Privacy Policy
1. Controller
The controller for data processing on this website and in the Fivora application is extrain.io GmbH, Am Kniebrecher 21, 66606 Sankt Wendel, Germany, email: hello@fivora.io.
2. Our principle
Fivora is built privacy-first: no ads, no advertising or cross-site tracking, no tracking cookies, no sharing for advertising, and no training of AI models on your content. We process only the data required to run the service, on servers in the EU (Germany).
To improve this website and the host dashboard we run cookie-free audience measurement on our own infrastructure (see section 8). Guest surfaces — the gallery at /e/… and the live wall — are excluded from it entirely.
3. Data we process
Account data (hosts): email address and display name, managed via our self-hosted sign-in service (Keycloak, OIDC).
Event content: photos and videos uploaded by you and your guests, plus the display name a guest chooses on joining. EXIF/location data is stripped during processing.
Payment data: for paid plans we process payments via Stripe. Card details are handled solely by Stripe and not stored by us; we keep only a customer reference and payment status.
Technical data: server logs and — for error detection — anonymised error reports via our self-hosted monitoring (Sentry).
Audience measurement: page paths visited, referrer, language, coarse device and browser information, and individual interaction events (e.g. "event created") on the website and in the host dashboard. Details and objection: section 8.
4. Purposes and legal bases
Providing the service and performing the contract (Art. 6(1)(b) GDPR): account, event galleries, uploads, payments.
Legitimate interest (Art. 6(1)(f) GDPR): secure and reliable operation, abuse and error detection, and designing our website and host dashboard around actual use (audience measurement, section 8). You may object to this processing at any time.
Legal obligations (Art. 6(1)(c) GDPR): e.g. retention of invoicing data under commercial and tax law.
5. Recipients / processors
We use carefully selected providers as processors (Art. 28 GDPR): hosting/infrastructure (Hetzner, Germany/EU), payments (Stripe), transactional email such as password resets (Resend). Sign-in, error monitoring and audience measurement run on our own EU infrastructure; no audience-measurement data is transmitted to any third party.
6. Retention
Event content is stored for the retention period of the respective plan and deleted afterwards. Account data is kept for the lifetime of the account. Invoicing and payment data is subject to statutory retention periods.
7. Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21), as well as the right to lodge a complaint with a supervisory authority. Contact hello@fivora.io.
8. Audience measurement and objection
We use OpenPanel, open-source analytics software that we run exclusively on our own infrastructure in the EU. No cookies are set, and nothing is stored on or read from your device, so §25 TTDSG/TDDDG does not apply. Your browser also never contacts a third-party server: every request goes through our own domain.
Visitors are not recognised persistently. Instead a daily-rotating hash is derived from IP address, browser identification and a secret salt; the IP address itself is not stored. Signed-in hosts are additionally attributed via a random identifier of their account — no name, no email address.
Measurement happens on the website and in the host dashboard only. Guest surfaces (gallery and live wall) and uploaded photos and videos are never recorded.
You can object at any time — right here, for this browser. We also automatically respect a browser signal (Global Privacy Control or "Do Not Track").
9. Contact
For any privacy questions, reach us at hello@fivora.io.