Introduction
This policy explains how Invilty handles information when you visit invilty.com or use its workspace features. Workspace operators may separately decide how data about their own customers and guests is used.
Information we collect
Depending on how you use Invilty, we handle information you submit, account and workspace records, order and invitation data entered into the service, uploaded files, and technical information needed to operate and protect the platform.
Information you provide
You may provide your name, email, business and brand details, workspace settings, storefront and product content, support requests, and other information you choose to add. Forms identify required fields.
Account and authentication information
We process account identifiers and authentication records needed to provide access. The platform supports Google sign-in and may support email-and-password sign-in when enabled. Login attempt records may be used to limit repeated password attempts.
Google Sign-In
When you choose Google Sign-In, Google may provide your name, email address, and profile image when available. The application requests only standard OpenID Connect identity scopes: `openid`, `email`, and `profile`. It does not request Gmail, Drive, Contacts, Calendar, or other Google API data through this flow. Google has its own privacy terms.
Business, brand, and workspace information
Workspace users can store business names, brand details, domains, storefront configuration, design settings, integrations, and access assignments. Brand information is managed in its workspace context.
Customer and order information
Storefront purchases may include customer name, email, phone, checkout details, products, order status, and payment reference. Fields depend on configuration. The brand’s configured payment provider handles payment details; Invilty receives information needed to create and reconcile orders.
Invitation and guest data
Workspace users may create invitations and guest records, including names and optional phone numbers. Workspace operators are responsible for having a lawful basis and providing any notices required before entering another person’s information.
Uploaded content and media
Uploaded files may be stored with metadata such as file name, media type, size, and related brand. Storage depends on the deployed configuration; preview links may be temporary. Do not upload information you are not authorized to provide.
Usage and device information
Our hosting environment may process IP address, browser and device characteristics, requested pages, timestamps, and error details to deliver and troubleshoot the service. The current public-site code does not configure advertising cookies or a third-party analytics tracker.
Cookies and similar technologies
We use cookies needed for authentication and session continuity. The public site stores your language preference in the `invilty-language` cookie for up to one year. Blocking cookies may prevent sign-in or preference features from working.
How we use information
We use information to provide accounts and workspaces; render storefronts and invitations; manage templates, media, products, orders, and checkout; answer support requests; troubleshoot; protect the service; and meet legal obligations. Google identity data is not used for advertising.
Authentication and account security
Sign-in uses the configured provider and Invilty session and access checks. Workspace access follows account roles and brand-level authorization. Keep credentials private and notify the workspace owner if you suspect misuse.
Service providers and infrastructure
Providers support hosting, the database, file storage, authentication, and configured payment processing. They process information as needed to provide their services under their applicable terms. Providers and deployment configuration may change.
Data sharing and disclosure
We share information with providers supporting Invilty, authorized workspace members, and payment providers when needed. We may disclose it to comply with law, respond to valid legal process, protect people or the service, or address fraud and security issues. Workspace operators control some storefront customer and guest data; contact them about their handling of it.
Data retention
We keep information as needed for the account, workspace, transaction, or feature and for legitimate operational, security, dispute, or legal purposes. Periods vary by record; the application does not set one fixed deletion period for all data. Deletion requests may not immediately remove backups or records that must be retained.
Data security
Invilty uses application-level authentication and authorization and relies on its configured infrastructure providers. No transmission or storage method is guaranteed completely secure. This policy makes no certification or absolute security guarantee.
International processing and transfers
Invilty and its providers may process information in countries other than yours. Locations depend on service configuration and selected providers. Where required, appropriate transfer safeguards should be used.
Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing, or withdraw consent where applicable. You can update some account details in the product. Requests about storefront customer or guest data should go to the workspace operator. We may verify identity and apply legal exceptions.
Children’s privacy
Invilty is a business platform and is not designed for children to create accounts. We do not knowingly request account information directly from children. If you believe a child has provided it, contact us through the configured channel.
Third-party services and links
The platform may connect to Google for sign-in and to payment or other services selected by a workspace. Linked third-party services and websites have privacy practices this policy does not control.
Changes to this Privacy Policy
We may update this policy as the service or legal requirements change. The “Last updated” date shows the latest revision. Where feasible, we will provide notice of material changes in the product or on the public website.
Contact
For privacy questions about Invilty, use the privacy contact configured below when available. For information controlled by a workspace, contact its operator.
This policy describes current application behavior and makes no certification or fixed retention promise.