Privacy Policy

How Grand Invitation handles your data and your guests' data. Written to describe what the service actually does, not what a template says it might.

Last updated 12 September 2026

1. Who is responsible

TOPSOL, at 2nd Floor, Sitara Techno Park, Lower Canal Rd E, near Jhal Khanuana, Block B People's Colony No 1, Faisalabad 38000, Pakistan, is the data controller for the data described in sections 2 and 3. For privacy questions, email support@grandinvitation.com.

There are no user accounts on this service and no passwords. Access to an invitation is proven by a secret link. We never ask you to create a login, and we never store one.

2. Data we collect from you, the host

  • Your email address. Entered at checkout. Used to send your invitation links, RSVP alerts and service notices about your purchase.
  • Your invitation content. Names, event dates, times, venues, addresses, wording, dress code, family names, and any photographs or music you upload. This is published on your public invitation page by design.
  • Purchase records. A transaction reference, amount, currency and status. We do not receive or store your card number — see section 5.

We process this to perform our contract with you: without it there is no invitation to deliver.

3. Data your guests give

When a guest submits an RSVP we store the name they enter, their attendance choice, party size, and — where you have enabled those fields — their phone number, email address, meal preference and message. This is shown to you on your private management page and emailed to you as an alert.

You are the controller of your guest list. We process guest responses on your behalf, as your processor. You are responsible for telling your guests how you will use their details and for having a lawful basis to do so.

4. View statistics, analytics and advertising

When someone opens an invitation page we record a view so the host can see how many people have looked at it. Each record holds:

  • A truncated, salted hash of the visitor's IP address. The salt changes daily and only the first 16 characters of the hash are kept, so a visitor cannot be recognised across days and the original address cannot be recovered.
  • A shortened browser user-agent string and the referring page, if any.

These view records are made on the server. They set nothing on your device and are not covered by the choice described below.

We also use Google Analytics to understand how our site is used — which pages people reach, how they arrived, and where they leave. Where it is active, it sets cookies on your device and sends Google Ireland Limited the pages you viewed, your approximate location, and your device and browser details. Google Analytics derives that location from your IP address and then discards it; we never receive your IP address from it, and we have not enabled any Google feature that would combine this with advertising profiles. Google processes it on our instructions, as our processor.

We use Microsoft Clarity to see where our own pages confuse people. Unlike the analytics above, Clarity does not simply count visits: it records your session and lets us replay it — the pages you moved through, where you scrolled, what you clicked, and how your mouse or finger moved. Where it is active it sets cookies on your device and sends Microsoft Corporation that recording together with your approximate location, device and browser details.

Three limits on it are worth stating plainly. Clarity never runs on a published invitation. If you reached this site by following an invitation somebody sent you, no session of yours is recorded at all — not the invitation, and not the RSVP form. It runs only on our own marketing pages, the design builder, the checkout and the host’s own dashboard. What you type is never recorded. Clarity masks the contents of every input box and drop-down before anything leaves your browser, so it is never uploaded. And on the host’s dashboard we mask the guest table outright, so guest names, contact details and messages never form part of a recording. Microsoft processes all of this on our instructions, as our processor, and does not sell it.

One consequence of how Clarity is built: Microsoft does not let us delete one person’s recordings. If you ask us to erase your data we can delete the entire Clarity project, and we will if you ask, but we cannot pick out a single session. Recordings expire by themselves within 30 days in any case — see section 7.

We use the Meta (Facebook) pixel to measure our advertising and to show our ads to people who have visited us. Where it is active, it sets cookies on your device and sends Meta Platforms Ireland Limited the pages you viewed on this site, along with your IP address and browser details. When you buy, we also send Meta a record of the purchase from our server — the amount, the currency and a one-way cryptographic hash of your email address, never the address itself. Meta uses this as an independent controller under its own terms.

In the UK, EEA and Switzerland none of these loads until you accept them. You are asked once, in a banner covering all three, and declining loads nothing at all — not the scripts, and no request to Google, Microsoft or Meta. Everything on this site works identically either way. To change your answer, clear this site’s data in your browser and the banner will be shown again. Elsewhere both are active by default, and you can stop them with any ad or tracker blocker.

Our lawful basis is your consent where you were asked for it, and our legitimate interest in promoting our own service where you were not. Nothing about your invitation content, your guests or their RSVPs is ever sent to Google, Microsoft or Meta. (Paddle’s checkout also sets its own cookies while it is open — those are covered by Paddle’s privacy notice.)

5. Payments

Payments are processed by Paddle.com Market Limited, our reseller and Merchant of Record. You enter your card details on Paddle’s checkout, not on our site, and we never see or store your card number, expiry date or security code. Paddle also collects the billing country and any tax identifiers it needs to charge the right tax.

Paddle is an independent controller for that data. See Paddle’s Privacy Policy.

6. Who else processes the data

  • Paddle — payment processing, tax, invoicing and refunds.
  • Supabase — the PostgreSQL database holding invitations and RSVPs, and the storage bucket holding uploaded photographs and music.
  • Resend — delivery of transactional order messages, invitation links and RSVP alerts through its email API.
  • Our hosting provider — running the application and serving the pages.
  • Google — website analytics, where you have not declined it. Google acts as our processor for this; see section 4.
  • Microsoft — session replay on our own pages, where you have not declined it. Never on a published invitation. Microsoft acts as our processor for this; see section 4.
  • Meta — advertising measurement, where you have not declined it. Meta acts as an independent controller of what it receives, not as our processor; see section 4.

We do not sell personal data. The only data shared for advertising is what the Meta pixel and our purchase reporting send, described in section 4 — never your invitation content, your guest list or any RSVP. Google Analytics and Microsoft Clarity are used to measure and improve our own site, not to advertise to you. Where a processor operates outside your region, transfers are made under the safeguards that provider offers, such as Standard Contractual Clauses.

7. How long we keep it

  • Invitation content and RSVP responses: for as long as the invitation is live, and for 30 days after it is unpublished or refunded. This data-retention period is separate from the 7-day period for requesting a refund.
  • Your email address and purchase record: for as long as required by tax and accounting law, typically 7 years.
  • View statistics: 24 months, then deleted.
  • Google Analytics records: kept by Google for the retention period configured on our property, then deleted by Google.
  • Microsoft Clarity session recordings: deleted by Microsoft 30 days after the recording, except recordings we mark as favourites and a randomly sampled subset, which Microsoft keeps for up to 9 months. Aggregated heatmaps are kept for up to 9 months.

8. Security

Traffic is encrypted in transit with TLS. Database access is restricted to the application. Your management link is a random token that is not listed or indexed anywhere.

Because that link is the only credential, treat it like a password. Anyone you send it to can see your guest responses and edit your invitation. We publish this warning in the email that contains it too.

9. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to our processing of your data, to receive a portable copy, and to lodge a complaint with your data protection authority.

Email support@grandinvitation.com and we will respond within 30 days. We may ask you to confirm the purchase email address or supply the management link, since we have no accounts against which to verify you.

If you are a guest who submitted an RSVP and want it removed, contact the host who sent you the invitation. Contact us if you cannot reach them and we will help.

10. Children

The service is sold to adults. We do not knowingly collect data from children. Where a host lists a child as a guest, that data is the host’s responsibility under section 3.

11. Changes

We will update this page when our processing changes, and will email customers about material changes. See also our Terms & Conditions and Refund Policy.