Privacy notice

August 24, 2026

We keep what your invitation needs to work and what your guests need in order to RSVP. Nothing more, and nothing that gets sold to anyone.

Who is responsible for your data

Invitations, based in Mexico, is responsible for the personal data collected at invitations.com.mx. This notice is issued under Mexico's Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) and its regulations.

For anything about privacy — including asking us to delete your data — write to hola@invitations.com.mx. It's a mailbox someone reads, not a form that disappears.

There are two different people here: you and your guests

This is the part worth understanding before any other. You open an account and create an invitation: that's your data, and we handle it because you gave it to us.

Your guests are a different matter. Their names, phone numbers and email addresses you enter yourself — by hand or by importing a file — and we store them so we can do exactly what you're asking for: build each person's link, send them the invitation, and collect their reply.

Which means that data is still your responsibility: you're the one who collected it and who decided to invite those people. We process it on your behalf and use it for nothing else.

What we store about you

The minimum for you to have an account and an invitation:

  • Your email address, and your name if you type it. If you sign in with Google, also what Google shares from your basic profile: email and name.
  • The language you use the site in.
  • Everything you create: the party's title, the date, the time, the city, the venue, the text, the photos you upload and the music you pick or upload.
  • If you pay: the payment reference, the amount, and whether it went through. Your card number never passes through here (see below).

What we store about your guests

What you enter for each one: their name or whatever you want to call them (“The Pérez family”), their phone, their email, how many passes they get, their tag and their language. That's what their personal link is built from.

And what happens afterwards: whether you sent them the invitation and through which channel, whether the email arrived or bounced, how many times they opened their invitation, and their answer — whether they're coming, with how many people, and any message they leave you.

What we don't do

This list is deliberately short, and every point can be checked:

  • We don't sell or rent data. Not yours, not your guests'.
  • There is no third-party analytics. No Google Analytics, no Meta, none at all: there isn't a single line of it on the site. The only cookie we set is your session, so you don't have to sign in again.
  • We don't know whether a guest opened your email. Our emails carry no tracking pixel. What we do know is whether their mail server accepted or rejected it, and whether they opened their invitation, because the link itself counts that.
  • We never see your card. Stripe handles the payment on its own page; all that's left here is the payment reference and whether it went through.
  • We don't build profiles or run advertising on what happens in your invitation.

What we use the data for

Necessary purposes, without which there is no service: creating and keeping your account; building, publishing and serving your invitation; building each guest's link and sending them the invitation by email or WhatsApp; receiving and showing you the RSVPs; processing your payment and giving you a receipt; and answering you when you write.

Optional purposes: improving the product with aggregate statistics. You don't have to accept those to use the service, and you can tell us you'd rather not by writing to the address above.

How many visits your invitation got, without knowing who visited

Your dashboard tells you how many visits and how many distinct visitors your invitation had. That's counted without storing who.

What gets stored is an irreversible code derived from mixing the IP address, the browser and your event's identifier. The IP itself is never stored. And because the event goes into the mix, the same person on two different invitations produces two different codes: the data can't be used to follow anyone from one invitation to another.

Who we share it with

Only the providers that make the service work, and only what each one needs:

  • Supabase — the database, your account sign-in, and storage for your photos and music.
  • Vercel — hosting the site.
  • Stripe — the payment. They're the ones who receive your card details, not us.
  • Resend — sending the invitation emails.
  • Google — only if you choose to sign in with Google.
  • OpenAI — only if you ask the AI to pre-translate the text you wrote. It gets that text and nothing else: not your email, not your guest list.

Your data leaves Mexico, and that has to be said

All those providers are in the United States or the European Union, so your data is transferred out of the country. The transfer is necessary to provide the service you signed up for, which is why it doesn't need your separate consent (article 37 of the LFPDPPP). None of them may use your data for their own purposes.

How long we keep it

Your invitation stays active for one year after the day of the event: your guests can keep opening it and you can keep checking who came. After that it stops being served.

If you delete an invitation, everything hanging off it goes with it: its guest list, its replies and the record of what was sent. It's immediate and can't be undone. Payment records are kept separately for as long as tax law requires.

Who can see your invitation

While it's a draft, only you. Its link doesn't lead anywhere until you publish it.

Once published, anyone with the link can see it: no account, no password, because your guests aren't going to create one. That's why the invitation isn't indexed by search engines and isn't in the sitemap — being openable with the link doesn't mean it should be findable by searching your child's name.

Each guest also gets their own link with a unique code, and that's what makes them see their greeting and their passes. That code is the key to their reply: whoever has it can RSVP as them, so it's shared the way an invitation is shared — with the person invited.

And if you unpublish, the link stops working for everyone.

How we look after the data

Everything travels encrypted (HTTPS) and is stored in Supabase with row-level security: every database query checks whose data it is before returning it, so a programming mistake isn't enough for one account to see another's invitation. The writes that grant something — marking an invitation as paid, publishing it — can only be done by the server, never by the browser.

None of this is a promise of absolute security: there's no such thing. If there's ever a breach that affects you, we'll tell you, and we'll tell you what happened.

Your rights, and how to exercise them

You can ask at any time for access to your data, rectification of anything wrong, cancellation (that we delete it) and objection to a specific use. You can also withdraw your consent.

Write to hola@invitations.com.mx with your name, your account's email address and what you want us to do. We answer within 20 business days at most. If you think we handled your request badly, you can go to Mexico's data protection authority, the INAI.

Children

The account is opened by an adult: you must be of legal age to use the service. Many of these invitations are for children's parties, so the names an organizer enters may include children — that data is provided by the adult responsible for the party. We don't collect it from any minor.

If you're reading this from outside Mexico

The service is operated from Mexico and under Mexican law. If you live somewhere whose laws give you additional rights over your data, write to hola@invitations.com.mx and we'll honor them the same way: the rights above — see it, correct it, delete it, object — are the ones we'd want ourselves.

Changes to this notice

If this changes in any meaningful way, we'll say so on the site and by email to anyone with an account. The date above says when it last changed.