Legal
What we collect, why, and what you can do about it — whether you're a host running an event or a guest invited to one.
On this page
This policy explains how Partyyy.Party — live at partyyy.party — handles personal data. It sits alongside our Terms & Conditions, our AI Policy, and our GDPR policy, which covers the controller/processor relationship and your formal data-protection rights in more detail.
Partyyy.Party is operated by AJH t/as Partyyy.Party, a UK sole trader. For anything in this policy, contact us at [email protected]. A postal address is available on request. We haven't appointed a statutory Data Protection Officer, as we're not currently required to — see our GDPR policy for more on that, including our current ICO registration position.
Partyyy.Party works differently depending on who you are:
About hosts: your name, email address, password (stored as a one-way hash, never in plain text), your Account's display name and web address, billing details if you're on a paid plan in future, login activity, and support correspondence.
About guests — collected by a host, or provided directly by a guest through an invitation, RSVP form, or their own guest page:
Technical data, from everyone: IP address, browser/device information, and security logs — kept to keep the Service running and to block malicious traffic (see section 14).
| Purpose | Lawful basis |
|---|---|
| Running a host's Account and event tools | Contract (with the host) |
| Sending guests invitations, reminders, and updates a host sets up | Legitimate interest of the host in running their event, which we process on their behalf |
| Letting a guest RSVP, vote, or use their guest page | Contract (performing the request the guest themselves made) / legitimate interest |
| AI photo renders | Consent — a photo is only processed if it's uploaded |
| Matchmaking | Explicit consent — opt-in only, see section 6 |
| Fraud, abuse and bot/scanner defence | Legitimate interest, in keeping the Service available and safe |
| Improving the Service | Legitimate interest |
| Meeting legal obligations (e.g. responding to a lawful request) | Legal obligation |
We don't sell personal data, and we don't use it for third-party advertising.
Our optional matchmaking feature lets a guest share a bio, personality-style answers, and whether they're open to romantic connections with other guests. Because "seeking romantic connections" can touch on the kind of information UK GDPR treats more carefully (special category data, such as details relating to sex life or sexual orientation), we only ever collect it with the guest's explicit, opt-in consent, a guest controls their own visibility, and a host can switch the whole feature off for their event. A guest can withdraw at any time by turning their profile off or contacting us.
We keep this deliberately simple. The Service sets one cookie — a first-party, strictly necessary session cookie that keeps you logged in (secure, HTTP-only, and not readable by other websites). We don't run any advertising or analytics trackers, and we don't use third-party tracking cookies.
A couple of related things worth knowing:
We use a small number of specialist providers to run the Service, each acting under our instructions and only for the purpose stated. Full detail, including where each is based, is in our GDPR policy. In short: Resend (sending email), a self-operated WhatsApp messaging integration (sending WhatsApp messages), Google Gemini and xAI (AI photo renders — see our AI Policy), Fly.io, Neon, and Cloudflare (hosting, database, file storage, and security).
Separately, if a host chooses to search for a guest's Instagram, Facebook, or LinkedIn photo, or runs a Gravatar sync, that's a lookup the host actively triggers from their own dashboard — we don't do this automatically, and it's the host's decision as controller, not a background process of ours.
We only ever disclose personal data to a third party outside this list where the law requires it, or with your consent.
Our hosting is based in London. Some of our providers (including Google and xAI) may process data outside the UK, including in the United States. Where that happens, we rely on the safeguard the provider itself offers — such as the UK International Data Transfer Addendum or the provider's participation in the EU–US Data Privacy Framework. More detail is in our GDPR policy.
We keep host Account data for as long as the Account is active, and for a limited period afterwards in case of legal, accounting, or fraud-prevention needs. We keep a guest's data for as long as the host's Account and event remain active, unless the host or guest deletes it sooner. If a host closes their Account, we delete associated guest data within a reasonable period, except where we're required to retain something for legal reasons.
Under UK GDPR you have the right to: access the personal data we (or, for guest data, your host) hold about you; have inaccurate data corrected; ask for data to be deleted; restrict or object to certain processing; receive your data in a portable format; and withdraw consent at any time where we rely on it (e.g. matchmaking or an AI render).
To exercise any of these, email [email protected]. If you're a guest, we may point you to your host first, since they're usually best placed to act quickly — but we'll help directly if that doesn't resolve it. See our GDPR policy for the full process and response times.
Partyyy.Party is built for adults organising and attending events, and we don't knowingly collect data directly from children under 13. If a host adds a younger guest to their list, that's the host's decision and responsibility as controller, and they should have an appropriate basis (such as a parent's consent) for doing so. If you believe a child's data has been added without appropriate consent, contact us and we'll look into it.
We don't use personal data to make any decision about a person that has a legal or similarly significant effect, without a human involved. AI photo renders are generated content for entertainment, not a decision about anyone, and karma/badges are simple rule-based totals, not profiling used to make decisions about a guest.
We encrypt traffic to the Service in transit, store passwords as salted one-way hashes, restrict access by role, and run automated defences against known attack and scanning patterns. No system is perfectly secure, but we take reasonable, proportionate steps for a service of our size, and we review them as the Service grows.
We may update this policy as the Service — and our name — changes. We'll update the date at the top of this page, and for significant changes we'll make a reasonable effort to let hosts know directly.
We'd rather put things right ourselves first — email [email protected] and we'll respond promptly. You also have the right to lodge a complaint with the UK's data protection regulator, the Information Commissioner's Office (ICO), at ico.org.uk or on 0303 123 1113, at any time.
Questions about this policy, or a request relating to your data: [email protected].
More of the small print