This Privacy Policy explains how MayoFlux LLC, doing business as EventSimpler ("EventSimpler," "we," "us," or "our"), collects, uses, discloses, and retains personal information through https://eventsimpler.com, related applications, and any other service that links to this Policy (collectively, the "Services").
1. Scope and important distinction for user-created Sites
This Policy applies to information we handle when you create or manage an account, build or visit a Site, submit an RSVP or form, communicate through the Services, purchase a plan, contact support, or submit a safety, privacy, or legal request.
EventSimpler allows Organizers to create Sites and collect information from Site Visitors. The Organizer decides what to ask for and how to use responses. For organizer-controlled Site Data, EventSimpler generally processes information on the Organizer's behalf as a service provider or processor, while the Organizer is responsible for its own privacy notice, legal basis, consent, and use of exported information. We may separately use limited Site Data for security, abuse prevention, support, legal compliance, and service reliability as described below.
A Site may include a privacy notice supplied by its Organizer. That notice governs the Organizer's independent use of your information, including information the Organizer exports, copies, or uses outside EventSimpler. Contact the Organizer about the Organizer's use of your RSVP, guest, contact, or form information.
2. Information we collect
2.1 Account and profile information
We collect information such as name, email address, organization name, profile details, account role, account settings, authentication information, preferred language, and communications preferences. If passwordless login or a connected identity provider is used, we receive authentication tokens or confirmation data rather than your third-party password.
2.2 User Content and Site configuration
We process content and settings you create or upload, including text, logos, images, audio, video, files, links, templates, page structure, custom domains, subdomains, theme choices, visibility settings, schedules, maps, galleries, buttons, and other Site elements. Content may contain personal information about you or other people.
2.3 Site Visitor, RSVP, guest, contact, and form data
Depending on the Organizer's choices, the Services may collect names, email addresses, phone numbers, postal addresses, attendance responses, guest names, household or group information, notes, meal or accessibility responses, schedule selections, claimed items, comments, contact-list membership, custom-field responses, and other information submitted through a Site. The Organizer may import similar information into the Services.
Site Visitors should review the Site and Organizer notice before submitting information. Do not submit highly sensitive information unless the Site clearly explains why it is needed and you are comfortable sharing it with the Organizer.
2.4 Payment and transaction information
When you purchase a plan, Stripe processes payment-card or bank information. We generally receive limited transaction information such as billing name, billing address, payment method type, last four digits, processor token, subscription status, invoices, tax information, and payment history. We do not intend to store full card numbers or security codes.
2.5 Communications and support
We collect messages and attachments sent to support, legal, privacy, safety, sales, or other teams; responses to surveys; product feedback; call or meeting notes; and records of service, billing, and marketing communications. Calls may be recorded only after any required notice or consent.
2.6 Device, usage, and log information
We automatically collect information such as IP address, approximate location derived from IP, browser and device type, operating system, referring and exit pages, timestamps, viewed pages, clicks, feature use, upload and delivery events, error logs, authentication events, Site URLs, and security signals. We may associate this information with an account, Site, device, or session.
2.7 Cookies, local storage, analytics, and embedded services
We and our providers may use cookies, local storage, pixels, SDKs, and similar technologies for authentication, preferences, security, fraud prevention, performance, analytics, communications, and feature operation. Embedded maps, videos, social content, fonts, payment tools, or other third-party features may collect information under their own privacy policies.
EventSimpler currently uses essential account and session storage and operational logs. Service providers include Stripe for payments and Twilio for email and SMS delivery. Google Maps or Google-hosted fonts may be used when those features are displayed. EventSimpler does not use third-party advertising cookies as of the Effective Date. Provider use may change as the Services evolve, and material changes will be reflected in this Policy.
2.8 Integrations and connected services
If you connect a third-party service, we may receive information such as account identifiers, profile information, files, calendars, contacts, media, or permissions, depending on the integration and your choices. We send information back to the provider as needed to perform your instructions.
2.9 Reports, legal requests, and safety information
When someone reports a Site or submits a copyright, privacy, security, child-safety, nonconsensual-intimate-image, or other legal request, we collect the requester's contact information, signature or attestation where required, URLs, descriptions, supporting information, correspondence, status, and actions taken. We may collect information needed to verify identity or authority.
3. Sources of information
We collect information directly from you; from Organizers and Site Visitors; automatically from devices and use of the Services; from connected services and service providers; from payment processors; from people who report content or exercise rights; from publicly available sources when needed to investigate fraud, security, or rights; and from business partners when you authorize the exchange.
4. How we use information
We use personal information to:
- Create, authenticate, secure, and administer accounts.
- Provide, host, display, deliver, and maintain Sites and requested features.
- Process RSVPs, forms, contacts, guest lists, claims, schedules, communications, and Organizer instructions.
- Process payments, subscriptions, invoices, taxes, refunds, and account changes.
- Provide support, troubleshoot problems, communicate service updates, and respond to requests.
- Analyze product performance, understand feature use, improve usability, and develop new features.
- Detect, investigate, prevent, and respond to fraud, spam, malware, abuse, security incidents, prohibited content, and policy violations.
- Moderate content, process reports, enforce agreements, protect rights and safety, and comply with legal obligations.
- Send marketing communications when permitted, measure their effectiveness, and honor opt-outs.
- Create aggregated or deidentified information that is not reasonably linkable to an individual and use it for lawful business purposes.
5. Legal bases for EEA, UK, and similar jurisdictions
Where a law requires a legal basis, we process information as necessary to perform a contract with you; to take steps you request before entering a contract; to comply with legal obligations; based on consent; and for legitimate interests such as providing and improving the Services, securing accounts, preventing abuse, supporting users, and protecting legal rights, balanced against your rights. You may withdraw consent when processing is based on consent, but withdrawal does not affect earlier lawful processing.
6. How we disclose information
6.1 Organizers, account administrators, and Site Visitors
Information submitted through a Site is disclosed to the Organizer and authorized account users. Depending on Site settings, guest names, attendance, comments, claims, media, or other Site Data may also be visible to other Site Visitors. Public or unlisted Site content is available to people who access the URL. Unlisted does not mean confidential.
6.2 Service providers
We disclose information to vendors that help us provide hosting, databases, storage, content delivery, authentication, email or SMS delivery, payments, analytics, customer support, AI features, error monitoring, security, moderation, and legal or professional services. We require providers to handle information for authorized purposes and under appropriate contractual restrictions, where required.
6.3 Connected services and Organizer-selected integrations
We disclose information to third parties when you or an Organizer enables an integration, embed, export, webhook, custom domain, payment feature, or other connected service. The third party's terms and privacy policy govern its independent handling of information.
6.4 Legal, safety, and rights protection
We may disclose information when we reasonably believe it is necessary to comply with law, legal process, regulatory requests, court orders, or reporting duties; investigate or prevent fraud, security incidents, child exploitation, threats, or other harm; enforce agreements; respond to valid copyright or rights notices; protect users or the public; or establish, exercise, or defend legal claims.
6.5 Business transfers
We may disclose information in connection with a merger, financing, acquisition, reorganization, bankruptcy, sale of assets, or transition of the Services. The recipient may use the information subject to this Policy unless you receive notice of a materially different practice and any choice required by law.
6.6 With consent or direction
We may disclose information for another purpose when you direct us or give consent.
7. Sale, targeted advertising, and profiling
As of the Effective Date, we do not sell personal information for money and do not share personal information for cross-context behavioral advertising. We do not use personal information for profiling that produces legal or similarly significant effects. If these practices change, we will update this Policy and provide legally required opt-out choices before beginning the new practice.
8. Cookies and tracking choices
You can control many cookies and similar technologies through your browser settings. EventSimpler does not currently provide a separate cookie-preference tool because it does not use third-party advertising cookies. Blocking essential storage may prevent login, publishing, or other features from working.
Some browsers transmit "Do Not Track" signals, but there is no universally accepted standard for responding to them. We therefore do not respond to DNT signals as a contractual instruction. Where required by law, we recognize supported Global Privacy Control signals as a request to opt out of sale or sharing. If we do not sell or share personal information, the signal will not change those practices.
Third-party analytics or embedded-content providers may collect device and usage information over time and across websites or services. Their handling is governed by their own policies and available controls.
9. Communications choices
You may unsubscribe from marketing email using the link in the message or account settings. EventSimpler may send event invitations, RSVP confirmations, reminders, schedule or location updates, and related customer-care text messages when a recipient has opted in or an Organizer has represented that it has lawful permission. Consent is not a condition of purchase. Message frequency varies, typically 1-5 messages per event. Message and data rates may apply. Reply STOP to opt out or HELP for help. Carriers are not liable for delayed or undelivered messages. We may still send service, security, billing, transaction, and legal notices that are necessary to operate your account or fulfill a request.
Mobile information, including mobile phone numbers, SMS opt-in data, and consent records, is not sold or shared with third parties or affiliates for their marketing or promotional purposes. It may be disclosed only to service providers and carriers as necessary to deliver messages, maintain consent and suppression records, prevent abuse, and comply with law.
Organizers are independently responsible for marketing messages they send or export from the Services. Contact the Organizer and use available unsubscribe controls if a message was sent by an Organizer.
10. Retention
We retain personal information only as long as reasonably necessary for the purposes described in this Policy, including providing the Services, maintaining account and transaction records, honoring deletion settings, resolving disputes, enforcing agreements, preventing fraud and abuse, maintaining security, meeting legal obligations, and completing backup cycles.
Account and User Content are generally retained while the account or Site remains active and until deleted by the authorized user, subject to limited backups, legal holds, security records, and information needed to document reports or enforcement. Deleted production data may remain in isolated backup snapshots until those snapshots expire under our disaster-recovery schedule. Backup copies are used only for restoration, security, fraud prevention, or legal needs and are not returned to routine use unless restored. Billing and tax records may be retained for legally required periods. Deidentified information may be retained where it cannot reasonably be used to identify you.
An Organizer may retain exported Site Data outside EventSimpler after it is deleted from the Services. Contact the Organizer regarding those copies.
11. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information, such as access controls, encryption in transit, logging, backups, provider review, and security monitoring, as appropriate to the Services. No system is perfectly secure. You are responsible for protecting account access, recovery email, magic links, connected services, and shared Site passwords.
Report suspected security issues to hello@eventsimpler.com. Do not use a privacy request form to send passwords, full payment-card numbers, illegal images, or unnecessary sensitive information.
12. Your controls and requests
Account Holders may review or update certain information in available account settings, export available data, change visibility settings, cancel a plan, or request account deletion by emailing hello@eventsimpler.com. Site Visitors may contact the Organizer to access, correct, or delete organizer-controlled RSVP, contact, or form information. You may also contact EventSimpler, and we may forward or coordinate the request with the Organizer when appropriate.
To protect users, we may verify identity, account control, authority, and the scope of a request. We will use verification information only for verification, security, fraud prevention, and legal compliance.
13. U.S. state privacy rights
Depending on where you live and whether a law applies to EventSimpler, you may have rights to request access to personal information, obtain a portable copy, correct inaccuracies, delete information, learn about categories and purposes, opt out of sale, targeted advertising, or certain profiling, limit certain uses of sensitive information, and appeal a denied request. You may also have the right not to receive discriminatory treatment for exercising a privacy right.
Submit a request through https://eventsimpler.com/contact/ or by emailing hello@eventsimpler.com. If required, an authorized agent may submit a request, but we may require proof of authority and direct verification with the individual. To appeal, reply to the decision email. We will respond within the time required by applicable law.
If the statement in Section 7 is accurate, we do not currently sell or share personal information for targeted advertising, so there is no separate sale or sharing opt-out required for our current practices. If that changes, we will provide a "Your Privacy Choices" or similar mechanism as required.
14. California notice at collection
For California residents, the categories of personal information we may collect include identifiers; customer-record information; commercial and subscription information; internet or electronic-network activity; approximate geolocation; audio, electronic, visual, and similar information; professional or organizational information; inferences about product preferences; and sensitive personal information only when voluntarily submitted or necessary for authentication, payments, safety, or a supported feature. We collect these categories for the purposes described in Sections 4 and 10 and retain them under the criteria in Section 10.
We disclose these categories to the recipients described in Section 6. We do not sell these categories or share them for cross-context behavioral advertising. We do not knowingly sell or share personal information of consumers under 16.
15. EEA, UK, and Swiss rights
Where applicable, you may have rights to access, correct, erase, restrict, or port personal data; object to processing based on legitimate interests or direct marketing; withdraw consent; and complain to a data-protection authority. Some rights are subject to exceptions. Contact hello@eventsimpler.com to exercise them.
If EventSimpler transfers personal data from the EEA, UK, or Switzerland to a country that has not been recognized as providing adequate protection, we will use an approved transfer mechanism where required, such as standard contractual clauses, together with appropriate safeguards.
16. Children
Account creation is limited to adults. The Services are not directed to children under 13, and we do not knowingly collect personal information directly from a child under 13 without legally required parental consent. A parent, guardian, or authorized adult may submit limited information about a child, such as a guest name, for a legitimate event or group purpose.
Organizers may not configure Sites to solicit personal information directly from children under 13 without our written approval and a compliant parental-consent process. If you believe a child submitted information improperly, contact hello@eventsimpler.com with the Site URL and relevant details.
17. International transfers and U.S. operation
EventSimpler is operated from the United States. Information may be processed in the United States and other countries where we or our service providers operate. Privacy laws in those countries may differ from those where you live. We use contractual and other safeguards when required.
18. Third-party sites and services
A Site may link to, embed, or integrate third-party services. We do not control their privacy practices. Review the third party's policy before providing information. The Organizer may also use your information outside EventSimpler, which is governed by the Organizer's notice and applicable law rather than this Policy.
19. Changes to this Policy
We may update this Policy to reflect changes in the Services, vendors, law, or data practices. We will post the revised version with an updated date. If a change is material, we will provide additional notice or obtain consent when required. Prior versions will be retained at https://eventsimpler.com/legal/archive/.
20. Contact us
MayoFlux LLC d/b/a EventSimpler
822 Bebout Road, Venetia, PA 15367, United States
Privacy requests: https://eventsimpler.com/contact/
Email: hello@eventsimpler.com
Telephone: (412) 444-7721
Data Protection Officer: No Data Protection Officer has been appointed. Privacy questions may be sent to hello@eventsimpler.com.