fun4.us
🔒 Legal

Privacy Policy

How we collect, use, and protect your personal information.

Effective date: June 30, 2026 Last updated: June 30, 2026 Applies to: celebrateat.com and all associated subdomains
Plain-language summary: We collect the information you give us when registering and booking, plus standard server logs and analytics. We do not sell your personal data. We share it only with the venues you book, our payment processor (Square), and the infrastructure services that run the platform (AWS). You can request deletion of your data at any time.

1. Overview

Celebratat Inc. ("Celebratat," "we," "our," or "us") operates the Celebratat platform — a marketplace and business-management suite for birthday party and event venues accessible at celebrateat.com and associated subdomains (collectively, the "Platform").

This Privacy Policy describes what personal information we collect from users of the Platform (venue owners, their customers, and guests), why we collect it, how we use and share it, and what choices and rights you have over your information.

By accessing or using the Platform you agree to the collection and use of information as described in this Policy. If you do not agree, please do not use the Platform.

2. Information We Collect

2.1 Information you provide directly

CategoryExamplesWhen collected
Account data Name, email address, password (hashed), account type Registration
Booking data Child's name & age, event date & time, guest count, occasion type, additional info Booking checkout
Health & safety data Food allergies or dietary restrictions you disclose (AllergyAware feature) Booking checkout (optional)
Payment data Card number, expiry, CVV — processed by Square; Celebratat receives only the last 4 digits and transaction ID Checkout & event payment
Invitation & RSVP data Guest names, email addresses, RSVP status, dietary notes FunInvite creation / guest RSVP
Waiver data Signatures, participant names, acknowledgement text (EzWaver feature) Pre-event waiver signing
Venue profile data Business name, address, contact info, photos, descriptions, pricing Venue owner onboarding & admin panel
Communications Messages sent via in-platform chat, support emails Ongoing use
Promo codes Promotional codes entered at checkout Checkout

2.2 Information collected automatically

  • Log data: IP address, browser type and version, operating system, referring URL, pages visited, time and date of visit, time spent on pages.
  • Device data: device identifiers, screen resolution, language preference.
  • Usage data: features used, search queries, booking flow steps completed or abandoned.
  • Cookies & similar technologies: see Section 5 below.

2.3 Information from third parties

  • Google Reviews: public reviews and ratings fetched from the Google Places API for venues that have a Google Place ID configured.
  • Google Maps / Geocoding: latitude and longitude resolved from a venue's ZIP code to power location-based search.
  • Square: transaction status, payment method metadata (last 4 digits, card brand), and receipt URLs.
  • Amazon Cognito: identity and authentication tokens for registered users.

3. How We Use Your Information

We use the information we collect to:

  • Provide the Platform: process bookings, collect payments, send confirmation and reminder emails, enable venue search, and operate all Platform features.
  • Communicate with you: send booking confirmations, deposit receipts, checkout receipts, RSVP updates, event reminders, unread message notifications, and service announcements.
  • Support venue owners: surface booking data, guest information, allergy flags, RSVP lists, waiver records, and analytics in the admin portal.
  • Improve the Platform: analyse usage patterns, debug errors, optimise user flows, and develop new features.
  • Personalise the experience: remember colour scheme preferences, display your upcoming bookings, and surface relevant venue recommendations.
  • Security & fraud prevention: detect and prevent fraudulent bookings, unauthorised access, and abuse of the Platform.
  • Legal compliance: fulfil our obligations under applicable law, respond to lawful requests from authorities, and enforce our Terms of Service.
  • AI features: when you use FunInvite's AI card generation, your event details are sent to Google Gemini API solely to generate invitation artwork; they are not used to train models.

We do not use your personal data for targeted advertising, and we do not sell your personal data to third parties.

4. How We Share Information

4.1 With Venue Owners

When you make a booking at a venue, we share your booking details (name, contact information, event details, allergy flags, and payment status) with that venue's owner and their authorised staff so they can deliver the services you booked. Venue Owners are independent data controllers with respect to the information you share with them and are responsible for handling it in accordance with applicable law.

4.2 With service providers

We share personal data with trusted service providers who process it solely on our behalf under appropriate data-processing agreements:

ProviderPurposeData shared
Amazon Web Services (AWS) Cloud hosting, database storage, email delivery (SES), authentication (Cognito), push notifications (Pinpoint), file storage (S3) All Platform data
Square Inc. Payment processing Card details (never stored by Celebratat), transaction amounts, booking reference
Google LLC Maps/Geocoding API (venue location); Places API (reviews); Gemini API (AI invitation art) ZIP codes (geocoding); venue Place IDs (reviews); event title/date (AI art generation)
Firebase (Google LLC) Mobile push notifications (FCM) Device tokens, notification payload

4.3 Legal requirements

We may disclose your information if required by law, court order, or governmental authority, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Celebratat, our users, or the public.

4.4 Business transfers

If Celebratat is involved in a merger, acquisition, asset sale, or bankruptcy, your personal data may be transferred as part of that transaction. We will notify you before your data is transferred and subject to a different privacy policy.

4.5 AI Spotlight (venue data only)

Venue Owners who enable the AI Spotlight feature make their public venue profile, package catalogue, and location data discoverable by third-party AI assistants (such as ChatGPT and Claude) via a publicly accessible MCP server and OpenAPI specification. No customer or guest personal data is included in AI Spotlight output.

4.6 No sale of personal data

We do not sell, rent, or trade your personal information to third parties for their own marketing or advertising purposes.

5. Cookies & Tracking

We use cookies and similar technologies (local storage, session storage) to operate the Platform. Specifically:

  • Session cookies: celebratat_user_session (localStorage) stores your Cognito authentication tokens so you remain logged in across page navigations. It is not a third-party tracking cookie.
  • Cross-domain auth cookie: celebratat_u (domain .celebrateat.com) carries your email address so all subdomains (www, my, invite, venue subdomains) can detect sign-in state. It contains no sensitive credentials.
  • Draft save cookie: celebratat_invite_draft temporarily stores an unsaved invitation draft across tabs during the FunInvite creation flow. It expires after 24 hours.
  • Admin preference: celebratat_admin_nav_hidden (localStorage) remembers your sidebar collapse preference.

We do not use third-party advertising or retargeting cookies. We do not use Google Analytics, Meta Pixel, or similar commercial tracking scripts.

Most browsers allow you to control cookies through their settings. Disabling cookies may prevent some features (such as staying logged in) from working correctly.

6. Third-Party Services

The Platform integrates with third-party services whose own privacy policies govern their data practices. We encourage you to review:

Links to external websites in venue profiles, confirmation emails, or chat messages are provided for convenience and do not imply endorsement. Celebratat is not responsible for the privacy practices of external sites.

7. Data Security

We implement industry-standard technical and organisational measures to protect your personal data, including:

  • Encryption in transit (TLS/HTTPS) for all Platform communications.
  • Encryption at rest for all data stored in AWS (S3 server-side encryption, DynamoDB encryption).
  • Authentication via Amazon Cognito with hashed password storage; passwords are never stored in plaintext.
  • Role-based access controls limiting which staff can access which data.
  • All production API routes require authenticated sessions; admin routes require venue-owner or administrator JWT tokens.
  • Payment card data is processed exclusively by Square and never stored on Celebratat servers.

Despite these measures, no system is completely secure. We cannot guarantee absolute security of your information. In the event of a data breach affecting your rights, we will notify you as required by applicable law.

8. Data Retention

We retain your personal data for as long as your account is active or as needed to provide Platform services. Specifically:

  • Account data: retained until account deletion is requested, plus a brief period thereafter to resolve disputes or comply with legal obligations.
  • Booking records: retained for 7 years after the event date to satisfy financial record-keeping requirements.
  • Waiver records: retained for as long as required by the venue's jurisdiction (commonly 3–7 years).
  • Chat messages: retained while the associated booking or event is active; may be purged on account deletion request.
  • Invitation & RSVP data: retained until the event owner deletes the event, or until account deletion is requested.
  • Server logs: retained for 90 days for security and diagnostic purposes.
  • Google Reviews cache: cached for 24 hours, then re-fetched from Google; not personally identifiable data of our users.

When data is no longer required, it is securely deleted or anonymised.

9. Children's Privacy

The Platform is intended for use by adults (18+) booking events on behalf of children. We do not knowingly collect personal data directly from children under 13. Booking forms may collect a child's first name and age for event personalisation — this information is provided by the adult organiser and is used solely to facilitate the booked event.

Allergy information provided for children is shared only with the booked venue and is not used for any other purpose.

If you believe we have inadvertently collected personal data from a child under 13 without parental consent, please contact us at privacy@celebrateat.com and we will promptly delete it.

10. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: request a copy of the personal data we hold about you.
  • Correction: request that inaccurate or incomplete data be corrected.
  • Deletion: request that we delete your personal data ("right to be forgotten"), subject to legal retention obligations.
  • Portability: receive your data in a structured, machine-readable format.
  • Restriction: request that we restrict processing of your data in certain circumstances.
  • Objection: object to processing based on legitimate interests.
  • Withdraw consent: where processing is based on your consent, withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at privacy@celebrateat.com. We will respond within 30 days (or the timeframe required by applicable law). We may need to verify your identity before processing your request.

You also have the right to lodge a complaint with your local data protection authority if you believe your rights have been violated.

11. California Residents (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

  • Right to Know: you may request disclosure of the categories and specific pieces of personal information we have collected about you in the past 12 months, the sources of that information, the business purposes for collection, and the categories of third parties with whom we share it.
  • Right to Delete: you may request deletion of your personal information, subject to exceptions.
  • Right to Correct: you may request correction of inaccurate personal information.
  • Right to Opt Out of Sale or Sharing: we do not sell or share personal information for cross-context behavioural advertising. No opt-out action is required.
  • Right to Limit Use of Sensitive Personal Information: we use sensitive information (allergy data) only to facilitate your booking. We do not use it for other purposes.
  • Non-Discrimination: we will not discriminate against you for exercising your CCPA rights.

To submit a CCPA request, email privacy@celebrateat.com with "CCPA Request" in the subject line or call us at the number listed on our contact page. We will respond within 45 days.

Categories of personal information collected in the past 12 months: identifiers (name, email, IP address); commercial information (booking history, payments); internet or network activity (log data, usage data); sensory data (uploaded event photos); health information (allergy disclosures, voluntarily provided).

12. EEA & UK Residents (GDPR / UK GDPR)

If you are located in the European Economic Area (EEA) or the United Kingdom, the General Data Protection Regulation (GDPR) or UK GDPR applies to our processing of your personal data.

12.1 Legal bases for processing

  • Contract performance: processing necessary to fulfil a booking or provide Platform services you have requested.
  • Legitimate interests: fraud prevention, platform security, service improvement, and sending operational communications.
  • Consent: AI card generation (event details sent to Gemini API); marketing communications (if you have opted in).
  • Legal obligation: compliance with tax, financial, and regulatory requirements.

12.2 International transfers

Your data is processed and stored in the United States (AWS us-east-1). Transfers of personal data from the EEA/UK to the US are made under the EU–US Data Privacy Framework or, where applicable, Standard Contractual Clauses.

12.3 Data Protection Officer

We do not currently have a designated DPO, as our processing activities do not meet the threshold requiring one under GDPR Article 37. For GDPR-related inquiries, contact privacy@celebrateat.com.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or applicable law. If we make material changes, we will notify you by email (to the address on your account) or by a prominent notice on the Platform at least 14 days before the changes take effect.

The current version of this Policy is always available at celebrateat.com/legal/privacy. The "Last updated" date at the top of the page indicates when the most recent changes were made.

14. Contact Us

For privacy-related questions, data access or deletion requests, or to report a concern, please contact us:

We aim to respond to all privacy requests within 30 days.