Effective 19 August 2026
What this policy covers
This policy explains how Your Invite Card handles information when you design an invitation, create an account, publish a guest link, collect RSVPs, or collaborate with a co-host. It covers the website, the installed progressive web app, and the Your Invite Card Android app distributed through Google Play, which opens the same web service. A host controls the personal details they place in an invitation or guest list and should have permission to use them.
Information we handle
- Account and access data: your email address, a one-way password hash, email-verification and password-reset requests, session records, account creation and last-sign-in times, current Invite Plus status for each event, and any historical trial or entitlement records associated with the account. Creating a free account does not require a payment card.
- Invitation and event data: draft names, invitation wording, dates, venues, phone numbers, uploaded images, custom-theme event and style descriptions, generated theme images, guest households, event functions, RSVP questions, co-host roles, reminders, and host notes you choose to add.
- Anonymous exported invitations: when someone who is not signed in generates a PNG or PDF download, we retain the invitation design that produced it. This can include its name, wording, dates, locations, contact details, selected artwork, uploaded-image references, theme, layout, page count and occasion, together with the export format, export count and first and latest export times. A one-way protected browser-draft reference lets repeated exports update the same record; we do not attach the record to an email account or retain the original browser-draft identifier.
- Published invitations, RSVPs, and Event Passes: the current invitation design explicitly published to each active guest link; optionally, a guest's family name, attendance choice, party size, answers, and update time. Confirmed households may receive a private Event Pass for host-published event photos and short videos. Guest edit and Event Pass tokens are stored in hashed form. Draft edits alone do not rewrite a guest link, but an authorised host can explicitly update the active link while retaining its URL and RSVP responses.
- Private event gallery: original uploads retained while processing, prepared photo and video files, thumbnails or posters, captions, order, processing state, dimensions, duration, file size, and host moderation actions. New uploads stay hidden until an authorised owner or editor publishes them.
- Invite Plus payment records: when a host starts or completes an Invite Plus purchase, we retain its event-linked order, entitlement, receipt, refund, currency, and status references for delivery, support, accounting, fraud prevention, disputes, and legal obligations. A hosted payment provider processes card or banking details; Your Invite Card does not store full payment-card numbers. Historical records continue to use the identifiers captured when they were created.
- Product measurement: first-party, aggregate funnel events such as landing on a public page, selecting a template, starting or completing an edit, publishing, receiving a first RSVP, issuing or opening an Event Pass, uploading or publishing gallery media, and, where applicable, completing a checkout. These events do not contain your email address, household name, raw token, file name, media bytes, raw IP address, browser user agent, page URL or referrer, invitation, account, publication, or payment identifiers. A random session identifier exists only in session storage and disappears when that browser session ends. GoatCounter measures visits to public marketing, editor, and policy pages and receives the page path, complete URL query string, and the referrer supplied by your browser. Query strings may include an occasion, draft reference, campaign value, or other value present in the public-page URL. GoatCounter does not use cookies or store raw IP addresses or full browser user-agent strings.
- Security and operations data: privacy-preserving IP hashes used for rate limits, including anonymous export-storage limits, request IDs, error events, and ordinary web-server records used to prevent abuse and diagnose failures.
- Android notifications: if you explicitly enable notifications in the Android app, we store an encrypted Firebase registration token, a random app-install identifier, device model and app version, notification preferences, delivery state, and the account-safe title, summary and destination of messages queued for you. Notification text never includes guest phone numbers, free-form guest messages, custom RSVP answers, private media names, or invitation and Event Pass secrets.
- Vendor marketplace data: vendor business profiles, team memberships and invitations, service areas, function coverage, prices, portfolio images, policies, response statistics, host shortlists, inquiry details and responses, verified-inquiry reviews, reports, moderation decisions, and aggregate profile analytics. Featured subscriptions retain Stripe customer, subscription, price, currency, status, period-end, and webhook references, but not full payment-card numbers.
Anonymous invitation drafts are normally kept in your browser using IndexedDB or local storage. When you generate a PNG or PDF while signed out, the current card is also sent to our servers as the anonymous exported-invitation snapshot described above. Draft content can also reach our servers when you upload media, sign in and synchronize, or publish a guest link.
Why we use it
We use information to provide, synchronize, publish and support invitations; review anonymous exported-card snapshots to understand completed designs and improve the editor and template library; generate a custom invitation theme when you ask us to; provide free features and event-specific Invite Plus access; verify account email addresses, reset passwords and deliver host reminders; collect RSVPs at the host's request; process and support transactions and refunds; secure accounts; investigate abuse and failures; meet accounting obligations; understand aggregate product progress; and improve service reliability.
Where data-protection law requires a legal basis, we rely on our legitimate interests to retain and review anonymous exported-card snapshots for product improvement. We limit this processing by keeping the records out of named accounts, restricting them to authorised administrators, honouring Do Not Track and Global Privacy Control, and deleting them 90 days after the latest export. You may object to this processing by contacting us.
Who can see it
Anyone who has an active guest link can view the information displayed on that invitation. Guest links are not listed in our sitemap and are marked not to be indexed, but a recipient can still forward a link. Co-hosts see only the event access their role permits. Hosts can view RSVP responses for invitations they own.
Anonymous exported-invitation snapshots are available only to authorised administrators through the private administration area. They are not published, added to the public template catalog, or connected to a named account.
Only a confirmed household with a current Event Pass, or an authorised event host, can open the private event gallery. Guests see published items only. Anyone in a household can forward its pass, so guests should keep it private; changing the RSVP away from Going, deleting the response, or revoking the invitation invalidates that pass.
Approved vendor profiles and published reviews are available only to signed-in hosts inside Planning Cockpit and are not listed in our sitemap. Each vendor receiving an inquiry sees only its own isolated lead. We share the host-approved name, email or phone, function type, date, metro, approximate venue area, budget range, and message. We do not share invitation content, an exact private address, collaborators, guests, or RSVP data with vendors.
We use specialist providers for hosting and delivery, Cloudflare for network security and performance, Brevo for account-verification, password-reset and service email, Firebase Cloud Messaging for Android notifications you enable, GoatCounter for privacy-conscious public-page visit counts, OpenRouter and its selected image-model provider when you request a custom theme, and a hosted payment provider for Invite Plus and vendor billing when checkout is enabled. Firebase receives the app registration token and notification delivery request, including the safe title, summary and destination described above; it does not receive the excluded guest or Event Pass data. GoatCounter receives the limited public-page measurement described above. The event and theme description you enter is sent to OpenRouter for that generation, so do not include private information. Payment providers process transaction information under their own legal obligations. We may disclose information when legally required or to protect users and the service.
Retention and deletion
- Expired account-verification and password-reset tokens, sessions, rate-limit records, and trashed drafts are removed by scheduled cleanup.
- Active drafts and public links remain until you delete your account, delete the relevant data, or revoke the link.
- Unused generated-theme previews expire after 24 hours. Accepted theme images remain with the invitation or published link that uses them.
- RSVP and event-management data remains available to the host until it is deleted with the associated event, invitation, or account.
- Private event-gallery files remain with the associated event until the host deletes them or the owning event or account is deleted. Failed processing sources remain private for host retry and are covered by storage limits and orphan cleanup.
- Vendor portfolio files and marketplace records remain while the profile or inquiry relationship is active. Account deletion removes host contact details from retained leads, removes vendor memberships, transfers a profile to an existing manager where possible, and otherwise suspends a sole-owned profile. Legally necessary subscription and billing records may remain.
- Aggregate product events are retained for up to 400 days. Daily rotating abuse-prevention hashes used for product-event and anonymous export-storage rate limits are retained for up to two days.
- Anonymous exported-invitation snapshots are retained for 90 days after the latest export and are then removed during routine cleanup.
- Active Android device registrations remain until you disconnect the device, sign out of the paired session, delete the account, or Firebase reports that the app registration is no longer valid. Revocation metadata, delivery results and admin-announcement audit records remain for security and operational review until routine cleanup.
- After account deletion, limited transaction, refund, fraud-prevention, and audit records may be retained where needed for legal, tax, chargeback, or security purposes, without keeping your editable invitation content.
- Deleted data can remain in restricted backups until routine rotation, normally no longer than 35 days.
Your choices
First-party product measurement and GoatCounter do not use analytics cookies. This site does not load GoatCounter or retain an anonymous exported-card snapshot when browser automation, Do Not Track, or Global Privacy Control is enabled.
You can download a machine-readable copy of server-held account data from the data export page. You can permanently delete your account and hosted invitation data from the account deletion page. Browser-only drafts are not part of the server export; clear this site's browser storage if you also want to remove them from that device.
Android notifications are off until you enable them. In Account, you can separately control action updates and announcements or disconnect a device. Android system settings provide channel-level controls and a master notification switch.
You may also ask for access, correction, restriction, or help with a privacy concern by emailing [email protected]. Rights differ by location, and we will honour rights required by applicable law.
Safety and updates
Your Invite Card is not directed to children under 13. Adults creating invitations for children are responsible for the details and images they publish. We use access controls, encryption in transit, hashed credentials and tokens, rate limiting, backups, and monitoring, but no online service can promise absolute security.
We may update this policy as the service changes. Material changes will be dated here and, when appropriate, communicated in the product.