InviteVibes

Legal & Compliance

Privacy Policy

How InviteVibes collects, processes, protects, and handles personal data for couples and their wedding guests, aligned with India's Digital Personal Data Protection Act, 2023 (DPDP Act).

Last updated: September 2026 · InviteVibes ("we", "us", or "Platform")

1. Statutory Commitment & Overview

InviteVibes provides an online software platform that enables couples and hosts ("Hosts" or "Users") to create, customize, preview, and publish digital wedding invitation websites with interactive RSVP tracking.

We are committed to upholding the highest standards of data privacy, integrity, and security in compliance with India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology Act, 2000. This Privacy Policy explains the specific categories of digital personal data we process, the lawful purposes for processing, the technical safeguards we maintain to prevent unauthorized access or breach, and your statutory rights as a Data Principal.

2. Roles Under the DPDP Act

Depending on how you interact with InviteVibes, our role under the DPDP Act is defined as follows:

  • For Account & Billing Data: InviteVibes acts as a Data Fiduciary in relation to your personal registration details (name, email address, account credentials, and transaction records).
  • For Wedding Guest RSVP Data: The Host (the couple or family organizing the wedding) is the primaryData Fiduciary who decides to collect guest attendance details. InviteVibes acts strictly as a Data Processoroperating on the Host's authorization, providing the secure infrastructure to collect and synchronize RSVP responses directly to the Host's private tracking dashboard and spreadsheet.

3. Information We Collect and Lawful Purpose

A. Account and Profile Information

When you register on InviteVibes, we collect your name, email address, and an encrypted, salted password hash.Purpose: To authenticate your identity, secure your account from unauthorized access, enable access to your invitation projects, and transmit essential transactional communications (such as password resets and deployment notices).

B. Wedding Invitation Content & Media

When designing an invitation, you provide couple names, family details, event schedules, venue addresses, love story narratives, photos, audio tracks, and video clips.Purpose: To render your interactive preview editor and deploy your public invitation website as directed by you. Uploaded media is stored in isolated cloud storage (Cloudflare R2) and namespaced strictly to your user account.

C. Guest RSVP Data — Purpose Limitation & Zero-Marketing Guarantee

If a Host enables RSVP on their wedding website, attending guests may submit their names, attendance confirmation, guest count, dietary preferences, and optional well-wishes.

Our Absolute Guarantee on Guest Data:
  • Guest RSVP information is used strictly and exclusively for the Host's wedding coordination.
  • We never sell, rent, monetize, or trade guest contact numbers or names to third parties.
  • We never market, spam, or advertise wedding vendor services to your guests.
  • Guest RSVP records stream into the Host's private spreadsheet and are never accessible to other platform users.

D. Payment and Transaction Details

Purchases of premium themes and deployment packages are processed directly through our secure payment gateway partner,Razorpay, complying with PCI-DSS standards. InviteVibes receives and stores only non-sensitive transaction receipts (transaction ID, payment status, amount, and timestamp). We never store credit card numbers, debit card details, or CVVs on our servers.

E. Technical & Diagnostic Logs

Standard technical logs (IP address, device/browser metadata, timestamps, and route requests) are recorded temporarily solely for cybersecurity monitoring, rate-limiting against automated attacks, and service reliability.

4. Technical & Organizational Security Safeguards

In accordance with Section 8(5) of the DPDP Act (which mandates reasonable security safeguards to prevent personal data breaches), InviteVibes enforces strict multi-layered technical protections:

  • Encrypted Transmission: All web traffic, API requests, and data in transit are strictly encrypted using modern TLS/HTTPS (TLS 1.2 and TLS 1.3).
  • Strict Multi-Tenant Authorization (IDOR Protection):Every authenticated database operation (viewing, editing, deploying, or deleting projects) enforces verified session ownership. No user can view, inspect, or modify another Host's project or RSVP details by manipulating IDs or URL parameters.
  • Cryptographic Preview Token Gating: Private preview data endpoints require short-lived, HMAC-signed cryptographic tokens minted exclusively for the authenticated project owner.
  • Password Security & Lockout: Passwords are irreversibly hashed using industry-standard salted bcrypt. Automated rate-limiting and account lockout mechanisms protect against credential stuffing and brute-force attacks.
  • Content Sanitization: All user-entered text is recursively filtered and sanitized against malicious script injections (XSS protection) before storage or deployment.
  • Cloud Media Isolation: Uploaded media assets are partitioned into account-specific namespaces with verified ownership checks on all deletion endpoints.

5. Sharing with Trusted Infrastructure Providers

We do not sell personal data. We share data only with trusted technical infrastructure providers bound by strict confidentiality and security obligations:

  • Cloudflare R2: Encrypted object storage for user-uploaded wedding photos, audio, and videos.
  • Razorpay: Payment processing and invoice generation.
  • Vercel & GitHub: Hosting infrastructure and automated static deployment for published invitations.
  • Transactional Email Services (Postmark / Resend): Delivering essential account notifications, receipts, and password resets.

6. Data Retention & Permanent Erasure

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or to comply with statutory legal and tax requirements.

Hosts may delete any of their projects directly from their account dashboard at any time. Initiating project deletion triggers automatic cleanup of the associated hosting resources, database records, and uploaded media. If you wish to delete your entire account and all associated personal data, you may submit an erasure request to our Grievance Officer.

7. Your Statutory Rights as a Data Principal

Under the DPDP Act, 2023, you have the following rights regarding your digital personal data:

  • Right to Access: You have the right to request a summary of the personal data we process about you and the processing activities undertaken.
  • Right to Correction & Updating: You can edit and correct your account profile and wedding invitation content at any time via your project editor.
  • Right to Erasure (Right to be Forgotten): You may request the permanent deletion of your account and personal data, subject to retention required by applicable tax or financial regulations.
  • Right to Grievance Redressal: You have the right to register grievances regarding the processing of your personal data with our designated Grievance Officer.
  • Right to Nominate: You have the right to nominate an individual who, in the event of death or incapacity, shall exercise your data rights.

8. Grievance Redressal Officer (DPDP Act Compliance)

In accordance with Section 8(9) of the Digital Personal Data Protection Act, 2023, InviteVibes has appointed a designated Grievance Officer to address any questions, feedback, or complaints regarding personal data privacy and security.

Grievance & Data Protection Officer

Entity: InviteVibes Digital Platforms

Email: privacy@invitevibes.in (cc: hello@invitevibes.in)

Response Timelines: Acknowledgment within 48 hours; substantive resolution within 7 to 14 business days.

If you are unsatisfied with the resolution of your grievance, you have the right to escalate the matter to the Data Protection Board of India.

9. Updates to this Policy

We may update this Privacy Policy periodically to reflect enhancements to our security architecture, service capabilities, or regulatory directives under the DPDP Act. When material changes are made, we will update the "Last updated" date at the top of this page and notify active account holders via email where appropriate.