Privacy Policy

Your privacy matters to us. This policy explains how JC Blossom collects, uses, and protects your personal information.

Last updated: April 21, 2026

Quick Summary

JC Blossom collects only the information needed to provide our event planning service. We do not sell your personal data to third parties. You can request deletion of your account and data at any time by contacting us at [email protected].

1. Information We Collect

Account Information

When you create an account, we collect your name, email address, and authentication credentials through our secure OAuth login system. We also store your preferences such as color theme and subscription tier.

Event Data

We store the event details you create, including event names, dates, venues, guest lists, budget information, vendor contacts, tasks, seating arrangements, and digital invitations. This data is necessary to provide the core event planning service.

Payment Information

Payment processing is handled entirely by Stripe, a PCI-compliant payment processor. JC Blossom does not store your full credit card number, CVV, or card expiration date. We only store your Stripe Customer ID and subscription identifiers to manage your plan.

Usage Data

We collect basic usage analytics such as page views and feature interactions to improve the platform. This data is aggregated and does not identify you personally.

Push Notification Tokens

If you enable push notifications, we store your device's push subscription token to send you event reminders. You can revoke this permission at any time through your browser settings.

2. Special-Category Data (GDPR Art. 9)

JC Blossom offers optional personalisation features that rely on special-category data under Article 9 of the General Data Protection Regulation (GDPR) — specifically your religious or cultural background. This data is used solely to suggest relevant event themes, invitation templates, and scripture features (e.g., daily Bible verses for Christian users).

Lawful basis

We process this data only with your explicit opt-in consent (Art. 9(2)(a) GDPR). You must actively tick the consent checkbox on your Profile page before these fields become active. Consent is freely given, specific, informed, and unambiguous.

Withdrawal

You may withdraw consent at any time by unchecking the opt-in on your Profile page. Upon withdrawal, your stored religious affiliation and cultural background are immediately erased from our database — no special-category data is retained without a valid lawful basis.

Retention

This data is retained only while your consent is active. It is deleted immediately upon consent withdrawal, account deletion, or upon your written request to [email protected].

No sharing

Special-category data is never shared with third parties, used for advertising, or included in aggregated analytics.

Providing this information is entirely optional. Declining or withdrawing consent has no effect on your ability to use JC Blossom's core features.

3. How We Use Your Information

We use your information solely to:

  • Provide and operate the JC Blossom event planning service
  • Send event reminders and RSVP notifications to you and your guests
  • Process subscription payments and manage your billing
  • Send transactional emails such as welcome messages, refund confirmations, and subscription receipts
  • Personalise your experience based on cultural/religious preferences you have explicitly consented to share
  • Improve the platform through aggregated usage analytics
  • Respond to your support requests and inquiries
  • Comply with legal obligations

We do not use your data for advertising, profiling, or selling to third parties.

4. Information Sharing

We do not sell, rent, or trade your personal information. We share data only with the following trusted service providers who help us operate the platform:

Stripe
Payment processing and subscription management
Privacy Policy →
Resend
Transactional email delivery
Privacy Policy →
Manus Platform
Hosting, authentication, and infrastructure
Privacy Policy →
Amazon S3
Secure file and image storage
Privacy Policy →

We may also disclose information if required by law, court order, or to protect the rights and safety of our users.

5. Data Security

We take the security of your data seriously and implement industry-standard measures to protect it:

All data transmitted over HTTPS/TLS encryption
Passwords and sessions managed via secure OAuth (no passwords stored)
Payment data handled exclusively by PCI-compliant Stripe
Database access restricted to server-side code only
File storage secured in private S3 buckets
Regular security reviews and dependency updates

While we implement strong security measures, no system is 100% secure. We encourage you to use a strong, unique password and to log out of shared devices.

6. Your Rights

You have the following rights regarding your personal data:

Access

Request a copy of all personal data we hold about you.

Correction

Update or correct inaccurate information through your Profile page or by contacting us.

Deletion

Request deletion of your account and all associated data. We will process deletion requests within 30 days. You can also delete your account directly from the Profile page.

Portability

Request an export of your event data in a structured format.

Opt-out of notifications

Disable push notifications and marketing emails at any time through your Profile page.

Withdraw consent

Withdraw consent for special-category data (cultural/religious background) at any time from your Profile page. Your data is erased immediately upon withdrawal.

To exercise any of these rights, email us at [email protected].

7. Data Retention

We retain your account and event data for as long as your account is active. If you cancel your subscription, your data remains accessible for 90 days, after which it may be deleted. You can request immediate deletion at any time by contacting [email protected]. Payment records are retained for 7 years as required by financial regulations. Special-category data (cultural/religious background) is deleted immediately upon consent withdrawal or account deletion.

8. Children's Privacy

JC Blossom is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us immediately at [email protected] and we will take steps to delete that information.

9. Changes to This Policy

We may update this Privacy Policy from time to time. When we make significant changes, we will notify you by email and update the "Last updated" date at the top of this page. Continued use of JC Blossom after changes take effect constitutes acceptance of the updated policy.

Contact Us

If you have any questions about this Privacy Policy or how we handle your data, please reach out to our privacy team.