Plain Summary
This Policy explains how CelebrateSync and HostHaven may use cookies, analytics, service messages, invitations, SMS, email, push notifications, in-app messages, marketing communications, affiliate links, sponsored placements, ads, and consent controls.
Operational messages may be used to provide the Services, such as account alerts, security messages, event invitations, RSVP reminders, event updates, QR/check-in information, service notices, and support communications.
Optional marketing, promotional messages, targeted advertising, promotional media use, contacts/calendar access, location-based features, AI personalization, or similar optional processing will require separate consent or preference controls where required.
At initial launch, targeted advertising, behavioral retargeting based on private Event Data, paid Spark Points, supplier-payment promotions, and undisclosed sponsored ranking are not enabled unless separately reviewed, approved, and released.
This summary is provided for convenience only. The full Policy governs.
1. Purpose and Scope
This Cookie, Marketing, Messaging, Affiliate, Ads, and Consent Policy governs cookies, pixels, SDKs, analytics, tracking technologies, SMS, email, push notifications, in-app messaging, invitations, reminders, event announcements, sender names, messaging credits, delivery limits, unsubscribe and opt-out controls, marketing permissions, affiliate disclosures, sponsored placements, advertising limits, consent records, and messaging-abuse enforcement.
This Policy applies to CelebrateSync, HostHaven, the Supplier Network, public pages, event workspaces, RSVP tools, QR passes, guest communications, supplier communications, app notifications, websites, web applications, and related Services.
This Policy should be read together with the Terms of Service, Privacy Notice and Data Rights Policy, Privacy Notice Acknowledgment and Consent Form, Community, Content, Child Safety, IP, and Enforcement Policy, Account Deletion and Retention Policy, Media Terms, Supplier Network and Public Trust rules, Review Guidelines, Spark Points Program Terms, App Permission Disclosures, and any applicable Event-specific or feature-specific rules.
2. Categories of Communications
CelebrateSync may support different categories of communications, including:
Account and security messages Event invitations RSVP requests and reminders Event updates and schedule notices QR pass and check-in communications Organizer-to-guest announcements Supplier or staff coordination messages Customer support messages Billing and platform-fee notices Privacy, legal, and policy notices Optional marketing or promotional messages Push notifications In-app notifications Email messages SMS or similar mobile messages
The rules that apply may depend on the sender, recipient, communication channel, Event context, user role, consent status, legal basis, and feature used.
3. Operational Messages
Operational messages may be sent where reasonably necessary to provide, secure, administer, support, or maintain the Services.
Operational messages may include account verification, password or authentication notices, security alerts, service updates, Event invitations, RSVP reminders, schedule changes, Event announcements, QR pass or check-in information, support replies, billing notices for platform fees, legal notices, privacy notices, and other messages related to the User’s use of the Services.
Users may not be able to opt out of certain essential operational, security, legal, or account-related messages while continuing to use the relevant Service.
4. Event Invitations and Organizer-Controlled Messaging
Event Organizers may use the Services to send or manage Event-related invitations, RSVP requests, reminders, announcements, guest updates, program notices, seating notices, check-in instructions, or other Event communications.
Where the Organizer determines the recipients, message content, Event purpose, or contact list, the Organizer may be responsible for having the lawful basis, authority, consent, relationship, or permission required to contact the recipients.
CelebrateSync may provide the technology platform used to send or manage such communications, but this does not mean CelebrateSync independently verifies every contact list, relationship, invitation, or message unless a review process is expressly provided.
5. Organizer Warranty and Contact-List Responsibility
The Organizer represents and warrants that:
The Organizer has a lawful basis or authority to upload, import, or use recipient contact information. The Organizer will use messaging features only for legitimate Event-related purposes. The Organizer will not use purchased, rented, scraped, harvested, unauthorized, misleading, or unlawfully obtained contact lists. The Organizer will honor opt-outs, suppression requests, and recipient objections where required. The Organizer will not use CelebrateSync or HostHaven to send spam, phishing, scams, harassment, threats, unrelated marketing, or bulk non-Event communications. The Organizer will provide accurate sender, Event, and contact information.
The Organizer remains responsible for the legitimacy of its contact lists, Event communications, and instructions to the platform.
6. User-Initiated and Role-Based Messages
Certain messages may be sent by or on behalf of Users, Organizers, staff, suppliers, coordinators, hosts, photographers, media operators, security personnel, parking personnel, volunteers, or other role holders.
Role-based messaging access must be used only for the assigned Event function. A role holder must not copy, export, reuse, sell, disclose, or contact guests, suppliers, staff, or other persons outside the authorized Event purpose.
The Operator may restrict role-based messaging access where misuse, privacy risk, spam, harassment, impersonation, security abuse, or Event-privacy violation is suspected.
7. Prohibited Messaging
Users, Organizers, suppliers, and role holders must not use the Services to send, facilitate, or attempt to send:
Spam or unsolicited bulk messages Unrelated marketing Purchased, rented, scraped, harvested, or unauthorized contacts Phishing, scams, malware, or malicious links Credential-harvesting messages Impersonation or deceptive sender names Harassment, threats, intimidation, blackmail, or extortion Messages exploiting minors or vulnerable persons Non-consensual intimate media or threats to share such media Fake Event invitations Fraudulent supplier offers False payment or refund claims Bulk non-Event messages Messages designed to evade rate limits, blocks, suppression lists, or opt-outs
The Operator may restrict or disable messaging features where prohibited messaging is suspected.
8. SMS Credits and Paid Messaging Features
Where SMS credits, messaging credits, or paid messaging features are enabled, they may be prepaid, limited to authorized channels, non-transferable, subject to usage rules, and subject to delivery limitations.
Purchase terms should disclose the amount of credits purchased, price, applicable taxes or charges, expiration rules where applicable, refund rules, permitted use, prohibited use, delivery limitations, and any material feature limits.
SMS credits do not guarantee successful delivery, recipient reading, RSVP completion, attendance, sales, supplier booking, or any Event outcome.
SMS credits may be restricted, suspended, reversed, or forfeited where permitted by law and applicable terms if used for spam, fraud, abuse, illegal activity, evasion, harassment, or unauthorized contact lists.
9. Delivery Limitations
SMS, email, push, in-app, and other message delivery may depend on third-party providers, telecommunications carriers, email providers, spam filters, app permissions, device settings, network availability, recipient device state, phone number or email validity, recipient preferences, suppression lists, rate limits, outages, legal restrictions, and other factors outside the Operator’s full control.
The Operator does not guarantee that every message will be delivered, opened, read, displayed, or acted upon.
The Operator may delay, throttle, block, suppress, or refuse messages where necessary for security, legal compliance, provider compliance, abuse prevention, deliverability protection, system integrity, or user safety.
10. Opt-Outs, Unsubscribes, and Suppression
CelebrateSync may provide opt-out, unsubscribe, notification settings, suppression, preference-management, or support-assisted controls where appropriate for the message type and channel.
Users may be able to opt out of optional marketing or promotional communications. Users may also manage push notifications or app permissions through device settings.
Certain operational, security, legal, billing, account, or Event-essential messages may continue where reasonably necessary to provide the Services, protect security, comply with law, or administer an active Event.
The Operator may maintain suppression records or opt-out logs to honor communication preferences and prevent re-contact where appropriate.
11. Cookies and Similar Technologies
CelebrateSync may use cookies, pixels, SDKs, local storage, device identifiers, log files, analytics tools, and similar technologies for Service operation, authentication, security, fraud prevention, session management, preferences, performance, diagnostics, analytics, product improvement, and legally permitted communications.
Some cookies or technologies may be necessary for the Services to function. Others may be optional, such as certain analytics, advertising, personalization, or marketing technologies.
Where required, CelebrateSync will provide notice, consent, opt-out, or preference controls for optional cookies or tracking technologies.
12. Analytics and Product Improvement
CelebrateSync may use analytics to understand usage patterns, diagnose technical issues, improve features, measure performance, prevent abuse, and maintain platform quality.
Analytics should be configured in a privacy-conscious manner appropriate to the feature, data category, user role, Event privacy setting, and applicable law.
Private Event Data should not be used for targeted advertising or behavioral retargeting at launch unless separately reviewed, approved, disclosed, and supported by required consent and platform controls.
13. Marketing Communications
CelebrateSync may send marketing communications only where permitted by applicable law and platform policy.
Marketing communications may include newsletters, promotional updates, feature announcements, service offers, partner offers, event-tool promotions, paid upgrades, storage upgrade offers, or other commercial communications.
Where consent is required, CelebrateSync will request consent through a separate mechanism or provide an appropriate preference or opt-out method. Refusal or withdrawal of optional marketing consent should not prevent a User from receiving essential operational messages required for the Service.
14. Sponsored Listings, Affiliate Links, and Advertising
CelebrateSync may identify sponsored, featured, promoted, affiliate, partner, or advertising placements where such features are enabled.
Sponsored or affiliate placement should be clearly disclosed where required and should not be presented as an ordinary unpaid ranking if the placement is influenced by payment, sponsorship, commission, affiliate relationship, or commercial arrangement.
At initial launch, targeted advertising, behavioral retargeting based on private Event Data, and undisclosed sponsored ranking are not enabled unless separately reviewed, approved, disclosed, and implemented with required consent and platform controls.
15. Targeted Advertising and Tracking Controls
Targeted advertising, behavioral retargeting, cross-app tracking, cross-site tracking, personalized ad audiences, lookalike audience sharing, advertising SDKs, and similar tracking-based advertising features require separate review before launch.
Where such features are enabled in the future, CelebrateSync should provide appropriate notice, consent or opt-out controls, app-store disclosures, privacy-policy updates, and any required device-level prompts.
Private Event Data, guest lists, RSVP records, sensitive Event notes, child/minor data, private media, QR activity, Event messages, and similar Event-context data should not be used for targeted advertising unless a separate lawful, counsel-approved, and clearly disclosed model is implemented.
16. App Permissions and Notification Consent
Push notifications, camera access, photos or media-library access, microphone access, contacts access, calendar access, location access, and similar app permissions may require device-level permission prompts.
Granting a device permission allows the relevant feature to function but does not authorize unrelated use of the information.
Where a permission supports optional processing, CelebrateSync may provide a feature-level explanation before or near the device permission prompt.
Users may manage app permissions through device settings, subject to feature limitations.
17. Contacts and Calendar Access
CelebrateSync will not access a User’s device contacts or calendar merely because the User receives an invitation, joins an Event, or creates an Account.
Where such features are enabled, CelebrateSync should explain the purpose of access, the categories of data accessed, whether information is uploaded or stored, whether contacts are messaged automatically, how users can control the feature, and how withdrawal or revocation works.
The Services should not send invitations or reminders to contacts imported from a device address book unless the User or Organizer has taken the required affirmative action and has the necessary authority or lawful basis to contact the recipients.
18. AI Personalization and Automated Suggestions
Where AI personalization, automated suggestions, message drafting, supplier recommendations, content suggestions, guest-list assistance, seating suggestions, or similar tools are enabled, CelebrateSync should disclose the nature of the feature and the categories of data used.
AI or automated tools should not be used to make legal, safety-critical, eligibility, credit, employment, insurance, or similarly significant decisions about Users.
Where personal data is shared with an AI or third-party suggestion provider, CelebrateSync should provide appropriate notice, consent, contractual safeguards, and configuration controls where required.
19. Spark Points, Rewards, and Promotional Controls
Spark Points may not be purchased with real money, exchanged for cash, transferred for value, used as raffle entries, used for chance-based eligibility, used for gambling or betting, used for supplier payments, used for external rewards, or used as cash-equivalent compensation unless separately reviewed, approved, and lawfully implemented.
Spark Points must not depend on the rating, tone, substance, positivity, star level, supplier approval, or outcome of a review.
Where Spark Points, rewards, perks, coupons, promotions, or loyalty-style benefits are used, CelebrateSync should apply the applicable Spark Points Program Terms, promotion controls, disclosures, consent rules, and any required approval or permit process before launch.
20. Abuse Reports and Provider Compliance
Messaging, marketing, affiliate, advertising, cookie, or tracking abuse may be reported through in-app tools where available, support@celebratesync.app, privacy@celebratesync.app, legal@celebratesync.app, or reportabuse@celebratesync.app, depending on the nature of the concern.
The Operator may investigate abuse reports and may take action to protect recipients, Users, Events, suppliers, rights holders, third-party providers, deliverability, platform integrity, and legal compliance.
The Operator may report abuse, spam, fraud, security incidents, unlawful content, or provider-policy violations to messaging providers, email providers, app stores, hosting providers, analytics providers, advertising providers, telecommunications providers, payment providers, or competent authorities where required or permitted.
21. Enforcement
Messaging, marketing, cookie, tracking, affiliate, advertising, or consent abuse may result in proportionate enforcement action.
Actions may include warning, message blocking, rate limiting, suppression, sender restriction, contact-list restriction, channel suspension, Event workspace restriction, Organizer restriction, supplier restriction, Account suspension, credit restriction where lawful, refund denial where permitted, evidence preservation, legal escalation, provider reporting, or referral to competent authorities.
The Operator may take urgent interim action before completing a full review where necessary to prevent spam, fraud, harm, security compromise, unlawful content, privacy violation, child-safety risk, non-consensual media distribution, or provider-policy violations.
22. Consent Records and Preference Logs
CelebrateSync may maintain records of consent choices, preference settings, unsubscribe actions, opt-outs, device permissions where available, policy versions, acceptance versions, timestamps, account identifiers, Event identifiers, communication settings, suppression status, and related evidence.
Consent records and preference logs may be retained where reasonably necessary to demonstrate compliance, honor user choices, prevent unwanted contact, manage suppression, respond to complaints, investigate abuse, comply with law, or establish, exercise, or defend legal claims.
Withdrawal of consent does not affect processing that occurred before withdrawal and does not require deletion of records that must be retained for lawful purposes.
23. Relationship With Other Policies
This Policy supplements, and does not replace, the Terms of Service, Privacy Notice and Data Rights Policy, Privacy Notice Acknowledgment and Consent Form, Community, Content, Child Safety, IP, and Enforcement Policy, Account Deletion and Retention Policy, Media Terms, Supplier Network and Public Trust rules, Review Guidelines, Spark Points Program Terms, App Permission Disclosures, and any applicable Event-specific or feature-specific rules.
In case of conflict, the document most specific to the relevant feature or processing activity will generally apply, subject to applicable law and counsel-approved publication hierarchy.
24. Contact Information
For questions about this Policy or reports involving messaging, cookies, marketing, ads, affiliate links, consent, opt-outs, or abuse, contact:
DIGITALFRAMEWORK I.T. SOLUTIONS CelebrateSync / HostHaven Data Protection Officer / Privacy Contact: Mark Baldus
Support: support@celebratesync.app Privacy: privacy@celebratesync.app Legal: legal@celebratesync.app Abuse / Safety Reports: reportabuse@celebratesync.app
Business Address: 14 Gregorio St., Barangay Mariano Espeleta II, Imus City, Cavite 4103, Philippines
25. Version Control
Policy: Cookie, Marketing, Messaging, Affiliate, Ads, and Consent Policy Version: v4.0 Publication Candidate Version Date: September 16, 2026 Effective Date: September 16, 2026