Privacy Policy - Posh Celebration

Effective date: 1st October 2025
Contact: legal@poshcelebration.com

1. Who we are & how this policy applies

Posh Celebration (“Posh,” “we,” “our”) operates an AI-native event platform and marketplace that helps Hosts (B2C/B2B) plan, book, and pay; and equips Vendors with tools to quote, coordinate, and get paid via escrow. This Privacy Policy explains what personal data we collect, why, how we use/share it, how long we keep it, and your choices and rights.

This policy applies to:

  • Visitors to our website/app
  • Registered Hosts and Vendors
  • Corporate users (HR/Admin/Comms, procurement, finance)
  • People who receive our updates (investors/mentors) or contact our support

If a separate agreement applies (e.g., a Vendor MSA/SLA or enterprise contract), that document will control where it’s more specific.

2. Roles under data protection laws

  • Posh Celebration is generally the data controller for Platform data (accounts, bookings, messaging, payments orchestration, fraud prevention, marketing preferences).
  • Vendors are independent controllers for services they deliver (e.g., their own customer records, invoices, photography).
  • For some corporate implementations we may act as a processor of limited fields on the customer’s behalf; where that’s the case, we’ll execute a Data Processing Addendum (DPA).

3. What data we collect

You provide

  • Account & profile: name, email, phone, password, organization/role, preferences, communication choices.
  • Booking details: event date/time, location/city, headcount, budget, vibe, service selections, special requests (e.g., dietary, décor themes).
  • Vendor onboarding: business name, owner/authorized person details, contact info, service categories, pricing, availability; KYC documents where required (e.g., license, tax/BIN, bank proof).
  • Payments: we receive tokens/IDs from our payment partners (card last4, brand, expiry month/year); we do not store full card numbers.
  • Comms & support: messages, calls, WhatsApp chat content you route via us, review content, survey responses (e.g., NPS).

Collected automatically

  • Device & usage: IP address, device type, OS/browser, log data, app version, referral source, session analytics, approximate location.
  • Cookies & similar tech: for sign-in, preferences, analytics, and performance (see Cookie Policy below).

From third parties

  • Payment/BNPL providers: payment status, risk signals, chargeback data.
  • Identity/KYC providers: verification status (pass/fail), risk flags (where used).
  • Lead/partner sources: referral codes, partner IDs, campaign info.
  • Vendors/Hosts: status updates and delivery evidence (timestamps, photos) for dispute resolution.

Special categories? We don’t seek sensitive data. If a Host voluntarily shares health-related preferences (e.g., allergies), we process it only to deliver the event and delete or minimize after use.

4. Why we use your data (purposes & legal bases)

We process data to:

Provide the Platform & services (contract)

  • Create and manage accounts; render AI plans; generate quotes; enable search→quote→book & pay; provide escrow and payouts (T+3).
  • Coordinate between Hosts and Vendors; send confirmations, reminders, and run-sheets.

Improve & secure the Platform (legitimate interests / contract)

  • Monitor performance, fix bugs, combat spam/fraud/bypass; ensure availability; perform analytics to enhance reliability and UX.

Communicate with you (contract / consent / legitimate interests)

  • Transactional emails/SMS/WhatsApp (bookings, payouts, policy changes).
  • Marketing updates and newsletters with your consent (you can unsubscribe anytime).

Compliance & risk (legal obligation / legitimate interests)

  • KYC (where required), tax accounting, responding to lawful requests, enforcing Terms (including Anti-Bypass), handling disputes and chargebacks.

AI features (legitimate interests / contract)

  • Use non-sensitive booking text and preferences to generate curated plans and vendor matches. We don’t use your content to train public models; we use data only to run and improve Posh.

Where we rely on consent, you may withdraw it at any time. Where we rely on legitimate interests, you can object if your privacy interests outweigh our purposes.

5. Who we share data with (and why)

We share only what’s needed, with:

  • Vendors: event details necessary to quote/deliver; contact is masked until booking/escrow when possible.
  • Payment/escrow/BNPL partners: to process payments, hold funds in escrow, issue refunds, and manage risk.
  • Messaging & customer-care tools: to deliver notifications and support.
  • Cloud & infrastructure providers: hosting, storage, security, backups.
  • Analytics & A/B testing tools: to understand performance and improve UX (de-identified or pseudonymized where feasible).
  • Compliance partners: KYC/AML, tax, accountants/auditors, legal advisors.
  • Corporate customers (B2B): limited reporting to your employer (e.g., usage, invoices, SLA/attendance proofs).
  • When required by law or to protect rights/safety.

We do not sell your personal data.

6. Cookies & similar technologies

We use:

  • Strictly necessary cookies (sign-in, security, cart/checkout).
  • Analytics/performance (traffic, feature usage).
  • Functional (remember preferences).
  • Marketing (only if/when you consent).

You can manage preferences via our Cookie Settings and your browser. See our Cookie Policy for details, list of cookies, and retention.

7. International data transfers

We may process/store data in countries different from yours (e.g., reputable cloud providers). Where law requires safeguards (e.g., EU/UK), we use Standard Contractual Clauses (SCCs) and additional measures as appropriate. You can request a copy of applicable safeguards at privacy@poshcelebration.com
.

8. Data retention (how long we keep data)

We keep data only as long as needed for the purposes above:

  • Accounts & profile: while your account is active; if you close it, we delete or anonymize within 90 days, except data we must keep by law.
  • Bookings & financial records: 7 years (accounting/tax).
  • Vendor KYC & payout records: typically 5 years or as required by law/banking partners.
  • Support tickets & chat: up to 24 months for quality and dispute history.
  • Marketing preferences & logs: until you unsubscribe or delete your account.
  • Device/analytics data: per our Cookie Policy; aggregated thereafter.

We may retain minimal “suppression” data to honor do-not-contact requests.

9. Your rights

Depending on your region, you may have the right to access, correct, delete, restrict, object, or port your data, and to withdraw consent.

  • EU/UK/Thailand/UAE residents: you also have the right to lodge a complaint with your local data authority.
  • We will not discriminate if you exercise a right.

To make a request, email privacy@poshcelebration.com
. We’ll respond within 30 days (or the statutory period).

10. Children

The Platform is not directed to children under 13 (or under the age of digital consent in your country). We do not knowingly collect children’s data without appropriate consent. If you believe a child provided data, contact us to delete it.

11. Security

We use administrative, technical, and organizational safeguards, including encryption in transit, hardened cloud infrastructure, access controls, least-privilege, audit logging, and vendor assessments. No system is 100% secure; if we discover a breach impacting you, we’ll notify you and regulators as required by law.

12. Automated decision-making & profiling

Our AI Planner and ranking features suggest vendors and packages based on your preferences and historical performance signals. These recommendations do not produce legal or similarly significant effects. You can request human review or opt for an assisted flow at any time.

13. Communications preferences

  • Transactional messages (bookings, payouts, policy updates) are essential and you may not opt out of those while using the service.
  • Marketing emails/newsletters require your opt-in consent. You can unsubscribe via the link in the email or by contacting us.
  • WhatsApp/SMS notifications follow your settings and applicable messaging platform terms.

14. Third-party links & social features

Our Platform may link to third-party sites or include integrations (e.g., maps, payment providers, social). Their privacy practices are their own; please review their policies.

15. Local addenda (if applicable)

  • EU/UK: Posh Celebration Limited is the controller. For international transfers, we use SCCs. You can contact your supervisory authority (e.g., ICO, your local DPA).
  • Thailand (PDPA): For questions or to exercise rights under PDPA, contact privacy@poshcelebration.com
    .
  • UAE (PDPL): For UAE users, we honor PDPL rights and transfer safeguards.
    (We can add specific local contact addresses if you appoint a local representative.)

16. Changes to this Policy

We may update this Policy to reflect changes in our practices, technology, or laws. We’ll post updates with a new effective date and, where changes are material, provide reasonable notice. Continued use constitutes acceptance.

17. How to contact us

  • Email: privacy@poshcelebration.com
    (preferred)
  • Postal: Posh Celebration Limited, 14, Sweden Plaza, Main Road, Mirpur-1, Mirpur PS, Dhaka-1216, Bangladesh
  • Data Protection Officer (DPO): NameNameName, EmailEmailEmail (optional—add if you appoint one)

Cookie Policy (summary)

We use cookies to operate the site, remember your settings, measure performance, and (with consent) personalize content/ads. You can change preferences any time via Cookie Settings. Full cookie table, partners, and retention are listed in our Cookie Policy page.

  • home