Privacy Policy
What personal data we collect, how we use it, and your rights.
Last updated September 11, 2026
Privacy Policy
This Privacy Policy explains how DTK Holdings (Pvt) Ltd collects, uses, and protects personal data when you use EventCraft. We are committed to handling your data responsibly and in line with Sri Lanka's Personal Data Protection Act, No. 9 of 2022.
1. Data we collect
- Account data: your name, email, phone number, and password (stored hashed).
- Social login data: if you choose to sign in with Facebook or Google, the limited profile data those providers send us — see section 2.
- Event data: event details, tasks, budgets, and the guest information you add (names, emails, phone numbers).
- Vendor data: if you list a business, your profile, packages, and media.
- Payment data: billing records and invoices. Card details are handled by our payment providers — we never store full card numbers.
- Usage data: device, browser, and basic analytics to keep the service reliable.
2. Signing in with Facebook or Google
You can create an account and sign in using Facebook Login or Google Sign-In instead of choosing a password. This is entirely optional — registering with an email address and password gives you exactly the same access.
What we receive. When you tap Continue with Facebook, Facebook asks for your permission and then sends us only the following, under the public_profile and email permissions:
- your Facebook app-scoped user ID — an identifier unique to EventCraft, not your public Facebook ID,
- your name,
- your email address,
- the web address of your profile picture.
Google Sign-In returns the equivalent fields under its profile and email scopes.
Why we use it. Only to create your EventCraft account, to sign you in on later visits, and to show your name and picture inside the app. Because the provider has already confirmed your email address, signing in this way also marks your email as verified, so we do not ask you to confirm it a second time.
What we never do. We do not post anything to your Facebook or Google account. We do not access your friends, photos, pages, or messages. We request no permission beyond those listed above, and we never use social login data for advertising or sell it to anyone.
What we store. Your name, email address, app-scoped user ID, and the link to your profile picture. The picture itself stays with the provider — we store its address, not a copy. We also keep the access token the provider issues so the connection keeps working; it is held in our database and shared with no one.
Disconnecting. You can remove EventCraft at any time from Facebook → Settings & privacy → Settings → Apps and Websites, or from your Google Account → Security → Your connections to third-party apps. Disconnecting stops future sign-ins, but it does not by itself delete the EventCraft account you already created — see Data Deletion for that.
3. How we use your data
- To provide the Platform — create events, manage guests, send invitations and reminders.
- To process payments and issue invoices.
- To send service messages (email/SMS) and respond to support requests.
- To improve and secure the Platform.
4. Guest data — your responsibility
When you upload a guest list you act as the controller of that data. Please only add contact details you are entitled to use, and tell your guests how their information will be used.
5. Sharing
We do not sell your personal data. We share it only with the service providers that help us run EventCraft, under contracts that limit them to processing it on our instructions:
- Vercel Inc. — application hosting.
- Neon Inc. — our managed PostgreSQL database, hosted in Singapore.
- Resend, Inc. — delivery of transactional email.
- Cloudflare, Inc. — bot protection and content delivery.
- Bunny.net — storage and delivery of images you upload, and of voice and video messages guests leave for a host.
- text.lk — SMS delivery, where you have given us a mobile number.
- Meta Platforms, Inc. — delivery of WhatsApp messages, if you contact us on our WhatsApp support number. Your messages pass through Meta’s WhatsApp Business service and are also subject to WhatsApp’s own terms and privacy policy.
- PayHere and PayPal — payment processing for paid plans.
We also disclose data where the law requires it — our Law Enforcement & Government Data Requests policy explains how we check, narrow, and record those demands. Some of these providers operate outside Sri Lanka, so your data may be processed abroad under appropriate safeguards.
6. Cookies
We use essential and analytics cookies as described in our Cookie Policy.
7. Retention
We keep personal data only as long as needed to provide the service and to meet legal and accounting obligations. You can delete events and guests at any time.
WhatsApp support conversations. If you message our WhatsApp support number without an EventCraft account, we keep that conversation — your phone number, your WhatsApp profile name, the messages, and any photo or document you send — for one year after your last message, and then delete it automatically, including the files. If the number belongs to an EventCraft account, the conversation is kept with that account instead and is removed when the account is deleted. Voice notes and video are never stored.
Notes guests leave for a host. A guest invited to an event can leave the host a written, voice or video message from their invitation link — one at a time. Voice and video messages are recordings of a person, so they are kept to a stated period rather than indefinitely: three months after the event date, and at least thirty days from the day the message was left, after which the recording is deleted automatically. Video messages are stored and delivered by Bunny.net (see section 6). The host can delete any message sooner, and everything attached to an event is removed when the event or the account is deleted. Written messages are kept with the event.
Guests can see and delete their own message. When a guest opens their invitation again, they see their RSVP answer and that they left a message — its type and the date — but never the message itself, because an invitation link can be forwarded to other people. To delete it, the guest confirms it is them with a six-digit code sent to a contact method the host has on record for them: email, which is free, or text message or WhatsApp, where each code is paid for from the host's messaging credit. Each contact method can send a guest at most five codes, and each code expires after ten minutes. The message — including any recording and its stored file — is then deleted, and the guest can leave a new one.
If the invitation was handed over in person, if the host has no contact method on record we can use, if the host's credit cannot cover a code, or if confirming does not work for them, the guest can instead ask the host to delete it. The host is the controller of their event's guest data (see section 4), so acting on that request is the host's responsibility; we show it to the host in their account and by email, and it stays open until the message is gone. If a host does not act on your request, contact us using the details below.
8. Your rights
You may request access to, correction of, or deletion of your personal data, and object to certain processing. To exercise these rights, contact us using the details below. To delete your account and the data attached to it — including any Facebook or Google connection — follow the steps on our Data Deletion page. If you are a guest who left a message for a host, you can delete it yourself from your invitation link, as described in section 7.
9. Security
We use encryption in transit, hashed passwords, and role-based access controls. No system is perfectly secure, but we take reasonable steps to protect your data.
10. Contact
For privacy questions or to exercise your rights, email info@dtkholdings.com. Postal: DTK Holdings (Pvt) Ltd, 166/B, Kommala, Bentota, 80500, Sri Lanka.