QRinvites

Privacy policy

Last updated: 21 July 2026

Controller

The data controller is the owner of QRinvites, reachable at hola@qrinvites.com. This policy explains what data we process, why and on what legal basis, under the GDPR.

Data we process

Account: your Google email when signing in. Invitations: the texts you write (names, dates, venues, story). Guest RSVPs: name, attendance, plus-ones, menu, notes and, only if the host enables it, allergies or intolerances. Payments: handled by Stripe; we store the amount, status and an identifier, never your card. First-party analytics: usage events with a random local identifier, no third-party cookies and no cross-site tracking.

Allergies: health data

Allergies and intolerances are health data (a special category under the GDPR). They are only collected if the host enables that question and the guest chooses to answer it (explicit consent), they are used exclusively to organise the event, only the host sees them and they are deleted with the invitation.

Legal basis and purposes

Performance of the service (creating and displaying invitations, managing RSVPs and payments), explicit consent (allergies) and legitimate interest (first-party analytics without identifying people, and service security).

Processors and recipients

We use providers acting as data processors: Supabase (database and authentication, EU-Ireland region), Cloudflare (hosting and delivery), Stripe (payments) and Google (sign-in). We do not sell data or share it with third parties for advertising.

Retention

Deleting an invitation immediately and permanently removes the invitation and all its RSVPs. Deleting your account (a visible option in your dashboard) removes your account, invitations and RSVPs; the payment ledger is kept anonymised for accounting.

Your rights

You can exercise your rights of access, rectification, erasure, objection, restriction and portability by writing to hola@qrinvites.com. You can also lodge a complaint with your data protection authority.