Privacy Policy

This policy explains what personal data we collect through Say Yes Digital Invitations (the “Platform”), why we collect it, on what legal basis, and what rights you have. The company behind the Platform is established in Croatia, in the European Union, so we handle personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”), wherever in the world you are using it from.

1. Who is responsible, and how to reach us

The controller of your personal data is:

For any question about how your data is handled, or to exercise your rights, write to the address above.

2. What we collect, and why

a) The contact form

When you fill in the contact form we collect your name, email address, phone number (if you give one), your event date and your message. We use it to answer your inquiry and, where you asked for one, to send you a quote.

b) Guest RSVPs

When you reply to an invitation as a guest we collect your name, phone number (if you give one), whether you are coming, how many adults and children are in your party, the names of anyone with you (if you enter them), any song request and any note to the couple. This is used by the couple (the hosts of the event) to plan it.

c) Your account (the hosts)

To create an account we collect your email address (through Supabase Auth) and the details of your event that you enter yourself (the name, date, venue, note to guests, and the plan you chose).

d) Planning tools (checklist, budget, seating, run sheet, extra events)

What you enter into the tools on your dashboard (tasks, budget items, where guests sit, the wedding-day run sheet, and the invited lists for extra events such as a rehearsal dinner) is visible only to you and tied to your account. It is deleted together with the event or the account.

e) Reminders and invitations to guests

The “reminder” and “invite” buttons prepare a message and open your text messages, WhatsApp or Viber on your own device, and you send the message to the guest yourself. We do not send messages to guests, and we do not pass guests’ numbers to WhatsApp, Viber or any other third party.

f) Photos on your invitation

Photos you upload are shrunk and stored so they can appear on your invitation. Anyone with the invitation link can see them, so only upload photos you are happy for your guests to see. Deleting a photo, or the whole account, removes the files.

g) Payments

Payments are handled by Stripe. We never see or store your card number; we receive only a confirmation that you paid, which plan, the amount and your email address. Records of payments are kept for as long as tax and accounting law requires, even after an account is deleted.

h) Emails we send to account holders

Besides the emails your account needs (confirming your address, resetting a password), we may send a couple a small number of messages about their own invitation, for example a reminder that it is still waiting to be published. Every such email has an unsubscribe link that works with one click.

i) Inquiries for custom invitations

If you ask for a custom design, we keep your name, email, phone number and what you asked for, so we can prepare and deliver it.

j) Security

To stop bots and attacks on our forms we count attempts per visitor. For that we keep only a scrambled (hashed) form of the IP address, from which the address cannot be read back, and we delete it after 24 hours.

3. Legal basis

You can withdraw consent at any time, without affecting the lawfulness of what was processed beforehand, by writing to sayyesinvite@gmail.com.

4. How long we keep it

These are not aspirations: a job runs every day and deletes whatever has passed its period, automatically.

5. Who else sees it

We do not sell your data. We share it only with the service providers (processors) that make the Platform work:

RSVP data is also visible to the couple whose invitation you filled in, since they are the recipients the whole exercise is for.

6. Transfers outside the EEA

Some of our processors may handle data outside the European Economic Area, including in the United States. Where that happens, the transfer is protected by appropriate safeguards under the GDPR, typically the European Commission’s Standard Contractual Clauses, and where applicable the EU–US Data Privacy Framework.

7. Your rights

In relation to your personal data you have the right to:

To exercise any of these, write to sayyesinvite@gmail.com. Account holders can delete individual guests themselves, and the whole account with everything attached to it, from the “Danger zone” section of their dashboard. The same dashboard has a “My data” section that downloads everything we hold about you in one machine-readable file (the right to portability, Art. 20). Guests and anyone who used the contact form should send erasure requests to the email address above.

If you are in California: we do not sell or share personal information as those terms are used in the CCPA/CPRA, and we do not use it for cross-context behavioral advertising. The rights above cover the access, deletion and correction rights you have under that law; exercise them the same way, and we will not discriminate against you for doing so.

8. Cookies

We use strictly necessary cookies only: the ones needed to sign you in and keep your session (Supabase Auth), plus one that remembers the currency (US dollars or euros) if you pick one with the currency switch, and only then. It holds nothing but “usd” or “eur”. We use no analytics or marketing cookies, so no separate consent is required for them. If that ever changes, we will ask for your consent before setting any such cookie.

For visitor numbers we use Vercel Web Analytics, which works without cookies and does not follow an individual across time or across other sites. Only aggregate figures are recorded (which page was opened, where the visit came from, country, device type), from which you cannot be identified, so no consent is needed for it.

When you open an account, we also note where you came from: your answer to the optional question “How did you hear about us?”, the source your browser reported by itself (Google, Pinterest or a link from someone else’s invitation, for example) and the page you started from. None of it is stored on your device: it travels only in the link to the sign-up. We use it solely to know which channels bring couples to us, and it is deleted together with your account.

9. Children

The Platform is not intended for children. We do not knowingly collect personal data from anyone under 16 (or under 13 in the United States) other than the details a parent or guest enters about children attending an event.

10. Complaints

If you believe we are handling your data unlawfully, you have the right to complain to a supervisory authority. Ours is:

If you live elsewhere in the EEA or in the UK, you may complain to your own national data protection authority instead.

11. Changes to this policy

We may update this policy from time to time. The current version is always on this page, with the date it was last changed.