Privacy Policy
Last Updated: September 19, 2026
UK Web Services Ltd (trading as InviteFor) is committed to protecting your personal data. This policy explains how we collect, use, and protect information when you use our platform.
1. The Data We Collect
We act as a Data Controller for our registered Hosts, and as a Data Processor for the Guests invited to events.
- Host Data: Name, email address, billing information, and encrypted account credentials.
- Guest Data: Information submitted via RSVP forms, which may include names, email addresses, phone numbers, and dietary requirements.
Note: We do not process or store sensitive credit card data on our servers. All payment data is securely handled directly by Stripe.
2. The 30-Day GDPR Data Wipe
We practice strict data minimization. 30 days after an event concludes, we automatically and permanently delete all personally identifiable Guest data (including names, emails, phones, and dietary notes) from our active databases. Only anonymized, aggregated headcount data remains for host analytics.
3. Third-Party Sub-Processors
To operate our platform, we securely share necessary data with trusted third-party services:
- Stripe: For processing payments, Pro Passes, and guest ticket sales.
- SMTP2GO: For securely dispatching transactional emails (e.g., ticket confirmations and daily digests).
- Cloudflare: For security routing and Turnstile bot-protection.
- Backblaze: For secure, encrypted off-site database backups.
4. Your Rights
Under the UK GDPR, you have the right to access, correct, or request the erasure of your personal data. Hosts may delete their accounts at any time from their dashboard. Guests wishing to have their RSVP data removed prior to the automated 30-day wipe should contact the Event Host directly, or contact us at [email protected].