Momento Studio Privacy Policy
This explains what data the service collects, why, where it is kept and how to have it deleted. No vague wording: what is listed here is what actually happens.
1. Who processes the data
The Momento Studio service at momento-studio.com and as an application inside Telegram. The service is provided by a private individual; details about the operator are available on request.
For anything concerning your data, including deletion: support@momento-studio.com.
2. Who this policy covers
It concerns three different groups of people, and their data is different:
- the customer — the person who builds and pays for an invitation;
- the guest — the person who opens an invitation by link and may reply to it;
- the site visitor — someone who came to look at the designs and ordered nothing.
3. What we collect
From the customer when placing an order:
- name — to find the order and address you;
- phone number — to contact you about the order;
- email address — optional; passed to the payment partner for the receipt.
Invitation content that you fill in yourself: names, occasion, date, time, venue and address, your story, the day's schedule, dress code, parents' names and addresses, contact persons' names and phone numbers, gift details, texts and additional events.
Files you upload: photos and music.
From a guest, if you enabled replies: name, whether they are coming, number of guests, a comment and answers to any extra questions you added.
From a guest in the wishes book, if you enabled it: name and the text of the wish.
From Telegram, if you use the app or the bot: your permanent numeric Telegram identifier, first name, username, language code, chat identifier and your device's time zone.
About the payment: order number, amount, currency, status, date and transaction reference.
About your visit to the site: an opaque visitor and session identifier in a cookie, the address of the page opened, where you came from, campaign tags, device class (phone, tablet, desktop) and funnel events — opened the catalogue, started building, went to payment.
4. What we do NOT collect
This matters as much as the list above:
- card details. They are entered on the payment partner's side and never reach us in any form;
- your IP address. It is used in memory to rate-limit requests and filter out robots, and is never written down;
- your browser string (User-Agent). Used only to tell a robot from a person, and likewise not stored;
- your Telegram surname and profile photo — we do not request or store them;
- device fingerprints. The service builds no hidden identifiers.
5. Why we process data
| Data | Purpose |
|---|---|
| Customer name and phone | Place the order, find it when you write, contact you about it |
| Customer email | Pass to the payment partner for the receipt |
| Invitation content and files | Build and display the invitation page — that is the service itself |
| Guest replies | Show you who is coming |
| Wishes | Display them on the invitation page |
| Telegram data | Recognise you in the app without a password, show your invitations, deliver guest replies, show times in your own time zone |
| Payment data | Fulfil the order, refund where needed, keep accounts |
| Visit data | Understand where customers come from and where they stop |
The legal basis for the first seven rows is performance of our contract with you. For the last one it is your consent, given in the cookie banner; without it no analytics are collected.
6. What we see, and what only you see
Guest replies and wishes are stored as part of your invitation and shown to you only — in the Telegram bot, in the Momento Studio app, and through a separate link you can open or pass on.
The service has no cross-cutting list of replies across all invitations. We do not use guest replies, analyse them or share them.
The honest boundary: technically the replies sit in our database, and a member of staff can reach them. That happens in two cases only — at your request in support, and where the law requires it. Claiming that no access exists at all would be untrue.
The same applies to invitation content: we open it when you ask for a change or when we investigate a fault.
Wishes in the wishes book, unlike guest replies, are visible to everyone who opens the invitation — that is their point.
7. Photos and music
Uploaded files are held in public storage: an invitation page is open to anyone with the link, and its contents cannot be private.
A file's address contains a random string, so it cannot be guessed. But if you have given someone a direct link to a photo, it will open without the invitation.
Files are deleted together with the invitation.
8. Other people's data in your invitation
You may enter parents' names, contact persons' phone numbers and other details about people who never gave us anything themselves. By publishing the invitation you take responsibility for them not objecting.
The invitation page is closed to search engines — it is marked as not to be indexed and does not appear in search results. It does, however, open for anyone who has the link.
9. Cookies and analytics
A full list with retention periods is in a separate document, Cookies. In short:
- Necessary cookies handle the interface language and sign-in inside the Telegram app. They always work; without them the service does not.
- Analytics cookies are set only after you consent in the banner. They hold an opaque visitor identifier (365 days) and a session identifier (12 hours).
External counters — Google Analytics and Yandex Metrica — are switched off as of this version and are not loaded. If we enable them, they will load only with your consent and this section will be updated first.
Our own analytics run on our own infrastructure and are shared with nobody.
10. Who receives data
We do not sell data and do not share it for advertising. It goes only to those without whom the service cannot run:
- Supabase — database and file storage. Servers in Ireland.
- Hosting provider — the application server. Servers in Germany.
- Telegram — if you use the app or the bot: messages, Stars payments, your Telegram profile data.
- Payment partner — when paying by card: the amount, the order number and your email if you gave one. The partner acts as a reseller of record and processes the payment under its own rules.
- Google Maps or Yandex Maps — if you added a map to an invitation, it loads from their servers. When the invitation is opened they receive the guest's IP address and details of the guest's browser. This happens on the guest's side and is outside our control. Do not add a map if that is unwelcome.
11. Transfers outside your country
Our servers are in Ireland and Germany. Telegram and the payment partner run on their own infrastructure in various countries.
This means your data is processed outside the country where you live. By placing an order you understand and accept this.
12. How long we keep data
| What | How long |
|---|---|
| Invitation, files, guest replies, wishes | While the invitation is live: until the event date and about two weeks after. The link then closes |
| All of the above on a deletion request | Deleted 24 hours after the request, permanently |
| Anonymised payment record | Kept after the invitation is deleted: order number, amount, date, transaction reference. Name, contacts and content are stripped from it |
| Telegram data | While you use the app or the bot. The /stop command turns off notifications |
| Visit analytics | 365 days, then deleted automatically |
13. Your rights
You may:
- find out what data about you we hold;
- correct it — simply tell us what to change;
- delete an invitation and everything connected to it;
- withdraw consent to analytics — clear the site's cookies in your browser;
- turn off Telegram notifications with the /stop command;
- complain to the data protection authority of your country if you believe we have breached your rights.
For any of these, write to support@momento-studio.com. We reply within 1–3 business days.
We may check that the request really comes from you — otherwise anyone could have someone else's invitation deleted.
14. How to have data deleted
Write and tell us which invitation to delete. Then:
- the invitation stops opening immediately;
- for the next 24 hours the decision can be reversed;
- after that the invitation, uploaded files, guest replies and wishes are deleted permanently.
Only the anonymised payment record remains — it is needed for accounting and payment disputes, and we cannot delete it on request.
15. Security
Access to the database is closed to everything except the application. Telegram's signed data is verified on the server rather than taken on the browser's word. Connections are protected with TLS. Tokens and keys are stored encrypted.
Absolute security does not exist and we will not promise it. If a breach occurs that affects your data, we will tell you and notify the supervisory authority as the law requires.
16. Minors
Placing and paying for an order requires you to be 18 or older.
There is no age limit for a guest who opens an invitation and replies to it: that needs no account and no payment. A guest gives their name and their answer — and nothing else.
If you include a child's details in an invitation, you are responsible for their legal guardian not objecting. If you believe a child's data reached us without such consent, write to us and we will delete it.
17. Changes to this policy
This policy may change. The version in force is always on this page, with the effective date shown at the bottom. We will notify people whose invitations are live about material changes.
18. Language of this document
The official versions are Russian and English. Translations into other languages are provided for convenience. Where the meaning differs, the Russian version prevails.
19. Contact
Related documents: Terms of Use · Refund Policy · Cookies