Privacy Policy
Service: Mommy's Little Party Planner Business: Protocol Media LLC Effective: August 21, 2026 Last updated: September 5, 2026 Contact: support@mommyslittlepartyplanner.com
This Privacy Policy explains how Protocol Media LLC ("Protocol Media," "we," "us," or "our") collects, uses, discloses, retains, and protects personal information when you use the Mommy's Little Party Planner mobile app, websites, public guest pages, support channels, and related services (the "Service").
Host accounts, party-management tools, and purchases are intended for adults who reside in the United States, the District of Columbia, or Puerto Rico. Invited guests may use shared guest links from other locations where lawful.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. Our optional first-party product analytics are off unless the account holder turns them on. The public website may use the cookie-free, anonymized website analytics described below.
1. Information we collect
Depending on how you use the Service, we collect:
- Account and legal acceptance information: email address, optional display name, password hash or social sign-in identifier, session records, language, age and service-territory confirmations, and records showing when you accepted the Terms and Privacy Policy. Historical records may retain a previously selected U.S. or Puerto Rico market.
- Google sign-in: Google handles account and technical information when you use its sign-in service in the native iOS app, including your IP address, which Google may use to estimate a general area for fraud prevention. Google's sign-in component also declares collection of device identifiers and usage information for analytics. Our optional in-app analytics setting controls our own product analytics; it does not turn off Google's sign-in data processing. The app does not request GPS or device-location permission. Google's Privacy Policy is available at https://policies.google.com/privacy.
- Party planning information: child first name or nickname, age, party date and time, theme, venue name and physical street address, budgets, checklists, itineraries, shopping lists, wishlists, invitation text, notes, and thank-you content. A venue address may be a home, business, or other event location entered or selected by the host; the app does not require the device's location.
- Guest and contact information: guest and parent names, child and sibling first names, email addresses, phone numbers, RSVP status, headcounts, ages, gift information, notes, and other information a host, co-host, or guest chooses to provide.
- Consumer health data: allergy and dietary information voluntarily entered for party planning. Our separate Consumer Health Data Privacy Notice describes this data and the related rights and choices.
- Contacts you choose to import: before a device-contact flow begins, the app explains what will be uploaded and asks for affirmative consent. On iOS, Apple's system picker lets you choose one contact at a time without giving the app general access to the address book. On Android, the device may ask for contacts permission so you can browse locally. When you add a chosen contact to a guest list, the contact's name, one phone number, and one email address, when available, are uploaded to our servers and saved with the party. We use those fields to manage the guest list, sync it across the host's devices, reuse guest details in Family Circle, support invitations and RSVPs, and make the party available to authorized co-hosts. We do not upload unselected contacts or the full address book, and we do not write changes back to device contacts. In the date-poll contact flow, only the chosen name is uploaded if the host creates the poll; the phone number remains on the device for an individual Messages handoff and the email address is not sent. If the host later converts poll participants into party guests, the app separately discloses that their saved names and phone numbers will be uploaded for the guest-list purposes above and asks for affirmative consent before doing so.
- Photos and uploaded files: party-album photos, guest-contributed photos, Highlight Reel media, invitation photos or rendered invitation images, private thank-you memory photos, and related media that a host or guest chooses to upload. Media selected for a cloud party, invitation, album, reel, or thank-you memory is uploaded through a signed upload flow to our configured cloud object storage, such as Supabase Storage, and associated metadata is stored on our servers. A guest-contributed album photo remains in a private host-review queue and is not added to the shared party album unless the host approves it. Depending on the feature, approved or host-provided media can then be shown to the host, authorized co-hosts, and intended guests who use the applicable private shared link. An invitation card or thank-you image that you choose only to save or export is written to the device destination you select; saving it locally does not by itself upload that exported copy.
- Purchases and entitlements: product, subscription, Party Pass, transaction status, and entitlement information from Apple and RevenueCat. Apple App Store purchases are the only purchase path currently offered by the Service. We do not currently offer web checkout or accept new purchases through Stripe, and we do not receive full payment-card numbers.
- Optional address searches: venue or physical-address text typed into address autocomplete is sent to Geoapify or the configured map provider to return suggestions. A selected or manually entered venue address is saved with the party on our servers and may be displayed to authorized co-hosts and intended guests through the party's invitation or other shared feature. Precise device location is not required or collected for this feature.
- Support and communications: email address, message contents, attachments provided to support, and an optional account-bound record when you join the vendor-directory launch email list.
- Security and technical data: IP address, request time, route, user agent, app version, device type, locale, time zone, authentication status, logs, errors, and security events. For guest-photo abuse prevention, the installed app also creates a random identifier kept in protected app storage. It is not derived from hardware, an Apple or Google account, contacts, or photo metadata. We associate it only with guest-photo submissions and party-specific uploader blocks.
- Public website analytics: when enabled, Vercel Web Analytics records anonymized page views, referring pages, approximate geography, browser, operating system, and device category without using cookies. We do not send party content, guest details, contact information, allergies, photos, or message text to website analytics.
- Optional first-party analytics: if the account holder opts in, a first-party random identifier and product-interaction events such as screens or features used. We instruct the app not to include party content, names, contacts, addresses, allergies, photos, or message text in analytics.
We collect information from account holders, guests, co-hosts, the devices they use, service providers involved in transactions or sign-in, and automatically from requests made to the Service.
2. How we use information
We use information to:
- create and secure accounts;
- provide party planning, syncing, invitations, RSVP, reminders, wishlists, photo, co-hosting, and related features;
- save the name, one phone number, and one email address from contacts a host affirmatively chooses for a guest list, so those guest details can sync across the host's devices, support invitations and RSVPs, be reused in Family Circle, and be available to authorized co-hosts managing the same party;
- store and deliver photos and invitation media that a host or guest affirmatively chooses to upload;
- display information to the host, authorized co-hosts, or guests as required by the feature they use;
- process and restore purchases and entitlements;
- provide optional address suggestions and deterministic planning suggestions;
- send transactional emails or reminders requested or scheduled by a host;
- send the one-time vendor-directory launch email when an account holder explicitly joins that list;
- answer support and privacy requests;
- place guest photos into host review before album sharing; support host approval, rejection, party-specific uploader blocking, and exact-photo safety reports;
- detect fraud, spam, abuse, security incidents, and service failures;
- maintain, debug, and improve the Service; and
- comply with law and enforce our Terms.
We do not use consumer health data for advertising, profiling, data brokerage, or unrelated product development.
3. Public and shared links
Hosts can create RSVP, wishlist, photo-upload, poll, private Highlight Reel, and shared-plan links. These links are designed to be difficult to guess, but anyone who receives or is forwarded a link may be able to access the information displayed through it. Hosts are responsible for sharing links only with intended recipients.
Public link previews use generic party language and do not intentionally display a child's name, age, venue, or custom invitation image. Published invite links expire after the party date plus approximately 30 days. Deleting the associated party invalidates its shared links sooner.
4. How we disclose information
We disclose information only as needed to provide the Service, complete a transaction, follow a user's instruction, comply with law, or protect rights and safety.
Recipients may include:
- hosts and authorized co-hosts managing the same party;
- guests using a shared party feature;
- Vercel and other hosting or security providers;
- Supabase and cloud database or object-storage providers;
- Resend and other transactional email providers;
- Apple and RevenueCat for the App Store purchases and entitlements currently offered by the Service;
- Google or Apple for social sign-in;
- Geoapify or the configured address-search provider;
- professional advisers, regulators, courts, law enforcement, or other parties when legally required or reasonably necessary to protect the Service, users, or others; and
- a successor involved in a merger, financing, reorganization, bankruptcy, or sale of all or part of the business, subject to applicable law.
We do not sell personal information or consumer health data. We do not share personal information for cross-context behavioral advertising.
5. Retention
We retain information only for as long as reasonably necessary for the purposes described above:
- Account information is retained while the account is active and removed when the account is deleted, subject to limited legal and transaction-integrity records.
- Selected contact fields are retained as part of the party and related Family Circle information while the relevant records remain active. Removing a guest from one party removes that guest from that party after synchronization, but does not remove the same person's information from another party where it was separately saved. Hiding someone from Family Circle does not erase that person's details from past parties. A host can edit or delete the relevant party records, delete the account, or contact us to request deletion of eligible contact information.
- Active party records are retained while needed by the account holder. When a party is deleted, its substantive planning content is scrubbed from the active server record immediately; a minimal deletion tombstone may remain for up to 30 days so other devices and co-hosts can process the deletion.
- Published invite data, guest RSVPs, allergy information, wishlist claims, and related public-link records expire and are deleted after the party date plus approximately 30 days, unless the associated party is deleted sooner.
- Optional first-party analytics events are retained for up to 90 days.
- Sessions expire after approximately 60 days. Password-reset codes expire after 30 minutes.
- Completed, cancelled, failed, or skipped reminder job records are generally removed after 30 days.
- Managed uploaded files are deleted when the associated party, invite, or account is deleted. If immediate storage cleanup fails, access is revoked and deletion is retried.
- Pending guest-photo submission records and party-specific blocked-uploader identifiers are retained with the published party link and are deleted when that link expires or the associated party is deleted. The random identifier in protected app storage is a non-account abuse-prevention control: logout, account switching, and account deletion do not clear it, because clearing it would let a blocked uploader resume by changing accounts. It is not used to reconstruct a deleted account.
- Limited purchase, tax, accounting, fraud-prevention, security, dispute, and transaction-integrity records may be retained for the period reasonably required by law or legitimate business need.
Backups may take additional time to cycle out, but deleted information is not restored to active use except when necessary for disaster recovery, security, or legal compliance.
6. Your choices and privacy rights
All users may request access, correction, deletion, or a portable copy of eligible personal information by emailing support@mommyslittlepartyplanner.com. You may also:
- edit or delete party and guest information in the app;
- delete an account from the Account screen;
- decline the in-app contact-upload consent and add guests manually instead;
- join or leave the vendor-directory launch email list from the Vendors screen;
- change contacts, camera, and photo permissions in device settings;
- turn our optional first-party analytics on or off from the Account screen;
- delete a party to invalidate its guest links;
- as a host, approve or reject each pending guest photo, block further submissions from that app installation for that party, remove an approved photo, or report an exact photo to support;
- withdraw consent for future collection or sharing of consumer health data and request deletion of that data; and
- manage a subscription through Apple.
State law may provide additional rights. See our Privacy Choices page and Consumer Health Data Privacy Notice. We will not discriminate against you for exercising a privacy right. We may need to verify your identity and authority before completing a request. If we deny a request, you may appeal by replying to our decision with the subject "Privacy Appeal."
7. Children and child-related information
The Service is designed for adult parents, guardians, caregivers, and hosts planning kids' parties. It is not intended for users under 18. Only adults aged 18 or older may create host accounts, manage parties, or make purchases. Guest pages are intended for adult invitees responding on behalf of their families; a parent or guardian should enter and submit information about a child. A child's name, birthday, or age describes the celebration and does not create a child account.
Parents, guardians, and hosts may provide child-related party information. The person providing that information represents that they have authority to do so and is responsible for choosing what to share. If you believe a child submitted personal information without appropriate adult involvement, contact us and we will investigate and delete eligible information.
8. Security
We use administrative, technical, and organizational safeguards designed for the nature of the information we process, including encrypted network transport, salted password hashes, access controls, rate limits, expiring sessions and links, and restricted server-side database access. No system is perfectly secure, and we cannot guarantee absolute security.
9. U.S. processing and service territory
Protocol Media LLC is based in South Carolina. Information is processed in the United States and in other locations where our service providers operate. Host accounts, party-management tools, and purchases are currently offered only to residents of the United States, the District of Columbia, and Puerto Rico. Invited guests may use shared guest links from other locations where lawful.
10. Changes
We may update this Policy to reflect changes to the Service, our practices, or legal requirements. We will update the date above and provide additional notice when appropriate. If a change requires renewed consent, the app will ask for it before continued account use.
11. Contact
Email privacy questions, requests, or appeals to support@mommyslittlepartyplanner.com. Include the email associated with the account or enough information for us to identify the relevant guest submission. Do not send passwords or full payment-card numbers.