Who we are and what this covers
SuspectParty is a United States-facing service that turns a host's guest list into a private, fictional murder-mystery party. This notice covers the website, the builder, checkout, the hosted party experience, and the printable kits. It applies to two kinds of people: hosts, who buy a party and give us information, and guests, whose first names and traits a host enters. Guests never need an account and we never contact them except with links the host chooses to share.
What we collect from hosts
When you build and buy a party we collect:
- Your email address, used for order confirmation, delivery, and account recovery.
- Your party configuration: occasion, theme, tone, player count, whether you play, and the tier you buy.
- Order records: what you bought, the price, refund status, and the payment identifiers Stripe gives us. We never see or store card numbers.
- Service and security logs: rate-limit counters and abuse-prevention records derived from network information, and error reports needed to keep the service working.
What hosts tell us about guests
To personalize a mystery, the host enters for each guest: a first name, two or three personality traits, an optional fun detail, and optionally whether the guest is a minor (which locks the party to Family tone rules). That is the entire guest profile - no emails, no photos, no accounts.
This is information about other people, so two commitments apply. The host confirms they reasonably believe every guest will enjoy taking part. And we use guest details for exactly one thing: casting and delivering that host's private game. Guest details are never used for marketing, never sold, and never combined across parties. Any guest can ask us to remove their details from a party - see Contact below.
How AI creates your mystery
The story is written by AI using the details the host provides. Guest first names and traits are sent to Anthropic (Claude) to write the fictional narration, character files, and clues. On the Deluxe tier, guest traits (never photos) are sent to OpenAI to draw fictional illustrated portraits. Under both providers' API terms, content submitted through their APIs is not used to train their models.
A moderation layer screens inputs before generation, and the game logic itself is decided by our own deterministic engine - the culprit is always a fictional role chosen before any personal detail is considered. Personality traits color the prose; they never determine who "did it."
Payments
Checkout happens on Stripe's hosted payment page. Card details go directly to Stripe and never pass through SuspectParty servers. Stripe collects and remits sales tax where required and issues the official payment receipt. We keep the order and refund records a business is required to keep.
Cookies and on-device storage
We use no third-party tracking cookies by default. What we do use:
- One HttpOnly cookie set during checkout, scoped to the payment-return endpoint, which proves your browser started the purchase. It expires with the checkout session.
- Browser storage (localStorage) on your own device: your builder draft, your host access keys, your guest-link list, your analytics consent choice, a first-visit attribution note, and a random visitor id. These stay in your browser so that a closed tab or lost connection never loses your party; clearing site data removes them.
Analytics and advertising
A consent banner controls everything optional. Essential only keeps just the storage the product needs to function. If you choose Allow analytics, we measure the purchase funnel (which may use PostHog) and, only if advertising campaigns are running, advertising pixels from Meta or TikTok may load. Declining or withdrawing consent keeps all of that off - advertising providers receive nothing about you without it. You can change your choice at any time from the banner, and client and server events are deduplicated so no extra data is created.
Service providers
We use a small set of providers, each doing one job:
- Vercel - application hosting (United States).
- Supabase - database for orders and parties (hosted in Canada, ca-central-1).
- Cloudflare R2 - private file storage for generated kits, served only through short-lived signed links.
- Stripe - payments, receipts, and sales tax (United States).
- Resend - transactional email dispatch (processed in the EU, eu-west-1).
- Anthropic - story text generation (United States).
- OpenAI - fictional portrait generation, Deluxe only (United States).
- ElevenLabs - text-to-speech for the detective briefing, Deluxe only. It receives the briefing text, never a guest's voice, and no guest voice is ever recorded or cloned.
- Sentry - error monitoring, with emails, names, tokens, and authorization headers scrubbed before storage.
- Inngest - background job queue for reliable generation and delivery.
Each provider processes data only to provide its service to us.
Where data is processed
SuspectParty operates from the United States. As the list above shows, some processing happens outside the US: the database is hosted in Canada and email dispatch runs in the EU. Wherever the data sits, the same access rules in this notice apply.
Retention and deletion
Data lives as long as the party needs it and no longer:
- Builder drafts live only in your browser until you buy.
- Party and guest data persist so your group can play and revisit the case; the host can delete the party and its guest data at any time.
- Emailed links expire: a sign-in link you request yourself lasts 24 hours, the link in your purchase email lasts 30 days, and kit download links are short-lived and re-signed on demand.
- A refund closes guest links and file access when it is processed.
- Order, payment, and tax records are retained as law requires. Error logs are scrubbed of personal detail and age out on the monitoring provider's schedule.
Security
Every private surface is token-gated: each guest link carries a hard-to-guess signed token and the server returns only that guest's visible fields - one guest can never read another's secrets, and no spoiler leaves the server before the host unlocks it. Host controls require a separate host token. All API routes sit behind rate limiting with brute-force lockouts, secrets are stored as environment configuration rather than code, and error reports are scrubbed before they leave the application.
Children's privacy
SuspectParty is sold to adults (18+). Hosts may include minors as guests only with the party in Family tone and with a parent or guardian's knowledge; the only child data involved is the first name and traits the host types. We do not knowingly collect personal information directly from children under 13, and a parent or guardian can have a child's details removed from any party by contacting us.
Your US privacy rights
Depending on your state (including under the California Consumer Privacy Act and similar laws in Virginia, Colorado, Connecticut, Texas, and others), you may have the right to:
- Know and access the personal information we hold about you;
- Correct inaccurate information;
- Delete your information;
- Receive a portable copy of it;
- Opt out of sale, sharing, or targeted advertising - noting that we do not sell personal information, and advertising pixels only ever run after opt-in consent, which you can withdraw at any time;
- Not be discriminated against for exercising any of these rights.
To exercise a right, email us from the address on your order so we can verify you. We respond within the timelines your state law sets, and we will not require an account to honor a request.
Contact and changes
Privacy questions, guest removal requests, and rights requests: support@suspectparty.com. If this notice changes in a way that matters, we update the date above and, for material changes affecting existing orders, notify hosts by email.
