Privacy policy
Last updated: 6 August 2026
This policy explains how Inviti handles the personal data of people who create an invitation and of those who receive one, under Regulation (EU) 2016/679.
Data controller
Mauro De Gennaro, VAT TODO — partita IVA (obbligatoria prima del primo incasso), Via Alberi 20b, 80069 Vico Equense (NA), Italia. For anything concerning your data, write to mauro_deg90@hotmail.it.
Who you are to us
There are two roles here. If you create an invitation you are our user, and we act as controller of your data. If you received an invitation and are only reading the event site, we ask nothing of you: RSVPs go over WhatsApp or email straight to whoever invited you, never through our systems.
What we collect
Event data: whatever you type into the creation form — title, date, venues, RSVP contacts, free-form details. It is meant to become public on the event site, so do not put anything there you would not want visible to everyone holding the link.
Payment data: handled entirely by Stripe. We never see or store your card number. From Stripe we receive your email address, the amount and the outcome.
Technical data: IP address and request logs, kept for security and diagnostics.
One technical cookie (evt_lang) remembering your chosen language. It needs no consent and does not profile you.
Why we process it
To deliver the service you bought, generate the flyer and publish the site: performance of a contract (Art. 6(1)(b) GDPR).
To send you the recovery email that lets you find your event again after changing device: also performance of a contract.
To meet tax and accounting obligations: legal obligation (Art. 6(1)(c) GDPR).
To protect the service from abuse through rate limits and logs: legitimate interest (Art. 6(1)(f) GDPR).
Who we share it with
We use the providers listed below, acting as processors. We do not sell your data and we do not pass it on for third-party marketing.
Transfers outside the European Union
Some providers may process data in the United States. Those transfers rely on the Standard Contractual Clauses approved by the European Commission or, where applicable, the EU-US Data Privacy Framework.
How long we keep it
Event data stays while the site is published and for twelve months after it expires, so you can renew without retyping everything. After that it is deleted.
Accounting records are kept for ten years, as the law requires.
Technical logs are kept for ninety days.
Your rights
At any time you can ask to access your data, correct it, delete it, restrict its processing, receive it in a portable format, or object to processing based on legitimate interest. Write to mauro_deg90@hotmail.it and we will respond within thirty days.
If you believe the processing breaches the Regulation you can lodge a complaint with your national supervisory authority.
Changes
If this policy changes we update the date at the top. Substantial changes are emailed to anyone with an active event.
Providers that process data
| Provider | Purpose | Region |
|---|---|---|
| Supabase | database, storage | EU (Frankfurt) |
| Vercel | hosting, CDN | EU / US |
| Stripe | payments | EU / US |
| Resend | transactional email | EU / US |
| Google Places | address lookup | EU / US |