House rules: privacy
Privacy policy
Your privacy matters. This policy explains what data we collect, how we use it, when we share it, and the rights available to you as a Reunion Fund user.
Effective June 13, 2026 · v1.2.0
1. Information We Collect
We collect only what we need to operate, secure, and improve the platform, always by fair and lawful means.
- Account information: Name, email address, profile photo, and password (stored hashed) when you create an account.
- Event & collaboration data: Events, committees, milestones, tasks, RSVPs, guest lists, memories, and announcements you create or contribute to.
- Subscription & billing data: Your chosen plan, billing interval, and subscription status. Payment card details are collected and stored solely by Stripe. We never see or store full card numbers.
- Communications: Messages you send via in-app team chat, announcements, or email broadcasts to guests.
- Usage data: Pages visited, features used, session duration, and interaction patterns, used to improve the product and detect abuse.
- Technical data: IP address, browser type, device characteristics, and error traces collected automatically when you use the platform.
2. How We Use Information
We use the information we collect to:
- Provide, operate, and maintain the Reunion Fund platform and all its features.
- Process subscription payments through Stripe and manage your plan status.
- Send transactional emails: RSVP confirmations, invitations, event announcements, and billing receipts.
- Send product updates and promotional communications (you can opt out at any time).
- Detect and prevent fraud, abuse, spam, and security threats.
- Improve and develop new features based on how the platform is used.
- Comply with legal obligations.
4. Data Security
We implement reasonable technical and organizational safeguards including:
- TLS encryption for all data in transit.
- Appwrite-managed authentication with server-side session validation.
- Role-based access controls limiting which team members can access which data.
- Collection-level permissions ensuring users can only access data they are authorized to see.
- Rate limiting and abuse detection to protect against automated attacks.
No internet transmission or storage system is completely secure. We cannot guarantee absolute security and encourage you to use a strong, unique password.
5. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your account and associated personal data.
- Export a portable copy of your data.
- Object to or restrict certain processing activities.
- Withdraw consent where processing is consent-based (this does not affect prior lawful processing).
- Opt out of promotional emails using the unsubscribe link in any email we send.
To exercise any of these rights, email support@reunionfund.com. We will respond within 30 days. We may ask you to verify your identity before fulfilling the request.
California residents (CCPA): You have additional rights under the California Consumer Privacy Act, including the right to know what personal information we collect and the right to non-discrimination for exercising your rights.
EEA / UK residents (GDPR / UK GDPR): The legal bases for processing your data are: (a) contract performance (to provide the service you signed up for); (b) legitimate interests (security, fraud prevention, product improvement); and (c) consent where explicitly requested. You have the right to lodge a complaint with your local supervisory authority.
7. Log Data
When you use the platform our servers automatically record standard log data including your IP address, browser user agent, pages requested, HTTP status codes, and timestamps. This data is used for security monitoring, debugging, and reliability improvements. Log data is retained for up to 90 days and then deleted or anonymised.
8. Third-Party Services
Reunion Fund integrates with the following key third-party services, each of which has its own privacy policy:
- Stripe: subscription billing and (future) event contributions. Stripe Privacy Policy
- Appwrite: database, authentication, and file storage.
- Vercel: hosting and edge infrastructure.
- Resend: transactional email delivery.
- Google (Gemini AI): AI invitation writer and event recap features. Input text may be processed by Google. We do not send personally identifiable information to AI features without your action.
Our platform may also contain links to external websites we do not control. We are not responsible for the privacy practices of those sites.
9. Children's Privacy
Reunion Fund is not directed at children under 13 (or under 16 in the EEA). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at support@reunionfund.com and we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes we will update the "Last updated" date and, where the changes significantly affect your rights, notify you by email or in-app notice. Continued use of Reunion Fund after the effective date constitutes acceptance of the revised policy.
11. Contact
Questions or requests about this Privacy Policy:
- Email: support@reunionfund.com
- WeeBie Media, LLC (Tampa, Florida)
Changelog
- v1.2.0 (2026-06-13): Updated to reflect pivot from crypto crowdfunding to event collaboration SaaS. Replaced crypto/KYC vendor language with accurate Stripe/Appwrite/Resend/Vercel service providers. Added cookies section, children's privacy, CCPA/GDPR notes, contact section.
- v1.1.0 (2025-09-25): Added table of contents, version tag, structured data, vendor responsibility section, user rights details.
- v1.0.0: Initial public release.