starvıte

Security and privacy at Starvite

Short answers for IT, security and procurement teams. For anything not covered, write to info@shoetracker.ai.

Who runs Starvite?

ADS Delivery OOD, Bulgaria (company number 208549000), the same company that runs ShoeTracker.ai.

What do you store about our employees or guests?

A name, and an email or phone only if you add one. Their answer, party size, optional vote, and whether they opened, made or shared their film. Nothing else.

Do you message our people?

Never. You send the invitations through your own email, Slack or WhatsApp. We do not send marketing, reminders or anything else to your guests.

Do guests need an account or an app?

No. Each guest opens a personal link that already carries their name. There are no passwords to leak.

Where is the data?

Application and database on Vercel and Neon. Event videos in private Vercel storage in Frankfurt, EU.

How long do you keep it?

Everything about an event is deleted automatically 90 days after the event date. Guests can delete themselves at any time.

Do you use our videos or data to train AI?

No. We do not sell data, run ad pixels, build profiles or train AI models on anything you upload.

Is there face recognition?

No.

How are videos protected?

They sit in private storage with no public address. Each view is authorized by our server and served through a signed link that expires within minutes.

How are organizer links protected?

Organizer and guest links carry at least 128 bits of randomness. Organizer keys are stored only as digests and compared in constant time. You can close all co-organizer links in one click.

What runs in the browser?

Only our own code. There are no third-party scripts, trackers or externally hosted fonts, and a strict content security policy enforces it.

How do you pay us or invoice us?

Through Stripe: by card, or by invoice payable within 30 days. Card details never reach Starvite.

Do you sign a DPA?

Yes. Our Data Processing Agreement under GDPR Article 28 applies to every event. It is published here, so procurement does not need to wait for it.

How do you ship changes safely?

Every change passes automated tests and code analysis before it can reach production, and nobody can bypass that gate. A health endpoint shows exactly which build is live.

Data Processing Agreement   Terms   Privacy