IvoryFolio / Privacy Policy
Privacy Policy
Last updated: 1 July 2026
This Privacy Policy explains how the Provider (Mauro Correia, trading as IvoryFolio, Coimbra, Portugal; shop@ivoryfolio.com) processes personal data in connection with the IvoryFolio App.
The core principle: your planning data stays with you. The data you enter into the planner (such as guest names, emails and contacts, menu and dietary choices, and budget figures) is created and stored inside your own Google account. As regards this planning data, the Provider does not collect it, does not store it, does not access it and does not process it. You control it, inside your own Google account. In relation to this planning data, the Provider is neither the controller nor a processor. (The RSVP is different and is described in section 10: there, the Provider stores an encrypted part that it cannot read.)
2.Dietary and health information
Some information you may enter (for example, dietary requirements, allergies) may reveal health-related data, which is a special category under the GDPR. In the planner, that information stays in your own Google account and the Provider never sees it. In the RSVP (see section 10), that information is encrypted on the guest's device before it reaches the Provider's bridge, so the Provider stores it but cannot read it. Encryption is the right protection, but it does not remove your role as controller of that data. To be clear: in the planner, the Provider never receives this information; in the RSVP, the Provider receives and stores the encrypted block that contains it, but cannot read it. In neither case does the Provider treat it as anything less than protected special-category data, and in neither case do you cease to be the controller of that data.
3.The access permissions
To work, the planner asks Google for a small, specific set of permissions, and nothing more:
- Only the file it creates in your Google Drive. The planner reads and writes only the single file it creates for your wedding (Google's "drive.file" permission). It cannot see or touch any of your other files, and it gives the Provider no access to your Drive.
- Your Google account's primary email address. This is used only, inside the app, to recognise the owner of the app so the correct branding is shown. It is never stored on the Provider's servers, never sold and never shared.
- A connection to the internet from the app, used only to reach the RSVP bridge when you enable RSVP and to look up your venue's location for the golden hour planner.
- Permission to run as a Google Apps Script web app, the standard permission such an app needs to run and serve its own pages.
These permissions do not give the Provider access to your Google account or to any planning data of yours.
4.What the Provider processes as controller (sales and support)
The Provider processes the limited personal data necessary to sell and support the App, for example: the order or contact information that reaches us when you purchase through Etsy or our website, or when you contact us by email for support. That data is used only to provide the App, process your purchase, respond to you and comply with legal obligations. We do not sell your data and we do not show advertising. This legitimate interest in managing and supporting the App covers only the sales/support data above and does not cover your guests' RSVP data, which the Provider processes exclusively as a processor under section 10 and the Data Processing Agreement.
On the ivoryfolio.com website itself, if you accept optional cookies, we use Google Analytics (with your IP address anonymised) to understand which pages are most helpful. It runs only after you accept, is never used to profile you or to sell data, and may involve a transfer to Google in the United States under the EU-US Data Privacy Framework. Details and how to change your choice are in our Cookies Policy.
5.Legal bases
When the Provider processes the limited sales/support data above, it does so to perform the contract with you, to comply with legal obligations, and in its legitimate interest in managing and supporting the App.
6.Your rights (GDPR)
As regards the limited sales/support data the Provider holds as controller, you have the rights of access, rectification, erasure, restriction, objection and portability, and the right to lodge a complaint with the Portuguese data protection authority (CNPD). To exercise them, contact shop@ivoryfolio.com. As regards the data inside your own Google account, you control it directly there at any time. As regards RSVP data, see section 10.
7.Google
Your planner data is stored in, and the planner runs inside, your own Google account. The RSVP bridge runs in the Provider's Google account. Google acts as the provider of that storage and infrastructure. See Google's privacy policy on how it handles accounts. Google may process and store data on servers located outside the European Economic Area, including in the United States. Those transfers take place under Google's transfer mechanisms, in particular the European Commission's Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.
Separately, when you type your venue into the golden hour planner, the app sends that venue name once to OpenStreetMap (Nominatim, run by the OpenStreetMap Foundation) to find its map coordinates, under OpenStreetMap's own privacy policy. No other planning data is sent.
8.Retention and security (sales and support)
The Provider keeps the limited sales/support data only for as long as necessary for the purposes above or as required by law, and takes reasonable measures to protect it. Your data in the planner is kept by you, in your Google account, for as long as you keep it.
9.Changes
We may update this Policy. The version in force is always the one published with the App.
10.Data processing in the RSVP (when you enable the feature)
If you enable the RSVP, the Provider then hosts a technical bridge in its Google account that receives, stores in encrypted form, and forwards your guests' replies to your planner. In that processing:
- What the bridge stores per reply: a wedding identifier, the invitation code, the yes/no answer, the number of people, the date/time, and an encrypted block containing the rest of the reply content (for example, name, message, menu choices and dietary/allergy information). The identifier, the code and the counts are pseudonymised data: on their own they do not identify anyone by name; only you, cross-referencing them with your planner, can link them to a person.
- What the Provider can read: only the pseudonymised counts above. The Provider cannot read the encrypted block, because it does not have the private key. The private key lives only in your planner data, and only you decrypt the content, locally.
- Roles: in relation to your guests' data, you are the controller and the Provider is a limited processor, acting only on your instructions and only to store in encrypted form and forward RSVPs. The Provider does not use this data for its own purposes (no marketing, profiling, resale or model training).
- Special categories: as regards any guest health information (such as allergies and diets), you are responsible for having a valid legal basis under Article 9 of the GDPR, usually the guest's explicit consent, and for informing guests before collecting such information.
- Retention: the RSVP entries on the bridge are removed when you delete the matching guests in your planner. You can also ask the Provider to delete your wedding's RSVP data at any time, and it is deleted on your request or on account closure. The Provider does not keep it for any other purpose.
- International transfers: the bridge runs on Google, which may transfer and store data outside the European Economic Area, including in the United States, under a valid transfer mechanism, as described in section 7 and in the Data Processing Agreement.
- Sub-processor: the bridge runs on Google (Apps Script/Drive), which acts as the Provider's sub-processor.
- Guests' rights: since the Provider cannot identify guests from the data it holds, guests' rights (access, rectification, erasure, etc.) are exercised through you, the controller. The App provides a way for the guest to contact you.
- Data breaches: if a security breach occurs on the bridge, the Provider notifies you without undue delay, so that you can comply with your legal obligations, including, where applicable, notifying the CNPD.
The full terms of this processing are set out in the Data Processing Agreement, which you accept when you enable the RSVP.
11.Contact
Mauro Correia, IvoryFolio, Coimbra, Portugal. Email: shop@ivoryfolio.com