Privacy Policy
Last updated April 24, 2026
The short version
We collect the minimum data needed to run InviteLux: your account details, the invitations you create, and the RSVPs your guests send back. We do not sell your data. We do not email your guests marketing. Guest contacts you add are visible only to you.
1. Who we are
InviteLux (“we”, “us”) provides a digital invitation platform at invitelux.com. You can reach us at hello@invitelux.com.
2. What we collect
- Account data — email address and password (hashed) via Supabase Auth.
- Invitation data — names, dates, locations, photos, and other content you enter in the builder.
- Guest contacts — names and phone numbers you add to send invitations. Stored only in your invitation record.
- RSVP responses — the name a guest types, their response (accept / decline), and optional wishes they leave.
- Payment data — handled by Stripe. We store only the resulting plan, duration, and Stripe session reference. We never see your card number.
- Basic technical data — browser type, approximate device, and minimal logs kept for security and debugging.
3. How we use it
- To run your account and render your invitations.
- To send transactional email you have asked for: signup confirmation, password reset, payment receipt, expiry warning.
- To process payments through Stripe and keep records required by tax and accounting rules.
- To fix bugs, prevent abuse, and improve the product.
We do not use your guests’ data to send them marketing. We do not sell or rent personal data to anyone.
4. Who we share with
- Supabase — database, authentication, and file storage.
- Stripe — payment processing.
- Resend — transactional email delivery.
- Vercel — web hosting.
Each is bound by its own privacy terms. We do not share your data with anyone else, except when legally required.
5. Cookies
We use a small number of strictly necessary cookies for authentication and session handling. We do not use third-party advertising or tracking cookies. If analytics are added later, this section will be updated and a cookie notice will appear.
6. Retention
Active invitations are stored for the duration of the plan you chose (Starter 6 months, Premium 1 year, Forever 2 years). Expired invitations are kept for a short grace period so you can reactivate, then deleted. You can delete your account and data at any time from the dashboard or by emailing us.
7. Your rights
You can request a copy of your data, correct it, or ask us to delete it. Email hello@invitelux.com and we will respond within 30 days.
8. Security
Data is transmitted over HTTPS and stored on reputable cloud providers with encryption at rest. No system is perfect — if we ever learn of a breach affecting your data, we will notify you promptly.
9. Children
InviteLux is not directed at children under 13 and we do not knowingly collect data from them.
10. Changes
If we change this policy in a material way, we will update the date above and notify account holders by email.
Questions? Email hello@invitelux.com.