1. Who is responsible
For guest lists, invitations and admissions, the event organiser determines the purposes and means of processing: it is the controller, and InviteKey acts on its behalf as processor, under section 6 of the terms of use.
For user accounts, billing, security and this website, InviteKey is the controller. We advise guests to also read the organiser’s privacy policy.
2. Data processed and purposes
Accounts and support: name, work email address, organisation and role, authentication data and exchanges with support. They are used to provide accounts, answer requests, and administer and protect the service. Legal basis: performance of the contract, our legitimate interest in operating a secure service, or a legal obligation, as the case may be.
Events and guests: event information and images, guests’ name, email address and category, any other field entered by the organiser, status of the invitation and of its delivery, pass identifiers, and the time, checkpoint and device of admissions. This data is processed on the organiser’s instructions to create, send and check access; it is for the organiser to determine its own legal basis and explain it to its guests.
Email tracking: for each invitation email, our sending provider records its delivery and, where the guest’s mailbox allows it, its opening and clicks on its links. This information tells the organiser whether the invitation arrived and makes it possible to handle addresses in error.
Technical use: IP address, access and security logs, essential session information and, for invitation verification devices (the phones and tablets that read QR codes at the entrance to an event) and Apple Wallet passes, the device’s technical identifiers, to run and secure the application and the API. Legal basis: our legitimate interest in the security and reliability of the service.
Anti-bot check: before a sign-in, a sign-up, the acceptance of an invitation to join a team or the resending of a code, Cloudflare Turnstile checks that the request is made by a person and not by an automated program. To do so, it analyses technical information about the browser and the device, including the IP address, usually without asking anything, sometimes by asking you to tick a box. Legal basis: our legitimate interest in protecting the service and its users against abuse.
Cloudflare — Website audience measurement: on the marketing website only, pages viewed, referring site, country, device and browser type, without cookies or storage in your browser and without cross-site tracking, to understand how the website is used. The application, including on verification devices, and invitation pages are not measured. Legal basis: our legitimate interest in knowing how the website is visited.
Google Analytics: with your consent, Google Analytics measures the pages viewed and the clicks towards a paid offer or a quote, on the marketing website only. Google may set cookies and receive technical data about your visit, including your IP address and browser characteristics. This measurement does not cover the application, invitation pages, access control or payments. You can refuse or withdraw your consent at any time with “Statistics choices” in the footer. Legal basis: your consent.
Billing: orders, offers and transactions, when a paid offer is purchased, to manage the purchase and meet our accounting and tax obligations. Card payments are collected by Paypercut (section 3).
No decision producing legal effects concerning you or similarly significantly affecting you is based solely on automated processing.
3. Recipients and service providers
We do not sell personal data and do not share guest lists with advertisers or with partners unrelated to the service. Access is limited to the organiser’s authorised users, to the people who need it for the service, and to the following service providers:
Brevo sends invitation and account emails; it receives the email address and the content of the message, and measures their delivery, opening and clicks; it keeps the sending history for one month, without keeping the content of the messages. Backblaze B2 stores the event images in a private space and, for the duration of an import, the imported guest list file, which is deleted no later than three days after it is uploaded. Railway hosts the API, background processing and the database; its technical logs keep the requests received, including the device’s IP address, for thirty days. Cloudflare delivers the website and the application, measures the audience of the marketing website and checks, before a sign-in or a sign-up, that the request does not come from an automated program. Paypercut collects card payments for offers bought online; it receives the buyer’s email address, to prefill their payment page, and the card details, entered directly on that page and never sent to InviteKey. Google: when a guest chooses “Add to Google Wallet”, the information on their pass — name, event, category, QR code — is sent to Google, which processes it under its own rules. Apple: when a guest chooses “Add to Apple Wallet”, the pass is downloaded directly to their device, without InviteKey sending its content to Apple; Apple services such as iCloud may then sync it between their devices, under Apple’s rules.
For a pass added to a Wallet, see the Apple Privacy Policy or the Google Privacy Policy. They describe how those companies process data; this page remains the one describing InviteKey’s processing.
The organiser may give access to its team and to its verification devices. We may also disclose information where the law requires it or to protect rights or people’s safety, strictly as far as necessary.
4. Transfers outside the European Union
Our data is hosted in the European Union. However, some service providers, or their infrastructure, may process data outside the European Economic Area. Such transfers are then covered by a recognised mechanism, such as an adequacy decision or the European Commission’s standard contractual clauses. Contact us to find out the safeguards that apply to your data. Apple and Google may also process Wallet data under their own rules.
5. Retention periods
The retention period of an event’s data depends on the chosen offer; it is shown in the service and runs from the day the event starts, which cannot be pushed back beyond the period covered by the offer. When it ends, access ends and the data is deleted from our active systems by our automated deletion process. As long as no invitation has been sent for an event, its data is kept until the offer used expires — with the free offer, twelve months after the event was created — and then deleted in the same way. Limited copies may remain temporarily after the period ends: at most four weeks in the database backups, thirty days in our hosting provider’s technical logs and one month in our email provider’s sending history. If a backup is restored, this data remains inaccessible and is deleted again. We do not promise the instant deletion of every copy when the period ends.
Three kinds of copies are outside our control and may remain after access ends.
Exports downloaded by the organiser are kept under its sole responsibility; it is up to the organiser to delete them.
The guest list kept offline on verification devices (names, categories and, if the organiser enables it, email addresses) is erased from the device when it is logged out or, failing that, as soon as the application is reopened on it after its access has ended. A device that is never reopened keeps it until its browser data is cleared: the organiser should therefore log out its devices at the end of the event.
Passes saved in the Wallet app of a guest remain on their device: the guest can delete them at any time, and Apple and Google decide on their own retention of Wallet data. When the event’s data is deleted, InviteKey replaces the pass with a version that no longer contains the guest’s name or QR code; a device left switched off or offline for more than 30 days may keep the previous version.
Account and support data is kept as long as the account exists and requests require it, then for a limited period where security, a dispute or a legal obligation requires it. Billing data is kept for the applicable accounting and tax periods. You can ask us for the period that applies to a specific piece of data.
The security and audit log is kept for one year, and for at least six months after the deletion of the data of the event it relates to; records of sendings, payments and decisions on offers are kept for five years.
6. Your rights
Depending on your situation and the processing concerned, you can request access to your data, its rectification, its erasure, the restriction of its processing or its portability, object to the processing, and withdraw your consent where it is the legal basis. These rights may be limited by law. Write to support@invitekey.app; we may need to verify your identity before acting.
If you are a guest at an event, the organiser is in principle the first point of contact for any request about your invitation or your attendance. You can also write to us: we will forward or handle the request as appropriate. You may lodge a complaint with the French data protection authority (Commission nationale de l’informatique et des libertés, CNIL), www.cnil.fr, or with the data protection authority of your country.
7. Security and storage on your device
We apply access controls and other technical and organisational measures designed to protect data. No online service can guarantee absolute security. Report any suspected abuse to support@invitekey.app.
The website stores your language, your light or dark theme preference and your statistics choice in your browser. The application stores there your language, your theme, the sign-in method you chose, the banners you dismissed and, for twenty-four hours, the purchase to resume after you sign in; during a sign-in or a sign-up, the tab also keeps the request in progress — the address entered and its reference —, which is erased when the tab is closed. It uses an essential session cookie to keep users signed in and secure access, and verification devices keep the event data needed for offline verification. The interface fonts and images are served by InviteKey itself; only Cloudflare’s anti-bot check, on the sign-in and sign-up pages — including the one for joining a team —, and Google Analytics, on the marketing website and with your consent, load a third-party script.
8. Changes and questions
We may change this policy as the service or the regulations evolve. The current version and its date appear at the top of this page. For any question or request: support@invitekey.app.
The controller is Adrian Tanasescu EI, sole proprietor registered in France (SIREN 529 157 810), 9 rue des Grisemottes, 69220 Belleville-en-Beaujolais, France, who publishes InviteKey.