Operator: DIGITALFRAMEWORK I.T. SOLUTIONS, a sole proprietorship registered in the Philippines, owned and operated by Mark Baldus, with business address at 14 Gregorio St., Barangay Mariano Espeleta II, Imus City, Cavite 4103, Philippines.
Contacts: support@celebratesync.app | privacy@celebratesync.app | legal@celebratesync.app | reportabuse@celebratesync.app
Version: v2.0 Publication Date: September 16, 2026
Plain Summary
This document supports Apple App Store and Google Play review by mapping CelebrateSync’s app permissions, privacy labels, data-safety disclosures, account deletion, support routes, age rating, demo access, and release-feature status to the actual production build.
The app should request permissions only when connected to live features. Unused permissions, unused SDKs, test ad units, sample app IDs, demo-only code, and gated feature claims should not remain in the release build.
At launch, CelebrateSync should be Philippines-first unless counsel approves broader territory availability.
Targeted ads, behavioral retargeting, facial recognition, biometric identification, broad AI decisioning, public child profiles/media, paid Spark Points, supplier settlement, marketplace checkout, escrow, and split payments remain disabled unless separately reviewed, approved, disclosed, and released.
This summary is provided for convenience only. The full Disclosure governs.
1. Purpose and Scope
This CelebrateSync App Permission and Store Disclosure supports Apple App Store and Google Play review by mapping app permissions, privacy labels, data-safety disclosures, support routes, account deletion, age rating, App Tracking Transparency status, advertising SDK status, in-app purchase status, reviewer demo access, and release-feature status to the actual launch build.
This Disclosure applies to the CelebrateSync mobile app, including guest access, personal accounts, RSVP, QR passes, Event Credentials, Event reminders, private galleries, media uploads, memories, push notifications, app upgrades, subscriptions where enabled, role workspaces, supplier-related mobile features, and support flows.
This Disclosure should be read together with the Terms of Service, Privacy Notice and Data Rights Policy, Privacy Acknowledgment and Consent Form, CelebrateSync App Addendum, Cookie and Marketing Policy, Messaging Addendum, Media Policy, Spark Points Program Terms, Supplier Network Policy, Platform Fees Terms, Account Deletion and Retention Policy, and Community Policy.
2. App Store Territory and Release Scope
The first production release should be configured as Philippines-first unless counsel approves broader availability.
Store country availability, screenshots, metadata, keywords, onboarding text, feature descriptions, support pages, privacy labels, and demo instructions should not imply global availability unless the legal, tax, privacy, app-store, payment, child-safety, and consumer-protection requirements for those territories have been reviewed.
The app should not display or advertise gated features as live unless they are actually available in the production build, supported by operational processes, and covered by the applicable legal documents.
3. Feature Accuracy Requirement
App Store and Google Play submissions should match the actual live production build.
The following must be accurate:
app name; subtitle or short description; long description; screenshots; preview videos; keywords; support URL; privacy URL; account deletion URL or instructions; age rating answers; data safety answers; privacy nutrition labels; permission purpose strings; in-app purchase descriptions; subscription descriptions; review notes; demo credentials; and feature availability.
The app should not claim that a feature is live, disabled, private, public, anonymous, encrypted, child-directed, ad-free, tracking-free, deletion-enabled, or moderation-enabled unless that statement matches the actual build and operational process.
4. Account Creation and Account Deletion
If the app permits account creation, the app must provide an in-app account deletion path where required by app-store rules or applicable law.
The app should also provide a web or support-assisted fallback for account deletion and data-rights requests.
Deletion disclosures must explain that account deletion may not immediately delete all information, including Organizer-controlled Event Data, legal records, security logs, billing records, support records, abuse records, moderation records, backups, and information subject to legal holds or lawful exceptions.
Deleting the app from a device does not necessarily delete the User’s account, Event Data, media, support records, billing records, or legal records.
5. Guest Access and Account Conversion
Guest access should be Event-scoped unless the User affirmatively creates or links a broader personal account.
A guest should not be silently converted into a permanent personal account, marketing profile, public profile, supplier profile, or unrelated account record merely because the guest receives an invitation, RSVPs, checks in, views a gallery, opens a QR pass, or uses an Event feature.
Where the app offers memory saving, Event linking, future Event access, personal profile creation, or app upgrades, the app should disclose the effect of that choice before or during the flow.
6. Camera Permission
Camera permission may be used only where connected to a live feature, such as:
QR scanning; Event Credential scanning; taking profile photos; capturing Event media; uploading Event memories; or other camera-based features shown in the live app.
The camera permission purpose string should match the actual live use. It should not mention features that are disabled, planned, demo-only, or not included in the production build.
Camera access should not be used for facial recognition, biometric identification, automatic person tagging, or AI face grouping unless separately reviewed, approved, disclosed, and released.
7. Photos, Media Library, and File Access
Photos, media library, or file access may be used to select, upload, download, save, manage, or share Event photos, private gallery media, profile images, memories, documents, or other files where enabled.
The app should prefer limited photo picker, scoped access, or user-selected media access where reasonably possible.
Broad media-library access should be avoided unless necessary for a live feature and disclosed accurately.
Photo and media access should not be treated as permission to use private Event media for advertising, supplier portfolio reuse, public display, AI training, facial recognition, or unrelated marketing.
8. Push Notifications
Push notifications may be used for Event invitations, RSVP updates, Event reminders, QR/check-in information, schedule changes, account alerts, security notices, support replies, privacy or legal notices, and platform updates.
Optional marketing or promotional push notifications should require separate preference or consent controls where applicable.
Users may manage push notifications through device settings and app-level preferences where available.
The notification permission prompt, onboarding text, and privacy disclosures should match the actual notification categories used in production.
9. Location Permission
Location permission should remain disabled unless a live feature requires it.
Possible location-based uses may include venue directions, venue routing, nearby Event context, nearby supplier context, check-in assistance, safety-related Event routing, or other disclosed location-based features.
Location should not be collected continuously, used for background tracking, used for targeted advertising, or used to build movement profiles unless separately reviewed, approved, disclosed, and supported by required consent and platform controls.
Approximate or one-time location should be preferred where sufficient.
10. Contacts and Calendar Permission
Contacts and calendar access should remain disabled at launch unless tied to a reviewed invite-import, contact-assisted invitation, calendar-save, or calendar-sync feature.
CelebrateSync should not access a User’s device contacts or calendar merely because the User receives an invitation, joins an Event, creates an account, RSVPs, or opens the app.
Contacts should not be used as Spark Points earning levers, referral pressure, marketing audiences, supplier solicitation lists, or unrelated growth mechanics without separate legal, privacy, and app-store review.
Where contacts or calendar access is enabled, the app should disclose what information is accessed, whether it is uploaded or stored, whether contacts are messaged automatically, how the User controls the feature, and how revocation works.
11. Microphone Permission
Microphone access should remain disabled unless audio, video, voice note, recording, livestream, or similar features are live and disclosed.
Microphone permission should not be requested merely because the app supports media uploads unless the specific live feature requires audio capture or recording.
The permission purpose string should clearly describe the live microphone use and should not include planned or disabled features.
12. Apple and Google Sign-In
If Google, Facebook, or another third-party login is available, Sign in with Apple must be correctly implemented where Apple rules require it.
Privacy disclosures should identify the authentication data received, such as name, email address, unique account identifier, profile image where applicable, authentication token metadata, and login activity.
The app should explain how account deletion, account unlinking, third-party login revocation, and identity-provider changes affect access to the CelebrateSync account.
The app should not request more authentication data than needed for the login or account feature.
13. App Tracking Transparency and Tracking
At launch, targeted ads, behavioral retargeting, tracking domains, cross-app tracking, cross-site tracking, personalized ad audiences, lookalike audiences, and Event Data advertising audiences should remain disabled unless separately reviewed, approved, disclosed, and released.
Where tracking under Apple rules is enabled, the app should provide the required App Tracking Transparency prompt, privacy nutrition labels, consent records, SDK disclosures, privacy policy updates, and preference controls.
Private Event Data, guest lists, RSVP records, QR activity, Event messages, private media, sensitive Event notes, and minor data should not be used for targeted advertising unless a separate lawful, counsel-approved, clearly disclosed model is implemented.
14. Advertising, AdMob, and Rewarded Ads
If AdMob, advertising SDKs, or rewarded ads are enabled, the app must disclose the advertising SDKs used, data categories collected, whether ads are personalized or non-personalized, whether identifiers are used, whether minors are excluded, and whether third-party ad networks receive data.
Rewarded ads are not part of Spark Points unless expressly enabled after legal and app-store review.
Where rewarded ads are enabled, rewards should be optional, not targeted to minors, not required for core app use, limited by fraud controls, and credited only through server-side verification where available.
Sample app IDs, test ad units, debug ad units, demo ad networks, and development SDK configurations must not remain active in release builds.
15. In-App Purchases, App Upgrades, and Subscriptions
If in-app purchases, app upgrades, paid storage, subscriptions, premium tools, or paid Event features are live, the product descriptions must match the actual feature delivered.
Purchase flows should disclose price, billing period, renewal terms, cancellation path, refund path, restore-purchase behavior, entitlement rules, feature limits, storage limits, and downgrade effects where applicable.
App-store purchase rules, Apple or Google refund processes, and the Platform Fees Terms may apply.
Spark Points are not a payment method, refund method, wallet balance, supplier credit, marketplace credit, or substitute for paid app upgrades.
16. Restore Purchases and Entitlement Behavior
Where app-store purchases or subscriptions are enabled, the app should provide restore-purchase functionality where required or expected by the applicable platform.
Entitlement behavior should be documented, including what happens when a subscription expires, renews, is cancelled, fails payment, is refunded, is downgraded, is restored on another device, or is linked to a different account.
The app should not leave Users with unclear paid access, duplicate entitlement, or misleading subscription status.
17. User-Generated Content Safety
If Users can upload media, post reviews, send messages, submit captions, create profiles, add supplier content, or otherwise submit content, the app should provide reporting, blocking, hiding, restriction, or moderation tools appropriate to the feature and launch stage.
Public reviews should remain disabled until moderation, eligibility, response, takedown, redress, logging, and publication controls are operational and counsel-approved.
Media uploads remain subject to the Media Policy. Supplier content remains subject to the Supplier Network Policy. Messages remain subject to the Messaging Addendum. Spark Points remain subject to the Spark Points Program Terms.
18. Child Safety, Minors, and Age Rating
The app-store age rating should reflect user-generated content, Event media, possible minor appearances, messaging, invitations, supplier content, public/private features, moderation process, and child-safety controls.
The app should not be submitted as a Kids Category app unless deliberately redesigned and separately reviewed for child-directed use.
Public child profiles, public child media, child-directed Spark Points, targeted ads to minors, rewarded ads for minors, public minor galleries, and minor-focused promotional mechanics are disabled unless separately reviewed, approved, disclosed, and implemented with appropriate safeguards.
The app should provide reporting routes for child-safety concerns and harmful content.
19. Data Safety and Privacy Label Mapping
Data safety and privacy label answers should be completed from the actual release build, live SDKs, production data flows, and enabled features.
The review should map, where applicable:
account data; contact information; guest information; RSVP records; Event Data; photos and videos; audio; user-generated content; messages; device identifiers; diagnostics; crash logs; performance data; app activity; purchase history; approximate location; precise location if enabled; contacts if enabled; calendar data if enabled; advertising identifiers if enabled; analytics data; support records; and optional data categories.
If a permission, SDK, analytics tool, advertising SDK, or payment provider is removed before launch, the store labels and privacy disclosures should be updated to match the release build.
20. Reviewer Demo Flow
Store review should receive a stable demo account or invite path that allows reviewers to evaluate the live app without exposing real private Events or production user data.
The demo flow should cover, where applicable:
account creation; login; guest invitation; RSVP; QR pass display; QR/check-in flow; Event page; private gallery access; media upload; media report; notification prompt; permission prompt; account deletion; support links; privacy policy link; terms link; and purchase flow only if purchases are enabled.
Demo Events, demo media, demo guest lists, and demo supplier content should be synthetic or cleared for review use.
Reviewer notes should clearly identify gated features that are not live in the submitted build.
21. Support, Privacy, and Abuse Links
The app and store listing should provide working support, privacy, and legal links.
At minimum, the following routes should be accurate and monitored:
support@celebratesync.app; privacy@celebratesync.app; legal@celebratesync.app; reportabuse@celebratesync.app; billing@celebratesync.app, where billing or paid features are enabled.
The app should provide accessible links to the Terms of Service, Privacy Notice, account deletion route, data-rights route, support route, and abuse-reporting route.
22. Release Build Hygiene
Before submission, the release build should be reviewed for unused permissions, debug code, test credentials, sample API keys, test ad IDs, debug logs, staging endpoints, development banners, internal-only screens, demo-only data, disabled but visible features, broken links, inaccurate privacy labels, and mismatch between app metadata and live features.
Permissions, SDKs, and app-store declarations should be based on what is actually shipped, not what may be built later.
23. Gated Features
The following features are disabled unless separately reviewed, approved, disclosed, and released:
targeted ads; behavioral retargeting; cross-app tracking; cross-site tracking; broad AI decisioning; facial recognition; biometric identification; AI face grouping; automatic person tagging; paid Spark Points; cash-out or transferable points; public child profiles; public child media; public Event galleries; public supplier reviews where moderation is not ready; supplier settlement; supplier payouts; marketplace checkout; escrow; split payments; supplier-service refunds; rewarded ads for minors; contacts import without consent; calendar sync without disclosure; continuous background location; public indexing of private Event media; AI training using private Event media;
A feature will be treated as enabled only when it is available in the production user interface, supported by the applicable operational process, and covered by any required terms, privacy disclosures, consent controls, app-store disclosures, billing disclosures, and internal launch approval.
24. Relationship With Other Policies
This Disclosure supplements, and does not replace, the Terms of Service, Privacy Notice and Data Rights Policy, Privacy Notice Acknowledgment and Consent Form, CelebrateSync App Addendum, Cookie and Marketing Policy, Messaging Addendum, Media Policy, Spark Points Program Terms, Supplier Network Policy, Platform Fees Terms, Account Deletion and Retention Policy, Community Policy, and any applicable Event-specific or feature-specific rules.
In case of conflict, the document most specific to the relevant app permission, store disclosure, feature, or release issue will generally apply, subject to applicable law and counsel-approved publication hierarchy.
25. Contact Information
For questions about app permissions, privacy labels, data safety disclosures, app-store review, account deletion, support routes, age rating, release scope, or gated features, contact:
DIGITALFRAMEWORK I.T. SOLUTIONS CelebrateSync / HostHaven Data Protection Officer / Privacy Contact: Mark Baldus
Support: support@celebratesync.app Privacy: privacy@celebratesync.app Legal: legal@celebratesync.app Billing: billing@celebratesync.app Abuse / Safety Reports: reportabuse@celebratesync.app
Business Address: 14 Gregorio St., Barangay Mariano Espeleta II, Imus City, Cavite 4103, Philippines
26. Version Control
Policy: CelebrateSync App Permission and Store Disclosure Version: v2.0 Publication Version Date: September 16, 2026 Effective Date: September 16, 2026