1 — Data controller
The data controller within the meaning of the GDPR is FoolMoon GmbH, a company under German law in the process of incorporation, with its registered office in Rheinau, Baden-Württemberg, Germany.
Data protection contact: contact@eventsmanager.app
2 — Data collected
As part of the FoolMoon service, the following categories of data are processed:
- Mobile phone number — identification of the organiser account, authentication via OTP code, sending SMS invitations to guests.
- First name and surname — personalisation of the SMS messages sent to guests.
- IP address — abuse prevention, platform security, server logs.
- Browsing data — server logs (method, URL, HTTP status, timestamp); retention period of 30 days.
- Calculated risk score — internal abuse-prevention indicator, not disclosed to third parties, not enforceable against the user.
- Vendors credited on an event — business name, trade, city, website and Instagram account, entered by the organiser to credit their event's vendors on their guests' page; e-mail address, only if the vendor leaves it themselves to be told about a new feature.
- Contact-form messages — name, e-mail address, company (optional) and message entered by the visitor, in order to answer their request.
- Organiser's contact book — for each contact, what the organiser enters or imports: number, first and last name, title, company, job title, e-mail addresses, postal addresses, social networks, birthday and photo; gender, only where provided or confirmed by the organiser (the service can suggest an estimate based on the first name, which is saved only if the organiser confirms it); internal tags and notes; where the record came from (import, form, QR code…) and the consent basis. The gender estimate based on the first name relies on open data: Insee (Fichier des prénoms, 2023 edition), City of Zurich, City of Bonn, Wikidata and the US Social Security Administration.
- Participation history — for each of an organiser's events: title, date, country and type, invitation status (invited, confirmed, arrived…), number of seats, reply and arrival dates, amount paid and number of SMS received, to produce attendance statistics.
3 — Purposes and legal bases
- Performance of the contract (Art. 6(1)(b) GDPR) — sending SMS invitations, managing guest lists, QR code check-in, post-event photo gallery.
- Legitimate interest (Art. 6(1)(f) GDPR) — detection and prevention of abuse, fraud and uses that do not comply with the terms of use. An organiser naming the vendors of their event; a vendor can remove their name at any time from the page whose link the organiser sends them.
- Legal obligation (Art. 6(1)(c) GDPR) — retention of server logs in accordance with applicable legal requirements.
- Consent (Art. 6(1)(a) GDPR) — e-mail address left by a vendor to be told when vendor profiles launch; can be withdrawn at any time.
- Organiser's contact book — the organiser is the controller of their book; FoolMoon GmbH acts only as processor. The basis is recorded record by record: the person's direct consent, consent attested by the organiser, or a box ticked on a public sign-up page. FoolMoon GmbH does not sell the book and does not pass it to any other organiser; it is shared only between accounts that the organiser has had attached to their team.
4 — Retention period
- Organiser account data — retained until the account is deleted, or for 2 years in the event of inactivity, then permanently deleted.
- Event photos — automatically deleted 30 days after upload.
- Event data (invitations, replies, entry scans) — automatically deleted after the event date, depending on the organiser's plan: 30 or 90 days for the entry-level plans, 1 year for a paid wedding (WeddingDay), and no limit for the higher plans for as long as the organiser does not delete them. Networking cards are deleted 30 days after the event, whatever the plan.
- Contact photos (organiser's address book) — erased after 12 months without an invitation or an edit to the contact; the contact itself is kept for as long as the organiser keeps it in their book.
- Server logs — retained on a rolling 30-day basis.
- OTP codes — deleted immediately after verification or expiry.
- Credited vendors — kept for as long as the organiser keeps them in their book; their mention on an event is deleted with that event's data. Removed immediately at the vendor's request, which also erases their e-mail address. Guest clicks on their links are counted as totals, with no record of who clicked.
- Contact-form messages — automatically deleted 12 months after they are received.
- Participation history (organiser's contact book) — kept for a rolling 36 months after the date of each event, then deleted automatically, even where the event itself has already been deleted. When the organiser deletes a record, its history, tags and notes are erased with it.
5 — Data recipients
FoolMoon GmbH does not resell any personal data. The following processors are involved in the provision of the service and are bound by a GDPR-compliant data processing agreement (DPA):
- Brevo (Sendinblue SAS), Paris, France — sending SMS to guests. DPA signed.
- Twilio Inc., San Francisco, USA — verification (lookup) of the mobile phone number during registration.
- Stripe, Inc., Dublin, Ireland — secure processing of card payments.
- OVH SAS, Roubaix, France — hosting of the application servers and databases.
- Sweego (MINDBAZ SAS), Lille, France — SMS delivery to guests for French phone numbers.
- BulkGate s.r.o., Šumperk, Czech Republic — SMS delivery to guests for non-French phone numbers.
- Resend, Inc., San Francisco, USA — sending of transactional emails (invoices, notification of contact-form messages).
Transfers outside the EU/EEA (Twilio, Stripe, Resend) are governed by the standard contractual clauses (SCCs) approved by the European Commission. If a guest chooses “Add to Google Wallet”, their ticket details (name, seats, event, QR code) are sent to Google at the guest's own initiative.
6 — Your rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure / “right to be forgotten” (Art. 17 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object to processing (Art. 21 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
To exercise these rights, contact us at: contact@eventsmanager.app. We will respond within one month in accordance with Art. 12 GDPR.
If the response is unsatisfactory, you may lodge a complaint with the competent supervisory authority in Germany: Landesbeauftragter für Datenschutz und Informationsfreiheit Baden-Württemberg (LfDI BW), Stuttgart.
7 — Cookies
FoolMoon does not use advertising, tracking or third-party analytics cookies. Only session cookies that are strictly necessary for the operation of the service are placed; these do not require prior consent within the meaning of the ePrivacy Directive.