MomentraBack to home

Privacy policy

Events are personal. Your data should be, too.

This policy explains how Momentra handles information across Momentra organiser workspaces, invitations, guest hubs, event communications, and galleries.

Effective 11 September 2026

1. Who this policy covers

This policy applies when you use Momentra as an organiser, team member, invited guest, attendee, or website visitor. Event organisers decide what guest information to collect and why. For that event information, the organiser is generally responsible for the event and Momentra processes it to provide the service. We are responsible for information used to operate, secure, improve, and bill for Momentra.

2. Information we collect

  • Account and organiser information, such as name, email address, authentication details, organisation, and workspace activity.
  • Event information, such as event names, schedules, venues, themes, guest-facing content, and enabled modules.
  • Invitation and RSVP information, such as guest names, phone numbers, email addresses, party details, attendance choices, dietary preferences, notes, and invitation status.
  • Security and access records, such as invitation opens, verification attempts, device or session information, recovery activity, IP-derived security signals, and audit history.
  • Guest content, such as photos, captions, and other media uploaded to an event gallery.
  • Communication information, such as event announcements, delivery status, notification subscriptions, and device push tokens.
  • Billing information, such as selected plan, add-ons, usage, DPO transaction references, payment status, and invoice records. Momentra does not store complete payment-card numbers.
  • Optional website analytics, such as public pages viewed and marketing actions selected, but only after consent. We do not place invitation IDs, guest names, phone numbers, or event slugs in analytics events.

3. How we use information

We use information to create and operate events; personalise invitation and guest experiences; process RSVP responses; verify invited guests; enable event-day uploads; send organiser and system communications; process payments; provide support; detect abuse; keep audit records; enforce plan limits; and maintain, troubleshoot, and improve the service.

4. When information is shared

We share information only where needed to provide Momentra, comply with law, protect users, or complete a transaction. Service providers may include Google Firebase and Google Cloud for hosting, authentication, databases, files, notifications, logs, and analytics; DPO for payment processing; and telecommunications providers involved in phone verification and message delivery. Organisers and their authorised team members can access information for their events. Guests may see content intentionally published to the same event experience.

We do not sell personal information. We do not use invitation or guest information for third-party advertising.

5. Phone verification and communications

When phone verification is enabled, Firebase Authentication and its delivery partners process the phone number to send a one-time code and prevent abuse. Event updates may be sent through in-app notifications, push notifications, email, or SMS where enabled by the organiser and permitted by law. Transactional messages may still be sent when needed to operate an invitation, account, payment, or security flow.

6. Photos and event media

Uploaded media is associated with the relevant event and may be available to that organiser and the audience the organiser selects. Upload only content you have the right and permission to share. Organisers can moderate or remove event media, and we may remove content that breaches our terms or the law.

7. Retention and deletion

We retain information for as long as needed to provide an active event, meet contractual and legal obligations, resolve disputes, prevent fraud, and maintain necessary audit records. Organisers can request event deletion. Deletion removes or schedules removal of associated guest records and stored media, subject to short-lived backups, security records, payment records, and information we must retain by law. Guests can ask the event organiser to correct or remove event-specific information.

8. Security and international processing

We use access controls, server-side authorisation, encrypted connections, scoped storage rules, abuse protection, audit records, and operational monitoring. No system can guarantee absolute security. Firebase, Google Cloud, payment, and communications providers may process information in countries other than your own under their applicable safeguards.

9. Your choices and rights

Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information. You may decline optional analytics, disable browser or device notifications, and withdraw communications consent where applicable. Declining optional analytics does not affect the event experience.

10. Children

Momentra is not directed to children who are not legally able to consent to online services. Organisers must obtain any permission required before adding information about a child or inviting a child to upload content.

11. Changes and contact

We may update this policy as Momentra changes. Material updates will be identified by a revised effective date or an in-product notice. Questions, requests, or complaints can be sent to your Momentra support channel. You may also have the right to contact the data-protection authority in your jurisdiction.

© 2026 Momentra. All rights reserved.

PrivacyTerms