Privacy Policy
How we collect, use, and protect your personal data
Last updated: June 2026
Who we are
La Maison de Fêtes is a bespoke event design studio. Our website is lamaisondefetes.com. For all privacy-related enquiries contact hello@lamaisondefetes.com.
What data we collect and why
We collect only the data necessary to deliver your design suite and communicate with you about your project:
- Name & partner name — used to personalise your designs and address emails.
- Email address — used to create and access your private portal, and send order and delivery notifications.
- Phone number — collected optionally; used only if we need to contact you urgently about your project.
- Event details — event type, date, venue, and name used exclusively to produce your bespoke design suite.
- Design briefing data — colour palette preferences, style descriptions, mood boards, inspiration images, and notes submitted through your portal. This forms the creative brief for your project.
- RSVP guest list data — when you use the RSVP feature, we collect your guests' names, attendance status, email addresses (if provided), meal preferences, and dietary requirements on your behalf. You are the data controller for your guests' data; we process it solely to generate your guest list and seating plan.
- Payment data — all payments are processed by Stripe. We never see or store your full card number or banking credentials. We store only the Stripe customer ID and payment status.
- IP addresses — logged for security purposes (rate limiting, fraud prevention). Not used for profiling or marketing.
- Portal session token — a cryptographic token stored in your browser's local storage to keep you logged in. Rotated on password reset.
How we use your data
- Deliver and personalise your design suite
- Send transactional emails (order confirmation, portal access, design delivery)
- Process and record payment via Stripe
- Maintain your private portal and project history
- Protect the platform from abuse and unauthorised access
- Comply with legal obligations
We do not use your data for advertising, sell it to third parties, or share it for any purpose other than those listed above.
Third-party processors
- Stripe (stripe.com) — payment processing under PCI-DSS compliance.
- Supabase (supabase.com) — secure database and file storage hosted on AWS in the US.
- Resend (resend.com) — transactional email delivery.
- Google reCAPTCHA v3 — bot detection on public forms. Google's privacy policy applies.
- Google Fonts — typography. Google may log your IP when serving font files.
- Vercel (vercel.com) — website and API hosting. Processes request metadata as part of normal hosting.
Data retention
- Client records & briefing data — 3 years from your last active project, then deleted or anonymised.
- RSVP guest data — 12 months after your event date, then deleted.
- Payment records — 7 years to comply with financial record-keeping obligations.
- IP address logs — 90 days for security purposes, then purged.
Your rights
Depending on your location (EU/EEA, UK, Brazil, California, Canada, etc.) you may have rights to access, correct, delete, export, or restrict processing of your personal data. To exercise any right write to hello@lamaisondefetes.com with the subject line "Privacy Request". We will respond within 30 days.
Cookies & local storage
We do not use tracking or advertising cookies. We use local storage to keep you logged in to your portal. Session cookies may be set by Google Fonts and Vercel as part of normal web operation.
Security
We protect your data with HTTPS everywhere, encrypted passwords (scrypt), Stripe-side payment handling, Row Level Security on our database, rate limiting on all API endpoints, and access tokens rotated on password reset. To report a vulnerability: hello@lamaisondefetes.com.
Children
Our service is not directed at children under 16. If you believe a minor's data has been submitted, contact us and we will delete it promptly.
Changes
The "Last updated" date above reflects the current version. Continued use of the portal after an update constitutes acceptance of the revised policy.
Contact
hello@lamaisondefetes.com
Terms & Conditions →