Birthday Planner

Privacy

Last updated 8 August 2026

Birthday Planner holds information about children, and about guests who never signed up for anything. That deserves a plain description rather than a page of hedging, so this is written to be read.

What we collect

From you, the host: your email address and name from your sign-in provider, and whatever you enter about the party — the birthday child’s first name and age, the date, the venue or suburb, your budget, and your plan.

From your guests: whatever they put in the RSVP form. That is typically a name, how many adults and children are coming, arrival time, and — where they choose to tell you — dietary requirements and allergies. Guests do not need an account, and we do not create one for them.

Photographs, if you or your guests upload them to a party album. These frequently show children who are not yours.

Payment records, if you subscribe: your subscription status and invoice history. Card numbers go to Stripe and never reach our servers.

Health and allergy information

Allergy and dietary information is sensitive health information under Australian privacy law. We collect it only because a birthday party with a nut allergy in the room is a real risk, and only because a guest typed it in. It is shown to the host of that party and used to flag conflicts in the menu and shopping list. It is not used for anything else, and it is deleted with the party.

How long we keep it

Photographs are deleted two years after upload. This is enforced by a job that runs hourly, not by a note in a document — every photo row carries an expiry date and a sweeper removes the file and the record when it passes.

Party data stays until you delete it or close your account. Delete a party and its guest list, RSVPs and photos go with it.

Payment records are kept for seven years, because Australian tax law requires it. This is the one category we cannot delete on request.

Who else sees it

We use a small number of processors, and no advertisers:

  • Clerk — sign-in. Holds your email address.
  • Stripe — payments. Holds your card and billing details; we never see the card number.
  • Neon — the database, hosted in Sydney.
  • Cloudflare R2 — photo storage.
  • OpenAI — party planning, when you use it. Sent: the child’s first name, age, theme, guest count and budget. Not sent: your guest list, email addresses, allergy details or photographs.
  • Open-Meteo — weather. Sent: the suburb or town name you typed.
  • Google Analytics — how many people find the site and which pages they read. Runs on the public pages and on your own account pages. It does not run on invitations, photo albums or guest passes, so a page carrying a child’s name is never reported to it.

We do not sell your data, and we do not share guest lists with anyone. There is no advertising on this service.

Cookies and analytics

Two things set cookies here. Signing in sets one, because that is what keeps you signed in. Google Analytics sets one so that a person who reads two pages is counted once rather than twice.

What analytics records is the page address, the page title, roughly where in the world the request came from, and what kind of device it was. It is how we know whether anybody is reading the party cost guide. We have not turned on advertising features, remarketing or any of Google’s signals products, and there are no advertising trackers on this site.

It does not run on the pages a guest is sent to. Invitations, shared albums and guest passes carry no analytics at all, and that is enforced in the code rather than promised here — an invitation’s page title is a child’s name and age, and it is nobody else’s business how many people opened it.

If your browser sends “Do Not Track”, the analytics tag is not loaded at all. Google Analytics does not act on that signal by itself, so this is something we check before loading it rather than something we rely on Google to do. A content blocker has the same effect, and nothing on the site breaks either way.

Photographs of other people's children

If you share an album link, anyone with that link can upload to it and see what is there. Treat it the way you would treat a group chat: send it to the parents who were at the party, not to a public page.

Any parent can ask us to remove a photograph of their child, whether or not they uploaded it and whether or not they have an account. Email the address below with the album link and we will remove it. You do not have to explain why.

Your rights

You can ask for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Email us and we will respond within 30 days. If you are unhappy with how we handle a request you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.

Contact

← Back to home · Terms