1. Data we handle and why
Accounts and support: names, work email addresses, organisation and role, authentication and support records. We use them to provide accounts, respond to requests, administer the service and protect it. Depending on the activity, the basis is performance of a contract, legitimate interests in secure operation, or a legal obligation.
Events and guests: event details, branding images, guest names, email addresses, categories and any other fields the organiser enters, invitation and delivery status, pass identifiers, and check-in time, checkpoint and device information. We process these on the organiser’s instructions to create, deliver and verify access. The organiser is responsible for identifying and explaining its own legal basis to guests.
Technical use: IP address, browser/device information, access and security logs, and essential session information may be processed to operate and secure the website, app and API. We rely on legitimate interests in security and reliable operation where we are controller, subject to applicable law.
Billing: order, plan and transaction records, if a paid offer is purchased, are used to administer the purchase and meet accounting or tax obligations. Payment providers, if introduced, will be identified before payment is taken.
2. Who receives data
We do not sell personal data or disclose guest lists to advertisers or unrelated partners. Access is limited to authorised organiser users and personnel who need it, and to providers needed for the service:
Brevo transmits transactional invitation and account emails and receives the email address and message content needed for delivery. Backblaze B2 stores event and branding images in private object storage. Apple Wallet and Google Wallet receive pass information only when a guest chooses the corresponding Wallet option; Apple and Google then handle their services under their own terms and privacy policies. Railway hosts the API, worker and database; Cloudflare delivers the website and app. These are operational disclosures, not a sale or permission for third-party marketing.
For a pass added to Wallet, read the provider’s own Apple Privacy Policy or Google Privacy Policy. Those policies explain the provider’s processing; this page remains the notice for InviteKey’s processing.
The organiser may give access to its authorised team and scanner devices. We may also disclose information if legally required or to protect rights and safety, limited to what is necessary.
3. International processing
Some providers or their infrastructure may process data outside your country, including outside the European Economic Area. Where required, we use an applicable transfer mechanism and safeguards, such as adequacy decisions or standard contractual clauses. Contact us for information about the safeguards relevant to your data. Apple and Google may also process Wallet data under their own policies.
4. How long data is kept
The event’s selected storage duration and expiry are shown in the service. The free offer provides 14 days from the event date; paid event duration depends on the selected option. Operational access ends at the configured expiry. Deletion from active systems is scheduled under our retention process; limited copies may remain temporarily in backups, security logs or provider systems under separate retention periods. We do not promise instantaneous deletion of every copy at event expiry.
An organiser’s downloaded exports, data temporarily stored on offline scanner devices, and passes saved in guests’ Wallet apps are separate copies. They may remain on those devices after event access ends. Organisers are responsible for exports and team devices; guests can remove saved passes from their Wallet. Apple and Google control their own retention of Wallet data.
Account and support records are kept while needed to provide the account and handle requests, then for a limited period where needed for security, disputes or legal obligations. Billing records may be retained for applicable accounting and tax periods. Ask us for the current periods that apply to a particular record.
5. Your choices and rights
Depending on your location and the processing concerned, you may ask for access, correction, deletion, restriction, portability or objection, and may withdraw consent where consent is the basis. These rights can be limited by law. Contact support@invitekey.app; we may need to verify your identity before acting.
If you are an invited guest, the organiser is normally the best first contact for requests about your invitation or attendance. You can also contact us and we will help route or handle the request as appropriate. If you are in the EEA, you may complain to your local data-protection authority.
6. Security and local storage
We use access controls and other technical and organisational measures intended to protect information. No online service can guarantee absolute security. Please report suspected misuse to support@invitekey.app.
The website stores a language and light/dark theme preference in your browser’s local storage. The app uses essential session mechanisms to keep users signed in and secure access. We do not use guest data for advertising profiles; if optional analytics or marketing trackers are introduced, this policy and any required consent controls will be updated first.
7. Changes and questions
We may revise this policy as the service or legal requirements change. The current version and its “Last updated” date appear here. For privacy questions or requests, email support@invitekey.app.
8. Data controller and contact
InviteKey is operated by Adrian Tanasescu, sole proprietor registered in France (SIREN 529 157 810), at 9 rue des Grisemottes, 69220 Belleville-en-Beaujolais, France. Contact us at support@invitekey.app.
For guest lists, invitations and attendance, the event organiser generally decides the purpose and details of processing and is the controller; InviteKey acts as its service provider/processor. For InviteKey accounts, billing, security and this website, the operator of InviteKey decides the relevant purposes and is the controller. Guests should also read the organiser’s own privacy notice.