Last updated: January 2025
Invitia ("we", "us") operates an online platform for digital wedding invitations. This Privacy Policy explains how we collect, use, and protect your personal data in compliance with the General Data Protection Regulation (GDPR).
Account data: email address and password (hashed) when you register.
Invitation data: names, wedding date, venue, photos, and other details you enter while creating your invitation.
Guest RSVP data: names, attendance, menu preferences, and any optional fields filled in by your guests.
Usage data: invitation view counts, browser type, and anonymised analytics.
Payment data: processed entirely by Stripe. We do not store card numbers.
We process your data on the basis of contract performance (to provide the Service you purchased), legitimate interests (platform security, fraud prevention), and — where required — your explicit consent.
We do not sell your personal data. We share data only with:
Active invitation data is retained for the duration of your plan plus 12 months. After that, data is permanently deleted unless you request earlier deletion. Account data is retained until account deletion.
Under GDPR you have the right to:
To exercise these rights, email privacy@invitia.co.
We use only technically necessary cookies for authentication (session token). We do not use tracking or advertising cookies.
Data is stored in Supabase with encryption at rest and in transit. Access to personal data is restricted to authorised personnel only.
For privacy enquiries or to exercise your rights, contact us at privacy@invitia.co. You also have the right to lodge a complaint with your local data protection authority.