Privacy
Privacy Policy
This policy explains how InvitaMe processes personal data. Clerk manages accounts, the application runs on Railway, images are stored in Cloudflare R2, venue search uses Google Maps Platform, payments are processed by Stripe, errors are monitored with Sentry and visits to the public website are counted with Umami, without cookies. InvitaMe uses no advertising, profiling or newsletter technology.
Last updated: 31 August 2026
1. Controller and contact details
Roberta-Ionela Preda
Julie-Pöhler-Straße 18, 74564 Crailsheim, Germany
Privacy contact: ionelarobertapreda@gmail.com
A data protection officer is not appointed; the statutory thresholds for a mandatory appointment are not met at the operator’s current size.
2. Website access and security
When you access the website, your browser transmits connection data required for technical delivery. This may include your IP address, time of access, requested address, referrer, browser and device information. The application records a random request ID, method, a path with any personalised-link credential redacted, response status and duration. Guest tokens, names, contact details, dietary information and messages are not written to the application logs.
On public pages, the IP address is processed in Redis for no more than one-minute windows as part of a rate-limit key. The purposes are delivery, abuse prevention, error analysis and IT security. The legal basis is Article 6(1)(f) GDPR; the legitimate interests are a secure and stable service.
The application, its PostgreSQL database and its Redis queue run in Railway’s europe-west4 (Netherlands, European Economic Area) region. Application logs are kept only as long as needed for security and error analysis; Railway may additionally process platform and edge logs as described in its data processing agreement.
3. Accounts, sign-in and Clerk
Clerk, Inc. provides accounts and sign-in sessions. Depending on the enabled sign-in method, Clerk may process a user ID, name, email address, sign-in information, session and device information and, for Google sign-in, profile data released by Google. InvitaMe normally stores only the Clerk user ID in its application database to identify the owner; it does not copy the email address or password into that database.
The purposes are registration, sign-in, session management and account security. The legal basis is Article 6(1)(b) GDPR, supplemented by Article 6(1)(f) GDPR for abuse prevention. Clerk processes customer data under its data processing agreement and states that it acts as an independent controller for certain account information. Its current agreement relies, among other mechanisms, on the EU-US Data Privacy Framework and Standard Contractual Clauses for transfers to the United States.
Further information is available in the Clerk Privacy Policy and Clerk Data Processing Addendum.
4. Couples’ invitations and media
Account holders can store a working title; names of the couple and family members; dates and times; venues and coordinates; invitation text, translations and notes; sharing text; RSVP settings; photographs; and design data. InvitaMe also stores status, creation, modification, publication and, where applicable, payment timestamps. Photographs are uploaded directly to S3-compatible object storage. Confirmed photographs in published invitations can be retrieved from hard-to-guess but publicly accessible object URLs.
This processing is necessary to create, store, publish and update the ordered digital invitation under Article 6(1)(b) GDPR. Content in the published general invitation is available to anyone with its public link. Personalised links are confidential access credentials and should be shared only with the intended household.
5. Guest lists and RSVP responses
Couples can enter a household or display name, optional contact name, telephone number, email address and private note, plus permitted adult and child numbers. Guests can submit attendance, party size, accommodation needs, optional dietary details and a message through their personalised link. The link contains a plaintext bearer token. Anyone who has it can view and, until the deadline, change that household’s response data.
The dietary field is optional and free-text. Please enter dietary information only if you are comfortable sharing it: it may reveal allergies or other health-related details, it is used solely so the inviting couple can plan their wedding, and it is visible only to them. You can change or remove it through your personalised link until the response deadline, or ask for its deletion at any time via the privacy contact. Guests should not enter unnecessary information about other people.
The operator is the controller for the technical operation, security and log data of the service. The inviting couple decides whom to invite and which household details to enter; guest data is processed to provide the couple’s invitation and RSVP collection. For a purely private wedding, the couple’s own use of its guest list may fall under the GDPR household exemption. Guests can direct questions and requests about their data to the privacy contact above or to the inviting couple.
6. Google Maps Platform and calendar links
When a signed-in user starts typing in the optional venue search, the browser sends the search text after three characters, language, a random session ID and technical connection data directly to Google Places. After a place is selected, its place ID, formatted address and coordinates are retrieved and stored with the invitation. An embedded Google map preview loads only after a venue has been selected. Static guest maps are generated by the server through Google, then copied to our object storage and are not delivered directly from Google to the guest.
Manual entry remains available. The purpose is the venue search and map display expressly requested by the user under Article 6(1)(b) GDPR, alternatively Article 6(1)(f) GDPR. Google states that it logs, among other information, account or project identifiers, status and IP address. The Google Maps Platform Terms and Google Privacy Policy apply. Google is opened only at the user’s request when they select “Google Calendar” or “Open in Maps”.
7. Hosting, storage and other recipients
- Railway Corporation: application hosting, PostgreSQL, Redis, network and platform logs; processing under the Railway DPA.
- Cloudflare, Inc.: R2 object storage for photographs, generated maps and planned encrypted database backups; processing under the Cloudflare DPA.
- Functional Software, Inc. (Sentry): error monitoring for the application and the website, in Sentry’s European data region. An error report contains technical error data such as the error message and stack trace, the requested address with any personalised-link credential redacted, the response status, and browser, device and operating-system information. Guest tokens, names, contact details, dietary information and messages are not transmitted: request bodies, authentication cookies and the values of program variables are all excluded from error reports, and no usage or session statistics are collected. The legal basis is Article 6(1)(f) GDPR; the legitimate interests are a stable and secure service. See the Sentry Privacy Policy and Sentry Data Processing Addendum.
- Umami Software, Inc. (Umami): cookieless visit statistics, in Umami’s European data region, for the public pages of the website (home page, template demos, legal pages, sign-in and sign-up) and the first page after sign-in. A page view contains the page address without query strings, the referring site, the page title, the browser language, and browser, device, operating-system and screen information; the IP address reaches Umami with each request, as with any web server, and is used to derive the country and an anonymised visitor identifier. Umami sets no cookies and stores nothing on your device; its only device access is a check for an opt-out flag a visitor can set themselves. It states that it stores no personally identifiable information and anonymises what it collects, and cannot follow a visitor across websites. Invitation and guest pages do not load Umami at all, and a referrer that points to one is removed before a page view is sent, so guest links, tokens, names and answers never reach Umami. Statistics are kept for six months. The legal basis is Article 6(1)(f) GDPR; the legitimate interest is knowing whether and how the website is used. See the Umami Privacy Policy and Umami Data Processing Agreement.
- Clerk, Inc. and Google: as described above.
7a. Payments through Stripe
The one-time publication fee is processed by Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin, Ireland (“Stripe”). Payment happens on Stripe’s hosted checkout page: the card number and other payment credentials are entered directly with Stripe and never reach our servers. Depending on the payment method, Stripe processes the data needed to complete and secure the payment, including name, email address, billing details and device information, partly as our processor and partly as an independent controller for its own fraud-prevention and regulatory obligations.
From each payment we receive and store the checkout session identifier, the amount, currency and payment status, and technical event records. We deliberately remove the name, email address and billing details that Stripe collects from the copies of payment notifications we keep; those details remain available in Stripe. If enabled, Stripe sends a payment receipt to the email address entered at checkout.
The legal bases are Article 6(1)(b) GDPR for performing the contract, Article 6(1)(c) GDPR for statutory accounting and tax obligations, and Article 6(1)(f) GDPR for fraud prevention. Stripe may transfer data to the United States under its data processing agreement, relying on the EU-US Data Privacy Framework and Standard Contractual Clauses. Details are in the Stripe Privacy Policy and the Stripe Data Processing Agreement.
9. Retention and deletion
Unconfirmed uploads are deleted after approximately one hour, and database backups are retained for 30 days. Deleting a household in the dashboard deletes its current RSVP response. Deleting a draft removes it from the account but retains the underlying records until deletion is requested, and published invitations cannot be deleted through self-service — in both cases, full deletion is available on request to the privacy contact.
A published invitation remains online for the agreed publication period — at least twelve months from publication. Couples can delete households, and with them the household’s current RSVP response, in the dashboard at any time. Beyond that, invitations, guest records, responses and photographs are deleted on request to the privacy contact; such requests are handled manually until automated deletion after the publication period is implemented.
Payment and accounting records are retained for the statutory German commercial and tax periods, currently up to ten years, and may remain blocked from ordinary use until those periods expire.
10. Your data protection rights
To the extent provided by law, data subjects have rights of access, rectification, erasure, restriction, data portability and objection. Consent may be withdrawn for the future. Data subjects also have the right to lodge a complaint with a data protection supervisory authority, in particular in the place of their habitual residence, place of work or place of the suspected infringement.
Requests should be sent to the privacy contact above. To help us identify the relevant record safely, guests should name the inviting couple and their household. They should not publish the complete secret link through publicly accessible channels.
11. Changes to this policy
We will update this policy when hosting, authentication, payments, analytics, email delivery, retention or other data flows change. The current version will always be available at this address.
Please also see the Legal Notice and Terms and Conditions.
