Privacy Policy
This Privacy Policy explains how Elena Kravtsova (a registered sole proprietor (עוסק) in Israel, the data controller) collects and uses personal data through this event website (https://inviteberry.com). It has a general part (A) that applies to everyone and regional parts that add rights for visitors in the EEA/UK, California, Israel and Russia.
Contact for all privacy requests: [email protected]
Who is responsible for what
This platform and the organiser of your event each decide different things, and data-protection law makes each of us responsible for what we decide.
The organiser decides who is invited, whether a photo gallery exists for the event, who may enter it, and, within limits we set, how long it stays open. For the guest list they give us and the messages sent from it, the organiser is responsible and we act on their instructions.
We decide how the platform is secured, what is screened and moderated, what happens when someone asks for a photo to be taken down, the outside limit on how long anything is kept, whether the "find photos of me" feature exists and where it is offered, and what is published from photo likes. For all of that we are responsible in our own right.
One thing we decide together: that photographs uploaded by guests are stored and shown to the guests of that event. For that, the organiser and we are jointly responsible.
Whoever is responsible, ask us. You do not need to work out which of us it is. Send any request to [email protected] and we will handle it, including where the organiser is the responsible party: we will not send you away. You may also go to the organiser directly, and to either of us where we are jointly responsible. The full allocation is set out in our Data Processing Addendum (/legal/dpa).
A. General
This is a private, invitation-based event platform used to invite guests, collect RSVPs, organise the event, share an event photo gallery and (where offered) take event-related payments.
What data we collect
- Name, email, phone number(s) and preferred language.
- Your RSVP: attendance, number of adults/children, names of additional guests you add, and an optional free-text message.
- An optional “needs accessible drop-off at the venue” flag, about physical venue access only, used for event logistics.
- Photo-gallery sign-in (username + access code; we store only a salted hash of the code) and any photos you upload.
- In the photo gallery: the photos you save (the bookmark) and the folders you sort them into, including the names you give those folders, all visible only to you and never shown to anyone else, including the organiser, and never counted; and, where the organiser has enabled it, the photos you publicly like (the heart). A like is a separate, deliberately public action: the gallery shows how many guests liked a photo, and only once at least three have, so a smaller number cannot identify the one or two people behind it. We never reveal who liked a photo. The organiser sees the exact numbers, still without names. Un-liking withdraws your like and lowers the count immediately.
- Where payments are offered: amount and transaction details (card data is handled by the payment processor; we do not store full card numbers).
- Technical data needed to run the site (IP, device/browser, logs).
- Sign-in records, for security: the time of each sign-in (or failed attempt) to the photo gallery or the organiser panel, together with the IP address, the country it points to, and the browser/device used.
- Only if you opt in: pseudonymous usage analytics via Google Analytics 4 (off by default).
We do not intentionally collect special-category data. Free-text messages and uploaded photos could incidentally contain such information, please avoid including it.
Why we use it & legal bases
| Purpose | Legal basis |
|---|---|
| Invitations & RSVP management | Steps toward / hosting the event; legitimate interest; consent |
| Seating, to-dos, gifts/finance | Legitimate interest of the hosts |
| Event messaging (invite, reminder, thanks, cancellation) | Legitimate interest; consent |
| Photo gallery | Legitimate interest (private album for the event's own guests) |
| Public photo likes and the counts shown from them | Legitimate interest (light social feedback in a closed gallery; the act is public by design, only a number is published, never below three guests). Privately saved photos are not used for this. Withdraw by un-liking |
| Payments (where offered) | Contract; legal obligation (tax/accounting) |
| Security & access control, incl. sign-in monitoring | Legitimate interest; legal obligation |
| Analytics (GA4) | Consent (opt-in) |
We do not use your data for advertising, ad-targeting, profiling with legal effects, or selling data.
Photos of you
The gallery is a private album for one event, open only to the people invited to it. We rely on legitimate interest to host it: sharing the photographs of an event with the people who were at it is what a guest would ordinarily expect, and asking every identifiable person in every group shot for consent is not something anyone could honestly obtain at a wedding.
You can object at any time, and the way to object is simply to ask us to remove the photograph. Guests can select the photos inside the gallery; anyone else, including someone who was never invited, can use our report form at https://inviteberry.com/legal/report without an account. We remove the photograph, tell the person who uploaded it, and keep a fingerprint of the image so the same photo cannot be uploaded again. That fingerprint is a number, not a picture: it cannot be turned back into the photograph, and it exists so that the removal sticks. Some galleries also let a guest find the photographs they appear in by comparing faces on their own device. That is biometric processing, it is asked for separately, and it has a policy of its own at https://inviteberry.com/legal/biometric.
Whoever uploads a photo confirms that they may share it and that identifiable people in it do not object. That is their promise to us, not your consent: it does not replace your right to have a photo of you taken down, and it never counts against you.
We do not analyse faces, do not identify people automatically, and do not use gallery photographs for advertising or for training anything.
How long we keep it
- Guest contact, RSVP, seating, dietary and messaging data: deleted or anonymised within 6 months after the event date. If the event host asks us to keep the event workspace active for longer (for example, to keep the photo gallery open), data is retained only for the extended period requested by the host and in any case deleted no later than 24 months after the event date.
- Consent records (your RSVP acceptance and any messaging opt-in): kept longer than the data above, as evidence of compliance, for the relevant limitation period.
- Sign-in records: gallery sign-ins are kept for 180 days; sign-ins to the organiser panel are kept for 24 months, as Israeli data-security rules require of access records.
- Photos: until the gallery is closed or you ask us to remove them.
- Fingerprints of removed photos: when a photo is removed on request, a numeric fingerprint of it (from which no image can be recovered) is kept on a blocklist for as long as we operate that blocklist, so the same image cannot be uploaded again; the reliance is reviewed yearly.
- Analytics: per Google Analytics 4 retention (e.g. 2-14 months).
- Payment/accounting records: as required by Israeli tax law (typically up to 7 years).
- Cookie-consent record: ~6-12 months.
Who we share it with (processors)
We do not sell your data. These are the service providers that may process personal data on our behalf when the platform is used, what each one does, and the safeguard covering any transfer outside the EEA or Israel.
| Provider | What it does | Processing location | Transfer safeguard |
|---|---|---|---|
| Google Cloud (Firebase, Cloud Vision, Vertex AI) | Hosting, database and file storage for the whole platform; automated screening of uploaded media and text (Cloud Vision, Video Intelligence); the AI features an organiser starts, which run on Vertex AI (Gemini) | United States | Google Cloud data-processing terms with SCCs; EU-US Data Privacy Framework |
| Google Analytics 4 | Usage analytics, only after cookie consent | United States | SCCs; EU-US Data Privacy Framework |
| Cloudflare | Content delivery in front of the site; storage and delivery of gallery media behind short-lived signed links | Global network; gallery media stored in Europe | SCCs; EU-US Data Privacy Framework |
| Meta Platforms (WhatsApp Business Cloud API) | Event messages to guests and their delivery statuses | United States and global | SCCs (Meta transfer addendum) |
| ActiveTrail | SMS delivery to Israeli numbers | Israel | No cross-border transfer |
| Cloudprinter | Print fulfilment of ordered photo albums (recipient name and shipping address) | European Union, plus the producing print facility | SCCs |
| Google Maps Platform | The venue map shown on invitation pages, and the venue and address lookup used in the organiser panel. A displayed map is loaded by your browser directly from Google | United States | Google Maps terms for independent controllers; EU-US Data Privacy Framework |
We also use an email service provider in the EU (the support mailbox and transactional email), an error-monitoring service in the United States (SCCs; EU-US Data Privacy Framework), and, where payments are offered, a payment processor and an Israeli invoicing service. Organisers are notified at least 30 days before a processor that touches guest data is added or replaced (see the Data Processing Addendum). We may also disclose data where legally required.
Where your data is processed
Data is hosted on Google infrastructure in the United States. The Google image, video and AI services process a file wherever Google routes it, normally the United States. Gallery media is additionally served from Cloudflare storage in Europe so that it loads quickly. Transfers outside Israel and the EEA rely on Standard Contractual Clauses and/or the EU-US Data Privacy Framework.
Security
TLS in transit and encryption at rest on Google infrastructure; role-based access and project isolation; photo access codes stored only as salted hashes; server secrets kept server-side; signature-verified WhatsApp webhook. We also monitor sign-ins: each sign-in and failed attempt is logged so that an unfamiliar device or country, or a run of failed attempts, can be spotted and acted on. We notify affected people and regulators where the law requires.
Children
The site is for adults arranging an event. Guests may enter the names and counts of children they bring; this is provided by the adult guest. Children do not create accounts or upload data themselves.
Your rights (everyone)
You can ask us to access, correct or delete your data, or withdraw consent (e.g. analytics) at any time, by emailing [email protected]. To remove yourself entirely, contact us and we will delete your guest, RSVP, finance, photo and lookup records.
B. EEA / UK (GDPR / UK GDPR)
If you are in the EEA or UK, you have the rights to access, rectification, erasure, restriction, objection, portability, to withdraw consent, and to lodge a complaint with your supervisory authority. We make no solely automated decisions with legal effect. Israel benefits from a partial EU adequacy decision; onward transfers by our providers rely on SCCs / the EU-US Data Privacy Framework.
An EU Article 27 representative may be required if EEA individuals are actively targeted and processing is not occasional; at this small, event-specific scale the Article 27(2) exemption is relied on, to be confirmed. That exemption also depends on the platform doing no large-scale processing of special categories of EEA data, which is why face matching is refused to visitors in the EEA and the UK at the server. No DPO is appointed or required.
C. California, USA (CCPA / CPRA)
Provided for transparency. The CCPA/CPRA apply only to businesses meeting thresholds (~$26.625M revenue, 100,000+ California consumers, or 50%+ revenue from selling/sharing data); this small private project does not meet them, so the law most likely does not apply. We do not “sell” or “share” personal information for cross-context behavioural advertising, so no “Do Not Sell or Share” link is required.
California residents may request to know, access, correct and delete their information, and not be discriminated against for it, via [email protected].
D. Israel (Protection of Privacy Law)
The Protection of Privacy Law, 5741-1981 (as amended, including Amendment 13, in force 14 August 2025) and the Data Security Regulations, 5777-2017 apply. You may review the data we hold, request correction and ask for deletion. We do not trade in personal data and do not run a direct-mail marketing database; given the small scale, database registration is not expected to be required (to be confirmed). The supervisory authority is the Privacy Protection Authority (PPA).
E. Russia (152-ФЗ)
This service is not offered to people located in the Russian Federation, and that is a settled decision rather than a stage we are passing through. The Russian-language interface exists for Russian speakers in Israel and elsewhere outside Russia.
We keep no database in Russia and are not building one, so the initial collection and storage that 242-ФЗ requires to happen there could not happen. We have not notified Roskomnadzor and are not seeking to. The face search in event galleries is refused outright to visitors in Russia, decided at our servers, whatever the organiser of an event has asked for. And we do not send messages to Russian phone numbers: invitations, reminders, thank-yous and photo-album access are refused at our servers before they reach any gateway, and a sign-in code for a photo album is refused the same way.
One exception, and it is narrow. A phone number is not an address: somebody living in Israel may simply have kept a Russian SIM. So the organiser of an event, who knows their own guests, can state for one named guest that this person is not located in the Russian Federation, and messages to that guest then go out. We record that statement with its wording, the time and who made it. It is about that one person and lifts nothing else. Separately, a message telling guests that an event has been cancelled is sent regardless, because the harm of withholding it falls on the guest.
There is a practical reason as well, and it is the one a guest would notice first: the only messaging channel this service has for a guest outside Israel is WhatsApp, which is not reliably reachable in Russia, so an invitation sent to a Russian number may never arrive. If you are located in Russia, please do not submit personal data through this site. If data about someone in Russia reaches us anyway, through the guest list of an event for instance, write to us and we will remove it.
Last updated: August 2026