Privacy Policy
Last updated: 15 August 2026
1. Who we are
evraft ("we", "us") is an event planning service available at evraft.io. It helps event organisers manage guest lists, send invitations, collect RSVPs, and coordinate guest travel.
evraft is operated by Toby Johnson, trading as evraft, a sole trader based in Australia. Our postal address is PO Box 126, Carlton South VIC 3053, Australia. We are the data controller for organiser account data and the data processor for guest data (see section 2).
For any privacy question or request, contact us at hello@evraft.io.
2. Two kinds of people use evraft
Organisers create an account and plan events. For organiser account data, we are the data controller.
Guests are added to events by their organisers and respond to invitations. For guest data, the organiser decides what is collected and why — the organiser is the data controller and we process that data on their behalf, under the data processing terms in our Terms of Service. If you are a guest and want your details corrected or removed, the quickest route is to contact your event's organiser. You can also contact us: we will act on the organiser's instructions, pass your request to them, and help them respond.
Two things we do decide ourselves, even for guest data, and are therefore controller for: keeping the service secure and free of abuse, and protecting email deliverability (see section 5).
3. What we collect
From organisers
- Account details: name, email address, and a password (stored as a secure hash).
- Event details: event name, dates, location, schedule, gift registry entries, and any photos the organiser adds to the event's public page (a cover photo and photo-wall pictures).
- Guest lists the organiser enters or imports: guest names, email addresses, phone numbers, postal addresses, age group, and grouping (e.g. families).
- Messages the organiser composes and sends to guests.
- Billing details when subscribing to a paid plan — payment cards are handled entirely by Stripe; we never see or store card numbers.
From guests
- RSVP responses, including attendance, dietary requirements, and special requests.
- Optional travel details a guest chooses to share: flight number and date, departure city, and hotel with check-in/out dates.
- Gift registry selections.
- Details of a companion ("plus-one") where the organiser allows one — the name, age group and dietary requirements the inviting guest provides on their behalf.
- Photos a guest chooses to add to the event's photo wall, with an optional caption. Wall photos are displayed on the event's public page (attributed by first name), unless the organiser has turned the wall off or holds photos for approval. Photos are re-encoded on the guest's own device before upload, which strips camera metadata such as GPS location. A guest can delete their own photos from their RSVP link at any time, and the organiser can hide or delete any photo. A photo awaiting approval, or one the organiser has hidden, is stored privately: it is not reachable by anyone who has not been shown it, including by its image address. Only the guest who uploaded it and the event's organisers can see it.
From email and notifications
- Email engagement. Guest emails contain a small invisible image ("open tracking") that records when a message was opened, and we record when a guest first opens their RSVP link. Organisers see both, so they know whether an invitation landed. We do not use click tracking on guest email: links are never rewritten to route through a tracking redirector.
- Delivery outcomes. When a message bounces or is reported as spam, we record that against the address so we stop sending to it. Correcting the address clears the block automatically.
- Push notifications. If an organiser turns on browser notifications, we store the subscription their browser issues (an endpoint URL and encryption keys for that device) so we can deliver the alert. Turning notifications off deletes it.
Automatically
- Aggregate, cookie-free usage statistics via Plausible Analytics — no individual visitors are identified, and nobody is tracked across sites.
- Error reports (via Sentry) so we can find and fix problems, and short-lived server logs kept by our hosting and network providers.
- Your IP address is used momentarily, in memory, to rate-limit abusive traffic. We do not store IP addresses in our database.
4. What we use it for, and our legal basis
Where the law requires us to have a legal basis for using personal data (as the GDPR and UK GDPR do), these are ours:
- Running the service — guest management, invitations, RSVPs, travel coordination, and the account itself. Basis: performance of our contract with the organiser.
- Guest data — held and processed on the organiser's instructions. The organiser is responsible for having a lawful basis for inviting their guests; we act as their processor.
- Payments — taking subscription payments and keeping the records tax law requires. Basis: contract, and legal obligation for the records.
- Account and service emails to organisers — including the occasional nudge when an event looks stalled (see section 6). Basis: our legitimate interest in helping you get the service working, which you can object to at any time by opting out.
- Marketing emails — only ever with your consent, given by ticking the optional box at signup or in Settings, and withdrawable at any time.
- Security, abuse prevention, and email deliverability — including suppressing addresses that bounce. Basis: our legitimate interest in a service that works and does not harm others.
- Aggregate analytics and error monitoring — basis: our legitimate interest in understanding and fixing the service, using data that does not identify anyone.
Dietary requirements and special requests can reveal sensitive information (for example allergies or religious practice). Guests choose whether to provide them, and that choice is the explicit consent they rest on. They are shown only to the event's organisers and are used for nothing else.
We do not sell personal data, and we do not use guest data for advertising or profiling. Travel booking suggestions shown after RSVP may use affiliate links (e.g. Skyscanner, Booking.com); these are ordinary links — no guest personal data is shared with those services.
5. Who processes data for us
We rely on a small set of service providers (subprocessors):
- Supabase — database, authentication, and file storage. Our database is hosted in Japan.
- Vercel — application hosting.
- Cloudflare — DNS, caching, and DDoS protection.
- Resend — email delivery. Guest email is sent from a separate subdomain (
mail.evraft.io) and routed through Resend's EU infrastructure. - Stripe — payment processing. Card details go to Stripe, never to us.
- Mapbox — maps, and the search suggestions used when entering a guest's postal address, an accommodation name on the RSVP form, or the event venue. Text typed into those fields is sent to Mapbox to return suggestions.
- Plausible Analytics — cookie-free, aggregate usage statistics.
- Sentry — error monitoring.
We are based in Australia, and these providers process data outside your country and ours — including in Japan (where our database is hosted), the European Union, the United Kingdom, and the United States. Before disclosing personal information overseas we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles. For people covered by the GDPR or UK GDPR: where a country has a UK or EU adequacy decision — as Japan and the United Kingdom do — we rely on that; otherwise transfers are covered by standard contractual clauses or an equivalent safeguard in our contract with the provider.
6. Emails we send, and how to stop them
To guests
Emails to guests — invitations, save-the-dates, reminders, and messages the organiser writes — are sent at the organiser's request. Every one includes an unsubscribe link; opting out stops all further emails about that event from evraft. Replies go to the organiser.
To organisers
We send you three different kinds of email, and they have separate controls in Settings → Email preferences:
- Essential account email — password resets, billing and payment notices, co-organiser invitations. These cannot be switched off while you have an account, because they are how we tell you about your own account.
- Helpful nudges — occasional prompts when an event looks stalled, for example if you have created an event but not added any guests, or your RSVP-by date is approaching with people still to reply. These are capped so you will not be sent more than one every few days, and you can turn them off at any time, either in Settings or with the one-click unsubscribe in the email itself.
- Tips and news — marketing. Off unless you explicitly ticked the box, and switchable off at any time.
7. Cookies
We use essential cookies only: they keep organisers signed in, carry a co-organiser invitation through signup, and protect forms from abuse. There are no advertising or cross-site tracking cookies, which is why there is no cookie banner. Guest RSVP pages work without signing in and set no tracking cookies. Our analytics are cookie-free. Note that email open tracking, described in section 3, does not use cookies but is still a form of tracking.
8. How long we keep data
- Organiser accounts and event data — for as long as the account exists and remains in use.
- Inactive accounts — accounts whose email address is never verified are deleted around 30 days after signup. Free accounts unused for six months (if no guests were ever added) or twelve months are deleted after we email a warning with the deletion date — at least 30 days ahead, 60 days plus a reminder for accounts holding guest data. Logging in before that date keeps the account. Paid accounts are never deleted for inactivity.
- Deleted events — hidden from everyone immediately, including from guest links. Every image belonging to the event — the cover photo, the guest photo wall, and any place-to-stay pictures — is permanently erased from our storage at the same time and cannot be recovered. The rest of the event's data (guest list, RSVPs, travel details, messages) is retained in our database until you delete your account. If you want that erased sooner, email us.
- Deleting your account (Settings → Delete account) — permanently and immediately removes your events, guest lists, RSVPs, travel details, messages, and notification settings, and cancels any active subscription.
- Payment records — kept by us and by Stripe for as long as tax and accounting law requires, which is longer than the account itself. These are billing records, not guest data.
- Logs and error reports — kept on short rolling windows set by our hosting, network, and monitoring providers, then discarded.
9. Keeping data safe
Traffic is encrypted in transit and data is encrypted at rest by our hosting providers. Passwords are stored only as hashes. Access between accounts is enforced in the database itself by row-level security, so one organiser cannot read another's guests, and guest RSVP links carry a unique unguessable token rather than exposing a login. If a breach ever affects your personal data, we will notify you and the relevant regulator as the law requires.
10. Your rights
We are an Australian business and handle personal information in line with the Australian Privacy Act 1988 and the Australian Privacy Principles. Because organisers and guests are all over the world, we also apply the GDPR and UK GDPR to the people they cover.
Depending on where you live, you may have the right to access, correct, export, delete, or restrict the use of your personal data, to object to processing based on legitimate interests, and to withdraw consent you have given. Organisers can export their guest list and delete their account directly in the app. For anything else — or if you are a guest — email hello@evraft.io and we will respond within one month, and within 30 days for requests under the Australian Privacy Act.
If you are not satisfied with our response you can complain to a regulator: in Australia the Office of the Australian Information Commissioner (oaic.gov.au), in the UK the Information Commissioner's Office, and in the EU your national data protection authority.
11. Children
evraft is not directed at children and does not knowingly collect data from them. Organisers may record that a guest is a child for catering and planning purposes; that information is provided by the organiser, who is responsible for having the right to share it.
12. Changes
If we make material changes to this policy we will notify organisers by email or in the app before they take effect. The date at the top shows when it was last revised.