GlowInvite

Privacy Policy

Last updated: 2026-10-02

This policy explains how GlowInvite (“GlowInvite”, “we”, “us”) processes personal data when providing digital invitation, RSVP, event management, guest media, payment and related services.

1. Who controls the data?

Service operator: GlowInvite. Privacy contact: contact@glowinvite.com.

2. What information may be processed?

Depending on the features used, the service may process client/contact data, guest names, email addresses, telephone numbers, RSVP responses, attendance counts, ceremony choices, seating assignments, event notes, uploaded guest photos/messages, invoices, payment status, device/security logs and technical data such as IP address and user agent.

3. Why is data processed?

Data is used to create and deliver event invitations, collect RSVP responses, operate guest and seating tools, support check-in, provide event galleries/guestbooks, manage subscriptions/invoices/payments, prevent abuse, maintain backups and security logs, and communicate service-related notifications.

4. Legal basis and client responsibility

The event organizer/client is responsible for having an appropriate legal basis to provide guest information to the service. Processing may rely on contract performance, legitimate interests, consent where required, or legal obligations, depending on the context and applicable law.

5. Service providers

GlowInvite may use hosting, email, SMS, payment and AI providers configured by the service operator. Only providers configured by the service operator are used for the corresponding features.

6. Retention

Event data is retained while the subscription is active and may remain in backups for a limited technical retention period. Event organizers should remove data they no longer need, subject to legal/accounting and backup requirements.

7. Guest photos and messages

Guest uploads may be moderated by the event organizer before appearing publicly. Guests should upload only content they are entitled to share. Event organizers can approve, reject or delete submissions.

8. Security

The platform includes access control, password hashing, CSRF protection, rate limiting, audit logging, restricted data directories, backup tools and HTTPS-oriented security headers. No online system can guarantee absolute security.

9. Your rights

Depending on applicable law, individuals may have rights to access, correct, delete, restrict or object to processing, and to request data portability or withdraw consent. Requests should be sent to the privacy contact above and may require identity verification.

10. International processing

Hosting, payment, communication or AI providers may process information in other jurisdictions. The service operator should select providers and contractual safeguards appropriate to the markets in which the service is offered.

11. Children

The service is not intended to collect children’s data independently of an event organizer. Organizers should not submit children’s personal data unless they have appropriate authority and a lawful purpose.

12. Changes

This policy may be updated as features, providers or legal requirements change. The current version is published on this page.

Commercial deployment note: this template must be reviewed and adapted to the operator’s actual company details, providers and applicable law before public launch.