Privacy Policy
Last updated: 15.08.2026
1. Who processes your data
The data controller is InviteCards, Bulgaria, email: [email protected].
2. What we collect
At registration: your name, email address and password. The password is stored only as an irreversible cryptographic hash — we do not keep it and cannot read it.
If you sign in with Google: we receive your name, email address and profile picture from Google. We never receive your Google password.
Content you create: the event details and invitation text you enter yourself.
Technical data: your language preference and server log entries (IP address, request time) needed for security and operation.
3. Why we process it
- To run your account and the service — performance of a contract (Art. 6(1)(b) GDPR).
- For security and abuse prevention — legitimate interest (Art. 6(1)(f) GDPR).
- To answer your enquiry — legitimate interest.
We do not use your data for advertising and we do not sell it to anyone.
4. Cookies and tracking
The site uses strictly necessary cookies only — the session cookie that keeps you signed in. It does not require consent.
There is no Google Analytics, no advertising pixel and no other tracker. Fonts are served from our own server rather than from Google, so opening the site sends no request to a third party.
Visitor counter. The number at the bottom of the site counts that day's visitors. It works without a cookie and without storing your IP address — we keep a one-way fingerprint that changes every day and is deleted after two days. We also keep a per-country total for each day (for example “Bulgaria — 11 people”); these are counts, not records about individual visitors.
5. Who we share with
- Hosting: DigitalOcean, server in Amsterdam, the Netherlands — inside the EU.
- Google — only if you choose to sign in with a Google account.
Beyond this we do not pass data to third parties.
6. How long we keep it
Account data is kept while the account exists. After deletion it is removed within 30 days unless the law requires otherwise. Server logs are kept for up to 90 days.
7. Your rights
You may request:
- access to your data and a copy of it;
- correction of inaccurate data;
- erasure (“the right to be forgotten”);
- restriction of processing;
- portability — your data in a machine-readable form;
- objection to processing based on legitimate interest.
Write to [email protected] and we will answer within 30 days. If you believe your rights have been breached you may complain to your national data protection authority.
8. Security
The connection is encrypted (HTTPS). Passwords are stored hashed with bcrypt. Access to the database is restricted. No system is perfectly safe, but we treat your data as our own.
9. Children
The Service is not intended for anyone under 16 and we do not knowingly collect children’s data.