Privacy Policy
Last updated: 4 October 2026
This policy explains what personal data we collect through Say Yes Digital Invitations (the “Platform”), why we collect it, on what legal basis, and what rights you have. The company behind the Platform is established in Croatia, in the European Union, so we handle personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”), wherever in the world you are using it from.
1. Who is responsible, and how to reach us
The controller of your personal data is:
Virtual M j.d.o.o.
Company ID (OIB): 69574478338
Address: Vatrogasna ulica 36/A, 31000 Osijek, Croatia
Email: sayyesinvite@gmail.com
Virtual M j.d.o.o., a limited liability company registered in Croatia (European Union), company ID (OIB) 69574478338, Vatrogasna ulica 36/A, 31000 Osijek, Croatia.
For any question about how your data is handled, or to exercise your rights, write to the address above.
2. What we collect, and why
a) The contact form
When you fill in the contact form we collect your name, email address, phone number (if you give one), your event date and your message. We use it to answer your inquiry and, where you asked for one, to send you a quote.
b) Guest RSVPs
When you reply to an invitation as a guest we collect your name, phone number (if you give one), whether you are coming, how many adults and children are in your party, the names of anyone with you (if you enter them), any song request and any note to the couple. This is used by the couple (the hosts of the event) to plan it.
Health data (a special category). The “allergies / dietary needs” field may contain health data, which is a special category of personal data (GDPR Art. 9). We process it only on the basis of your explicit consent and only so the menu for that event can be adjusted. Filling that field in is entirely optional.
c) Your account (the hosts)
To create an account we collect your email address (through Supabase Auth) and the details of your event that you enter yourself (the name, date, venue, note to guests, and the plan you chose).
d) Planning tools (checklist, budget, seating, run sheet, extra events)
What you enter into the tools on your dashboard (tasks, budget items, where guests sit, the wedding-day run sheet, and the invited lists for extra events such as a rehearsal dinner) is visible only to you and tied to your account. It is deleted together with the event or the account.
e) Reminders and invitations to guests
The “reminder” and “invite” buttons prepare a message and open your text messages, WhatsApp or Viber on your own device, and you send the message to the guest yourself. We do not send messages to guests, and we do not pass guests’ numbers to WhatsApp, Viber or any other third party.
f) Photos on your invitation
Photos you upload are shrunk and stored so they can appear on your invitation. Anyone with the invitation link can see them, so only upload photos you are happy for your guests to see. Deleting a photo, or the whole account, removes the files.
g) Payments
Payments are handled by Stripe. We never see or store your card number; we receive only a confirmation that you paid, which plan, the amount and your email address. Records of payments are kept for as long as tax and accounting law requires, even after an account is deleted.
h) Emails we send to account holders
Besides the emails your account needs (confirming your address, resetting a password), we may send a couple a small number of messages about their own invitation, for example a reminder that it is still waiting to be published. Every such email has an unsubscribe link that works with one click.
i) Inquiries for custom invitations
If you ask for a custom design, we keep your name, email, phone number and what you asked for, so we can prepare and deliver it.
j) Security
To stop bots and attacks on our forms we count attempts per visitor. For that we keep only a scrambled (hashed) form of the IP address, from which the address cannot be read back, and we delete it after 24 hours.
3. Legal basis
- Consent (Art. 6(1)(a), and for health data Art. 9(2)(a)): for the contact form and for guests’ RSVP data, including the explicit consent for allergies and dietary needs.
- Performance of a contract (Art. 6(1)(b)): for running your account and providing the service.
- Legitimate interests (Art. 6(1)(f)): for basic security, preventing abuse of the Platform, and the few emails about your own invitation (which you can stop at any time).
You can withdraw consent at any time, without affecting the lawfulness of what was processed beforehand, by writing to sayyesinvite@gmail.com.
4. How long we keep it
These are not aspirations: a job runs every day and deletes whatever has passed its period, automatically.
- Contact form data: 12 months from the day the inquiry arrives, after which it is deleted automatically (or sooner, on your request).
- Guest RSVP data: 60 days after the event date, after which it is deleted automatically, unless the hosts remove it sooner.
- Account data: for as long as the account is active; deleting the account permanently removes everything connected to it.
- Payment records: as long as tax and accounting law requires.
- Security traces (hashed IP addresses): 24 hours.
5. Who else sees it
We do not sell your data. We share it only with the service providers (processors) that make the Platform work:
- Supabase: the database, sign-in and photo storage (EU (Frankfurt)).
- Vercel: hosting and serving the pages (EU and USA).
- Resend: sending email (confirmations, notifications about inquiries) (EU and USA).
- Stripe: processing payments for the plans (EU and USA).
RSVP data is also visible to the couple whose invitation you filled in, since they are the recipients the whole exercise is for.
6. Transfers outside the EEA
Some of our processors may handle data outside the European Economic Area, including in the United States. Where that happens, the transfer is protected by appropriate safeguards under the GDPR, typically the European Commission’s Standard Contractual Clauses, and where applicable the EU–US Data Privacy Framework.
7. Your rights
In relation to your personal data you have the right to:
- access the data we hold about you;
- have inaccurate data corrected;
- have data erased (the “right to be forgotten”);
- restrict how it is processed;
- receive it in a portable form;
- object to processing;
- withdraw consent at any time.
To exercise any of these, write to sayyesinvite@gmail.com. Account holders can delete individual guests themselves, and the whole account with everything attached to it, from the “Danger zone” section of their dashboard. The same dashboard has a “My data” section that downloads everything we hold about you in one machine-readable file (the right to portability, Art. 20). Guests and anyone who used the contact form should send erasure requests to the email address above.
If you are in California: we do not sell or share personal information as those terms are used in the CCPA/CPRA, and we do not use it for cross-context behavioral advertising. The rights above cover the access, deletion and correction rights you have under that law; exercise them the same way, and we will not discriminate against you for doing so.
8. Cookies
We use strictly necessary cookies only: the ones needed to sign you in and keep your session (Supabase Auth), plus one that remembers the currency (US dollars or euros) if you pick one with the currency switch, and only then. It holds nothing but “usd” or “eur”. We use no analytics or marketing cookies, so no separate consent is required for them. If that ever changes, we will ask for your consent before setting any such cookie.
For visitor numbers we use Vercel Web Analytics, which works without cookies and does not follow an individual across time or across other sites. Only aggregate figures are recorded (which page was opened, where the visit came from, country, device type), from which you cannot be identified, so no consent is needed for it.
When you open an account, we also note where you came from: your answer to the optional question “How did you hear about us?”, the source your browser reported by itself (Google, Pinterest or a link from someone else’s invitation, for example) and the page you started from. None of it is stored on your device: it travels only in the link to the sign-up. We use it solely to know which channels bring couples to us, and it is deleted together with your account.
9. Children
The Platform is not intended for children. We do not knowingly collect personal data from anyone under 16 (or under 13 in the United States) other than the details a parent or guest enters about children attending an event.
10. Complaints
If you believe we are handling your data unlawfully, you have the right to complain to a supervisory authority. Ours is:
Croatian Personal Data Protection Agency (AZOP)
Selska cesta 136, 10000 Zagreb, Croatia
Email: azop@azop.hr · Web: azop.hr
If you live elsewhere in the EEA or in the UK, you may complain to your own national data protection authority instead.
11. Changes to this policy
We may update this policy from time to time. The current version is always on this page, with the date it was last changed.