1. Overview
Invitee.live ("Invitee", "we", "us", or "our") is a SaaS product operated from Portugal. Invitee helps professionals create appointment invite pages, share details and files, collect form submissions, exchange comments, send transactional emails, and monitor basic engagement such as invite opened and last seen.
When a professional creates an account and decides what information to collect from clients, that professional is generally responsible for the client data they place into Invitee. In that context, Invitee acts as a service provider or processor to deliver the platform. Clients with questions about the content of an invite should also contact the professional who sent it.
2. What Data We Collect
We collect different categories of data depending on how Invitee is used.
- Account data, such as name, email address, and authentication-related identifiers.
- Billing and subscription data, such as plan, status, invoices, and limited payment-related information handled through Stripe.
- Client data entered by professionals, such as client names, contact details, appointment details, instructions, FAQs, files, and related notes.
- Form submissions and comments, including intake answers, attachments, and messages submitted by clients through invite pages.
- Usage and analytics data, such as IP address, browser and device information, timestamps, page activity, invite opened events, and last seen signals.
- Support and communication data if you contact us directly.
3. How We Use Data
We use personal data to operate and improve Invitee.
- To create and manage accounts and authenticate users.
- To host invite pages, files, comments, and form submissions.
- To send transactional emails such as invites, updates, and reminders.
- To process subscriptions, billing, and payment records.
- To monitor performance, prevent abuse, troubleshoot issues, and keep the service secure.
- To understand product usage and improve Invitee over time.
- To comply with legal obligations and handle legitimate business records.
4. GDPR Bases for Processing
Where GDPR applies, we generally rely on one or more of the following legal bases:
- Performance of a contract, when we provide the service you signed up for.
- Legitimate interests, such as keeping Invitee secure, preventing misuse, and improving the product.
- Legal obligations, such as accounting, tax, or compliance requirements.
- Consent, where consent is required for a specific activity.
5. Third-Party Processors
We use third-party providers to run the service. These providers process data on our behalf or in connection with the services they supply to us.
- Clerk for authentication and account management.
- Stripe for subscription billing and payments.
- Supabase for database hosting and file storage.
- Resend for transactional email delivery.
- PostHog for product analytics.
We may also share data where necessary with professional advisers, law enforcement, regulators, or in connection with a business transfer, but only where there is a lawful reason to do so.
6. International Transfers
Some of our service providers may process personal data outside the European Economic Area or the country where you are located. When that happens, we use appropriate safeguards as required by applicable law, such as contractual protections or other valid transfer mechanisms.
7. Data Retention
We keep personal data for as long as needed to provide the service, maintain records, resolve disputes, protect the platform, and comply with legal obligations.
- Account and subscription data is usually kept while the account is active and for a reasonable period afterwards.
- Invite content, files, and form submissions are kept until deleted by the professional, removed through account closure, or no longer needed for the service.
- Backups and logs may remain for a limited period after deletion before being overwritten or removed.
8. Your GDPR Rights
If you are in the EU, EEA, or UK, or where similar laws apply, you may have rights including:
- The right to access your personal data.
- The right to correct inaccurate or incomplete data.
- The right to request deletion of your data.
- The right to restrict or object to certain processing.
- The right to data portability where applicable.
- The right to withdraw consent where processing is based on consent.
- The right to lodge a complaint with a supervisory authority, including Portugal's CNPD where relevant.
To exercise your rights, email contact@invitee.live. We may need to verify your identity before acting on a request.
9. Security
We use reasonable technical and organizational measures to protect personal data. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will publish the updated version here and revise the "Last updated" date. Continued use of Invitee after changes take effect means the updated policy applies.
11. Contact
If you have questions about this Privacy Policy or your personal data, contact contact@invitee.live.