← Back to home
Template — not yet legally reviewed. Will be updated before launch.

Privacy Policy

Last updated: 2026-05-28

1. Data controller

The controller of personal data processed via the „Ceva Memorabil" platform is [COMPANY NAME] SRL, registered office at [REGISTERED ADDRESS], tax ID RO[CIF], e-mail privacy@ceva-memorabil.ro.

We process personal data in accordance with Regulation (EU) 2016/679 (GDPR) and Romanian Law no. 190/2018. This policy explains what data we collect, why, with whom we share it, how long we retain it, and what rights you have.

2. Categories of data processed

Depending on the user type, we process:

  • Buyers: e-mail address (required to deliver the voucher); recipient name, if the voucher is a gift; the unique order code; transaction amount and date; technical information (IP, user-agent) generated when accessing the Platform.
  • Partners: name, e-mail, password (stored as a bcrypt hash), venue name and address, phone number, geographical coordinates, Google Places identifier, data about listed experiences, Stripe Connect account information.
  • Payment: card data does not pass through our servers; it is collected and processed directly by Stripe as an independent controller.

3. Purposes and legal bases

  • Performance of a contract (Art. 6(1)(b) GDPR): issuing vouchers, managing orders, supporting use of the Platform.
  • Legal obligations (Art. 6(1)(c) GDPR): invoicing, accounting, tax reporting, replying to authorities.
  • Legitimate interests (Art. 6(1)(f) GDPR): fraud prevention, Platform security, service improvement, transactional communications.
  • Consent (Art. 6(1)(a) GDPR): marketing communications, if you explicitly opt in. You can withdraw consent at any time.

4. Recipients and processors

To operate the service, we share strictly necessary data with the following processors, under data-processing agreements compliant with Art. 28 GDPR:

  • Stripe Payments Europe Ltd. (Ireland) — payment processing and fraud prevention; Stripe Connect for payouts to Partners.
  • Brevo SAS (France) — delivery of transactional e-mails (order confirmation, partner e-mail confirmation, voucher).
  • Vercel Inc. (US, with EU infrastructure) — application hosting, content delivery, image storage (Vercel Blob).
  • Neon Inc. (US, with EU regional instances) — PostgreSQL database.
  • Google Ireland Ltd. — Google Calendar (only if the Partner enables sync); Google Places (address suggestions in the admin interface).

5. International transfers

Some processors are entities established in the United States. Transfers are made on the basis of the European Commission's adequacy decision (EU-US Data Privacy Framework) or, where applicable, the Commission's Standard Contractual Clauses.

6. Retention periods

  • Partner account data: for the duration of the account, plus 6 months after deletion (to handle complaints).
  • Transaction, voucher and invoice data: 10 years, as required by Romanian Accounting Law no. 82/1991.
  • E-mail and technical logs: maximum 12 months.
  • E-mail confirmation tokens: until used or expired (24 hours).
  • Marketing data (with consent): until consent is withdrawn.

7. Cookies and similar technologies

We use a single essential cookie, session, for Partner authentication. The cookie is HttpOnly, SameSite=Lax, with a maximum lifetime of 7 days. We do not use tracking or marketing cookies and do not call third-party advertising networks.

We also use a language-preference cookie (NEXT_LOCALE), strictly necessary for the multilingual interface.

8. Your rights

As a data subject, you have the following rights:

  • Access — to obtain a copy of the data we hold about you.
  • Rectification — to correct inaccurate data.
  • Erasure („right to be forgotten") — within the limits of our legal retention obligations.
  • Restriction — to limit processing in certain situations.
  • Portability — to receive your data in a structured, commonly used format.
  • Objection — to processing based on legitimate interests.
  • Withdrawal of consent — at any time, without affecting the contract.

To exercise your rights, send a request to privacy@ceva-memorabil.ro. We respond within 30 days.

9. Complaints

You have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP):

B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest, 010336.
Phone: +40.318.059.211 / +40.318.059.212.
E-mail: anspdcp@dataprotection.ro.
Web: dataprotection.ro.

10. Security

We apply appropriate technical and organizational measures: passwords stored as bcrypt hashes, TLS-encrypted communications, role-based access control, logging of administrative access, backups managed by Neon. We will notify the competent authority and affected users within 72 hours in the event of a high-risk security breach.

11. Changes

We may update this policy to reflect legal or operational changes. Changes are published on this page, together with the last-updated date above. We notify users by e-mail in the event of material changes.

12. Contact

For any data-protection question: privacy@ceva-memorabil.ro.