← Home

Privacy Policy

Last updated: 28 August 2026

This is the privacy policy for Invitee (“the Service”). It explains what personal data we collect, why, how long we keep it, and how you control it. We aim for the data-minimization principle of GDPR and the European Data Protection Board: collect only what we need, keep it only as long as necessary.

1. Who is the data controller

The operator of Invitee acts as the data controller. For data requests (access, export, deletion, rectification), email [email protected] or use the contact form. You do not need an account to contact us, and we answer within 30 days.

2. What we collect

We do not collect: tracking cookies for advertising, browser fingerprints, location data, contact lists, payment information.

Legal basis for each purpose (GDPR Art. 6)

If you are a guest, not a host

You are reading this because you were sent an invitation link. The host of that event decides who to invite and what to ask you; we provide the platform, store your answer, and show it to that host and nobody else. We never use a guest’s details to market anything, never add guests to a mailing list, and never make a guest create an account. To correct or delete an RSVP you already sent, ask the host (they can delete it from their dashboard) or contact us directly — either route works.

3. Cookies

Strictly-necessary cookies, always set:

That is the only cookie we set. No analytics cookies, no advertising cookies, no third-party trackers, and no cookie banner — because there is nothing to ask you about. We do not count you, profile you, or measure which pages you read.

Third-party content on invitation pages

4. How long we keep your data (retention schedule)

DataRetentionWhy
Your account & drafts While you actively use it Product utility
Inactive accounts Deleted after 24 months without sign-in Data minimization
Published events Kept until you unpublish or delete them, or delete your account Hosts often want post-event reference
Unpublished drafts (server-side) Deleted 12 months after last edit if still unpublished Data minimization
RSVPs Deleted with the event they belong to (when the host deletes the event or their account) Guest privacy
Publish IP hash + user-agent 6 months Abuse investigation
Magic-link token records Deleted 30 days after creation Already useless; debug aid
Rate-limit counters 2 hours Auto-cleared
Abuse reports (the report itself) 5 years Legal evidence; DSA moderation record
Server access logs (Hostinger) Per Hostinger’s policy Out of our direct control

You can request immediate deletion of any data using the “Delete my account” button in the studio (signed-in users) or the contact form. We honor erasure requests within 30 days.

5. Who we share data with

We share data with these processors strictly to operate the Service:

We do not sell, rent, or trade your data, we run no advertising, and we share nothing with anyone for measurement or profiling.

6. Where data is stored

All data is stored on Hostinger servers within the European Union. Two things can travel outside the EU/EEA, both under the EU-US Data Privacy Framework, and both only if you choose them:

If you decline analytics and don’t use social sign-in, no personal data leaves the EU/EEA.

7. Your rights under GDPR

If you’re in the EU/EEA you have the right to:

To exercise any of these rights, sign in and use the contact form. Standard response time: 30 days.

8. Children

The Service is not intended for users under 16. If you become aware of a user under 16, please report it via the contact form. We will delete the account.

9. Security

10. Changes

We may update this policy. Material changes are reflected in the “last updated” date above. If you have an account, we’ll email you about substantive changes.

11. Contact

For data requests, questions, or concerns: email [email protected], or use the contact form. See also the Terms of Use. If you are a guest who was sent an invitation, you can write to us directly — you do not need an account and you do not need to go through the host.