United States
Privacy Notice
Updated September 15, 2026
Family permissions and guest sharing
The Owner chooses which planning areas an invited Family member may use. Membership alone does not give access to every area, guest administration, ownership or business conversations. The Owner can change or revoke access.
An Owner may explicitly share payment instructions and one optional celebration photo with holders of the guest link who satisfy its password, if required. A mailing address is optional. The Owner confirms authority to share the image. Images are normalized and embedded metadata removed. Unpublishing prevents new image access through Quince.Casa; recipients may already have copied it. Replaced or removed photos follow the existing 30-day private recovery window plus up to 24 hours for processing.
A verified guest may make a sponsorship pledge or report an outside payment. This is not a payment processor or proof that money arrived. The Owner confirms received funds. Payment instructions are not included in notification bodies or separate QR data. New guest-linked pledge, report and confirmation records remain while the Event is active; closing the Event or removing the guest or report makes affected records inaccessible immediately and schedules deletion within 30 days, except an explicitly approved legal hold.
Private business conversations
Saving a private shortlist does not notify a business. Before the first inquiry, the Owner sees the exact Event display title and message that will be shared with the business’s current authorized adult operator. No guest list, budget or other planning area is shared by this action. Only that Owner and current operator can read or send these messages; other Family members and former business operators cannot.
Messages are plain text without attachments. Read status is recorded when a participant explicitly confirms opening the displayed messages. Conversations refresh manually on every tier. Either party can archive a conversation to stop new messages. Either party can request deletion: message content becomes inaccessible immediately, the other party sees an in-app notice, and content is deleted within 30 days. Event removal also starts deletion. Minimal moderation action, reason and timestamp records use the existing 90-day retention class plus up to 24 hours for deletion processing (91 days maximum). There is no indefinite private-message dispute hold by default.
Public reviews and self-service business publication
An adult may create and publish a new business listing they are authorized to operate. This does not claim an existing listing, verify the business’s quality or automatically give access to another business. Content with uncertain publication authority may be held from public access while the text listing remains available.
An Event Owner may publish one review per Event and business after both parties acknowledge their relationship. This confirms the stated relationship, not a purchase, contract, payment or quality. The Owner previews and consents to publishing the chosen adult reviewer name, one-to-five-star score, optional text and month. The review does not publish the Event name, child identity or guest information. Paid plans do not affect ratings or moderation priority.
Reviews remain public until the author withdraws them, the listing is removed or justified moderation removes them. Withdrawal hides the review immediately and deletes its body and reviewer name within 30 days. Minimal moderation records use the existing 90-day class plus up to 24 hours for deletion processing (91 days maximum). A report does not automatically hide a review. Appeals can be sent to support@quince.casa. Relationship checks reduce some misuse but do not prove that every review is free from collusion.
Who operates Quince.Casa
Quince.Casa is operated by Birnbaum Grove LLC, a Wyoming limited liability company. Privacy questions and requests may be sent to support@quince.casa.
Information we collect
We process account email addresses and the information an adult account holder or invited family member adds to an Event Record. This may include participant names and roles, celebration date and location, tasks and notes, budget amounts, sponsorships, contributions, vendor contact details, and invitation history. Guest RSVPs include a name, email address, attendance response, number attending, and verification and change history. Guests do not need an account. Supabase and Vercel also process limited authentication, security, and operational information needed to provide the service.
How we use information
We use information only to authenticate users, maintain private Event Records, provide owner-authorized family collaboration, publish the Event details its Owner chooses to share, verify and manage guest attendance, deliver transactional invitations, account recovery and RSVP emails, provide consented business listings and private saved listing details, secure the service, respond to requests, and operate Quince.Casa. We do not sell personal information or use Event Record or RSVP information for targeted advertising. We do not create unrelated guest profiles.
Owner-controlled guest pages and RSVPs
Event Records are private and unpublished by default. An Owner may publish selected celebration details on an unlisted guest page, including the celebrant display name, date, locations, times and guest information the Owner approves. Anyone with that link can view the published details unless the Owner requires an Event password. Links and passwords can be forwarded; an unlisted page is not a guarantee of confidentiality. We ask search engines not to index these pages. The Owner can unpublish the page or change its link and password, but cannot erase copies others already kept.
Public pages do not display private planning sections or guest response lists. The Owner can see and administer individual RSVPs; Family membership does not grant RSVP administration. A guest verifies their email before their response counts and can use a private return link to review or change it before guest editing closes. Verification does not grant membership or establish a family relationship. Keep verification and return links private.
Family and children's information
Quince.Casa is intended for adult account holders planning a family celebration. It is not intended for children under 13 to create accounts or submit information. Adults may enter limited planning information about family members, including a quinceañera. Please do not add unnecessary sensitive information. Guest forms ask for a household attendance count, not the names of individual children. Contact us if you believe a child under 13 created an account.
Business listings and saved details
A business controller chooses which business contact, service-area, offer and image information to publish. We do not automatically publish an account email address. We keep a minimal record of business-control verification and moderation decisions. Public listings can be viewed without an account. Optional images are resized and re-encoded to remove embedded metadata; original uploaded photos are not retained in listing storage.
Saving a listing into an Event Record copies selected public text and its capture date into that private record. It does not copy photos, notify the business or give the business access to the family's plans. Saved text can remain after a listing changes or is withdrawn. Contact us about a legitimate personal-information removal request. Withdrawing a listing stops new public access through Quince.Casa, but cannot recall copies already downloaded.
Business billing tests with Stripe
Business subscription billing is currently limited to development sandbox testing, with no real charges. Family planning and Basic listings remain free. When an authorized tester opens checkout or subscription management, Stripe hosts those pages and collects the billing contact and test payment information entered there. Use only the supplied synthetic test details, never a real payment card. We do not send private Event Records or RSVP information to Stripe.
Quince.Casa uses limited billing information to associate the test subscription with the correct business listing, check payment status and paid-through time, and handle repeated payment updates. Our billing records contain provider identifiers, status and timing information, and payment-event identifiers, types and processing results. We do not store card or bank details or copies of raw payment-event payloads in our application database or logs.
Our development retention policy is 90 days for processed payment-event records and 30 days after test closeout for synthetic billing records, followed by up to 24 hours for deletion processing (maximum 91 and 31 days, respectively). These periods apply to Quince.Casa's live application records, not Stripe's systems or provider backups. Stripe also processes browser and connection information under its Privacy Policy. Live billing and its financial-record retention policy have not been activated.
Sharing and service providers
Information is shared only as needed with Supabase for authentication, database hosting and private listing-image storage, Vercel for application hosting, Resend for transactional email delivery, and Stripe for the development billing tests described above. These services process the information needed for their roles, including limited authentication, delivery and security information. We may also disclose information when required by law or necessary to protect the service and its users.
We use Cloudflare Turnstile on account sign-in, signup and recovery to help distinguish people from automated abuse. Cloudflare processes IP addresses, browser and connection signals, the site key and site origin for protection and improvement of Turnstile. We do not send account passwords, email addresses, Event Records or RSVP contents to Turnstile or store challenge tokens in application logs or tables. Cloudflare's Turnstile Privacy Addendum explains its processing. We do not promise a fixed provider deletion period.
Retention and security
We retain active Event Records while they are used and keep limited operational information for security and service administration. Pending unverified RSVPs are deleted or irreversibly redacted within 30 days. Direct RSVP identifiers are deleted or irreversibly redacted 90 days after the Event, subject to documented unresolved support, security or legal matters. Event deletion also removes its guest projection and dependent RSVP data, subject to documented exceptions. We retain minimized change history for Event operation and security.
To limit repeated invitation and recovery emails, we keep a hashed representation of the requested address, the email purpose, a request count and a short time window. These records can still be linked to an email address; they are not anonymous. They expire after one hour and are removed by request-time cleanup or an hourly cleanup job. Credential verifiers are invalidated on use, expiry or revocation as applicable. We use authentication, database row-level security, access controls, validation, and infrastructure safeguards. No online service can guarantee absolute security.
To limit repeated Event-password checks, we keep a random reservation identifier, the Event identifier and the reservation time for no more than one hour. These records are linked to an Event and are not anonymous. They do not contain passwords, email addresses, IP addresses, browser fingerprints or guest identities. Both correct and incorrect password checks count toward temporary guest-access limits.
To limit repeated RSVP notification emails, we keep response-linked operation identifiers, attempt times, status and fingerprints used to recognize the same notification. These records are not anonymous and are retained for at most 48 hours. They do not contain email bodies, additional email addresses, IP addresses or credentials. Attendance changes still save when a notification cannot be sent.
Your choices and requests
You may request access to, correction of, or deletion of your account, Event Record or guest RSVP information, or help revoking an RSVP credential, by emailing support@quince.casa. We may need to verify your identity and authority over the relevant Event Record or RSVP before completing a request. Guests can also review and correct their attendance through their private return link while editing is open.
Changes to this notice
We will update this page when our information practices materially change and will revise the effective date above.