Happy2date
Privacy Policy
Last updated: [DATE]
This Privacy Policy explains how [LEGAL COMPANY NAME] (“DateInvite”, “we”, “us” or “our”) collects, uses, stores and protects personal information when you access or use the DateInvite website and services.
The data controller responsible for your personal information is:
- Legal entity: [LEGAL COMPANY NAME]
- Registered address: [REGISTERED ADDRESS]
- Registration number: [COMPANY REGISTRATION NUMBER]
- Email: [PRIVACY EMAIL]
1. About DateInvite
DateInvite allows users to create and share private digital invitations. A creator can add names, a date, time, location, map link and a personal message. The recipient can open the private invitation link and respond with Yes or No, together with an optional short message.
2. Personal information we collect
2.1 Account information
When you create or access an account, we may process:
- Your email address
- Email verification and one-time sign-in code information
- The date your account was created
- Your latest sign-in date
- Your account role and status
We use passwordless authentication. Sign-in codes are generated for a limited period and are stored in hashed form.
2.2 Invitation information
When you create an invitation, we may process:
- Your name or the name you choose to display
- The recipient’s name
- The proposed date and time
- The location
- An optional Google Maps or location link
- The invitation message
- The selected invitation language and theme
- The selected behaviour of the No button
Please do not include sensitive personal information, financial information, passwords, identification numbers, health information or other confidential information in an invitation.
2.3 Recipient responses
When a recipient responds to an invitation, we may process:
- The Yes or No response
- An optional short message
- The response date and time
- Limited device and browser information used for security
- A cryptographic hash derived from the IP address, where enabled
A recipient does not need to create a DateInvite account in order to respond to an invitation.
2.4 Technical and security information
We may automatically collect limited technical information, including:
- Browser type and operating system
- Approximate request time
- Security and authentication logs
- Pages requested and application errors
- Cookie and consent preferences
2.5 Analytics information
If you consent to analytics cookies, we may use Google Analytics or similar technologies to understand how visitors use the website. Analytics may include information such as pages viewed, session duration, device category, approximate geographical region and referral source.
Analytics technologies will not be activated before the required consent has been obtained, where applicable.
2.6 Payment information
DateInvite is currently offered free of charge. If paid plans are introduced, payments may be processed by an external payment provider such as Stripe. We would not normally receive or store your complete card details. The payment provider would process those details according to its own privacy policy.
2.7 Affiliate information
DateInvite may display optional offers from partners, such as cinema tickets, restaurants, activities, travel or gifts. If you click an affiliate link, we may record:
- The partner selected
- The placement of the offer
- The click date and time
- A unique referral reference
The partner may use its own cookies or tracking technologies after you leave DateInvite. Its own privacy policy will apply.
3. How we use personal information
We process personal information to:
- Create and manage user accounts
- Send secure one-time sign-in codes
- Create, display and manage invitations
- Record and display invitation responses
- Notify creators when an invitation has been answered
- Generate calendar files and map links
- Prevent abuse, fraud and unauthorised access
- Maintain technical logs and troubleshoot errors
- Respond to support, privacy or legal requests
- Measure website usage where valid consent has been provided
- Display and measure affiliate offers where applicable
- Comply with legal obligations
4. Legal bases for processing
Depending on the context and applicable law, we rely on one or more of the following legal bases:
- Performance of a contract: to provide your account, create invitations and deliver the services you request.
- Legitimate interests: to secure the platform, prevent misuse, improve essential functionality and maintain necessary technical records.
- Consent: for optional analytics, advertising or other non-essential cookies and communications, where required.
- Legal obligation: where processing is necessary to comply with applicable legislation, accounting requirements or lawful requests.
5. Information about invitation recipients
The creator is responsible for ensuring that they have a legitimate and appropriate reason to enter another person’s name and send them an invitation.
Creators must not use DateInvite to harass, threaten, deceive, impersonate or repeatedly contact another person against their wishes.
Private invitation pages are intended to be accessible only through their unique link. They are marked as not intended for search engine indexing and are excluded from the public sitemap. However, anyone who receives or obtains the link may be able to open it.
Creators should therefore avoid including highly sensitive, confidential or embarrassing information.
6. Who receives personal information
We may disclose limited information to service providers that help us operate DateInvite, including:
- Website hosting and infrastructure providers
- Email delivery and SMTP providers
- Security, backup and monitoring providers
- Analytics providers, where consent has been provided
- Payment processors, if paid services are introduced
- Affiliate or commercial partners when you choose to visit their offers
- Professional advisers such as accountants, lawyers or auditors
- Public authorities where disclosure is legally required
We do not sell personal information to advertisers.
7. International transfers
Some service providers may process information outside your country or outside the European Economic Area.
Where required, we will use appropriate safeguards, such as an adequacy decision, Standard Contractual Clauses or another legally recognised transfer mechanism.
8. Data retention
We retain personal information only for as long as reasonably necessary for the purposes described in this policy.
Our intended retention periods are:
- One-time sign-in codes: expired and used codes may be removed within [NUMBER] days.
- Active invitations: until deleted, disabled or expired by the creator or according to the invitation expiry setting.
- Deleted invitations: removed or anonymised within [NUMBER] days, subject to backups and legal requirements.
- Account information: while the account remains active and for up to [NUMBER] months after deletion, where necessary.
- Security and audit logs: generally for up to [NUMBER] months.
- Payment and accounting records: for the period required by applicable law.
Backup copies may remain for a limited additional period before being securely overwritten.
9. Security
We use reasonable technical and organisational measures designed to protect personal information, including:
- HTTPS encryption
- Hashed one-time sign-in codes
- Secure and HttpOnly session cookies
- Session inactivity timeouts
- Random private invitation tokens
- Protection against cross-site request forgery
- Prepared database queries
- Role-based administration access
- Access and security logging
No online service can guarantee absolute security. You are responsible for keeping private invitation links and access to your email account secure.
10. Your data protection rights
Depending on where you live, you may have the right to:
- Request access to your personal information
- Request correction of inaccurate information
- Request deletion of your information
- Request restriction of processing
- Object to certain processing based on legitimate interests
- Receive certain information in a portable format
- Withdraw consent at any time
- Complain to a competent data protection authority
Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
To exercise your rights, contact us at [PRIVACY EMAIL]. We may need to verify your identity before completing a request.
11. Children
DateInvite is not intended for children under the age of 18. We do not knowingly allow children under 18 to create accounts or use the service.
If you believe that a child has provided personal information, contact us at [PRIVACY EMAIL].
12. Third-party links
Invitations may contain Google Maps links or other links entered by users. DateInvite may also display optional partner links.
We are not responsible for the privacy practices, availability or content of external websites. Review the privacy policies of those services before providing information to them.
13. Changes to this Privacy Policy
We may update this Privacy Policy when the service, legal requirements or our providers change.
The current version and its effective date will always be displayed on this page. Where changes are significant, we may also provide an additional notice.
14. Contact
For privacy questions or requests, contact:
- Email: [PRIVACY EMAIL]
- Legal entity: [LEGAL COMPANY NAME]
- Address: [REGISTERED ADDRESS]
