The fine print
Privacy notice
In effect from 4 August 2026, updated 4 August 2026 to describe the anonymous usage counts in §2. This also serves as our notice at collection under California law.
The short version. We hold what you type in and almost nothing else.
- No third-party analytics. No Google Analytics, no Facebook pixel, no ad network, no session recording. We do count what gets used — how many people opened a page, how many pressed a button — but those are numbers with no name on them, and there is no field anywhere that could tie one to you.
- No cookies of our own — which is why you were not shown a banner.
- We never see a card number. There are no payments on this site.
- We do not sell or share your personal information, and never have.
- Marketing email is off unless you switch it on.
- Delete your account and your information goes with it.
1. What you give us
All of this arrives because you typed it.
- Your account — your name, your email address, and a password. We never see the password itself; it reaches our authentication provider as a one-way hash and there is no screen anywhere that can display it.
- Your event — the city, the date, the kind of celebration, your budget if you enter one, the vendors you save, your checklist and your notes.
- What you send to people — enquiries, the description of your idea, the notes you attach when you ask us to reach a business.
- Guest lists and RSVPs — names and contact details of the people you are inviting, and their answers. See §4, because that information is about them, not you.
- Referrals — the name and contact details of a business you tell us you already love, so we can invite them.
- If you are a business — your listing, your trading details, your public contact information, your photographs and your posts. A listing is published, which is the point of it.
- Your consent record — whether marketing email is on, and the date and time you switched it on or off. We keep the dates deliberately: a consent nobody can date is a consent nobody can prove.
2. What arrives on its own
Very little, and none of it is a profile.
- Ordinary server logs. Our host and our database provider record the standard things any web server records — IP address, time, the page requested, the browser's user-agent string, and whether it worked. This is how a service stays up and how abuse gets blocked. We do not build behavioural profiles from it and we do not link it to your account for marketing.
- Error reports. When something breaks, the failure is logged so it can be fixed.
We count what is used. When a page is opened or a button is pressed, a number goes up. That is the whole of it, and it is worth being exact about what is and is not recorded:
- Not recorded: who you are, any account or session or visit identifier, your IP address, your device, your screen, your referrer, how long you stayed, or the order you did things in. Two actions by one person are indistinguishable from two actions by two people — there is no column that could tell them apart.
- Not recorded: anything you typed. A search is counted as "somebody searched here". What you searched for is never stored.
- Not recorded: which vendor you looked at. A vendor page counts as
/v/:slug, without the name.
So we can tell you that the directory was opened four hundred times last week. We cannot tell you, or anyone else, that you opened it — and neither can a court order, because it is not written down.
We do not use tracking pixels, advertising identifiers, fingerprinting, cross-site tracking or session-replay tools. We do not buy information about you from data brokers. We do not track you across other websites, so there is nothing for a Global Privacy Control signal or a Do Not Track header to switch off — we honour them by not doing it in the first place.
3. What we never collect
- Card numbers, bank details or any payment credentials. There is no card field anywhere in this application. Where a business shows a Book & pay button it opens their checkout, run by their own payment company — you are on their page, paying them, and nothing about that transaction comes back to us. We are not told the amount, the card, or whether it went through.
- Government identifiers — no social security number, driver's licence or passport number.
- Precise location. We ask which city your event is in. We do not read your device's GPS.
- Sensitive personal information as California defines it — we do not seek your racial or ethnic origin, religion, health, sexual orientation, union membership, or the contents of your private messages elsewhere, and we do not use anything you volunteer to infer characteristics about you.
- Your contacts. Nothing here reads your address book. A guest list gets typed or pasted in by you.
4. Other people's information
When you enter a guest list, send an invitation, or tell us about a business you love, you are giving us information about somebody else. We treat it as theirs:
- A guest list is held for you. We do not market to your guests, do not add them to any list of ours, and do not pass them to vendors or sponsors.
- An invitation is sent as your invitation, and the reply comes back to you.
- A business you refer to us is contacted once to be invited. If they say no, that is the end of it and we keep only enough to remember not to ask again.
- Delete a guest list and it goes.
Please only enter details you are entitled to use, and only to invite people who are expecting to hear from you.
5. Why we hold it
- To run your account, and to keep your plan there when you come back on another device.
- To pass your enquiry to a business, and their reply back to you.
- To read requests before they go out — which is how a bad one gets stopped.
- To send invitations for you and record the answers.
- To send the account messages described in §11 of the terms.
- To send marketing, only if you switched it on.
- To keep the service secure, spot abuse, enforce the terms, and keep the records the law requires.
We do not use your information for automated decisions that produce legal or similarly significant effects about you. Where a tool suggests which vendors might suit a request, the shortlist is read by a person before anything is sent.
6. Notice at collection
California requires that we say, at or before the point of collection, what categories of personal information we collect, why, how long we keep it, and whether we sell or share it. In the language of Civil Code §1798.140:
- Identifiers — name, email address, IP address. Collected to run your account and reach you. Kept while your account is open.
- Customer records (§1798.80) — telephone number where you give one. Same purposes, same retention.
- Commercial information — the vendors you save, the enquiries you send, the event you are planning. Kept while your account is open.
- Internet activity — server logs of pages requested, kept for a short period for security and diagnosis, then discarded; and anonymous counts of which pages and buttons were used, kept indefinitely because they are numbers and carry no identifier of any kind.
- Geolocation — the city you name for your event. Not device location.
- Audio, electronic or visual information — photographs and video a business uploads to its own listing.
- Inferences — none. We do not build profiles, and the usage counts above cannot become one: a profile needs actions linked to a person, and nothing here links them.
- Sensitive personal information — none collected.
Sold or shared for cross-context behavioural advertising: no. Not in the last twelve months, and not at any time.
7. Cookies and browser storage
This site sets no cookies of its own. That is why you have not been asked to dismiss a banner. There is no advertising cookie, no analytics cookie and no cookie that follows you anywhere.
What the site does use is your own browser's local storage, which stays on your device and is never transmitted to us as a tracking signal. The whole list:
lpx.session— your sign-in token, so you are not asked to sign in on every page. Removed when you sign out.lpl.modeandlpl.picks— whether you are planning an event or looking for one thing, and what you have picked so far.lpl.city— the city you are planning in, so the page says the right one.lpl.keep.dismissed— that you closed the "keep this one" prompt, so it never asks twice.lpl.pending— your name and your marketing choice, held only between submitting the sign-up form and confirming your email, then deleted.
Clearing your browser's storage for this site removes all of it and costs you nothing but the sign-in.
One third-party cookie is worth naming because you may see it: our database provider
sits behind Cloudflare, which sets a short-lived bot-management cookie
(__cf_bm) on its own domain when the page loads your data. It is a security
measure, it expires in about half an hour, and it is not used for advertising.
8. Who else touches it
The complete list. Each is a service provider under California law, contractually limited to processing information on our instructions and forbidden from using it for anything of their own.
- Supabase — the database, the sign-in system, and the emails that confirm an address or reset a password. Everything in your account lives here.
- Cloudflare — hosting and content delivery for the site itself. Sees the requests, not your account contents.
- Google Fonts — two typefaces are served from Google's servers, which means your browser makes a request to them and Google's logs will show your IP address. No cookie is set and nothing about your account is involved. If this matters to you, a content blocker stops it and the site still works.
- YouTube and Vimeo — only on a listing where a business has embedded a video, and only when that page loads. YouTube embeds use the no-cookie player.
Beyond that, information leaves us in exactly three situations: you sent it — an enquiry goes to the business you sent it to, and an invitation goes to your guest; the law required it, through a valid legal process we will tell you about unless we are forbidden to; or the business changes hands, in which case this notice goes with it and we will say so here before it happens.
9. We do not sell or share it
We have never sold personal information and we do not share it for cross-context behavioural advertising, as the CPRA uses those words. There is no data-broker relationship, no advertising network and no exchange of your details for anything of value.
Sponsors pay for a marked slot on a page. They do not receive your information, and paying us buys visibility to whoever is reading — not a list of who read.
10. Marketing, and stopping it
The box on the sign-up form is not pre-ticked, and we record the moment you tick it and the moment you untick it.
Turning it on means we may email you ideas, offers and news from us and about the businesses listed here. It does not give any of them your address.
To stop: use the unsubscribe link in any marketing message, switch it off in your account, or email [email protected] and ask. We act on it promptly and in any event within ten business days, as CAN-SPAM requires. Account messages — a password reset, a vendor's reply — keep coming, because they are the service rather than marketing.
11. How long we keep it
- Your account and your plan — while your account is open.
- Enquiries and tickets — while open, then up to two years, because a dispute about an event usually surfaces after it.
- Guest lists — until you delete them or delete your account.
- Server logs — a short period for security and diagnosis, then discarded.
- Consent records — kept after you unsubscribe and after you close your account, because the proof that you asked to be removed is the whole defence if anyone later says you were not.
- Business listings and posts — while the listing is live.
Backups are cycled and overwritten on their own schedule, so deleted information can persist there briefly after it has gone from the live system.
12. Your California rights
If you live in California, the CCPA as amended by the CPRA gives you the right to:
- Know what personal information we hold about you, where it came from, why we have it and who we disclosed it to.
- Get a copy of it in a portable form.
- Correct anything inaccurate.
- Delete it, subject to the narrow exceptions the law allows.
- Opt out of sale or sharing — nothing to opt out of here, because we do neither.
- Limit the use of sensitive personal information — again nothing to limit, as we collect none.
- Not be discriminated against for exercising any of these. Your account works exactly the same afterwards, at the same price, which is nothing.
Ask by emailing [email protected] with Privacy request in the subject, or by calling 818 849 9179. We confirm receipt within ten business days and answer within forty-five days, extendable once by a further forty-five if we tell you why. It costs nothing.
We will need to be satisfied you are who you say you are, which usually means replying from the address on the account. An authorised agent may act for you with written permission we can verify.
13. Deleting your account
Email us and it is done — you do not have to give a reason and there is no retention offer waiting.
Your profile, your saved vendors, your plan, your guest lists and your notes are removed. Three things survive, and here is exactly why:
- The record that you unsubscribed, so nothing ever mails you again by accident.
- Messages already delivered to a vendor, which are in their inbox and are no longer ours to withdraw.
- Anything we are legally required to retain, for as long as we are required to retain it.
14. If you are outside California
The site is operated from and aimed at Los Angeles, and information is stored in the United States. If you use it from elsewhere, you are sending your information here.
Several other US states — Colorado, Connecticut, Virginia, Utah, Texas and others — give residents rights broadly similar to the Californian ones above. We do not run a different policy per state: ask for any of them and we will honour it wherever you live. If you are in the UK or the EU, write to us and we will deal with your request under the same principle.
15. Children
You must be 18 or older to hold an account. The site is not directed at children and we do not knowingly collect personal information from anyone under 13. If you believe a child has given us information, tell us and we will delete it.
Children are often at the events planned here. That is not the same as being a user of the site, and we hold nothing about them — a guest list you enter is covered by §4.
16. How it is protected
- Everything travels over HTTPS. There is no unencrypted path in.
- Access to your rows is enforced by the database itself, per row, on every single request — not by the page you are looking at. A page cannot ask for somebody else's information and get it, because the refusal happens underneath the page.
- Passwords are stored as one-way hashes by our authentication provider. Nobody here can read yours, including us.
- Privileged operations run through specific, named functions with the narrowest permission that does the job, rather than through broad access.
No system is perfect, and anyone who tells you theirs is should be read carefully. If a breach ever affects your information we will tell you and the California Attorney General as the law requires, and we will tell you what actually happened.
17. Changes to this notice
When the site changes, this page changes with it, and the date at the top moves. If we ever start doing something materially different with your information — adding analytics, say — we will say so plainly here and email account holders before it begins, rather than hoping the date change is noticed.
18. How to reach us
A real person reads all of these.
- Email — [email protected]
- Phone — 818 849 9179
- Or the form on our contact page
LA Party Lights, Los Angeles, California.