Privacy Policy
Last updated: February 2026
1. Introduction
EventInvites ("we", "our") respects your privacy. This policy explains how we collect, use, store, and protect your personal data when you use our event invitation and management service, in line with the EU General Data Protection Regulation (GDPR) and other applicable laws.
2. Data we collect
We may collect:
- Account data: phone number (for authentication), time zone, language preference.
- Event data: event titles, dates, locations, and content you create.
- Guest data: names and phone numbers of guests you invite; RSVP and dietary/accessibility preferences.
- Memories: photos and messages that you or guests upload to events.
- Technical data: IP address, device type, and logs necessary for security and operation.
3. How we use your data
We use your data to provide the service (creating events, sending invitations, managing RSVPs, storing memories), to authenticate you, to comply with legal obligations, and to improve our product. We do not sell your data.
4. Legal basis
Under GDPR we process your data on the basis of: contract (to provide the service), consent (where we ask for it, e.g. cookies), and legitimate interests (e.g. security, fraud prevention) where applicable.
5. Data retention
We retain your data for as long as your account is active or as needed to provide the service. We may retain some data (e.g. audit logs) for longer where required for legal or compliance reasons. Our data retention policy is documented separately and available on request.
6. Your rights
You have the right to:
- Access your personal data and receive a copy.
- Rectification of inaccurate data.
- Erasure ("right to be forgotten") in certain circumstances.
- Restrict or object to certain processing.
- Data portability — receive your data in a machine-readable format.
- Lodge a complaint with a supervisory authority.
You can exercise these rights via the Privacy Settings in your account, or by contacting us (see section 12).
7. Security
We implement appropriate technical and organisational measures to protect your data (encryption, access controls, secure hosting). We do not store your password; we use phone-based authentication and secure tokens.
8. Cookies
We use cookies only as necessary for authentication and essential operation. See our Cookie Policy for details.
9. Third parties
We use trusted service providers (e.g. hosting, SMS for verification) who act as processors under GDPR. We do not share your data with third parties for their marketing. If we use messaging services (e.g. WhatsApp Business API) for notifications, their privacy terms also apply.
10. Children
Our service is not directed at children under 16. If you are a parent or guardian and believe we have collected a child's data, please contact us and we will delete it promptly.
11. Changes
We may update this policy from time to time. We will post the updated version here and, where appropriate, notify you. Continued use after changes constitutes acceptance of the updated policy.
12. Contact & supervisory authority
For privacy requests or questions, contact us at the address provided in our app or website. If you are in the EEA/UK, you have the right to lodge a complaint with your local data protection supervisory authority.