Skip to content
← Back to Graevents

Privacy Policy

Effective September 14, 2026 · Last updated September 15, 2026

1. Overview

This Privacy Policy explains how Graevents collects, uses, and protects information when you use our digital invitation platform during our Philippines beta. It covers both your information as an account holder, and information collected from your guests when they RSVP or check in to your event.

2. Information we collect

When you create a Graevents account and use the platform, we collect:

  • Account information: your name, email address, and password (stored securely, never in plain text).
  • Event details you enter: event title, date, venue, and other invitation content.
  • Content you upload: photos and other media used to personalize your invitation.
  • Payment-related information when you purchase a package or plan. See “Third-party service providers” below for how it's currently handled.
  • Basic usage information (such as device and browser information) to keep the service secure and working correctly.

3. Information about your guests

When your guests open your published invitation, RSVP, or check in via QR code, we collect the information they submit (such as name, RSVP status, number of guests, and check-in time) and make it available to you, the event host. As the host, you control this information and are responsible for using it appropriately and in line with applicable law.

Separately, the RSVP form includes an optional, unchecked-by-default checkbox asking whether a guest would like to receive occasional marketing email directly from Graevents (not from you, the host). We only ever email a guest for marketing if they explicitly checked that box. Providing an email address to RSVP never subscribes anyone on its own. Every marketing email includes an unsubscribe link that permanently removes that address from future sends.

4. How we use information

We use the information above to:

  • Provide, operate, and maintain the Graevents platform.
  • Render and host your published invitations for your guests.
  • Process payments for packages and subscription plans.
  • Communicate with you about your account, purchases, and important service updates.
  • With a guest's explicit opt-in at RSVP, send that guest occasional marketing email about Graevents: see “Information about your guests” above.
  • Keep the platform secure and prevent abuse.

5. Third-party service providers

We rely on trusted third-party providers to operate Graevents, including:

  • Supabase, for account authentication and database/file storage.
  • During this beta, payments are made manually (bank transfer, GCash, and similar methods) and proof of payment you upload is reviewed by our team. We do not currently route payments through an automated payment gateway. This may change as the product evolves.
  • An email delivery provider, to send account and event-related notifications, and (only to guests who opted in) occasional marketing email.

These providers only receive the information necessary to perform their function and are bound by their own privacy and security obligations.

6. Data retention

After your event date passes, your published invitation moves through a few automatic stages. Once a post-event access period has elapsed, the invitation is marked expired: the public link is disabled and editing is locked. Once a further invitation expiration period elapses, the event is archived. These windows are configurable and may differ by organization or event; the current defaults are shown in your account settings.

Archiving disables public access and editing, but does not delete your data: your invitation content and guest RSVP/check-in data remain stored in our systems. Account and event data is otherwise retained for as long as your account remains active. You can request an export or closure and eventual deletion of your organization's data at any time from Settings → Privacy & Data. See "Your rights and choices" below. Records we're required to retain by law, such as billing records, are kept regardless.

7. Cookies and similar technologies

We use a small number of first-party cookies and browser storage entries to keep the platform working. We do not use third-party advertising or analytics trackers, and we do not sell or share this information for advertising purposes. Specifically:

  • Authentication cookies (set by Supabase, our authentication provider) keep you signed in between visits. Strictly necessary — without them, you'd have to log in again on every page.
  • Referral attribution cookie (gv_ref) — set only if you arrive via a referral link, so we can credit the right referrer if you later sign up or make a purchase. Expires after 30 days and is never set otherwise.
  • Promotional banner dismissal — browser session storage, not a cookie. Remembers that you closed a promotional banner for the rest of that browser session only.
  • Theme preference (light/dark) — browser local storage, not a cookie. If you're signed in, this preference is also saved to your account so it follows you across devices.

Because these are limited to keeping the platform functional (or, for the referral cookie, to a program you or someone else opted into by following a referral link), we don't currently show a separate cookie-consent banner. You're still in control: your browser's settings let you block, delete, or be notified about cookies and clear local/session storage at any time. Doing so may sign you out, reset your theme preference, or clear a pending referral attribution.

8. Your rights and choices

You can update your account information at any time from your account settings. From Settings → Privacy & Data, an organization owner can request an export of the organization's data, or request closure of the organization, which submits a request to close and eventually delete its data (except records we're required to retain by law, such as billing records). These requests are handled manually by our support team, who will follow up by email. Guests wishing to have their RSVP information removed should contact the event host directly, as hosts control the guest data collected through their own events. A guest who opted in to marketing email can unsubscribe at any time using the link in any marketing email they've received. This permanently removes their address from future sends and does not require contacting the host.

9. Children's privacy

Graevents is not directed at children, and we do not knowingly collect personal information from children.

10. Security

We use industry-standard safeguards, including encrypted storage and access controls, to protect the information you and your guests share with us. No method of storage or transmission is completely secure, but we work to protect your information appropriately.

11. Changes to this policy

We may update this Privacy Policy from time to time. We'll update the "Last updated" date above when we do, and material changes will be communicated to active account holders.

12. Contact us

Questions about this Privacy Policy? Reach us using the contact details at the bottom of this page.

Questions about this document? Email us at support@graevents.com.