This Privacy Policy explains how Inviteease ("we," "us," "our") collects, uses, and shares information when you use inviteease.app. It applies to two groups of people: Hosts, who create accounts and events, and Guests, who RSVP to or register for events but do not create accounts themselves.
From Hosts
— Name and email address (account creation)
— Payment information (processed by Paystack or Stripe — we do not store full card details ourselves)
— Event details you create (title, date, location, description, theme choices)
— Any guest data you upload or enter (see below)
From or About Guests
Guests do not create accounts. Depending on the event's settings, Guest information reaches us in one of two ways:
Guest-submitted: When a Guest fills out an RSVP or registration form directly, we collect what they enter — name, email, phone number (if requested), dietary requirements, plus-one details, attendance status, answers to any additional questions the Host has added to their event's form, and whether they opted in to hear from Inviteease itself (see Section 2a). The Host decides which optional fields and additional questions appear on their form, and is responsible for the questions they choose to ask (see our Terms of Service, Section 4).
Host-submitted: For events using Whitelist RSVP modes, the Host may upload Guest names, phone numbers, and emails in advance (via manual entry, CSV import, or contact picker) before the Guest ever interacts with Inviteease. In this case, Inviteease processes this data on the Host's instructions; the Host is responsible for having a lawful basis to share it with us. See our Terms of Service, Section 4.
Automatically Collected
Basic usage and device information (browser type, general location inferred from IP for currency detection, pages visited) for security and product improvement purposes.
We use collected information to:
— Operate the RSVP, registration, guest list, check-in, seating, and messaging features
— Process payments and apply early booking discounts
— Send transactional emails (RSVP confirmations, guest codes, reminders, and host-initiated broadcast messages) via Resend
— Send post-event and follow-up communications to Guests (see Section 2a)
— Detect and prevent fraud or abuse
— Improve and maintain the service
We do not sell personal information to third parties, and we do not share it with advertisers or data brokers.
When a Guest provides an email address — whether by submitting an RSVP or registration, or by a Host adding them to a guest list — that address may be used to send communications relating to the event and to Inviteease, including after the original event has ended:
— Event communications: RSVP and registration confirmations, reminders, updates from the Host, and check-in details.
— Post-event communications: thank-you messages, photo or recap links, feedback requests, and invitations to a Host's future events — sent after the event date has passed.
— Inviteease communications: occasional messages inviting the Guest to create their own events on Inviteease, plus limited product news. When a Guest submits an RSVP or registration with an email address, their confirmation email tells them these messages may follow and includes a one-click way to stop them; a Guest who declines attendance is never added. Every such message carries a one-click unsubscribe, and opting out is immediate. We do not sell these addresses or share them with third parties for their own marketing.
Every non-transactional email includes a one-click way to unsubscribe. Unsubscribing from Inviteease's own or post-event messages does not stop essential, service-related emails for an event you are actively RSVP'd or registered to attend. Guests can also request removal of their data entirely at any time (see Section 6).
Where a Host uploads Guest data before the Guest has interacted with the platform (Whitelist mode), Inviteease processes that data as a data processor acting on the Host's instructions. The Host is the data controller and is responsible for ensuring they have a lawful basis (such as legitimate interest in event planning, or consent) to provide that data to us. If you are a Guest and believe your information was added without a proper basis, contact the Host directly, or reach us at inviteeasehq@gmail.com and we will assist in resolving the request with the Host.
We share information only as necessary to operate the service:
— Supabase — database hosting and storage for all account, event, and guest data
— Paystack (Nigerian users) and Stripe (international users) — payment processing
— Resend — sending transactional emails (confirmations, guest codes, host broadcast messages)
— Vercel — application hosting infrastructure
Each of these providers processes data solely to help us deliver the service and is bound by its own data protection obligations. We do not share Guest or Host data with advertisers or data brokers.
Host account data is retained as long as the account is active. If you delete your account, we will delete your personal account data within a reasonable period, except where retention is required for legal, tax, or dispute-resolution purposes.
Guest data tied to an eventis retained for as long as the event and its Host account exist. A Guest's name and email may be retained after the event has ended so that we and the Host can send the post-event and follow-up communications described in Section 2a. We retain it until the Guest unsubscribes and requests deletion, the Host deletes the event or guest record, or the Host account is closed — whichever comes first.
Payment records are retained as required by applicable financial regulation, typically longer than other data categories.
If you are a Guest, you can:
1. Unsubscribe from post-event and non-essential emails using the one-click link in any such message — this stops future follow-up and marketing communications immediately, with no login required. You can also use your email app's own unsubscribe button where it offers one.
2. Ask the Host to remove your record — they control the guest list and can delete it at any time from their dashboard.
3. Contact us at inviteeasehq@gmail.com with the event name and your details if the Host is unresponsive, and we will assist in removing your data from our systems where legally appropriate.
We rely on Supabase's infrastructure security and apply access controls so that Hosts can only view and manage guest data for their own events. Payment information is handled entirely by Paystack and Stripe; we do not store full card numbers on our servers. No system is completely secure, and we cannot guarantee absolute security of information transmitted to or stored by the service.
Because Inviteease serves both Nigerian and international users, data may be processed or stored in locations outside your home country (for example, via Supabase's or Resend's infrastructure providers). We take reasonable steps to ensure data is handled consistently with this Policy regardless of where it is processed.
For users and Guests located in Nigeria, we aim to process personal data consistent with the NDPR, including principles of purpose limitation, data minimization, and accountability. Nigerian data subjects may exercise rights available to them under the NDPR by contacting inviteeasehq@gmail.com.
Inviteease is not directed at children under 18, and Host accounts may only be created by adults. Event types such as birthday parties or baby showers may involve event details related to a minor (e.g., the person being celebrated), but this does not involve the minor directly using the service or creating an account.
We only use cookies that the service needs in order to work. We do not use advertising cookies, tracking pixels, or third-party analytics, and we do not track you across other websites. Because these cookies are strictly necessary, we do not ask for consent before setting them. This section applies to inviteease.app and all of its subdomains, including myplusone.inviteease.app and event pages such as yourevent.inviteease.app.
Cookies we set
— Sign-in cookies (named sb-…-auth-token): keep a Host signed in to their account. They are set by our database provider, Supabase, and are removed when you sign out.
— manage_event: remembers which event a managed client last opened in their dashboard. It lasts one year.
— ie_host_…: keeps the buyer of a myplusone design signed in to that event's host dashboard. It lasts 30 days, and changing the dashboard password cancels it on every device.
— ie_buy_…: lets the browser that paid for a design set the dashboard password straight after checkout. It lasts 8 days.
— seating_…: keeps a seating chart unlocked after its password has been entered. It lasts 30 days.
Guests who only view an invitation or submit an RSVP or registration do not receive any cookie from us.
Storage in your browser
Some pages save small items in your browser's local storage instead. These stay on your device and are not sent to us:
— A design you are customising on myplusone, or an event you started before signing up, so your work is still there if you leave and come back
— Unfinished answers on our client brief and feedback forms
— Prompts you have dismissed, such as upgrade banners and first-time guides
— On some invitation designs, small details such as which passport stamps you have collected or which messages you have already seen
You can remove any of these by clearing your browser's data for inviteease.app.
Visit counting
We count visits to our home page without cookies. For each visit we store a code made from your IP address, browser type and the date. The code cannot be turned back into your IP address, and because it changes every day, it cannot be used to follow you from one day to the next.
Payment pages
When you pay, you are sent to Paystack or Stripe. Those pages are on their own websites and may set their own cookies, for example to prevent fraud. Their cookies are covered by their own privacy policies, not this one.
Blocking cookies in your browser will stop sign-in and the host dashboards from working. The rest of the site, including invitations and RSVP forms, will still work.
If we ever add analytics or advertising cookies, we will update this section before we do, and where the law requires it we will ask for your consent first.
We may update this Privacy Policy periodically. Material changes will be communicated via email or in-app notice. The "Last updated" date at the top reflects the most recent revision.
Questions about this Privacy Policy or your data can be directed to inviteeasehq@gmail.com.
This document is a starting template and has not been reviewed by a licensed attorney. Bracketed fields must be completed. Legal review is strongly recommended, particularly to confirm NDPR compliance obligations, and whether GDPR or other regional frameworks apply based on where your Guests and Hosts are located.