Legal
Privacy Policy
1. Overview
Reveal Party (reveal-party.com) (the "Service") is operated by Mikasa Labs LLC ("we," "us," or "our"), a United States company. The Service lets an event host create a gender-reveal guessing poll and RSVP page for a single event, share it by link and QR code, and run a reveal moment. We collect only the data needed to operate the Service, we do not run ads, and we do not sell personal data.
This Privacy Policy explains what we collect, how we use it, who we share it with, and the choices you have. It covers two kinds of users: event hosts, who create and pay for events, and event guests, who vote or RSVP through an event link without creating an account.
The Service is operated from, and hosted in, the United States and is intended for users in the United States. We honor verifiable privacy requests from any user where feasible (see Section 9), but we do not represent that the Service complies with the privacy laws of every jurisdiction, and we have not appointed a data protection officer or a representative in the European Union, the United Kingdom, or any other jurisdiction.
2. Information We Collect
2.1 Information Event Hosts Provide
Account and event data: Your email address (used to send sign-in links), event details (event name, event date, deadline), optional venue information (venue name and address), and customization settings for your event pages.
Terms acceptance records: We record your agreement to our Terms of Service when you start a checkout for an event or an add-on, and when you agree to an updated version of the Terms through the review notice shown to signed-in hosts in the app. Each record contains your account identifier, the version of the Terms you accepted, the time of acceptance, and the context of the acceptance (a purchase or an in-app re-acceptance); records made at checkout also identify the event, while in-app re-acceptances are not tied to an event. These records are stored server-side, are not readable from the app, and are kept as business records of your agreement; they are among the records we may retain for legal reasons when handling a deletion request (Section 9.1).
2.2 Information Event Guests Provide
Voting: A guess (girl, boy, or surprise), a name (optional, unless the host has required names for votes), and an optional message.
RSVP: Your name (required), your response (yes, no, or maybe), your party size, and an optional message.
Guests do not create accounts and are not asked for email addresses. Section 4 explains how guest submissions are displayed and shared.
2.3 Automatically Collected Information
Security data (no consent required): The Service uses Google reCAPTCHA v3, through Firebase App Check and Google Identity Platform, to protect against bots, abuse, and fraudulent traffic. reCAPTCHA loads on every page of the app, before any consent choice, because it is strictly necessary for security. It collects your IP address and device and interaction signals, and it sets the _GRECAPTCHA cookie (see Section 5). This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
Technical data: IP addresses, request timestamps, and related request data are processed by our cloud infrastructure for security, rate limiting, and service operation.
Analytics (only with consent): If you accept analytics through our consent banner, we collect usage data through Google Analytics, including pages visited, interactions, device and browser type, and approximate location (city or region level). Error reports from the app may also be sent to Google Analytics after consent. If you decline, Google Analytics is not loaded at all. Advertising features stay disabled in our analytics even after you accept: the advertising storage, advertising user data, and ad personalization signals are kept denied at all times.
2.4 Payment Information
Payments are processed by Stripe on Stripe-hosted checkout pages. Your card details go directly to Stripe and are never received or stored by us. We receive transaction metadata only (payment status, session and transaction identifiers, and the items purchased), which is stored with your event.
3. How We Use Your Information
We use collected information to:
- Provide and operate the Service
- Authenticate event hosts via emailed sign-in links
- Process payments for event activation and optional add-on packs (through Stripe)
- Send service-related communications: sign-in links and RSVP notifications to event hosts (we do not send payment emails ourselves; any payment receipt comes from Stripe)
- Display event content to visitors of an event link according to the host's settings (see Section 4)
- Improve the Service through analytics, only with your consent
- Detect and prevent fraud, abuse, and security incidents, including rate limiting and reCAPTCHA checks
- Comply with legal obligations
4. Guest Submissions, Public Display, and Host Notifications
When a guest votes or RSVPs, the submission is stored with the host's event and handled as follows:
- Public display: Depending on the settings the host chooses (for example, live results or display after the reveal), guest names, guess choices, messages, and aggregate vote counts may be shown to anyone who opens the event's shared link while the event remains open. Once the event closes, the link serves only an expired notice with basic event details (event title, host name, event date, and theme); guest names, choices, messages, and vote counts are no longer available through the link. Event links are not published in a directory, but anyone who has the link can open it.
- Host notification: Each RSVP is emailed to the event host, including the guest's name, response, party size, and any message.
Guest submissions are authored by guests, at the invitation of the event host, for the host's event. We store, transmit, and display them as directed by the host's settings; we do not review, edit, select, or endorse them.
If you are a guest and want a submission corrected or removed, contact us (Section 14) or ask your event host.
5. Cookies and Device Storage
First-party cookies: We do not set any first-party cookies. In particular, we do not use authentication session cookies.
Sign-in storage: To keep event hosts signed in, Firebase Authentication stores sign-in credentials in your browser's local storage and IndexedDB. This storage is required for the Service to function and does not require consent.
Other local storage on your device: The Service uses your browser's localStorage and sessionStorage to remember, on your device only, the following entries:
- reveal-party-analytics-consent (localStorage, all visitors): your analytics consent choice, stored with the time of the choice and the consent notice version (entries saved in an older format carry only the choice and the time they were migrated to the current format).
- reveal-party-theme (localStorage, all visitors): your theme preference.
- reveal-party-auth-email (localStorage, hosts): the email address you entered, kept so your sign-in link can complete on this device.
- reveal-party-auth-pending-link (localStorage, hosts): a flag noting that a sign-in link is pending.
- reveal-party-create-form (localStorage, hosts): a draft of the event you are creating.
- reveal-party-event-name (localStorage, hosts): the event name you entered during setup.
- reveal-party-current-event (localStorage, hosts): your current event session.
- voted_ followed by the event's link ID (localStorage, guests): your vote choice for that event.
- rsvp_ followed by the event's link ID (localStorage, guests): your RSVP response for that event.
- guest_name_ followed by the event's link ID (localStorage, guests): the name you entered for that event, so you are not asked again on the same device.
- adminToken (sessionStorage, hosts): your event admin token.
- reveal-party-tos-reacceptance-dismissed (sessionStorage, hosts): a flag noting that you chose "Later" on the Terms of Service review notice, so it is not shown again during the same browser session.
The localStorage entries persist until you clear them or the app removes them (for example, the sign-in entries are cleared when your sign-in completes or you sign out); the sessionStorage entries last only until you close the browser tab or you sign out. You can remove all of this data at any time by clearing your browser's site data for reveal-party.com. If you do, hosts are signed out on that device, your consent choice and theme preference reset (the consent banner will appear again), and event pages will no longer remember the votes, RSVPs, or names you previously entered on that device.
Third-party cookies: Google reCAPTCHA sets the _GRECAPTCHA cookie on every page for security purposes (see Section 2.3); this is strictly necessary and not consent-gated. Google Analytics cookies are set only after you accept analytics through our consent banner. You can change your analytics choice at any time using the "Privacy preferences" link in the footer or through your browser settings.
6. Service Providers and Data Sharing
We do not sell personal data. We do not share personal data for cross-context behavioral advertising, and the Service contains no advertising of any kind. We use no third-party error-tracking service: app error reports go only to Google Analytics, and only after you consent (Section 2.3).
We share personal data with the following service providers, which process it to run the Service:
- Google LLC (Firebase / Google Cloud Platform): Hosting, host authentication, database storage of service data (event details, votes, RSVPs, and guest names and messages), and serverless processing. Our cloud infrastructure runs in the United States. See the Google Privacy Policy.
- Google LLC (reCAPTCHA): Bot and abuse protection across the Service, as described in Section 2.3.
- Google LLC (Google Analytics): Usage analytics, only after you consent through the consent banner.
- Stripe, Inc.: Payment processing on Stripe-hosted checkout pages. Stripe collects your payment details directly under the Stripe Privacy Policy; we receive transaction metadata only.
- Plus Five Five, Inc. (Resend): Transactional email delivery. Resend processes host email addresses and sign-in links and, for RSVP notification emails, guest names, responses, party sizes, and messages. Resend delivers email using its own subprocessors, published at resend.com/legal/subprocessors.
Third-party features that depend on host choices:
- OpenStreetMap Foundation (venue map): If the host turns on the venue map, the event page shows a map placeholder with a "Load map" button and the note "The map loads from openstreetmap.org". The map is embedded from www.openstreetmap.org only if you choose to load it: after you tap "Load map", the OpenStreetMap Foundation receives your IP address and browser information, the venue's coordinates appear in the embed address, and the embedded page may set its own OpenStreetMap cookies in your browser. Until you tap the button, the event page sends no data to the OpenStreetMap Foundation. When a host previews the venue map in the event design screen, the preview map loads in the host's browser without a separate tap. See the OSMF Privacy Policy.
- komoot GmbH (Photon address search): When a host uses the venue address search during event setup, each search runs against the Photon geocoding service at photon.komoot.io, operated by komoot GmbH in Germany, which receives the typed address query and the host's IP address in order to return suggestions. See the komoot privacy policy.
We may also disclose personal data:
- Legal requirements: When required by law, court order, or legal process, or to protect our rights, users, or the public.
- Business transfers: In connection with a merger, acquisition, or sale of assets, with notice to you.
7. International Data Transfers
Mikasa Labs LLC is a United States company and the Service is hosted in the United States. If you use the Service from outside the United States, your information is transferred to and processed in the United States, where privacy laws may differ from those of your country. Our service providers may also process data in other countries under their own published terms. If a host uses the venue address search, the search query is processed in Germany by komoot GmbH (Section 6).
8. Data Retention and Deletion
Event, vote, and RSVP data: Retained for as long as the event and the host's account exist. We do not currently delete event data automatically on a schedule.
Deleting an event in the app removes it from view but does not immediately erase the underlying records. To have the underlying records erased, submit a deletion request (Section 9); deletion is a manual process that we perform after verifying the request.
Authentication data: Retained while your account exists. You may request deletion of your account and its data at any time (Section 9).
Technical data: Rate-limiting records are deleted automatically on a recurring schedule. Other operational logs are retained by our infrastructure provider under its standard log retention settings.
Analytics data: Retained by Google Analytics in accordance with that service's retention settings and Google's policies.
Payment records: Stripe retains payment records under its own policy. We retain the transaction metadata attached to an event for as long as the event data exists and as needed for tax, accounting, and legal purposes.
9. Your Privacy Rights
9.1 Rights for All Users
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your data, subject to records we must keep for legal, tax, accounting, or security reasons
- Analytics choice: Decline or withdraw analytics consent at any time via the "Privacy preferences" link in the footer
9.2 US State Privacy Rights
Depending on where you live, state privacy laws such as the California Consumer Privacy Act may give you rights to know, access, correct, and delete personal information, and the right not to be discriminated against for exercising those rights. Whether or not a particular state law applies to Mikasa Labs LLC, we honor verifiable requests of these kinds from any US user through the process in Section 9.4.
Because we do not sell personal information and do not share it for cross-context behavioral advertising, there is no sale or sharing to opt out of. For the same reason, browser opt-out signals such as Global Privacy Control and Do Not Track have no sale or sharing to act on with respect to the Service, and receiving such a signal does not change how we process your data.
If we decline a request, we will explain why, and you may ask us to reconsider by replying to our response.
9.3 Users Outside the United States
We are a US-based service. If you contact us from outside the United States, we will honor verifiable access, correction, and deletion requests where feasible, using the same process described in Section 9.4. We have not appointed a representative in the European Union, the United Kingdom, or any other jurisdiction, and we do not claim compliance with non-US privacy regimes.
9.4 Exercising Your Rights
To exercise any of these rights, email us at the address in Section 14. Hosts should write from the email address associated with their account. Guests should include enough detail for us to locate the submission, such as the event link and the name used. We verify every request before acting on it: for hosts, by confirming control of the account email address; for guests, by confirming details only the submitter would know. Requests are handled manually by a small team. We respond and act within a reasonable time and within any deadline that a law applicable to your request imposes. We do not charge a fee for reasonable requests and will not discriminate against you for making one.
10. Data Security
We protect your data with measures that include:
- Encryption in transit (HTTPS/TLS); data is encrypted at rest by our cloud provider
- Database security rules and server-side authorization checks that restrict who can read and write event data; guest-facing data is served through controlled server endpoints according to host settings
- Bot and abuse protection (Google reCAPTCHA with Firebase App Check) and server-side rate limiting
- Length limits on guest submission fields, with guest text escaped when it is displayed on event pages or included in notification emails
However, no method of transmission or storage is 100% secure. While we work to protect your data, we cannot guarantee absolute security.
11. Data Breach Notification
If a data breach affects your personal information, we will notify affected users and, where required, regulators, in the manner and within the time frames required by applicable law.
12. Children's Privacy
The Service is not directed to children under 13. Event hosts must be at least 18 years old under our Terms of Service. Guests do not create accounts, and the only information the Service asks a guest for is a name, a guess or RSVP response, a party size, and an optional message. We do not knowingly collect personal information from children under 13. If you believe a child has submitted personal information through an event page, contact us (Section 14) and we will delete it.
13. Updates to This Policy
We may update this Privacy Policy to reflect changes in our practices, legal requirements, or Service features. Each version is identified by the "Last updated" date at the top of this page. If a change materially expands how we use personal data we have already collected, we will provide additional notice or seek consent where required by law.
14. Contact Information
Mikasa Labs LLC operates the Service and is responsible for the personal data described in this policy. For privacy questions or to exercise your privacy rights, contact us at: