1. Who's the controller
RSVPeas is the data controller for personal information processed through RSVPeas. Privacy questions go to [email protected].
RSVPeas c/o the host Update this in src/lib/legal/constants.ts2. What we collect
From hosts (signed-in users)
- Email address (required for magic-link sign-in)
- Display name and optional vanity handle
- Pods you create, with all their content (title, vibe, photos, chat messages, settings)
- If you upgrade to Premium: Stripe customer ID and subscription status (Stripe stores the card, not us)
- Session cookies and IP / user-agent attached to each session
From guests (invited)
- Name and email address (added by the host who invited you)
- Your RSVP status, plus-one count, and any answers you give to host questions
- Photos and chat messages you choose to upload
- Email delivery events from our provider (delivered, bounced, complained)
- Click events when you tap an email link (no open tracking, no pixels)
Operationally
- Server logs (request paths, status codes, error stack traces)
- Web push subscription IDs if you enable browser notifications
3. Why we collect it
- To run the service. Delivering invites, showing RSVPs, hosting chat, generating recap pages.
- To prevent abuse. Rate limiting, spam detection, suppression of bounced or complained addresses.
- To bill Premium. Stripe processes the payment; we store only the customer ID and status.
- Legal compliance. Tax records, abuse reports, lawful requests.
We don't sell personal data. We don't share it with advertisers.
4. Who we share with
We use a small set of subprocessors to run the service:
- Resend. Email delivery.
- Telnyx. SMS sign-in code delivery when you use phone verification.
- Stripe. Payment processing for Premium.
- DigitalOcean. Hosting (compute, database, object storage).
- OpenAI. AI image and text generation for the studio admin tool (admin users only, not guest-facing).
Each subprocessor only receives the data it needs to do its job. We won't add new subprocessors that handle sensitive data without updating this page.
5. How long we keep it
- Active accounts: as long as the account exists.
- Deleted accounts: we anonymize personal data within 30 days. Some records (Stripe receipts, abuse logs) may be kept longer where required by law.
- Email logs: 90 days for delivery / bounce / complaint events.
- Server logs: 30 days.
6. Your rights
You can exercise these rights from your account settings:
- Access and export. Download a JSON copy of everything we have on you.
- Deletion. Delete your account and have your data anonymized within 30 days.
- Correction. Update your name, email, or other profile info.
- Unsubscribe. Every email has a one-tap unsubscribe link. Unsubscribed addresses are suppressed system-wide.
EU/UK residents: you also have the right to lodge a complaint with your local data protection authority. California residents: the rights above cover the CCPA “right to know,” “right to delete,” and “right to opt out of sale” (we don't sell).
If you can't reach what you need from your account settings, email [email protected] and we'll respond within 30 days.
7. Cookies
We use one cookie: a session token to keep you signed in. No tracking cookies, no third-party advertising cookies. See our Cookie Policy for details.
8. Children
RSVPeas isn't directed at children under 13. If you're hosting a kids' event, you need to be the adult organizer. If we learn we've collected data from a child under 13 without parental consent, we'll delete it.
9. Security
All traffic is encrypted in transit (HTTPS). Sessions are server-side rows keyed by a hashed cookie. We don't store passwords because we don't use them. Stripe handles all card data and is PCI-DSS compliant.
10. International transfers
Our infrastructure runs in the United States. If you're in the EU or UK, your data will be transferred to the US to process. We rely on Standard Contractual Clauses where applicable.
11. Changes
When we update this policy materially, we'll email signed-in users at least 14 days before changes take effect. The “Last updated” date at the top of this page always reflects the current version.
12. Contact
Privacy questions: [email protected].