QRinvites
Privacy policy
Last updated: 21 July 2026
Controller
The data controller is the owner of QRinvites, reachable at hola@qrinvites.com. This policy explains what data we process, why and on what legal basis, under the GDPR.
Data we process
Account: your Google email when signing in. Invitations: the texts you write (names, dates, venues, story). Guest RSVPs: name, attendance, plus-ones, menu, notes and, only if the host enables it, allergies or intolerances. Payments: handled by Stripe; we store the amount, status and an identifier, never your card. First-party analytics: usage events with a random local identifier, no third-party cookies and no cross-site tracking.
Allergies: health data
Allergies and intolerances are health data (a special category under the GDPR). They are only collected if the host enables that question and the guest chooses to answer it (explicit consent), they are used exclusively to organise the event, only the host sees them and they are deleted with the invitation.
Legal basis and purposes
Performance of the service (creating and displaying invitations, managing RSVPs and payments), explicit consent (allergies) and legitimate interest (first-party analytics without identifying people, and service security).
Processors and recipients
We use providers acting as data processors: Supabase (database and authentication, EU-Ireland region), Cloudflare (hosting and delivery), Stripe (payments) and Google (sign-in). We do not sell data or share it with third parties for advertising.
Retention
Deleting an invitation immediately and permanently removes the invitation and all its RSVPs. Deleting your account (a visible option in your dashboard) removes your account, invitations and RSVPs; the payment ledger is kept anonymised for accounting.
Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction and portability by writing to hola@qrinvites.com. You can also lodge a complaint with your data protection authority.