Legal

Privacy Policy

Effective date: 23 July 2026

Last updated: 23 July 2026

1. Who we are

Cevel is a booking and payments platform for independent creators, operated by:

Noshiro OÜ
Estonian registry code: 16594740
Harju maakond, Tallinn, Kesklinna linnaosa, P. Süda tn 4-150, 10119, Estonia
Email: hello@cevel.app

In this policy, "Cevel", "we", "us" and "our" mean Noshiro OÜ. Noshiro OÜ is the data controller for the personal data described below.

We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 of the GDPR. Privacy questions can be sent to hello@cevel.app.

2. Who this policy covers

This policy applies to two groups:

Where something applies only to one group, we say so.

3. What data we collect

3.1 Creator account data

When you create a Cevel account, we collect and store:

Our authentication system also records technical security metadata, including IP address, browser user-agent and sign-in timestamps, for the purpose of account security and abuse prevention.

3.2 Subscription and payout data

If you subscribe to Cevel Pro or set up payouts, we store:

We do not store your card details, bank account number, IBAN, national identity document or date of birth. Those are collected and held directly by Stripe during their hosted onboarding and checkout flows. They never pass through or rest on Cevel's systems.

3.3 Event and class data

Creators publish events through Cevel. This includes the class title, description, date and time, location, capacity, price and any images uploaded. Where a Creator includes personal information in this content, that content is published on a publicly accessible page.

3.4 Participant booking data

When someone books a place on a class, we collect:

This information is visible to the Creator hosting the class. It is not visible to other Creators or to other participants.

3.5 Studio room bookings

Where the studio room rental features of Cevel are used, we also store room listings, availability and booking records associating a Creator with a booked room and time slot.

3.6 What we do not collect

We do not use analytics, advertising or tracking technologies. We do not run Google Analytics, advertising pixels, session recording, heat-mapping or behavioural profiling of any kind. We do not build advertising profiles, and we do not sell personal data.

4. Why we process your data, and our legal basis

What we doWhyLegal basis (GDPR Art. 6)
Create and operate Creator accountsTo provide the service you signed up forPerformance of a contract
Publish public booking and schedule pagesTo deliver the core function of the productPerformance of a contract
Record and manage class bookingsTo register a participant's place and inform the CreatorPerformance of a contract
Send booking confirmations and host notificationsTo confirm bookings and notify CreatorsPerformance of a contract
Send account emails (sign-up, password reset, magic link)Account access and securityPerformance of a contract
Take subscription paymentsTo bill for Cevel ProPerformance of a contract
Enable payouts to CreatorsSo Creators can be paid by participantsPerformance of a contract
Keep accounting and transaction recordsEstonian and EU accounting and tax lawLegal obligation
Protect accounts, prevent fraud and abuseTo keep the platform and its users safeLegitimate interests
Respond to support requestsTo help you when you contact usLegitimate interests

Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights and freedoms, and we believe they are not. You can object to this processing — see section 9.

We do not carry out automated decision-making that produces legal or similarly significant effects on you.

5. Public visibility

Some information is deliberately public, because Cevel exists to help Creators be found and booked:

Participant booking details are never public. Names, email addresses, phone numbers and Instagram handles of participants are visible only to the Creator hosting that class.

Creators can unpublish a class at any time, which removes it from public view. Draft classes are never publicly visible.

6. Who we share data with

We share personal data only with the service providers we need to run Cevel. Each acts under contract and is bound to protect your data.

Lovable — application hosting and infrastructure platform. Lovable operates the environment in which Cevel runs, including the database and email delivery gateway.

Supabase (via Lovable) — database and authentication. All Cevel account data, event data and booking data is stored here. Hosted in Ireland (AWS eu-west-1).

Resend — transactional email delivery. Receives recipient email addresses, names and event details in order to send booking confirmations, host notifications and account emails. Configured for Ireland (eu-west-1).

Stripe — payment processing. For users in the European Economic Area, the responsible Stripe entity is Stripe Payments Europe, Limited (SPEL), an Irish company regulated by the Central Bank of Ireland. Stripe receives email addresses, names, transaction details and, for Creators taking payouts, identity and bank details collected directly by Stripe. Stripe is certified to PCI-DSS Level 1 and SOC 2 Type 2.

Stripe acts as our processor when carrying out payments on our instruction, and as an independent controller for its own fraud prevention, anti-money-laundering and regulatory obligations. You can read Stripe's privacy policy at stripe.com/privacy.

We may also disclose personal data where we are legally required to do so — for example in response to a valid order from a court or competent authority.

We do not sell personal data, and we do not share it with advertisers.

7. International transfers

Cevel's core data — accounts, classes, bookings and participant details — is stored within the European Union, in Ireland.

Stripe operates globally and may transfer personal data outside the EEA, including to the United States, as part of providing payment services. Stripe protects these transfers using the European Commission's Standard Contractual Clauses and the EU-U.S. Data Privacy Framework, under which Stripe, Inc. is certified.

Where any other transfer outside the EEA occurs, we will ensure an appropriate safeguard under Chapter V of the GDPR is in place.

8. How long we keep data

DataRetention
Creator account and profile dataFor as long as your account is open, and deleted on request or on account closure
Class and booking recordsFor as long as the Creator's account is open, so Creators keep access to their own history
Payment and transaction records7 years from the end of the financial year, as required by the Estonian Accounting Act
Email delivery logsUp to 12 months, for deliverability troubleshooting
Security and sign-in metadataUp to 12 months

When you close your Cevel account, your profile, subscription and payout records are deleted. Where we are legally required to keep transaction records, we retain only the minimum necessary for that purpose.

Participants: if you would like your booking record removed, you can contact the Creator who hosts the class, or contact us directly at hello@cevel.app.

9. Your rights

Under the GDPR you have the right to:

To exercise any of these rights, email hello@cevel.app. We will respond within one month. If your request is complex we may extend this by a further two months, and will tell you if we do.

We do not charge for handling these requests, unless a request is manifestly unfounded or excessive.

10. Complaints

If you believe we have handled your personal data improperly, please contact us first at hello@cevel.app so we can try to resolve it.

You also have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is:

Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate)
Tatari 39, 10134 Tallinn, Estonia
www.aki.ee

You may also complain to the supervisory authority in the EU country where you live or work.

11. Cookies and local storage

Cevel uses a small number of strictly necessary cookies and browser storage items. We do not use advertising, analytics or tracking cookies, and therefore we do not display a cookie consent banner.

ItemTypePurpose
Authentication session tokenLocal storageKeeps you signed in to your Cevel account
Interface preferencesCookieRemembers layout preferences such as whether a panel is collapsed

When you pay for a class or subscription, Stripe sets its own cookies on Stripe's checkout pages for fraud prevention. These are governed by Stripe's cookie policy, available at stripe.com/cookies-policy/legal.

12. Security

We protect personal data using:

No system can be guaranteed completely secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Estonian Data Protection Inspectorate within 72 hours and inform affected individuals where required.

13. Children

Cevel is not directed at children. You must be at least 18 years old to create a Creator account. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact hello@cevel.app and we will delete it.

Where a Creator's class is aimed at under-18s, the Creator is responsible for obtaining any consent required from a parent or guardian before submitting that child's details.

14. Changes to this policy

We may update this policy from time to time. If we make a material change, we will update the "Last updated" date at the top and, where the change significantly affects you, notify Creators by email.

15. Contact

Questions, requests or concerns about this policy or your personal data:

Noshiro OÜ
Harju maakond, Tallinn, Kesklinna linnaosa, P. Süda tn 4-150, 10119, Estonia
Registry code: 16594740
hello@cevel.app