This is the privacy policy for Invitee (“the Service”). It explains what personal data we collect, why, how long we keep it, and how you control it. We aim for the data-minimization principle of GDPR and the European Data Protection Board: collect only what we need, keep it only as long as necessary.
The operator of Invitee acts as the data controller. Full identification and postal address are on the Service information page.
For data requests (access, export, deletion, rectification), email [email protected] or use the contact form. You do not need an account to contact us, and we answer within 30 days.
We do not collect: tracking cookies for advertising, browser fingerprints, location data, contact lists, payment information.
You are reading this because you were sent an invitation link. The host of that event decides who to invite and what to ask you; we provide the platform, store your answer, and show it to that host and nobody else. We never use a guest’s details to market anything, never add guests to a mailing list, and never make a guest create an account. To correct or delete an RSVP you already sent, ask the host (they can delete it from their dashboard) or contact us directly — either route works.
A host can send messages to guests who said they are coming — a change of venue, a thank-you. Every one of those carries an unsubscribe link, and an unsubscribe applies to every event you have ever replied to, not just the one you clicked from. You do not have to give a reason and you do not need an account. Your reply itself is untouched by unsubscribing; ask us if you want that deleted too.
Strictly-necessary cookies, always set:
PHPSESSID: identifies your browser session. Set when you open a page with a form that must be protected against forged submissions (an invitation's RSVP form, sign-in, the report forms) and when you click a magic link; it then also identifies your sign-in session. Strictly necessary, so no consent is required. Cleared on sign-out or when the browser session ends.That is the only cookie we set. No analytics cookies, no advertising cookies, no third-party trackers, and no cookie banner — because there is nothing to ask you about.
We do look at visitor statistics, and we would rather say so plainly than hide behind the absence of a cookie. They come from our network provider (Cloudflare, below), which counts requests as it passes them on. That means totals: how many visits a page got, which country they came from, and which site linked to us. It uses no cookie, sets nothing on your device, runs no script in your browser, and cannot follow you to any other website. We cannot tell who you are from it, and there is no per-person history to look at even if we wanted one.
a.nel.cloudflare.com. It fires only when something breaks, contains no page content, and exists so outages can be diagnosed. Nothing is requested from that address during a normal visit.| Data | Retention | Why |
|---|---|---|
| Your account & drafts | While you actively use it | Product utility |
| Inactive accounts | Deleted after 24 months without sign-in, together with the events and RSVPs attached to them. We email you a warning a month beforehand, and signing in once resets the clock. | Data minimization |
| Published events | Kept until you unpublish or delete them, delete your account, or your account is removed for 24 months of inactivity | Hosts often want post-event reference |
| Unpublished drafts (server-side) | Deleted 12 months after last edit if still unpublished | Data minimization |
| RSVPs | Deleted with the event they belong to (when the host deletes the event or their account) | Guest privacy |
| Publish IP hash + user-agent | Erased 6 months after the event is first published. The event itself is not affected. | Abuse investigation |
| RSVP IP hash | Erased 6 months after the reply. The reply itself is not affected. | RSVP spam prevention |
| Magic-link token records | Deleted 30 days after creation | Already useless; debug aid |
| Rate-limit counters | Expire after 2 hours; the row is deleted within 24 hours | Auto-cleared |
| Administrative audit log | 24 months | Accountability for administrator actions; DSA record-keeping |
| Abuse reports (the report itself) | 5 years | Legal evidence; DSA moderation record |
| Bug reports | 24 months | They carry an email address and a free-text description |
| Email unsubscribe record | Kept indefinitely, as a keyed hash of the address and nothing else | An opt-out we forget is an opt-out we break |
| Server access logs (Hostinger) | Per Hostinger’s policy | Out of our direct control |
You can request immediate deletion of any data using the “Delete my account” button in the studio (signed-in users) or the contact form. We honor erasure requests within 30 days.
We share data with these processors strictly to operate the Service:
We do not sell, rent, or trade your data, we run no advertising, and we share nothing with anyone for advertising, profiling, or tracking you across other websites.
All data is stored on Hostinger servers within the European Union.
Getting it there is a separate question. Traffic reaches us through Cloudflare, a US company operating a worldwide network; visitors from Europe are normally served by a European location (for Italy, Milan), but Cloudflare is capable of routing through others and is subject to US law wherever the request lands. Transfers rely on the EU-US Data Privacy Framework and on standard contractual clauses. This applies to every visit, not only the ones listed below — it is a property of how the site is delivered, not something you can opt out of by avoiding a feature.
Beyond that, two things travel outside the EU/EEA only if you choose them, both under the EU-US Data Privacy Framework:
If you don’t use social sign-in and never press “Show map”, nothing of yours reaches Google or Facebook at all.
If you’re in the EU/EEA you have the right to:
To exercise any of these rights, use the contact form or email [email protected]. You do not need to be signed in, and you do not need an account at all — guests can write to us directly. Standard response time: 30 days.
The Service is not intended for users under 16, and we do not knowingly let anyone under 16 create an account. If you become aware of one, please report it via the contact form and we will delete the account.
That is a separate question, and an honest policy has to answer it. Christenings, first birthdays, baby showers and graduations are among the most common things people make invitations for, so children’s names, dates and photographs pass through this Service constantly — uploaded by adults, about children who cannot consent for themselves.
Where that happens, the adult who uploads is responsible for having the right to do so, and we ask them to confirm it in the Terms of Use. For our part: an invitation is only reachable by someone holding its link, published pages carry noindex so search engines do not list them, and we never use uploaded photographs for anything but showing that invitation to the people it was sent to — not for promotion, not for training anything, not for any purpose of our own.
If a child of yours appears on an invitation and you did not agree to it, tell us and we will take it down. You do not need an account, you do not need to identify yourself beyond a way for us to reply, and you do not need to approach the host first.
httponly + SameSite=Lax cookies (Lax not Strict so OAuth sign-in callbacks from Google/Facebook keep your session; Lax still blocks cross-site form CSRF, and the JSON APIs additionally require an X-CSRF-Token header)We may update this policy. Material changes are reflected in the “last updated” date above. If you have an account, we’ll email you about substantive changes.
For data requests, questions, or concerns: email [email protected], or use the contact form. Our full legal and postal details are on the Service information page. See also the Terms of Use. If you are a guest who was sent an invitation, you can write to us directly — you do not need an account and you do not need to go through the host.