Aurora — Privacy Policy

Last updated: September 22, 2026

This Privacy Policy explains how Aurora ("we," "us," "our") collects, uses, and protects personal information through the Aurora platform at auroraguest.com (the "Service").

We act as data controller for information about Organizers (account holders). For information about wedding guests, entered or collected by an Organizer through the Service, we generally act as a data processor on the Organizer's behalf — the Organizer is responsible for deciding what guest information is collected and why.

Controller contact details: LUMIN E.E. (LUMIN L.P.), a Greek limited partnership registered with the General Commercial Registry (Γ.Ε.ΜΗ.) under number 184372803000, Tax ID (ΑΦΜ) 802873400, registered address Mousaiou 13, Palaio Faliro, 17563, Greece — contactable at privacy@contact.auroraguest.com.

1. Information We Collect

From Organizers (account holders):

  • Name, email address, and password (stored securely; we never see your password in plain text).
  • Language and display preferences.
  • Any wedding/event details you create (event names, dates, locations, descriptions).
  • Custom wording, theme choices, and any images you upload.

From or about Guests (entered by an Organizer, or submitted directly by the guest through an invitation or Save-the-Date link):

  • Name, email address, and phone number.
  • RSVP responses (attending status for the main event and any additional events).
  • Plus-one names, where applicable.
  • Free-text notes a guest chooses to add.
  • Transportation and accommodation preferences or details, where the Organizer has enabled those features.
  • Preferred language.
  • A guest's chosen language and RSVP responses are linked to a unique, non-guessable access token rather than a public account.

Technical and security information:

  • Standard web request information (such as browser type and IP-adjacent connection data) processed by our bot-protection provider (Cloudflare Turnstile) to distinguish real visitors from automated abuse. We do not otherwise track visitors across other websites, and we do not use advertising or behavioral-tracking cookies.
  • Message delivery logs (e.g. whether a reminder email was sent successfully), used for troubleshooting and to avoid duplicate sends.

2. How We Use Information

We use the information described above to:

  • Provide and operate the Service (creating events, managing guest lists, collecting RSVPs and logistics).
  • Send transactional communications on an Organizer's behalf (invitations, reminders, confirmations).
  • Send account-related communications to Organizers (e.g. password reset emails).
  • Protect the Service against spam, abuse, and automated attacks.
  • Maintain short-term configuration backups so an Organizer can recover from accidental changes.
  • Improve and maintain the Service.

We do not sell personal information, and we do not use guest information for advertising.

3. Legal Basis for Processing (where GDPR applies)

  • Organizer account data: processed under contract (to provide the Service you've signed up for) and legitimate interest (service security and improvement).
  • Guest data: processed on the basis of the Organizer's own lawful basis for collecting it (typically the guest's consent, given by engaging with an invitation link, or the Organizer's legitimate interest in organizing their event) and our contract with the Organizer to provide the processing service.

4. Who We Share Information With

As of the date of this Policy, we share information with the following categories of service providers, each of which processes data on our behalf under their own security and confidentiality obligations. This list reflects our current providers and is expected to grow as the Service develops — for example, a payment processor once commercial billing launches. We will update this Policy when that happens, and notify Organizers of material changes as described in Section 11.

  • Hosting and database infrastructure (Supabase / Lovable Cloud) — stores all account, event, and guest data.
  • Email delivery (Resend) — sends transactional emails (invitations, reminders, password resets) on our behalf.
  • Bot and abuse protection (Cloudflare Turnstile) — verifies that form submissions come from real visitors.
  • Optional integrations: if an Organizer chooses to enable Google Sheets sync, their guest data will also be sent to Google Sheets under that Organizer's own Google account and Google's terms. This only happens if the Organizer actively turns this on.

We do not share guest or Organizer data with any other third party except: to comply with a legal obligation, to protect the rights and safety of Aurora, our users, or others, or in connection with a merger, acquisition, or sale of assets (in which case affected users would be notified).

5. International Data Transfers

Our service providers may process data in countries outside your own, including the United States. Where this involves transferring personal data out of the European Economic Area, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission, as required by applicable law.

6. Data Retention

  • Guest data is retained for as long as the associated event exists, or until the Organizer deletes it.
  • Deleted events are held in a recovery state for approximately 5 days before permanent deletion.
  • Configuration backups (event settings, not guest data) are retained on a rolling 5-day basis.
  • Communication logs are retained for up to 12 months to support delivery troubleshooting and prevent duplicate sends.
  • An Organizer may delete their account and associated data at any time by contacting us.

7. Your Rights

Depending on your location, you may have the right to:

  • Access the personal information we (or an Organizer, through us) hold about you.
  • Correct inaccurate information.
  • Request deletion of your information.
  • Request a copy of your information in a portable format (Organizers can already export their event data directly from the Service).
  • Object to or restrict certain processing.
  • Withdraw consent, where processing is based on consent.

If you are a guest and want to exercise these rights, we recommend contacting the Organizer of the event directly, since they control what information is collected. You may also contact us at privacy@contact.auroraguest.com and we will assist or forward your request to the relevant Organizer.

If you are an Organizer, you can exercise most of these rights directly within the Service (editing or deleting guest records, exporting your data) or by contacting us.

8. Children's Information

Wedding guest lists commonly include children as part of a family or household. Where an Organizer or another adult guest includes a child's name (and, where relevant, related information such as dietary or accessibility notes) as part of their own guest-list entry, we treat this as ordinary guest data provided on the child's behalf by the adult responsible for them — the child does not interact with the Service directly.

The Service itself is not directed at children, and no one under the age of 18 may create an Organizer account. We only collect the minimum information about a child necessary to support the family's RSVP and logistics for the event (for example, a name for the headcount, or a dietary note), and this information is used solely for that purpose. If you are a parent or guardian and believe a child's information has been included inappropriately or you would like it removed, contact us at privacy@contact.auroraguest.com or contact the event's Organizer directly, and we will assist.

9. Cookies and Similar Technologies

Aurora uses only the cookies or local storage strictly necessary to keep you signed in and to remember your language preference. We do not use advertising cookies or third-party analytics trackers.

10. Security

We use industry-standard measures to protect personal information, including encrypted connections (HTTPS), database-level access controls that restrict data to the relevant Organizer, and rate-limiting to prevent abuse. No system can be guaranteed 100% secure, and we encourage Organizers to use a strong, unique password.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will update the "Last updated" date above and, for material changes, make reasonable efforts to notify Organizers.

12. Contact Us

For any question about this Privacy Policy or to exercise your data rights, contact us at privacy@contact.auroraguest.com.