All legal documents

Privacy Policy

Last updated: 2026-08-28

How Invitari handles personal data. Written to be read — no dark patterns, no tracking.

DRAFT. This document is generated from the product's actual behaviour and data model and is pending professional legal review before commercial launch.

The operating company is not yet registered. Placeholders in square brackets will be replaced with verified legal details before the service is offered commercially.

1. Who is responsible

Invitari ("the Service") is operated by [company name not yet registered], [legal form], [registered address], [country] ([company registration number], VAT [VAT/EIK number]).

For most account and service data the operator acts as a data controller. For guest RSVP data submitted through an invitation, the operator generally acts as a processor on behalf of the person who created that invitation. See our role analysis for detail.

No Data Protection Officer has been appointed; this will be reviewed as the service grows.

2. What we collect, why, and on what basis

When you create an account: your email address, your name, a bcrypt hash of your password (never the password itself), and your preferred interface language. Basis: performance of our contract with you (the Terms of Service).

While you are signed in: a session record containing an opaque session identifier, your user id, your browser's User-Agent string and timestamps. Basis: strictly necessary to keep you logged in.

Invitation content you enter: event title, host or celebrant names, date and time, location name and address, a maps link, your written messages, dress code, additional notes and a contact phone number. This is your content — it may include information about other people (a partner, a child, co-hosts). Basis: performance of our contract; you are responsible for having a lawful basis to include other people's details.

Images you upload: the image file (stored in object storage, not in our database) plus metadata — a generated storage key, the public URL, image type, size, dimensions, your alt text and display order. Original file names are discarded.

Guest RSVP submissions: a guest's name, whether they will attend, a guest count, an optional message, a one-way salted hash of their IP address for spam protection (the raw IP is never stored), and a timestamp. Basis: the legitimate interests of the invitation's host in organising their event, and our legitimate interest in preventing abuse for the anti-spam hash.

3. What we deliberately do NOT collect

No analytics, advertising or tracking technologies of any kind.

No third-party analytics service, no advertising pixels, no fingerprinting.

No raw IP addresses stored (only a salted hash for RSVP anti-spam).

No payment data — payments are not part of the current product.

No AI processing of your content.

No marketing consent capture, because we run no marketing programme.

4. Cookies and local storage

We use two cookies, both strictly necessary: invitari_session (keeps you logged in; HttpOnly, SameSite=Lax, Secure in production; ~30 days) and INVITARI_LOCALE (remembers your chosen interface language; ~1 year).

We do not use localStorage or sessionStorage for tracking, and we set no analytics or marketing cookies. Because only strictly necessary cookies are used, we do not show a consent banner. See the Cookie Policy for the full list.

5. Who else can see your data

Platform administrators can view accounts, invitations and RSVP records for support, moderation and abuse handling. Administrators never see password hashes or session tokens, and there is no "log in as this user" feature.

A published invitation and its images are reachable by anyone who has the link — that is the point of an invitation. Draft invitations are private and are not indexed by search engines.

In production, infrastructure providers (hosting, database, object storage and — once implemented — an email provider) will process data on our behalf under written data-processing agreements. These providers are not yet selected; this section will name them before launch.

We do not sell personal data and we do not share it for advertising.

6. International transfers

The hosting region and sub-processors are not yet chosen. If any processor is located outside the EEA/UK, we will put an appropriate transfer mechanism in place (such as Standard Contractual Clauses) and describe it here before launch.

7. How long we keep data

Account data: for the life of your account.

Invitations, their images and their RSVP responses: for the life of the invitation. Deleting an invitation permanently deletes its database record, its uploaded images and all RSVP responses attached to it.

Sessions: 30 days, or until you log out.

When you delete data, it is removed from the live database promptly. Encrypted backups (once a production backup policy exists) may retain copies for a limited, documented period before rotation; we will state that period here once backups are configured.

8. Your rights

Subject to applicable law, you can request access to your data, correction, deletion, restriction of processing, portability, and you can object to processing based on legitimate interests.

Today: you can edit or delete each invitation yourself from your dashboard, which removes its content, images and RSVP data. Account self-deletion and a one-click data export are not yet built — until they are, contact us at the address below and we will action your request manually.

If you are an event guest and want to exercise rights over an RSVP you submitted, contact the host who created that invitation; we will assist them as their processor.

You have the right to lodge a complaint with a data-protection supervisory authority — the authority in your country of residence, or the lead authority for the operator once the company is established.

9. Automated decision-making

We do not carry out automated decision-making with legal or similarly significant effects, and we do not profile users.

10. Security

Passwords are hashed with bcrypt and are never stored or logged in plain text. Sessions use opaque, random identifiers in HttpOnly cookies. Access to your invitations, guest lists and images is checked against your account on every request. Uploaded files are validated by their actual content, not their name. We set security headers including a Content-Security-Policy. We do not claim to be "100% secure" — no service can.

11. Children

The Service is for adults creating invitations. Some invitations (for example a child's birthday) may include a child's name or photograph, entered by the adult account holder, who is responsible for that content. If you believe a child's data is on the Service without a proper basis, contact us and we will act.

12. Changes and contact

We will update this policy as the product and company develop. Material changes will be highlighted.

Privacy questions and requests: [privacy email].

Privacy requests and questions: [email protected]