Privacy Policy
How we collect, use, and protect your personal data
Last updated: July 2026
Who we are
Evorrah is a bespoke event design house, operated by Innovatech Brazil LLC, a Florida limited liability company, doing business as Evorrah. Our website is lamaisondefetes.com. For all privacy-related enquiries contact hello@lamaisondefetes.com.
What data we collect and why
We collect only the data necessary to deliver your design suite and communicate with you about your project:
- Name & partner name — used to personalise your designs and address emails.
- Email address — used to create and access your private portal, and send order and delivery notifications.
- Phone number — collected optionally; used only if we need to contact you urgently about your project.
- Event details — event type, date, venue, and name used exclusively to produce your bespoke design suite.
- Design briefing data — colour palette preferences, style descriptions, moodboards, inspiration images, and notes submitted through your portal. This forms the creative brief for your project.
- RSVP guest list data — when you use the guest-list and RSVP features, we collect on your behalf the details you or your guests provide, which can include: guests' names and plus-one names, household members (including children's names, where you add them), email addresses and phone numbers, postal addresses (for mailed pieces), attendance status, accessibility needs, transport needs, and personal messages left in the guestbook. You are the data controller for your guests' data and confirm you are authorised to share it; we process it solely to produce your guest list, personalised pieces, seating plan, and RSVP tracking — never for marketing to your guests.
- Payment data — all payments are processed by Stripe. We never see or store your full card number or banking credentials. We store only the Stripe customer ID and payment status.
- IP addresses — logged for security purposes (rate limiting, fraud prevention). Not used for profiling or marketing.
- Portal session token — a cryptographic token stored in your browser's local storage to keep you logged in. Rotated on password reset.
How we use your data
- Deliver and personalise your design suite
- Send transactional emails (order confirmation, portal access, design delivery)
- Process and record payment via Stripe
- Maintain your private portal and project history
- Protect the platform from abuse and unauthorised access
- Comply with legal obligations
We never sell your personal data, and we do not share it for any purpose other than those listed above and the advertising measurement described next.
We do use advertising and analytics services to understand how people find us and whether our ads work: Google Analytics 4, Google Ads and the Meta (Facebook/Instagram) pixel. These set identifiers in your browser and, when you make a purchase, we may send Google and Meta a one-way cryptographic hash of your email address and phone number so they can confirm the sale came from an ad. A hash cannot be reversed back into your details, and we never send these companies your name, address, event details or design work. All of this is off by default and only runs if you accept cookies on the banner — decline, and no advertising or analytics identifier is set at all.
Text messages (SMS)
If you are a client, we may text you about your own commission — a design ready to review, a question that is holding up production, or a reminder about a deadline you set. If you are a guest at an event we are running the guest list for, the host may send you messages about that event: an invitation link, an RSVP reminder, a change of time or place, or travel and arrival details.
- How you come to receive them. Clients give a mobile number when they book or in their portal. Guests are added by their host, who is responsible for having a reason to contact them. We do not buy phone numbers and we never send marketing texts to a number we were given for an event.
- How often. There is no recurring campaign. Message frequency varies with your event — typically a handful of messages across the weeks around it, and none once it has passed.
- How to opt out. Reply STOP to any message to opt out. That number is opted out immediately; we will send one confirmation and nothing after it. Reply START to opt back in. Every message we send carries this instruction. You can also email us and we will remove the number by hand.
- Help. Reply HELP, or write to hello@lamaisondefetes.com.
- Cost. We do not charge for messages. Message and data rates may apply from your own mobile carrier, and delivery depends on your carrier — we cannot guarantee it.
- What we keep. The number, the message we sent, when it was sent, whether the carrier accepted it, and whether you opted out. We keep opt-outs indefinitely, because forgetting one would mean texting someone who asked us not to.
- Who sees it. Your number and the message pass through Twilio, our messaging carrier (listed below). Nobody else. We never sell or share phone numbers, and we never pass them to advertisers.
Third-party processors
- Twilio (twilio.com) — SMS delivery. Receives the recipient's phone number and the message text in order to deliver it, and returns whether the carrier accepted it. Twilio's privacy policy applies.
- Stripe (stripe.com) — payment processing under PCI-DSS compliance.
- Supabase (supabase.com) — secure database and file storage hosted on AWS in the US.
- Resend (resend.com) — transactional email delivery.
- Anthropic / Claude (anthropic.com) — AI assistance inside the house's workflow. Your briefing content is sent to this service: to check your brief for gaps before you submit it, to help our designers develop your creative direction, and to draft copy for the house and its marketing. Under Anthropic's commercial terms, data sent through their API is not used to train their models. We never send your payment details, and every design that reaches you is reviewed by a person.
- Image generation services — Recraft (recraft.ai), fal.ai and Google Gemini — used by our designers to originate artwork elements such as motifs, textures and backgrounds. They receive the design prompt and any wording that is to appear on the artwork itself (for example your names and event details). They never receive your contact details, payment information or guest list.
- Google reCAPTCHA v3 — bot detection on public forms. Google's privacy policy applies.
- Google Fonts — typography. Google may log your IP when serving font files.
- Google Analytics 4 & Google Ads — audience measurement and advertising performance. Only active if you accept cookies. Google's privacy policy applies.
- Meta (Facebook/Instagram) — advertising performance measurement. Only active if you accept cookies. Receives a hashed (non-reversible) email address and phone number on a completed purchase, never your name or event details.
- Vercel (vercel.com) — website and API hosting. Processes request metadata as part of normal hosting.
Data retention
- Client records & briefing data — 3 years from your last active project, then deleted or anonymised.
- Delivered design files — 1 year after your event date, then deleted. We email you 30 days beforehand, and you can ask us to extend the window.
- RSVP guest data — 12 months after your event date, then deleted.
- Payment records — 7 years to comply with financial record-keeping obligations.
- IP address logs — 90 days for security purposes, then purged.
Your rights
Depending on your location (EU/EEA, UK, Brazil, California, Canada, etc.) you may have rights to access, correct, delete, export, or restrict processing of your personal data. To exercise any right write to hello@lamaisondefetes.com with the subject line "Privacy Request". We will respond within 30 days.
Cookies & local storage
We use advertising and analytics cookies and identifiers — Google Analytics 4, Google Ads and the Meta pixel — but only if you accept them on the cookie banner. Until you accept, they are set to “denied” and no such identifier is stored; if you decline, they stay off. You can change your mind at any time by clearing this site’s data in your browser and choosing again.
Separately from that choice, we use local storage and session storage to keep you signed in to your portal and to remember which version of a page you were shown. These are required for the site to work and are not used for advertising. Session cookies may also be set by Google Fonts and Vercel as part of normal web operation.
Security
We protect your data with HTTPS everywhere, encrypted passwords (scrypt), Stripe-side payment handling, Row Level Security on our database, rate limiting on all API endpoints, and access tokens rotated on password reset. To report a vulnerability: hello@lamaisondefetes.com.
Children
Our service is for adults: we do not offer accounts to under-16s, and we never market to or
collect information directly from a child. We do, however, hold children's names
when a host includes them on a guest list — a family invited as a household, or a child's
birthday party. That information is provided by the adult organising the event, never by the
child, and is used only to produce and send their stationery.
It is covered by exactly the same protections as every other guest detail: it is never sold
or shared, it is excluded from guest-list exports, and it is deleted on the schedule set out
in Retention — 12 months after the event date. If you would like a
child's details removed sooner, or believe information about a child has been added without
the organiser's knowledge, write to
hello@lamaisondefetes.com and we will remove it.
Changes
The "Last updated" date above reflects the current version. Continued use of the portal after an update constitutes acceptance of the revised policy.
Contact
hello@lamaisondefetes.com
Terms & Conditions →