This Privacy Policy explains how Elena Kravtsova (a registered sole proprietor (עוסק) in Israel, the data controller) collects and uses personal data through this event website (https://inviteberry.com). It has a general part (A) that applies to everyone and regional parts that add rights for visitors in the EEA/UK, California, Israel and Russia.
Contact for all privacy requests: [email protected]
Who is responsible for what
This platform and the organiser of your event each decide different things, and data-protection law makes each of us responsible for what we decide.
The organiser decides who is invited, whether a photo gallery exists for the event, who may enter it, and, within limits we set, how long it stays open. For the guest list they give us and the messages sent from it, the organiser is responsible and we act on their instructions.
We decide how the platform is secured, what is screened and moderated, what happens when someone asks for a photo to be taken down, the outside limit on how long anything is kept, whether the "find photos of me" feature exists and where it is offered, and what is published from photo likes. For all of that we are responsible in our own right.
One thing we decide together: that photographs uploaded by guests are stored and shown to the people given access to the gallery of that event. For that, the organiser and we are jointly responsible.
Whoever is responsible, ask us. You do not need to work out which of us it is. Send any request to [email protected] and we will handle it, including where the organiser is the responsible party: we will not send you away. You may also go to the organiser directly, and to either of us where we are jointly responsible. The full allocation is set out in our Data Processing Addendum (/legal/dpa).
A. General
This is a private, invitation-based event platform used to invite guests, collect RSVPs, organise the event, share an event photo gallery and (where offered) take event-related payments.
What data we collect
- Name, email, phone number(s) and preferred language.
- Your RSVP: attendance, number of adults/children, names of additional guests you add, and an optional free-text message.
- An optional “needs accessible drop-off at the venue” flag, about physical venue access only, used for event logistics.
- Where the event’s organiser has switched them on: your answers to a fixed set of RSVP questions, each a number for your whole invitation rather than about any one person (for example how many vegetarian, kosher or gluten-free meals, a food allergy and what it is, a high chair, parking).
- Photo-gallery sign-in (username + access code; we store only a salted hash of the code) and any photos you upload.
- In the photo gallery: the photos you save (the bookmark) and the folders you sort them into, including the names you give those folders, all visible only to you and never shown to anyone else, including the organiser, and never counted; and, where the organiser has enabled it, the photos you publicly like (the heart). A like is a separate, deliberately public action: the gallery shows how many guests liked a photo, and only once at least three have, so a smaller number cannot identify the one or two people behind it. We never reveal who liked a photo. The organiser sees the exact numbers, still without names. Un-liking withdraws your like and lowers the count immediately.
- If you join the InviteBerry waitlist: your email address, whether you signed up as a couple or as a planner, your language and the record of your opt-in, used only to tell you about the product launch. You can unsubscribe at any time via the link in each message or by emailing us.
- Where payments are offered: amount and transaction details (card data is handled by the payment processor; we do not store full card numbers).
- Technical data needed to run the site (IP, device/browser, logs).
- Sign-in records, for security: the time of each sign-in (or failed attempt) to the photo gallery or the organiser panel, together with the IP address, the country it points to, and the browser/device used.
- Only if you opt in: pseudonymous usage analytics via Google Analytics 4 (off by default).
Some of those RSVP answers can reveal health or religious observance: a gluten-free, lactose-free, kosher or mehadrin meal, a food allergy, and the accessible drop-off flag. We ask for the meal and allergy answers only as numbers for the whole invitation, only where the organiser has switched them on, and only with your separate, explicit consent on the form. Answering them is optional and does not affect your RSVP. They go to the event’s organiser, and through the organiser to the venue and the caterer (including through iPlan, the venue’s planning system), to prepare the meal. By sending them you also confirm that you answer for yourself and your children under 18, and that the other adults on the invitation agreed to your passing these answers on. The answers are deleted 30 days after the event, and you can withdraw your consent or correct an answer at any time through your personal invitation link or by asking the organiser. Apart from those, we do not intentionally collect special-category data. Free-text messages and uploaded photos could incidentally contain such information, please avoid including it.
Providing data is voluntary: there is no legal duty to give it to us. Without contact details, though, we cannot deliver an invitation, record an RSVP or open the gallery to you. This notice, and the purposes set out below, are given under Section 11 of the Israeli Protection of Privacy Law.
Why we use it & legal bases
| Purpose | Legal basis |
|---|---|
| Invitations & RSVP management | Steps toward / hosting the event; legitimate interest; consent |
| Seating, to-dos, gifts/finance | Legitimate interest of the hosts |
| Event messaging (invite, reminder, thanks, cancellation) | Legitimate interest; consent |
| Photo gallery | Israel: consent (gallery rules accepted, RSVP consent) and the Section 11 notice above; EEA: legitimate interest (private album for the guests of the event and the people its hosts let in) |
| Public photo likes and the counts shown from them | Legitimate interest (light social feedback in a closed gallery; the act is public by design, only a number is published, never below three guests). Privately saved photos are not used for this. Withdraw by un-liking |
| Product waitlist updates | Consent (opt-in; withdraw at any time) |
| Payments (where offered) | Contract; legal obligation (tax/accounting) |
| Security & access control, incl. sign-in monitoring | Legitimate interest; legal obligation |
| Analytics (GA4) | Consent (opt-in) |
We do not use your data for advertising, ad-targeting, profiling with legal effects, or selling data.
Service messages that reach you after an opt-out
Opting out stops the invitations, reminders and thanks an organiser sends through us. It does not stop a small group of service messages, which we send whatever you chose, because they are part of running the service or are owed to you. We name only the categories:
- Sign-in and confirmation codes.
- Security of, and access to, an organiser’s account.
- A notice that an event has been cancelled.
- Replies and reminders about a message you sent, or a request or order you made.
- Notices about complaints, hiding or removal of content, and how long we keep data.
Photos of you
The gallery is a private album for one event. It is open to the guests of the event and to people the organiser lets in by name who are not on the guest list, such as family who could not come or the photographer. Someone let in by name sees the photos and can download them, but does not see who uploaded them. The organiser can also issue codes shared by several people, such as a vendor's team or a tablet at the venue, and can turn on a screen in the hall that shows approved photos during the event, without the names of who uploaded them. The gallery is never public. Israeli law has no concept of legitimate interest, so for a guest in Israel the basis for hosting the gallery is consent, given when the gallery rules are accepted and again in the RSVP, together with the Section 11 notice given above. For a guest in the EEA, the basis is legitimate interest under GDPR Art. 6(1)(f): sharing the photographs of an event with the people who were at it is what a guest would ordinarily expect, and asking every identifiable person in every group shot for consent is not something anyone could honestly obtain at a wedding. That basis has been assessed, and we consider it justified.
You can object at any time, and the way to object is simply to ask us to remove the photograph. Guests can select the photos inside the gallery; anyone else, including someone who was never invited, can use our report form at https://inviteberry.com/legal/report without an account. We remove the photograph, tell the person who uploaded it, and keep a fingerprint of the image so the same photo cannot be uploaded again. That fingerprint is a number, not a picture: it cannot be turned back into the photograph, and it exists so that the removal sticks. Some galleries also let a guest find the photographs they appear in by comparing faces on their own device. That is biometric processing, it is asked for separately, and it has a policy of its own at https://inviteberry.com/legal/biometric.
Whoever uploads a photo undertakes to upload only content they are allowed to share: content that, as far as they know, nobody who can be recognised in it objects to, that breaks no agreement or restriction on publishing it, that infringes nobody else's rights, and that contains nothing unlawful. That undertaking is their promise to us, not your consent: it does not replace your right to have a photo of you taken down, and it never counts against you.
We do not analyse faces, do not identify people automatically, and do not use gallery photographs for advertising or for training anything.
How long we keep it
Three different rules set these periods, and they are not interchangeable. Data about your event is kept only as long as the event needs it. Records of sign-ins to the organiser panel are kept for 24 months, because the Israeli data-security rules require it of access records. Records that prove afterwards what we did, such as the log of consents and opt-outs, a receipt of a removal or an acceptance of the gallery rules, are kept for as long as a claim about them can be brought: 7 years, the general limitation period under Israel's Prescription Law, 5718-1958. Payment and accounting records follow tax law.
- Guest contact, RSVP, seating, dietary and messaging data: deleted or anonymised within 6 months after the event date. If the event host asks us to keep the event workspace active for longer (for example, to keep the photo gallery open), data is retained only for the extended period requested by the host and in any case deleted no later than 24 months after the event date. An event its host archives or deletes is deleted six months after the day it was archived, if that comes earlier.
- Answers that can reveal health or religious observance (the gluten-free, lactose-free, kosher, mehadrin and food-allergy answers, the allergy’s description among them) and the accessible drop-off flag: deleted 30 days after the event date, sooner than the rest of the RSVP.
- Consent records (your RSVP acceptance, waitlist opt-in and any messaging opt-in): kept longer than the data above, as evidence of compliance, for the relevant limitation period.
- Records that you asked not to be messaged, and the log of consents and opt-outs: held as a keyed cryptographic hash of your phone number or email, never the contact itself. A request not to be messaged is kept for as long as it stands; once you lift it, and for every entry in the log, 7 years, the general limitation period under Israel's Prescription Law, 5718-1958. They are used only to stop messages to you and to prove that we stopped, never to decide whom to contact, to target or to profile anyone.
- Sign-in records: gallery sign-ins are kept for 180 days; sign-ins to the organiser panel are kept for 24 months, as Israeli data-security rules require of access records.
- Waitlist emails: until you unsubscribe or the launch mailing is completed.
- Photos: kept until the event's data is deleted on the dates above, or removed sooner if you ask us to; guests stop seeing them when the gallery closes.
- Fingerprints of removed photos: when a photo is removed on request, a numeric fingerprint of it (from which no image can be recovered) is kept on a blocklist for as long as we operate that blocklist, so the same image cannot be uploaded again; the reliance is reviewed yearly.
- Analytics: per Google Analytics 4 retention (e.g. 2-14 months).
- Payment/accounting records: as required by Israeli tax law (typically up to 7 years).
- Cookie-consent record: ~6-12 months.
Who we share it with (processors)
We do not sell your data. These are the service providers that may process personal data on our behalf when the platform is used, what each one does, and the safeguard covering any transfer outside the EEA or Israel.
| Provider | What it does | Processing location | Transfer safeguard |
|---|---|---|---|
| Google Cloud (Firebase, Cloud Vision, Vertex AI) | Hosting, database and file storage for the whole platform; automated screening of uploaded media and text (Cloud Vision, Video Intelligence); the AI features an organiser starts, which run on Vertex AI (Gemini) | United States | Google Cloud data-processing terms with SCCs; EU-US Data Privacy Framework |
| Google Analytics 4 | Usage analytics, only after cookie consent | United States | SCCs; EU-US Data Privacy Framework |
| Cloudflare | Content delivery in front of the site; storage and delivery of gallery media behind short-lived signed links | Global network; gallery media stored in Europe | SCCs; EU-US Data Privacy Framework |
| Meta Platforms (WhatsApp Business Cloud API) | Event messages to guests and their delivery statuses | United States and global | SCCs (Meta transfer addendum) |
| ActiveTrail | SMS delivery to Israeli numbers | Israel | No cross-border transfer |
| Cloudprinter | Print fulfilment of ordered photo albums (recipient name and shipping address) | European Union, plus the producing print facility | SCCs |
| Google Maps Platform | The venue map shown on invitation pages, and the venue and address lookup used in the organiser panel. A displayed map is loaded by your browser directly from Google | United States | Google Maps terms for independent controllers; EU-US Data Privacy Framework |
We also use an email service provider in the EU (the support mailbox and transactional email), an error-monitoring service in the United States (SCCs; EU-US Data Privacy Framework), and, where payments are offered, a payment processor and an Israeli invoicing service. Organisers are notified at least 30 days before a processor that touches guest data is added or replaced (see the Data Processing Addendum). We may also disclose data where legally required.
Separately from the processors above, the organiser of your event may pass your name, the size of your party and, where it applies, the accessible-drop-off flag to the suppliers running that event, such as the venue and its seating system or, in future, a transport company, and for that event only. Those suppliers are engaged by the organiser rather than by us: they are not our processors, we do not choose them and we do not instruct them.
Where your data is processed
Data is hosted on Google infrastructure in the United States. The Google image, video and AI services process a file wherever Google routes it, normally the United States. Gallery media is additionally served from Cloudflare storage in Europe so that it loads quickly. Transfers outside Israel and the EEA rely on Standard Contractual Clauses and/or the EU-US Data Privacy Framework.
Security
TLS in transit and encryption at rest on Google infrastructure; role-based access and project isolation; photo access codes stored only as salted hashes; server secrets kept server-side; signature-verified WhatsApp webhook. We also monitor sign-ins: each sign-in and failed attempt is logged so that an unfamiliar device or country, or a run of failed attempts, can be spotted and acted on. We notify affected people and regulators where the law requires.
Children
The site is for adults arranging an event. Guests may enter the names and counts of children they bring; this is provided by the adult guest. Children do not create accounts or upload data themselves.
Your rights (everyone)
You can ask us to access, correct or delete your data, or withdraw consent (e.g. analytics, waitlist) at any time, by emailing [email protected]. To remove yourself entirely, contact us and we will delete your guest, RSVP, finance, photo and lookup records.
A removal request covers, for the event in question: your guest record and RSVP answer, your gallery account and sign-in history, the record of which messages were delivered to you, your saved photos, your reactions and the folders you sorted them into, your biometric-search consent if you gave one, and the photographs and videos you uploaded, which disappear from the gallery for everybody, not only for you. Save anything you want to keep before asking. Requests you made about somebody else's photograph are not deleted, because the decision on them concerns the person whose picture it was, but your name and phone number are removed from them. If you are on somebody else's invitation as a companion, the same applies to you alone and the rest of the party is untouched.
What deletion means in practice: we stop the processing and remove the data from the live system straight away. A photo removed on a takedown request leaves no service copy at all: we keep the record of the removal and a fingerprint of the image, never the image itself. If a removal turns out to have been wrong we reverse the decision rather than restore a file, and whoever uploaded the photo can upload it again from their own copy. One thing is deliberately slower, and we would rather say so than let you assume otherwise: backups and our providers' own recovery windows still hold data for a bounded period after live deletion: at most 14 weeks in a backup copy, and 7 days in the point-in-time and deleted-object recovery windows. Those copies are put beyond use: nobody searches them, and nothing is taken out of one to find or reinstate a particular person's data. After a serious failure we may put part of the database back from within that recovery window; if we do, anything that returns which should already have been deleted is deleted again before anyone can see it. Otherwise the copies are overwritten on their own schedule. We keep, without the content itself, a record that the deletion happened, for as long as a legal claim about it could be brought.
What survives a removal request, and why: a small number of records outlive the data they are about, each because holding it is what makes the removal answerable rather than in spite of it, and none of them is a copy of what was removed. The record that you asked not to be messaged, and the log of consents and opt-outs, are kept by an irreversible cryptographic hash of your phone number or email, never the contact itself: forgetting that you asked us to stop is how you would be contacted again. Receipts of photos removed after a complaint, records of what left the platform as a download, and the evidence of which gallery rules were accepted are kept for 7 years on their own clocks. Album orders are kept as long as tax law requires. The fingerprint that stops a removed photo being re-uploaded holds no image and identifies nobody. Finally, we write one short receipt of the removal itself: the date, the event, which categories were cleared, and the same hash of your contact. It contains no name, no phone number and no email, is kept for 7 years and is our only evidence that we did what you asked. We do not keep a hidden full copy of removed data; that would not be a removal.
B. EEA / UK (GDPR / UK GDPR)
If you are in the EEA or UK, you have the rights to access, rectification, erasure, restriction, objection, portability, to withdraw consent, and to lodge a complaint with your supervisory authority. We make no solely automated decisions with legal effect. The European Commission recognises Israel as providing an adequate level of protection, a decision reviewed and reaffirmed on 15 January 2024, so data may flow from the EEA to Israel without additional safeguards; onward transfers by our providers to the United States rely on Standard Contractual Clauses and the EU-US Data Privacy Framework.
InviteBerry is established in Israel and does not target individuals in the EEA or the UK: album printing does not ship to addresses there. Where the GDPR or the UK GDPR applies to our processing, we will appoint a representative under Article 27 if required. Album printing also does not ship to Jersey, Guernsey, the Isle of Man or Gibraltar, which are in neither the EEA nor the UK: each has a data protection law of its own, with its own requirement to appoint a representative. Apart from the RSVP answers a guest gives with their explicit consent (above), face matching is the only special-category operation this platform performs, and it is refused to visitors in the EEA and the UK at the server. No DPO is appointed or required.
C. California, USA (CCPA / CPRA)
Provided for transparency. The CCPA/CPRA apply only to businesses meeting thresholds (~$26.625M revenue; buying, selling or sharing personal information of 100,000+ California consumers or households; or 50%+ revenue from selling/sharing data); this small private project does not meet them, so the law does not apply to us. We do not “sell” or “share” personal information for cross-context behavioural advertising, so no “Do Not Sell or Share” link is required.
California residents may request to know, access, correct and delete their information, and not be discriminated against for it, via [email protected].
D. Israel (Protection of Privacy Law)
The Protection of Privacy Law, 5741-1981 (as amended, including Amendment 13, in force 14 August 2025) and the Data Security Regulations, 5777-2017 apply. You may review the data we hold, request correction and ask for deletion. We do not trade in personal data, are not a data broker and do not run a direct-mail (דיוור ישיר) marketing database. Under the rules as narrowed by Amendment 13 our database is not subject to registration or notification with the Privacy Protection Authority: registration applies mainly to public bodies, data brokers and direct-marketing databases covering more than 10,000 people, and notification to databases holding highly sensitive data on more than 100,000, and neither describes this platform. We count how many people we hold data about, so that we would know well before either line was approached. A privacy protection officer (ממונה על הגנת הפרטיות) is likewise not required for processing of our kind and scale. The supervisory authority is the Privacy Protection Authority (PPA).
Transfers of your data outside Israel (see "Where your data is processed" above) rely on the Protection of Privacy (Transfer of Data to Databases Abroad) Regulations, 5761-2001: on the destination's recognised adequate protection, or on the contractual safeguards named there.
E. Russia (152-ФЗ)
This service is not offered to people located in the Russian Federation, and that is a settled decision rather than a stage we are passing through. The Russian-language interface exists for Russian speakers in Israel and elsewhere outside Russia.
We keep no database in Russia and are not building one, so the initial collection and storage that 242-ФЗ requires to happen there could not happen. We have not notified Roskomnadzor and are not seeking to. The face search in event galleries is refused outright to visitors in Russia, decided at our servers, whatever the organiser of an event has asked for. And we do not send messages to Russian phone numbers: invitations, reminders, thank-yous and photo-album access are refused at our servers before they reach any gateway, and a sign-in code for a photo album is refused the same way.
One exception, and it is narrow. A phone number is not an address: somebody living in Israel may simply have kept a Russian SIM. So the organiser of an event, who knows their own guests, can state for one named guest that this person is not located in the Russian Federation, and messages to that guest then go out. We record that statement with its wording, the time and who made it. It is about that one person and lifts nothing else. Separately, a message telling guests that an event has been cancelled is sent regardless, because the harm of withholding it falls on the guest.
There is a practical reason as well, and it is the one a guest would notice first: the only messaging channel this service has for a guest outside Israel is WhatsApp, which is not reliably reachable in Russia, so an invitation sent to a Russian number may never arrive. If you are located in Russia, please do not submit personal data through this site. If data about someone in Russia reaches us anyway, through the guest list of an event for instance, write to us and we will remove it.