A formal DPA is required before enterprise or vendor-scale guest data.
Current position
EventTale processes host-submitted event content, RSVP responses, and host-uploaded photographs today, under the security rules, retention windows, and subprocessors described below. We do not process imported bulk guest lists. A formal, negotiated Data Processing Agreement for enterprise or vendor-scale use is not yet available. This page states our current position and is not a signed contract.
Subprocessors
Google/Firebase: Authentication, Firestore (database), and Cloud Storage (photograph hosting). Cloudflare: Workers (application hosting and the live origin) and email routing. Google reCAPTCHA Enterprise, via Firebase App Check: bot detection on sign-in and publishing requests; this collects user-interaction signals.
Retention and international transfer
Event drafts are retained for 90 days by default; host-uploaded photographs are retained until 30 days after the hosting window ends (see Data Deletion for the enforcement status). EventTale serves hosts in India, the United States, Europe, the Middle East, Southeast Asia, and Latin America; data is processed and stored on Google Cloud/Firebase and Cloudflare infrastructure, which may be located outside the host's or guest's own country.
Required controls before enterprise or vendor-scale processing
A negotiated DPA, formal access logging, a documented encryption strategy, and named incident-response ownership are still required before EventTale takes on enterprise or vendor-scale guest data. Contact hello@eventtale.com to discuss terms.