Privacy and guest data
A guest list is a pile of personal data that somebody trusted you with. Here is what Invitatum does about that, and the two settings that are yours to make.
Who is responsible for what
When you run an event, you decide what to ask and why — in data-protection language you are the controller. Invitatum is the processor: we hold and handle the data on your behalf and do nothing else with it. This guide explains the tools; the decisions are yours.
Consent at registration
Every registration form carries a required checkbox accepting your privacy policy, linked from the form itself. The moment a guest consented is stored with their row, so if anyone ever asks, the answer is a date rather than a shrug.
Your privacy policy
In your Profile, under Privacy policy (shown to guests), you can write the policy guests read. Leave it empty and Invitatum uses a sensible bilingual default covering what is collected, why, who processes it, and how long it is kept.
Edit it if you collect something unusual, or if you are an organisation with a policy of your own. Only the owner can change it.
Retention: data that does not outlive the event
Data retention (days after event end) sits in the same place. The default is 365 days; the allowed range is 30 to 1095.
That many days after each event ends, guest details are anonymised automatically: names, email addresses and answers go, an anonymous headcount row stays so your past statistics remain truthful, and any caterer share link is force-disabled. It happens without you doing anything, which is the only kind of data hygiene that actually survives contact with real life.
Erasing everything now
On the event's Review step there is a purge guest data action for when the party is over and you would rather not hold the list any longer. It asks you to confirm properly, because it cannot be undone. It stays available even if your plan has lapsed — deleting data should never require a payment.
What guests can do themselves
From the personal link in their confirmation email, every guest can:
- Download my data — a file containing their row, their answers and the emails we hold for them.
- Delete my data permanently — after cancelling, their name and email are anonymised and their answers deleted, leaving an anonymous headcount row.
Both work on every plan, always, including a lapsed one. These are the guest's own rights exercised through their own link, and they never depend on you paying us.
Food answers deserve extra care
A dietary restriction can reveal a health condition or a religion, which European law treats as a special category of personal data. Invitatum prints a fixed purpose note under the dietary question, includes those answers in the automatic purge, and builds the caterer's list to share the minimum — the exceptions, optionally with surnames shortened to an initial, and never the contact details.
Who else touches the data
Invitatum runs on named processors, each under a data processing agreement: hosting, the database, the email provider that delivers your invitations, and Paddle for payments. They are listed in the default privacy policy text, so your guests can read exactly who is involved.
Two settings, five minutes. Read the default privacy policy once and decide whether it describes your event. Set the retention period to something you can defend. That is the whole job.