Invitica
Privacy Notice
In effect since 14 August 2026
Version 1.1
This notice explains what personal information Invitica handles, why, who else touches it, how long it is kept, and what you can ask us to do about it. It covers creator accounts, invitations, guests, replies, our AI assistant, and our public site.
It describes what the product actually does today. Where a safeguard is not built yet, this notice says so rather than promising it.
1. Who is responsible for your information
Invitica is operated by Theo Cedric Chan, an individual based in the Philippines, who is the personal information controller for the information described in section 2 as Invitica's own.
Accountable person for privacy: Theo Cedric Chan. Address: Tuyan, Naga City, Cebu, Philippines. Email for any privacy question, request, or complaint: [email protected].
2. When Invitica decides, and when you do
Invitica is the personal information controller for your creator account, for authentication and session security, for abuse prevention and rate limiting, for account emails, and for the aggregate view counts described below. We decide what is collected for those purposes and why.
For the guest information you enter — names, party groupings, personalized links, replies — you are the personal information controller and Invitica is your personal information processor. You choose whom to invite and what to record about them. We store, process, and deliver that information on your instructions, under section 7 of the Terms of Service.
This matters for a guest who wants to ask a question. We will answer, and we will also tell the creator, because for most guest information the creator is the person who decides.
3. What information Invitica handles
Creator account information: your name, email address, authentication identifiers, email-confirmation and password-recovery state, your Google account identifier and profile name if you sign in with Google, your workspace, your display preferences, and the record of which document versions you accepted and when.
Invitation information: event titles, host names, dates, schedules, messages, venue names and map coordinates, attire guidance, participant and entourage names, gift or registry details, photographs, and the template and design choices used to render the invitation.
Guest information: recipient or household names, the members of each party, the status of each personalized link, the delivery state you recorded yourself, and each reply — attending or not, party count, an optional short message, and the history of revisions to that reply.
Assistant conversations: the messages you send to Invi, its answers, and — when you use it to organize a guest list — the names in the list you pasted. These are saved to your account so you can return to a conversation, and you can delete them.
Service information: publication versions and job state, media file metadata, daily aggregate view counts per invitation, request-budget and abuse-prevention state, single-use account-deletion tokens stored as a hash, and operational logs.
Invitica's own view counting stores no viewer identifier of any kind — no IP address, user agent, referrer, account, raw URL, personalized token, or unique-person identifier. It counts opens per invitation per day and nothing else. The providers listed in section 8 still process ordinary request data under their own systems.
4. Where the information comes from
Most of it comes from you. Some comes from guests who reply. Some comes from Google, if you choose to sign in that way. The rest is generated by the systems that run the service.
A creator may enter another person's name or photograph before that person has any contact with Invitica. That is normal for an invitation, and it is why section 7 of the Terms asks you to confirm you have a basis for it. If you are named in someone's invitation and want to know what is held about you, write to us and we will help.
5. Why the information is used, and on what basis
Philippine data-protection law requires a lawful basis for each purpose. Accepting the Terms of Service is not treated as blanket consent to everything below.
| What we do | Whose information | Lawful basis |
|---|---|---|
| Create and run your creator account, confirm your email, and let you recover your password | Creator | Necessary to perform our contract with you |
| Store, validate, preview, publish, and deliver your invitation | Creator, and people named in the invitation | Our contract with you; for people you name, your own lawful basis as the controller of that content |
| Hold guest parties and personalized links, and receive replies | Guests | Processed on your instructions, on your lawful basis as controller |
| Answer your requests to Invi and save your conversations | Creator, and any names you type or paste | Our contract with you for a feature you chose to use |
| Send account emails, including the account-deletion link | Creator | Necessary to perform our contract with you |
| Record which document versions you accepted, and when | Creator | Our legal obligation to show a lawful basis, and our legitimate interest in accountability |
| Show creators how many times an invitation was opened each day | Nobody — the count identifies no person | Our legitimate interest in a useful product |
| Protect accounts, links, and public endpoints from abuse | Creators, guests, visitors | Our legitimate interest in a secure service |
| Respond to a lawful request from an authority | Anyone concerned | Our legal obligation |
6. What Invitica does not do
Invitica does not sell personal information, does not show advertising, and has no advertising partners.
It runs no product analytics, no session replay, and no guest-level open, read, or click tracking. It does not tell a creator whether a particular guest opened their invitation, because it does not know.
It does not use your content, your guests' information, or your conversations with Invi to train any AI model.
If any of this changes, it will be a new version of this notice with a clear explanation, not a quiet edit.
7. Google sign-in
Google sign-in is optional and runs through Supabase Auth. Invitica asks Google only for the basic identity needed to sign you in: your Google account identifier, your email address, and your profile name where available.
Invitica does not request or receive your Google Drive files, Gmail, Calendar, contacts, or advertising data, and uses Google user data only to authenticate your account and identify it afterwards. If you would rather not involve Google, use email and password instead.
8. Invi and our AI provider
Invi is available only inside a signed-in creator account and never on a published invitation. When you send it a message, the message is sent to Anthropic, our AI provider, along with Invitica's own help material and — depending on what you asked — the invitation you have selected or the guest list you pasted.
Invitica's account with Anthropic is a paid one with model training on our data switched off. Anthropic processes the request to produce an answer and does not use it to train models.
Invi proposes and never writes. Nothing it produces changes your invitation, your guest list, or a published page until you apply it yourself.
Your conversations, including any guest names in them, are saved in Invitica's database so you can return to them. They are visible only to you, you can delete them, and they are removed with your account. They are never linked to your published invitation or shown to any guest.
Invitica logs that an assistant request happened, which kind it was, and whether it succeeded. It does not log your message or the answer.
9. Providers and processing outside the Philippines
Invitica is run by one person on managed services. These providers process personal information on our behalf:
| Provider | What it does for Invitica | Where it processes |
|---|---|---|
| Supabase | Authentication and the main database, including accounts, invitations, guests, replies, and assistant conversations | Singapore |
| Cloudflare | Stores published invitation files and media in private storage, and serves published invitations to guests | Global edge network, outside the Philippines |
| Vercel | Hosts the creator application and the public site | Singapore |
| Trigger.dev | Runs the background jobs that publish an invitation | Outside the Philippines |
| MapTiler | Supplies map tiles, loaded only when someone opens a map | Outside the Philippines |
| Optional sign-in only | United States and elsewhere | |
| Anthropic | Produces the AI assistant's answers | United States |
| Resend | Sends Invitica's account emails, including confirmation, password recovery, and the account-deletion link | Asia Pacific (Tokyo) |
10. How we handle transfers abroad
Most of the providers above process information outside the Philippines. Philippine law allows this, and it keeps us accountable to you for information we hand to them.
We choose providers that publish security and data-processing commitments, we pass them only what a task needs, and we remain responsible to you for what happens to it. If you want to know more about a particular provider before you use a feature, write to us.
11. Published links and personalized links
Published invitations sit at unlisted, hard-to-guess addresses and ask search engines not to index them. Anyone holding a working link can open and forward it. Treat an invitation as shareable, not private, and leave sensitive details out of it.
A personalized guest link carries its token in the part of the address after the `#`, which browsers do not send to a server in an ordinary page request and do not pass on as a referrer. The invitation sends it once, in a no-referrer request, to work out which party is reading. Our database resolves it through a keyed hash rather than by storing the token, and the material needed to rebuild an active link for your own copy button is separately encrypted and reachable only through your signed-in account.
13. How long information is kept
The table below is what the product does today, not a target. Where nothing deletes something automatically, it says so.
| What | How long it is kept |
|---|---|
| Creator account and profile | When account-deletion confirmation succeeds, Invitica immediately attempts to take every published invitation offline and signs the account out. A background process repeats any failed link removal and then erases the remaining account records and stored files; provider delays or retries can extend completion. The deletion cannot be cancelled. |
| Invitation drafts | Until you delete the invitation or your account. Nothing deletes an inactive draft automatically. |
| Guest parties, personalized links, and replies | For the life of the invitation. Deleted with it, and with your account. |
| Published invitation files | The guest link is taken down as soon as you delete the invitation or your account. Image files are stored by their content, so a file two invitations happen to share is not removed while the other invitation still needs it. |
| Invi conversations | Until you delete them. Deleted with your account. Nothing expires them automatically. |
| Account-deletion links | The link expires 30 minutes after it is sent and works once. Only a hash of it is stored. |
| Record of which documents you accepted | While your account exists. It is deleted with your account. |
| Operational logs | Held by the providers in section 9 under their own default retention. We do not extend it. |
| Provider backups | Copies may remain in a provider's backups for a limited period after deletion, then age out. |
14. How information is protected
Access to creator data is enforced in the database itself through row-level security, so a request that is not yours returns nothing rather than relying on the application to remember. Server actions and database functions are narrow and check ownership. All input is validated at runtime.
Public identifiers are high-entropy and non-sequential. Personalized links resolve through a keyed hash. Recoverable link material is encrypted. Media is stored privately and served through controlled routes. Published snapshots are immutable and served with restrictive security headers.
No system is perfectly secure, and Invitica is currently operated by one person. If something matters more than an invitation should carry, keep it somewhere else.
15. Your rights and how to use them
Under the Data Privacy Act you may be informed about how your information is used, object to processing, get a copy of what is held, correct what is wrong, ask for erasure or blocking where the law allows, ask for a portable copy where it applies, claim damages for a violation, and complain to the National Privacy Commission.
Write to [email protected] and say what you want. We will acknowledge you and respond within 15 working days. If a request is complex we will tell you why it needs longer and how much longer.
Before acting we need to know you are who you say you are. For a creator, replying from your registered email address and confirming one detail of your account is normally enough. For a guest or someone named in an invitation, we will ask for enough to link you to the record without collecting more than we need.
If your request concerns information a creator entered — your name on someone's guest list, your photograph in their invitation — we will answer you and pass the request to that creator, because they decide what the invitation holds. Where we hold the information as a processor, we will act on their instruction and we will not simply ignore you.
16. Children and family events
You must be 18 or older to hold an Invitica account. Invitica is not for children to use.
Invitations for christenings, birthdays, and family gatherings often name children or show their photographs. If you are the creator, upload that content only when you hold parental authority or the parent's permission, and leave out details a child does not need published — a school, a home address, a routine.
A parent or guardian who wants a child's name or photograph removed from an invitation can write to [email protected]. We will contact the creator, and where the content is in a published invitation we can take that publication offline while it is resolved.
17. If something goes wrong
If a security incident affects personal information and is likely to put someone at real risk, Invitica will notify the National Privacy Commission and the people affected within 72 hours of learning about it, as Philippine rules require. We will say what happened, what information was involved, what we have done, and what you can do.
Report a suspected problem to [email protected]. Say what you saw and when. We would rather look at a false alarm than miss a real one.
18. Automated decisions
Invitica does not use personal information for profiling or for automated decisions that produce legal or similarly significant effects. Template validation, publication checks, rate limits, and abuse controls keep the service working; they do not score a person or decide anything about their rights.
19. Changes to this notice
Every version of this notice carries a version number and an effective date. When we change what we collect, why, who processes it, or how long it is kept, we publish a new version.
We will email active creators at their verified account address about a significant change and give them an opportunity to object or withdraw consent where that right applies. A privacy notice is not itself consent. If new processing requires consent, we will ask before starting it. Earlier versions are available on request.
20. Complaints
If you are unhappy with how Invitica handled your information, tell us first at [email protected] — we can usually fix it faster than anyone else.
You also have the right to complain to the National Privacy Commission of the Philippines, whether or not you have come to us first.
21. How to reach us
Invitica, operated by Theo Cedric Chan. Tuyan, Naga City, Cebu, Philippines. Email: [email protected].
Theo Cedric Chan is the accountable person for privacy and answers privacy requests at that address.
Primary sources
These are the primary Philippine rules and provider policies Invitica followed when writing this notice. They are published here so you can read them yourself.
- National Privacy Commission — Data Privacy Act implementing rules (opens in a new tab)
- National Privacy Commission — Guidelines on consent (opens in a new tab)
- National Privacy Commission — Right to object (opens in a new tab)
- National Privacy Commission — DPO and data-processing-system registration (opens in a new tab)
- Google OAuth 2.0 policies (opens in a new tab)
- Google OAuth brand and privacy-policy verification (opens in a new tab)
