Privacy Policy

Effective date: March 24, 2026

·

Last updated: March 24, 2026

Summary

Eventably is a business tool for equipment rental management. We collect only the data needed to run the app, store it securely via Supabase, never sell it, and respect your rights under the GDPR.

1. Who We Are (Data Controller)

Eventably ("we", "us", "our") is the controller of the personal data you provide through our mobile application and web platform. If you have any questions about this Privacy Policy or your data, please contact us:

This policy applies to all users of the Eventably iOS and Android mobile applications.

2. What Data We Collect

2.1 Account & Profile Data

  • Email address (used for authentication and account recovery)
  • Full name
  • Company name, phone number, business address
  • VAT / company registration number (optional)
  • Profile photo and company logo (optional)

2.2 Business Data You Enter

  • Equipment/Inventory: Item names, descriptions, categories, pricing, images, QR code identifiers, condition notes
  • Client records: Customer names, emails, phone numbers, company names, and addresses
  • Events/Bookings: Event names, locations, dates, assigned equipment, payment status
  • Financial data: Rental prices, invoice amounts, payment statuses

2.3 Device Permissions

PermissionPurposeRequired?
CameraScanning QR codes on equipmentRequired for QR scanning
Photo LibraryUploading equipment images and logosOptional
Push NotificationsEvent reminders and booking alertsOptional

3. Legal Basis for Processing (GDPR)

Processing ActivityLegal Basis
Creating and managing your accountContract performance (Art. 6(1)(b) GDPR)
Providing core app featuresContract performance (Art. 6(1)(b) GDPR)
Sending push notification remindersConsent (Art. 6(1)(a) GDPR)
Security and fraud preventionLegitimate interests (Art. 6(1)(f) GDPR)

4. How We Use Your Data

  • To create and maintain your account
  • To provide core app features (inventory management, QR tracking, event scheduling)
  • To send push notifications you have opted in to
  • To generate invoices and reports
  • To respond to support requests
  • To diagnose bugs and improve app stability

We never sell, rent, or trade your personal data to third parties for marketing purposes.

5. Data Sharing & Third-Party Processors

ProcessorPurposeLocation
Supabase, Inc.Database hosting, authentication, file storageEU region (AWS eu-central-1)
Expo / EASApp build infrastructure, crash reportingUnited States
Apple Inc.Push notification delivery (APNs)United States
Google LLCPush notification delivery (FCM)United States

6. Data Storage & Security

  • All data is stored in Supabase with Row Level Security (RLS).
  • Data is transmitted over HTTPS / TLS encryption at all times.
  • Authentication is handled via Supabase Auth with secure session tokens.
  • We do not store payment card data.

7. Data Retention

  • Account data: Retained until you delete your account.
  • Business records: Deleted upon account deletion.
  • QR scan logs: Retained for up to 2 years.
  • Crash/error logs: Retained for up to 90 days.

8. Your Rights Under GDPR

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Correct inaccurate or incomplete data.
  • Right to Erasure: Request deletion of your personal data.
  • Right to Restriction: Limit processing of your data.
  • Right to Portability: Receive your data in a machine-readable format.
  • Right to Object: Object to processing based on legitimate interests.

To exercise any of these rights, please email privacy@eventably.app. We will respond within 30 days.

9. Children's Privacy

Eventably is intended for users 18 years of age or older. We do not knowingly collect personal data from children under 18.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you via push notification or in-app message when material changes are made.

11. Contact Us