Privacy Policy
Last updated August 2026
Written to match what the product actually stores and does. Not legal advice — have it reviewed before relying on it commercially.
What we collect
From you, when you buy: your name, email address, and a password we store only as a hash — we cannot read it.
From you, as you build your card: whatever you enter — names, dates, venues, family contacts, photos — and your guest list, including guest names and any phone numbers you add.
From your payment: the amount, currency, provider and status. We never receive your card number. It is entered on the payment provider's own page.
Automatically: standard server logs, and a session cookie that keeps you signed in. We do not run advertising trackers on the invitation cards themselves.
Why we hold it
- To provide the card you bought and keep it online for your access period
- To let you sign back in and edit it
- To email you order confirmations and expiry reminders
- To answer you when you contact support
- To keep records of payments, as tax law requires
Your guests
Guest names and phone numbers exist only so your card can greet a guest by name and so you can share a link with them. We do not market to your guests, sell their details, or contact them for our own purposes.
Invitation cards are excluded from search engines, so a guest's name cannot surface in a Google result.
Who we share it with
Only the services needed to run this, each handling one part:
- Our hosting and database provider — stores the data
- Our payment providers — take the payment
- Our email provider — delivers order and reminder emails
We do not sell your data to anyone, ever.
How long we keep it
While your card is active, and for a grace period after it expires so you can extend without losing anything. After that we delete the card and its guest list. Payment records are kept longer where tax law requires it.
You can ask us to delete your account and everything in it sooner.
Your rights
You can ask us to show you what we hold, correct it, delete it, or send you a copy. Email us and we will act within 30 days.
Security
Passwords are hashed. Access to a card is restricted to the account that owns it. No system is perfectly secure, but we do not store the most sensitive data at all — card numbers never reach our servers.