Who we are
Invite In is an app and website for sending event invitations and checking guests in at the door. It is made and run by De Bruine Solutions, a sole proprietorship (eenmanszaak) in Amsterdam, the Netherlands, registered with the Dutch Chamber of Commerce (KvK) under number 97437921, VAT number NL005270681B48. In this policy, "we" and "us" mean De Bruine Solutions.
For questions about your data, email info@debruinesolutions.com.
Who is responsible for which data
Invite In has two kinds of users.
- Organizers have an account in the app. They create events, add guests and send invites. Co-hosts and door helpers are organizers who joined someone else's event through a team link.
- Guests do not need an account or the app. They get a personal invite from an organizer and open it in a web browser.
We are the controller for the personal data in Invite In, including the guest details that organizers enter: we decide what Invite In stores, how it uses the data and how long it keeps it.
The organizer decides whom to invite and which details to add. A private person inviting friends and family to a private event does that as a household activity, to which the GDPR does not apply. An organizer who is not acting privately, such as a business or an association, is responsible together with us for adding guests and inviting them. In that case we provide this information to guests, answer requests to exercise privacy rights and keep the data secure, and the organizer makes sure it may contact the people it adds. Guests can contact either of us.
What we keep about organizers
- Email address, when you sign in with an email link, or the address Apple or Google gives us when you use their sign-in. If you hide your email with Apple, we only get the address Apple creates for you.
- Name, if you enter one or Apple passes it to us when you first sign in. It is optional.
- Sign-in identifiers from Apple or Google, if you use their sign-in.
- Settings: your language and whether you want notifications for replies and arrivals.
- Sign-in links: when you ask for one, we store your email address, a hash of the link's code, the language and when the link expires. The code itself is only in the email.
- Sessions: one access token per phone you are signed in on, labelled with the type of phone (iPhone or Android), and when it was last used.
- Push tokens: the notification token of each phone that allows notifications, and whether it is iOS or Android.
- Purchases: whether you have Pro and until when, and for each event you unlocked, the store's transaction ID and product. We never receive card or bank details.
- Your events: title, date, time and time zone, venue name and address, description, language, cover photo, your own invite design if you upload one, and the event's settings.
- Your guest book: everyone you added as a guest or walk-in, with the name, email address, phone number and tags you entered, so you can invite them again.
- Door activity: every scan and check-in at your events, which team member did it, and walk-ins added at the door.
What we keep about guests
Guest details come from the organizer who invited you, except what you send us yourself. Every invite page and every email we send to guests links to this policy.
What the organizer enters
- Your name. If the organizer gives each person in a party their own QR code, each person's name.
- Your email address and phone number, if the organizer adds them. Both are optional. The organizer can pick you from their phone's contacts; the app then fills in the name, one email address and one phone number of the contact they picked, and nothing is saved until they confirm.
- Tags the organizer gives you, such as "family", and the size of your party.
- A personal message to you, if the event uses them.
- Whether your invite is a link with a reply form or an image to show at the door.
When an organizer adds a guest in the app, the guest's name, email address, phone number and tags are also saved in that organizer's guest book, so they can invite the same person to a later event.
What is recorded when the invite is used
- A personal invite link with a random code. Your QR code contains this link.
- Each email we send you about the event (the invite, a reminder the day before, a change, a cancellation, or a place opening up from the waitlist): the type, the address it went to and when.
- Whether that email was delivered or bounced, and the bounce reason, as reported by our email provider.
- The first and last time your invite page was opened.
- That the organizer shared your invite themselves, for example on WhatsApp, if they mark it as sent.
- Your reply (going, maybe or can't), how many of you are coming, when you replied, whether the organizer set the reply for you, and whether you are on the waitlist.
- If the organizer asks: your answers to their questions and the names of the people coming with you. Only the organizer and their co-hosts see them. Answer only what you are comfortable sharing; questions are optional unless the organizer marked one as required.
- When you were checked in, for how many people, and the name of the team member who scanned you.
What you send us yourself
- Your reply on the invite page.
- A report about an invite, with the reason you pick and any details you write.
Walk-ins
If you arrive without an invite and the organizer adds you at the door, we store your name, the number of people with you, and a phone number or email address if the organizer enters one. Organizers can require one of the two for walk-ins. Walk-ins are also saved in the organizer's guest book.
Why we use it, and on what basis
- Running organizer accounts, events and purchases
- To provide the service an organizer signed up for. Basis: performance of a contract (Article 6(1)(b) GDPR).
- Sending invites, reminders, changes and cancellations to guests
- So the organizer's invitation reaches the guest and the guest hears when the event changes. Basis: the legitimate interests of the organizer and of us in delivering the invitation (Article 6(1)(f) GDPR). Guests are not party to a contract with us, so this is not based on a contract.
- Replies, waitlist and check-in at the door
- So the organizer knows who is coming and only invited guests get in. Basis: legitimate interests (Article 6(1)(f) GDPR).
- The guest book
- So an organizer can invite the same people again without typing their details twice. Basis: legitimate interests (Article 6(1)(f) GDPR).
- Delivery and bounce status of emails, and invite page opens
- So the organizer can see whether an invite arrived and follow up with guests who did not get it. Basis: legitimate interests (Article 6(1)(f) GDPR).
- Push notifications to organizers
- To tell organizers about replies and arrivals, only on phones where they allowed notifications. Basis: performance of a contract (Article 6(1)(b) GDPR).
- Reports and take-downs
- To act on spam, abuse, impersonation and illegal content. Basis: our legal obligations as a hosting service under the Digital Services Act (Article 6(1)(c) GDPR) and our legitimate interest in keeping the service safe (Article 6(1)(f) GDPR).
- Security and error logs
- To keep the service running and find faults. Basis: legitimate interests (Article 6(1)(f) GDPR).
Where we rely on legitimate interests, you can object at any time (see Your rights). We do not make automated decisions about people, and we do not build profiles for advertising.
Invite page visits
Emails we send to guests contain no tracking images, so we do not know whether you opened one. When your invite page is opened, we record the first and the most recent time. Apps that fetch a page to show a link preview, such as WhatsApp, iMessage, Slack and Telegram, are not counted. Here too we store only the times.
The organizer and their co-hosts see these times in your timeline, together with whether your email was delivered, your reply and your check-in.
Cookies
The website sets two cookies, both needed for it to work:
- invite-in-session keeps your visit together between pages, for example to show a confirmation after you reply. It expires after two hours.
- XSRF-TOKEN protects the reply, report and remove forms against forged requests. It expires after two hours.
For each visit, the server keeps a session record with your IP address and browser type until the session expires. There are no analytics, advertising or third-party cookies, and the pages load no scripts from other websites. The app contains no analytics or advertising software. The app and our server do send reports of crashes and errors to Sentry, described below.
Who can see your data
Within Invite In
- The organizer and co-hosts see the guest list, each guest's details and timeline, and the door activity.
- Door helpers see guests' names and whether they are checked in when they scan or search at the door. Their phone keeps the names, seats and replies of the event's guests so the door works without internet, but they do not see the guest list.
- Guests see the event details and the organizer's name. Emails to guests come from the organizer's name "via Invite In", and replies to those emails go to the organizer's email address, so a guest who replies sees it.
- The organizer and co-hosts also see the names and email addresses of everyone on the event's team. Someone opening a team link sees the name of the person who invited them.
- We handle reports. Our moderation screen shows events with their organizer's email address and the reports sent about them.
Service providers that process data for us
Each of these works under a data processing agreement with us and may only use the data to provide its service.
- Hetzner Online GmbH, Germany
- Hosts our server and database in Falkenstein, Germany. All data on this page is stored there, including uploaded photos.
- Amazon Web Services (Amazon SES and Amazon S3), Frankfurt, Germany
- Sends our emails: sign-in links and guest emails. It receives the recipient's address and the content of the email, and tells us whether it was delivered or bounced. It also stores our nightly backups, encrypted with a password only we hold.
- Google (Firebase Cloud Messaging)
- Delivers push notifications to organizers' phones, through Apple's notification service on iPhones. It receives the phone's push token and the notification text, which contains the event title and a guest's name, for example "Noor is going".
- RevenueCat
- Keeps track of purchases of Pro and event unlocks from the App Store and Google Play. It receives your Invite In account number and your purchase history from the store. We do not send it your name or email address.
- Sentry (Functional Software, Inc.)
- Receives reports when the app crashes or the app or server runs into an error, so we can fix it. A report contains what went wrong and where in our code, the app version, the type of phone and its system version, and the address of the page or request that failed. We do not send it names, email addresses or your account, and Sentry is set not to store IP addresses.
Cloudflare provides the domain name service for invitein.app. Your visits do not pass through Cloudflare, and it receives no personal data from us.
Apple and Google
When you buy Pro or an event unlock, Apple (through the App Store) or Google (through Google Play) sells it to you and handles the payment, under their own terms and privacy policies. The same applies when you sign in with Apple or Google. For that data they are responsible themselves.
We do not sell personal data and do not use it for advertising.
Outside the European Economic Area
Our server and email sending are in Germany. Some providers are based in the United States, so data they receive can be processed there:
- Google LLC and Amazon Web Services are certified under the EU-US Data Privacy Framework, which the European Commission has found to give adequate protection. So is Sentry (Functional Software, Inc.), which stores error reports in the United States.
- Transfers to RevenueCat are covered by the European Commission's standard contractual clauses in its data processing agreement.
- Apple handles App Store purchases in the EU through Apple Distribution International in Ireland, and is responsible for its own transfers.
How long we keep data
- Events are deleted 6 months after they end, with their guests, timelines, replies, door activity, photos and reports. An event without an end time counts as ended 12 hours after it starts. Before that, the organizer can delete a guest or the whole event at any time.
- Guest books are kept until the organizer deletes an entry or the account.
- Reports are kept until the event they are about is deleted.
- Sign-in links stop working after 15 minutes or once used, and are deleted within a day after that.
- Push tokens are removed when you sign out of the app, when Google reports that the token no longer works, or when you delete your account.
- Door copies: so the door keeps working without internet, a phone in door mode keeps a temporary copy of the event's guest names, seats, replies and check-ins, with a one-way code (a hash) of each invite's QR code instead of the code itself. It never holds email addresses or phone numbers. The copy is deleted when door mode is closed after the event and when you sign out. Scans made without internet stay on the phone until they are sent.
- Website sessions expire after two hours and are then cleared from the server.
- Logs: our web server keeps no log of visits. Error logs, which can contain the IP address of a request that failed, are kept for 14 days. Error reports at Sentry are deleted after at most 90 days.
- Backups: every night we make an encrypted backup of the database and uploaded images. Each backup is kept for 14 days and then deleted, so data you delete is gone from the backups within 14 days as well. A backup is only used to restore the service after a fault.
Removing your details as a guest
At the bottom of your invite page, "Remove my details" removes from your invite:
- your email address and phone number, also from the record of every email we sent you and from your timeline,
- the personal message to you,
- the times your invite page was opened,
- your answers to the organizer's questions and the names of the people coming with you.
It also removes your email address and phone number from the organizer's guest book entry for this invite. Your name, your reply and the fact that emails were sent stay, so the invite still works at the door. Without an email address you get no more emails from Invite In about this event.
It does not touch other events where the same organizer added you separately. To have your details removed there too, or to have your invite deleted completely, email us at info@debruinesolutions.com or ask the organizer.
Deleting an organizer account
You can delete your account in the app under Account, Delete account. This deletes your account, your events with their guests, timelines, replies and door activity, the cover photos and designs uploaded for them, your guest book, your team links and memberships, and your push tokens and sessions. Guests' invite links stop working.
Without the app, you can ask us to delete your account by emailing info@debruinesolutions.com from the address on your account. We delete it within one month.
Deleting your account does not cancel a Pro subscription. Cancel it in the App Store or Google Play.
Your rights
You can ask us for access to your data, to correct it, to delete it, to restrict its use, or to receive it in a common file format, and you can object to its use based on legitimate interests. Email info@debruinesolutions.com. We answer within one month; if a request is complex we can extend that by two months, and we tell you so within the first month. We may ask you to confirm that the data is yours.
Organizers can see, change and delete their own events, guests and guest book in the app. Guests can also ask the organizer who invited them, since the organizer can change or delete their details directly.
You also have the right to complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, or the authority in the EU country where you live.
Children
You must be 16 or older to create an organizer account. Invite In does not ask guests for their age. An organizer who invites children is responsible for being allowed to add their details, for example as their parent or with their parent's agreement.
Security
- All traffic to invitein.app is encrypted with HTTPS.
- Each invite link contains a random 24-character code.
- Sign-in links work once, expire after 15 minutes, and are stored only as a hash.
- Signing out of the app ends the session on that phone.
- Only accounts we mark as administrators can open the moderation screen.
Changes to this policy
When we change this policy, we change the date at the top of this page. Before a significant change takes effect, such as a new purpose, a new kind of recipient or a new transfer outside the European Economic Area, we email organizers at least 30 days in advance.
Contact
De Bruine Solutions
Hoptille 301
1102 PE Amsterdam
the Netherlands
+31 6 2480 0527
info@debruinesolutions.com