ECTreasure Events.
Effective date: September 2026
This Privacy Policy explains how Eagle Crest Treasure LLC (“we,” “us,” or “our”), the operator of ECTreasure Events (the “Service”), collects, uses, shares, and protects personal information. It applies to account holders who plan events (“Owners”) and to people who are invited to or visit an event page (“Guests”). It should be read together with our Terms of Use, Data Processing Addendum, and Cookie Policy.
For information about an Owner’s own account (registration and billing details), Eagle Crest Treasure LLC is the data controller. For the personal data an Owner collects or uploads about their Guests — names, email addresses, phone numbers, RSVP responses, meal choices, messages, and photographs (“Guest Data”) — the Owner is the controller and Eagle Crest Treasure LLC acts as the Owner’s processor, handling Guest Data on the Owner’s instructions. The terms of that processing are set out in our Data Processing Addendum (DPA). If you are a Guest with a question about how a particular event uses your information, please contact the Owner (host) of that event first.
Account information. When you register we collect your name, email address, optional phone number, and a securely hashed version of your password — we never store your password in readable form. We also keep your plan, add-ons, and account settings.
Event content and Guest Data. As you plan an event you may add event details (dates, venues, schedules), guest lists and contact details, RSVPs and meal choices, budgets and tasks, seating, photos and videos, music, invitations and messages, event programs, and the content of your public event page.
Payment information. Paid plans are processed by third-party payment providers (Stripe and Paystack). We do not collect or store full card numbers or bank credentials; we receive only limited confirmation details (such as a transaction reference and status) needed to activate your plan and issue receipts.
Usage and device data. To keep the Service secure and working, and to give Owners basic visitor analytics for their pages, we automatically log limited technical data such as IP address, browser and device type, referring page, and the pages viewed. Visitor analytics are aggregated and identify visitors only by a non-reversible technical signature, not by name.
Cookies. We use a single essential session cookie to keep you signed in; see our Cookie Policy.
We use personal information to: provide, operate, and secure the Service and perform the actions you request, such as publishing your public page and sending the emails you initiate (legal basis: performance of our contract with you); keep the Service safe, prevent fraud and abuse, and troubleshoot (legitimate interests); comply with legal obligations (such as tax and accounting); and send essential account and transactional emails (contract). Where the law requires consent — for example, for certain non-essential communications — we rely on that consent, which you may withdraw at any time. We do not sell your personal information, and we do not show third-party advertising.
Account and event emails are delivered through the email provider configured for the account. Verification and password-reset codes are time-limited and single-use; if you receive one you did not request, you can ignore it — no change is made unless the code is used. Owners are the senders of the invitations and messages they initiate and are responsible for their content and recipients.
We share personal information only as needed to run the Service: with service providers (sub-processors) who process data on our behalf under contract — currently our hosting provider, our email-delivery provider, and our payment processors (Stripe and Paystack); when you choose to publish an event page or item, with anyone who can view it; to comply with law or a valid legal request, or to protect rights, safety, and the integrity of the Service; and in connection with a merger, acquisition, or sale of assets, subject to this policy. We do not sell or rent personal information.
We and our service providers may process personal information in the United States and other countries whose data-protection laws may differ from yours. Where we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland, we use appropriate safeguards, such as the European Commission’s Standard Contractual Clauses (and the UK Addendum) or another lawful transfer mechanism.
We keep account information and event content while your account is active. If your account or an event is deleted, the associated data is removed from active systems, with residual copies cleared from routine backups within a limited period. We may retain limited information longer where required to meet legal, tax, security, or dispute-resolution obligations. Audit-log records of administrator access are kept independently as a security record even if the referenced account is later removed.
We apply appropriate technical and organizational measures to protect personal information, including encryption of traffic in transit (HTTPS), hashing of passwords, access controls, and administrator-access logging (described below). No method of transmission or storage is completely secure, but we work to protect your information and to address issues promptly.
Depending on where you live, you may have rights over your personal information. Under the EU/UK GDPR these include the rights to access, correct, delete, restrict, or object to processing, to data portability, and to withdraw consent; you may also lodge a complaint with your local supervisory authority. Under the California Consumer Privacy Act as amended (CCPA/CPRA), California residents may request to know, delete, or correct personal information and to opt out of the “sale” or “sharing” of personal information — which we do not do — and we will not discriminate against you for exercising your rights.
You can review and update your name, email, and password anytime from your Profile, control which pages and items are public, and remove content you have added. To make any other request, including deletion of your account, contact us at sales@ectreasure.com. We will verify your request and respond within the time the law requires. Requests that concern a specific event’s Guest Data are directed to the relevant Owner, whom we will support as their processor.
An authorized administrator may need to access an account to provide support, resolve a problem, or maintain the Service. To protect your privacy, this access is controlled and recorded:
We use a single essential session cookie to keep you signed in. It is not used for tracking or advertising. Your interface preferences (such as theme) may be stored locally in your browser. See the Cookie Policy for details.
The Service is intended for adults (18+) and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us personal information, contact us and we will delete it.
We may update this policy from time to time. We will revise the “Effective date” above and, for material changes, take reasonable steps to notify you. Continued use of the Service after a change takes effect means you accept the updated policy.
ECTreasure Events is operated by Eagle Crest Treasure LLC, which is the controller of your account information and can be reached at sales@ectreasure.com or via ectreasure.com. For Guest Data tied to a specific event, the event’s Owner is the controller and your first point of contact.
See also: Terms of Use · Data Processing Addendum · Agreement of Use · Refund Policy · Cookie Policy · Disclaimer