos or videos through the app or an invite-only browser page when the event allows it.
2. Scope, roles, and contact
This notice covers the EVENTY iOS and Android apps, eventalbums.app public pages, invite routing, invite-only guest album pages, support, venue enquiries, and related backend services. Organizers manage events in the mobile app; invited guests may join with a display name and contribute through the app or browser. The EVENTY service operator determines how account, billing, security, support, and service-operation data is used. An organizer determines the event purpose, invite audience, album settings, and how participant media is shared, and may have separate privacy responsibilities. Privacy, deletion, security, legal, and abuse requests can be sent to duvariangames@gmail.com.
3. Information and sources
Information comes from organizers and guests, their devices and browsers, app stores and sign-in providers, venue or agency partners, and service providers. It may include account and anonymous session identifiers; email or sign-in identifiers; event title, date, location, pack, settings, roles, invite membership and display name; photos, videos, original filenames, file type, size, dimensions, duration, capture time and upload status; device, app, language, network, notification-token, security and diagnostic signals; purchase product, entitlement, platform and transaction references; venue-lead details; support messages; deletion or abuse reports; and operational records. JPEG EXIF is removed during supported server validation, but metadata in other formats may remain, so do not upload unnecessary location or sensitive metadata.
4. Purposes and legal bases
EVENTY processes information to provide and administer the requested service, authenticate or maintain anonymous sessions, open the correct invite, upload and display media, apply organizer settings, send requested service notifications, manage purchases and entitlements, prepare exports, expire albums, answer support and privacy requests, secure the service, prevent fraud or abuse, diagnose failures, and meet legal obligations. Depending on the purpose and applicable law, processing is based on performing or preparing a contract, complying with law, legitimate interests such as service security and reliability where those interests are not overridden, or consent when EVENTY specifically asks for it. The guest album acknowledgement explains sharing inside the event; it is not used as blanket privacy consent.
5. Private albums and organizer responsibility
Event media belongs to an invite-only event album, not an open social feed or public album directory. A valid QR code or invite can be forwarded, so organizers must share it only with the intended audience and refresh or revoke it when needed. Access and visibility follow the organizer's settings, membership, role, reveal, moderation, and retention rules. Organizers are responsible for telling participants how the album will be used and for obtaining permissions required for the event and its media.
6. Browser storage and guest uploads
The public site stores a language preference and may use essential security or routing storage. Guest album pages create an anonymous Supabase authentication session and may store invite and membership context, upload state, and selected files in session storage, IndexedDB, local storage, or equivalent browser storage so an upload can continue or recover. This information remains on the device until the flow, browser, or storage is cleared according to product and browser behavior. The public and guest web surfaces do not use non-essential product analytics by default; if that changes, EVENTY must provide the required notice and controls before enabling them.
7. Mobile analytics and diagnostics
When runtime keys are configured, the mobile app may send allowlisted, pseudonymous product-use events to EU-hosted PostHog and redacted crash or error diagnostics to Sentry. Automatic capture, session replay, screenshots, person profiles, default personally identifiable information, and interaction tracing are disabled in the configured mobile integration. These tools must not intentionally receive raw invite codes, private media, full card data, access tokens, or message contents. EVENTY uses the data to understand feature reliability, upload failures, crashes, and security incidents; provider retention and region settings remain subject to the approved production configuration.
8. Payments, notifications, and venue credits
Organizers manage event packs and purchases in the mobile app; the guest website has no checkout. Apple App Store or Google Play processes payment details, and EVENTY does not receive full card numbers. EVENTY may receive and store user or purchaser linkage, product and entitlement information, platform, transaction references, and provider status through RevenueCat and the stores. Firebase Cloud Messaging may process device tokens, platform, app version, and language to deliver service notifications. Venue, planner, or agency codes may activate a pack for a customer-managed event, and venue enquiries may include a name, work email, organization, event volume, and message.
9. Service providers and international processing
EVENTY uses providers for authentication, database, private media storage, web delivery, notifications, purchase entitlement, mobile analytics, crash diagnostics, sign-in, email, and support. The current architecture may include Supabase; Cloudflare, Workers, and private R2 storage; Firebase Cloud Messaging; RevenueCat; Apple and Google; conditionally configured PostHog and Sentry; and support-mail tools. Providers may process information outside the user's country or the EEA. EVENTY will use the transfer mechanism and contractual safeguards required for the relevant provider and jurisdiction after those arrangements are verified; this notice does not claim that all data remains in one country.
10. Retention criteria
Retention is limited by the purpose and the shortest period reasonably needed. Event media follows the purchased pack, add-ons, organizer settings, and the expiry date displayed in the product; it is not permanent archival storage. Account, anonymous-session, device-token, billing, support, security, fraud-prevention, deletion-request, diagnostic, and backup records follow operational, contractual, store, tax, safety, and legal criteria. Expired or deleted objects may be removed asynchronously and may remain in limited backups until the backup cycle completes. Where an exact period is not stated in the product, EVENTY applies review or deletion criteria rather than promising indefinite storage.
11. Deletion and account closure
Account holders can start deletion from Account > Delete account in the mobile app. A request may complete immediately when no ownership, billing, security, or event-integrity review is required; otherwise it may remain pending while EVENTY verifies and resolves the blocker. Invited browser guests can delete their own completed uploads while their guest session remains valid or request removal through support. Account deletion does not reverse or refund a completed event-pack purchase, and limited billing, tax, fraud-prevention, security, abuse, audit, or legal records may be retained when required. See the Data Deletion page for scope and the web request path.
12. European and Turkish privacy rights
Where the GDPR, UK GDPR, or Turkey's Law No. 6698 applies, you may request information and access, correction, deletion, restriction, objection, portability where applicable, and information about recipients; withdraw consent without affecting earlier lawful processing; and complain to the competent supervisory authority, including the Turkish Personal Data Protection Authority where applicable. Some rights depend on the legal basis and may be limited by another person's privacy, event integrity, security, or law. EVENTY may verify identity, authority, and event access through a separate safe step.
13. United States privacy rights
EVENTY does not sell personal information and does not share it for cross-context behavioral advertising. EVENTY does not use private event media for targeted advertising. Residents of California and other applicable U.S. states may request access or categories, correction, deletion, or portability and may exercise opt-out or appeal rights where the relevant law applies, without unlawful discrimination. An authorized agent may submit a request, but EVENTY may verify the agent's authority and the account or event relationship.
14. Children and event guests
EVENTY is not directed to children under 13 and is not designed for children to create or use accounts independently. Events may include minors in photos or videos, but EVENTY does not provide a technical age gate or guardian-consent workflow. Organizers are responsible for the permissions required before inviting uploads or sharing QR materials involving minors. A parent, guardian, or participant should contact EVENTY promptly about a child privacy or safety concern.
15. Questions and complaints
Send a request to duvariangames@gmail.com with the product support reference when available, device platform, approximate event date, and only the minimum explanation needed. Do not email raw invite links or codes, credentials, private media, full receipts, or card data. EVENTY may ask for identity, authority, or event-access verification through a separate secure step. You may also complain to the privacy or consumer authority that has jurisdiction over you.
16. Contact
For legal, privacy, security, deletion, or abuse requests, use the support reference shown in the product when available and include only the minimum event date, device platform, and issue summary needed to route the request. Never email raw invite links or codes, credentials, private media, full payment receipts, or card data.
