Privacy Policy for the Use of CelebrationBase
Effective as of July 2026
Privacy at a Glance
The following notes provide a simple overview of what happens to your personal data when you visit this website.
End-to-End Encryption:
This Web App pursues a strict “zero-knowledge” approach. The personal content of Invitations is encrypted directly
on your device before being transmitted to our servers. We have no technical way to read, moderate, or attribute
this encrypted content to specific individuals. Your private data remains private.
General Information and Legal Obligations
Subject Matter of the Application
Through the CelebrationBase application (hereinafter “Web App”), users can create, manage, access, view, and use the features of a digital Invitation. Access to an Invitation is granted exclusively via a specifically generated Invitation link in combination with the corresponding authentication data (password). The term “Web App” covers all forms of provision and access channels, regardless of the device used, including, in particular, direct access as a website via a browser. In this Privacy Policy, a digital Invitation is collectively referred to as an “Invitation” regardless of its specific content (e.g., even if it consists solely of a wishlist).
Who is responsible for data processing?
The party responsible for data processing on this Web App is:
Leonard Scholz
CelebrationBase
Wilhelmstraße 74
38100 Braunschweig
info@celebrationbase.com
Your Rights as a Data Subject (GDPR)
Under the General Data Protection Regulation (GDPR), as a user of this website, you are entitled to comprehensive rights that you can assert against us at any time. You have the right to request free information regarding whether and what personal data we have stored about you. Likewise, you can demand the correction of inaccurate data, the restriction of processing, or the complete deletion of your data. If you have granted us consent, you can informally revoke it at any time with effect for the future. You also have the right to lodge a complaint with a competent data protection supervisory authority.
Special Note on Anonymity (Art. 11 GDPR): Since this Web App is designed to be used without registration and all Invitation content is end-to-end encrypted, the data stored on the servers is anonymous to us. Under normal operation, we cannot attribute it to any real person. Technically, we can therefore only fulfill your rights to access or deletion if you provide us with additional information during a contact attempt (e.g., via support email) that enables unambiguous identification.
Your Legal Right to Object (Art. 21 GDPR)
IF WE PROCESS DATA BASED ON OUR LEGITIMATE INTERESTS (PURSUANT TO ART. 6 (1) (F) GDPR), YOU HAVE THE RIGHT TO OBJECT TO THIS PROCESSING AT ANY TIME FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION. IF YOU OBJECT, WE WILL STOP PROCESSING YOUR DATA UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR FURTHER PROCESSING THAT OVERRIDE YOUR RIGHTS, FREEDOMS, AND INTERESTS.
Infrastructure, Performance & Security (Collaboration with Cloudflare)
To ensure this Web App can be loaded, protected, measured, and secured against abuse, we use external infrastructure services operating at both the server and client levels. For this purpose, we collaborate with Cloudflare Inc. (101 Townsend St., San Francisco, CA 94107, USA). Data processing is carried out on the basis of a Data Processing Addendum (DPA). Data transfers to the USA are based on the Standard Contractual Clauses (SCCs) of the EU Commission (the company is certified under the EU-US Data Privacy Framework).
Secure Data Transmission (HTTPS) & Protection at Rest (Encryption at Rest)
To optimally protect the confidentiality of your data, this website enforces modern transport encryption using SSL/TLS (HTTPS) for every visit. You can recognize that the connection is encrypted by the lock symbol in your browser’s address bar and the “https://” prefix. This process prevents the data stream between your device and our systems on the internet from being intercepted or manipulated by third parties.
Furthermore, all datasets stored on our server provider’s infrastructure (Cloudflare) in databases such as Durable Objects are consistently stored encrypted at rest (Encryption at Rest).
Terminology Regarding End-to-End Encryption: When certain variables, protocols, or log files are referred to below as “non end-to-end-encrypted”, these data are naturally fully encrypted during transport (HTTPS) and storage (Encryption at Rest) in accordance with current industry standards. In this document, it merely means that no end-to-end encryption is present for these data, as we or the server provider must technically access these data to execute the app logic. Systemically, the only genuinely “unencrypted” data in the entire chain are metadata from traditional communication channels, such as the subject line in emails.
Important Security Note on End-to-End Encryption
Client-side end-to-end encryption effectively protects your data from unauthorized access during transit and on our servers. However, the security of this procedure stands and falls with the secrecy of your authentication data and the security of your device.
Please note that the protection scope of encryption ends at your browser’s interface. If your device is infected with malware (e.g., keyloggers), unauthorized third parties have access to your device, or potentially insecure or compromised browser extensions (add-ons) are active, data can be intercepted prior to encryption or following decryption within the browser. Securing the device and browser you use, and keeping the authentication data confidential are solely your responsibility.
Cloudflare (Infrastructure, CDN & Security Filter)
Data traffic between your browser and our server is routed through Cloudflare’s globally distributed network. This serves to deliver app files quickly (Content Delivery Network) and protects our application from potentially malicious traffic or overload (e.g., DDoS attacks). Cloudflare may also use technically necessary cookies to recognize internet users.
In the course of this process, the infrastructure automatically collects technical telemetry data (edge protocols / Workers logs) that your browser inherently transmits. This includes: browser type and version, operating system used, the website from which you visited us (referrer URL), the exact date and time of the request, and your IP address. These log data are not merged with other data sources.
Legal Basis: Our legitimate interest in providing a secure, stable, and error-free web offering (Art. 6 (1) (f) GDPR).
Retention Period: Transient data in pure network traffic are processed ephemerally. Log data used for error analysis and defense against cyberattacks are completely and irreversibly deleted by the system after 14 days at the latest (pure performance and access logs often automatically after 3 to 7 days).
Cloudflare Turnstile (Bot and Spam Protection for Forms)
We use Cloudflare Turnstile to prevent automated creation of Invitations by bots (spam). Turnstile is a privacy-friendly alternative to traditional CAPTCHAs. In the background, it analyzes your browser’s behavior (e.g., IP address, duration of stay, or mouse movements) without requiring you to solve tedious image puzzles. The collected technical data are forwarded to Cloudflare.
Legal Basis: Our legitimate interest in protecting the Web App from overload and abuse (Art. 6 (1) (f) GDPR).
Retention Period: The data are evaluated only for the immediate validation process of the session, lasting just seconds, and are subsequently deleted within a few weeks.
Cloudflare Web Analytics (Privacy-Friendly Performance Measurement)
This is a hybrid analytics solution: A minimal JavaScript snippet is executed in your browser (client) to measure purely technical performance data (e.g., how fast the app loads, which pages are accessed, the browser type used, and the country of origin based on an anonymized IP address). These data are transmitted to Cloudflare and aggregated there.
The tool operates entirely without cookies and does not store any information on your device (no local storage). No tracking takes place across different websites, and no user profiles are created. Your identity remains completely anonymous.
Legal Basis: Our legitimate interest in statistical evaluation to optimize the stability and user-friendliness of our Web App (Art. 6 (1) (f) GDPR).
Retention Period: As no personal raw data or IP addresses are permanently stored, but rather directly aggregated, only anonymous statistical key metrics remain on the servers.
Use of the Web App: What Data Are Processed Server-Side?
When using our Web App, our server strictly distinguishes between content that is completely unreadable to us and purely technical data that we must process to provide the service.
A. End-to-End-Encrypted Content (Content Data)
All personal content of your Invitations (e.g., texts, gift titles, links, descriptions) is encrypted client-side (in your browser). It is stored on our servers as unreadable gibberish. Neither we nor third parties have access to this data.
Legal basis: The processing and storage are necessary for the performance of the Web App’s Terms of Use (Art. 6 (1) (b) GDPR) and on the basis of our legitimate interest in providing a privacy-friendly and anonymous service (Art. 6(1)(f) GDPR).
Retention Period: This encrypted data remains on the server until the specified deletion date is reached or you manually delete the list. Upon expiration, it remains in internal server backups for a maximum of 30 days before being permanently overwritten.
B. Non End-to-End-Encrypted Data (Technical Data)
In order to control the app logic server-side, protect the application from abuse, and enable synchronization, certain technical structural data, metadata and variables must be transmitted to our database and processed there. These data are technical in nature and do not allow us to draw conclusions about your person or the private content of your Invitation.
The following technical data are processed server-side:
- Invitation ID: A unique string identifying the Invitation (the random string you see in the Invitation link) so the server knows which encrypted dataset to serve to the browser.
- System Metadata: We log the website version at creation, a short designation of the processing Cloudflare edge server (region), and a flag indicating whether an Invitation was modified after initial creation. These data serve exclusively for monitoring and optimizing our automated security and bot defense measures.
- Cryptographic Salt: A value uniquely and randomly generated for each Invitation. This is transmitted to your browser to secure the client-side encryption process and technically prevent precomputed table attacks (rainbow tables).
- Technical Structural Data of the Invitation: This includes information about the type and the sequence of Invitation modules used, internal IDs for error-free entry assignment, and the internal version number of the dataset. These structural data contain no personal content whatsoever; they purely serve server-side technical operations upon user request (e.g., for user-specific data delivery and data synchronization during user edits).
- Pseudonymous User and Authentication Data: To manage access permissions, we process internal, pseudonymous user IDs and assigned roles (e.g., guest or host). For authentication, we exclusively use cryptographic values (hashes) derived from passwords. These values are mathematically strictly separated from the encryption keys. They never allow us to infer your actual password and provide the server with no access whatsoever to the end-to-end-encrypted content data.
- Specified Deletion Date: An automatically calculated date, adjustable by the host, on which the
entire dataset is irrevocably deleted from the servers.
Protection Against Timing Attacks (Jittering): To prevent inferences about the exact creation time of an Invitation from being drawn via the specified deletion date, we add a random time offset (so-called noise or “jittering”) to the regular duration. The date of the celebration is unrelated to this and resides fully protected within the end-to-end-encrypted scope.
Legal Basis: Processing these technical data is necessary for the performance of the Web App’s Terms of Use (Art. 6 (1) (b) GDPR), as well as to safeguard our legitimate interests in IT security and service stability (Art. 6 (1) (f) GDPR).
Retention Period: These technical data remain on the server until the specified deletion date is reached or you manually delete the list. Upon expiration, they remain in internal server backups for a maximum of 30 days before being permanently overwritten.
Local Storage on Your Device
To ensure this Web App functions without traditional registration, works offline, and features true end-to-end encryption, we utilize your browser’s local storage technologies (IndexedDB, Local Storage, and Session Storage). Data is stored directly on your device. Automated transmission of this local data to our servers does not occur.
Legal Basis: Storage of this information is carried out on the basis of Section 25 (2) No. 2 TDDDG (Telecommunications Digital Services Data Protection Act). This storage is technically strictly necessary to provide the service explicitly requested by you (the use, navigation, and management of encrypted Invitations). A separate cookie consent banner is therefore not required, as no tracking or marketing purposes are pursued.
We divide local storage into two categories:
A. Data Tied to the Lifespan of the Invitation
These data generally remain on your device only for as long as the respective Invitation exists on the server (specified deletion date) – with the exception of the master key, which can additionally be cleared by logging out or closing the tab:
- Cryptographic Master Key: This is a mathematical derivation of your personal password. This key is used to authenticate you to the server and encrypt/decrypt content data directly in the browser. Depending on whether you checked the option (“Remember login credentials?”) upon login, this key is stored either ephemerally for the duration of the session (Session Storage – automatically cleared when closing the tab) or persistently (Local Storage – until you manually log out). This prevents you from having to re-enter your authentication data every time the page loads.
- Cryptographic Fingerprint: An identifier derived from the master key. It serves to accurately identify the local dataset associated with you within browser storage.
- Cryptographic Salt: A random value uniquely generated for each Invitation, required for the client-side encryption process to maximize security and defend against precomputed table attacks (rainbow tables).
- Encrypted Content Data: The actual contents of the Invitation are cached locally in fully encrypted form. Reading or decrypting this data is only possible on your device using the master key stored there.
- Specified Deletion Date: An automatically calculated date, adjustable by the host. It is kept locally to trigger automated browser-side cleanup of local data once validity expires.
B. Cross-Cutting Data Remaining Beyond the Lifespan of the Invitation
Certain purely functional variables remain in your browser’s persistent storage (IndexedDB / Local Storage) to maintain user-friendliness, enable navigation, and display correct status offline even after deletion:
- Invitation ID: The unique string you see in the Invitation link. It remains in local storage to uniquely identify and map the associated dataset within your browser.
- Server Timestamp (Time of Data Provision): The timestamp transmitted by the server at the time of the last data query. Persistent storage of this value on your device is technically required to accurately identify the most recent data state when multiple diverging datasets exist on the same device, ensuring the browser displays the correct, newest information (preventing stale data rendering). As a functional secondary feature, this existing value is also used to chronologically list locally logged-in users.
- Invitation Status States (Server Response): We store the last known technical status of the Invitation (e.g., “exists”, “deleted on server”, or “error”). This ensures that the Web App in the browser can display the correct state without delay and fully offline, even if the server is temporarily unreachable.
- Selected Language: The language used during creation or manually changed within the application. This setting is stored across Invitations so that future app launches automatically start in your preferred language.
Manual Deletion: You can remove all data specified in Sections A and B at any time in your browser’s security settings.
Contact Form & Support Requests (Central Storage at Mailfence)
When you send us a message, we process your information exclusively to handle your support request.
Central Storage Location: All support requests – regardless of whether they arrive via the contact form or as a direct email – converge in our inbox at the privacy-focused email provider Mailfence (ContactOffice Group, Belgium) and are stored there. Under no circumstances are messages deposited in a separate app database on our server. Depending on which channel you use, different levels of encryption apply:
A. Use of the Contact Form (Hybrid Encryption)
Our contact form converts your input into an encrypted email in the background and forwards it to our Mailfence inbox. The location where encryption takes place depends on the technical capabilities of your browser:
Important Note on Form Metadata:
Regardless of where encryption occurs, the subject line of the email generated in the background always remains
unencrypted on the internet due to technical protocol constraints. We therefore use a fixed,
predefined subject line for the form (e.g., “Support request via contact form”). This guarantees that none of your
personal input ends up in the unencrypted subject line.
- Standard Case (With Active JavaScript): Your message is encrypted via PGP directly on your device (client-side). Our server receives only this unreadable gibberish and forwards it to Mailfence. You can attach your own public PGP key so that we can reply to you in encrypted form. Using this method, no server has insight into your message at any time.
- Fallback Case (Without JavaScript / Technical Errors): Should JavaScript be disabled, your
message is transmitted to our server via the encrypted HTTPS connection. The server encrypts the message using
our PGP key after receipt (server-side) and forwards it. The message is never stored on our server or used for
any other purpose.
Security Note on this Fallback: Because PGP encryption takes place on the server here, the server provider is technically capable of viewing the contents of the message during the millisecond of processing (even though the transit path is protected via HTTPS). For maximum security, we therefore recommend enabling JavaScript or using direct PGP email communication.
B. Direct Email Contact
If you do not wish to use the form and instead write us a traditional email directly, security depends on the transit path:
- Standard Email: Although a standard email is secured via standard procedures (transport encryption in transit and server-side encryption during storage), it remains technically possible for third parties (e.g., participating email providers) to view the content. Therefore, this route is not recommended for sensitive data.
- Full End-to-End Encryption via PGP: For maximum confidentiality, you can encrypt your email
directly using our public PGP key (which we provide on the website) before sending it. In this case, please
attach your own public PGP key.
Important Security Note on PGP Metadata: With PGP encryption, technical protocol limitations dictate that only the actual message body and any file attachments are encrypted. Metadata such as sender, recipient, and the subject line remain visible as plain text in unencrypted form across the internet. Therefore, please never write sensitive or personal data into the subject line of your email!
Legal Basis: Art. 6 (1) (b) GDPR (insofar as your inquiry is necessary for the performance of a contract or pre-contractual measures) or Art. 6 (1) (f) GDPR (our legitimate interest in effective, secure, and privacy-optimized support processing).
Retention Period for Support Requests: We delete support messages accumulated in the Mailfence inbox (both from the form and from direct email contact) as soon as the inquiry has been conclusively answered and the matter resolved – at the latest, however, after 6 months, unless statutory retention obligations (e.g., tax or commercial law requirements for business correspondence) require longer storage.