1. About This Privacy Policy
This Privacy Policy describes how Invitea processes information through the current platform, invitation experience, account workspace, managed services, payment flows, and support tools. In this policy, “Invitea”, “we”, “our”, and “the service” refer to the Invitea platform and the services made available through it.
The information involved can vary depending on which parts of Invitea you use. Not every category described in this policy is required for every visitor, account, invitation, or service flow.
2. Information You Provide
Depending on the feature or service you use, information you provide to Invitea may include:
- account and profile details;
- invitation and event details;
- uploaded images, media, and other supported content;
- RSVP and Guestbook submissions;
- payment or managed-service information; and
- support messages and attachments.
The exact fields involved depend on the workflow you choose and the features available to the applicable invitation, account, or package.
3. Accounts & Social Sign-In
Account information can include your email address, display/profile name, and internal account identifiers used to operate your Invitea account and connected invitation workflows.
If you choose a supported social sign-in method, Invitea may receive the identity information required by that selected provider flow. Current supported providers may include Google, Facebook, and Apple. Depending on the provider, this information can include a provider account identifier, verified email, display or name information, and profile/avatar information where the provider supplies it.
Choosing one social sign-in provider does not mean your account information is automatically sent to every other supported provider.
4. Invitation Content & Media
Invitation content can include couple details, event details, story or other invitation copy, gallery and media files, and information entered into other supported invitation sections.
When an invitation is published, the invitation content selected for publication becomes available to the audience of that invitation according to its configured visibility and the features enabled by the invitation owner.
For applicable public images, Invitea may re-process uploaded files for web delivery, optimization, and reduction of embedded metadata. This does not mean that metadata is removed from every possible file type or from every file used in every workflow.
5. RSVP & Guestbook
RSVP submissions can include guest name, optional phone where enabled, attendance status, guest count, meal preference where enabled, a message to the couple, timestamps, and a privacy-preserving visitor identifier used for the applicable interaction and anti-abuse controls.
Guestbook submissions can include guest name, relationship where enabled, guest message, moderation status, timestamps, and a privacy-preserving visitor identifier.
If the invitation owner enables public Guestbook display, approved entries may be shown publicly. A public entry can include the guest name, relationship, and message. Entries that are not approved for public display are not automatically treated as public invitation content.
6. Usage & Analytics
When internal invitation analytics is enabled, Invitea may process limited technical and usage information such as an invitation or page visit, a privacy-preserving visitor hash, a hashed IP-derived identifier, device type, user-agent or browser information, referrer information, and event or visit timestamps.
This statement is limited to those Invitea application tables. It does not mean that hosting, network, security, or other infrastructure involved in serving a web request can never process network information. Invitea does not describe current internal invitation analytics as collecting precise GPS location.
7. Payments & Billing
Payment and billing records can include account, invitation, or package references, customer email, amount and currency, selected payment method or provider, transaction/reference identifiers, payment status, related transaction metadata, and timestamps.
Current checkout providers can include PayPal and Midtrans. Applicable payment details are processed through the provider selected for that checkout flow. Invitea keeps payment records needed to operate billing, package activation, payment verification, receipts, refunds where applicable, and reconciliation.
This policy does not state that Invitea stores full payment-card numbers.
8. Managed Services
Managed domain and bespoke-design workflows may process customer or account identity, customer name and email, invitation or project identifiers, domain or service target information, design-brief or project communications, managed-service status, timestamps, and relevant private service attachments or previews where the workflow uses them.
Managed-service information is used to progress the requested service and maintain its workflow state. Commercial plan and pricing terms remain on the applicable pricing, checkout, and service surfaces rather than being duplicated in this policy.
9. Customer Support
Support Tickets can process account or user ID, invitation reference, ticket subject, category and status, customer and staff messages, attachments, and related timestamps.
Support attachments are private workspace content. Download access is subject to authentication and authorization checks so a customer can access attachments associated with the support conversation they are permitted to view.
Private support messages and attachments are not embedded or displayed as public content on this Privacy Policy.
11. Third-Party Services
Information may be processed through a third-party service where you choose that provider or where the applicable feature requires the provider to operate.
- Google, Facebook, or Apple may be involved when you choose the corresponding supported social sign-in flow.
- PayPal or Midtrans may be involved when you choose an applicable payment checkout flow.
- An embedded-media provider may process information when an invitation uses that external media feature.
These are current product-facing examples, not a complete processor inventory and not a statement of any particular cross-border transfer mechanism.
12. How We Use Information
Invitea processes information for current service purposes that can include:
- providing and operating accounts and invitations;
- publishing invitation content selected for publication;
- operating RSVP and Guestbook functionality;
- processing billing, payment verification, and package entitlement;
- performing managed domain and bespoke-design workflows;
- providing customer support;
- preventing abuse and maintaining service security;
- understanding invitation usage through internal analytics where enabled; and
- maintaining operational and audit records needed for the service.
This policy does not add advertising or data-broker purposes that are not part of the current Invitea product authority.
13. Public & Private Information
Some information is intentionally used for a published invitation, while other information belongs to private account, transaction, service, or support workflows.
Invitation content selected for publication, and approved Guestbook content when public Guestbook display is enabled.
RSVP phone, billing/payment records, Support Tickets and private attachments, managed-service workspace information, and account/session information.
Actual visibility depends on the applicable feature, configuration, publication state, and account permissions.
14. Data Retention
Retention varies by information category and by the lifecycle of the account, invitation, transaction, support conversation, or managed service. Invitea does not apply one universal retention period to every category described in this policy.
- active account, invitation, and service records may remain while needed for the applicable workflow;
- transaction, support, and operational records may follow their own lifecycle;
- certain media and operational logs are subject to configured cleanup or retention processes; and
- expired, superseded, or no-longer-needed media may become eligible for retirement after applicable grace or retention periods.
This policy does not promise immediate deletion of every record and does not state that all personal data is deleted after one fixed number of days.
15. Security
Invitea uses technical and access-control measures designed to protect information used by the service. Depending on the workflow, these measures can include authentication and access controls, authorization checks for private resources, anti-spam/rate-limit mechanisms, privacy-preserving hashes, authorization for private support attachments, and relevant image privacy processing.
No online service can guarantee absolute security. This policy therefore does not make an absolute-security promise or claim an external security or privacy certification that has not been established.
16. Your Choices & Privacy Requests
Privacy-related questions or requests can be routed through the Contact Invitea page. This policy does not describe a self-service export or erasure feature that is not currently established as a public Invitea workflow.
The availability and handling of a particular request may depend on applicable law and on records that need to remain for service, payment, security, support, or operational purposes. No jurisdiction-specific statutory response deadline is created by this policy.
17. Changes to This Policy
This Privacy Policy may be updated as Invitea's product or data practices change. The “Last updated” date at the top of this page identifies the current published version.
Please review the current version when you need to understand the privacy information published for the service.
18. Contact
If you have a question about this Privacy Policy or want to make a privacy-related request, use the Contact Invitea page.