The Cordially Invited · Privacy
Privacy notice
Effective September 4, 2026 · Private beta
The short version
We use personal information to provide wedding websites, invitations, RSVP tools, planning features, support, security, and billing. We do not sell personal information, share it for cross-context behavioral advertising, or use Guest information to advertise. Optional marketing analytics is currently disabled.
Who we are
The Cordially Invited is operated by Crafted Kit LLC d/b/a The Cordially Invited. Questions and privacy requests can be sent to hello@craftedkit.io.
Who this notice covers
This notice covers people who browse our public pages, request access, create or help manage a Wedding, purchase the service, visit a published wedding website, receive an invitation, or submit an RSVP. It does not replace the privacy notice of a couple or another organization that independently decides how to use Guest information.
For account, product, security, support, and billing information, The Cordially Inviteddetermines why and how the information is used. For Guest rosters, invitations, and RSVP information, the couple generally makes those decisions and we process the information to provide the service on their behalf. We may still use limited operational information as needed to secure the service, prevent abuse, comply with law, and maintain delivery records.
Information we collect
- Account and contact information: email address, authentication records, collaborator details, and communications with us.
- Wedding and website information: names, wedding date and location, stories, schedules, travel details, registry links, FAQs, design choices, identity settings, photos, and other content a couple provides.
- Guest and RSVP information: names, household groupings, email or phone details supplied by the couple, attendance, meal selections, plus-one details, answers to custom questions, and optional dietary, accessibility, travel, or lodging notes.
- Invitation and delivery information: message content, audience, send status, delivery events, bounces, complaints, suppressions, and private invitation-link records.
- Billing information: plan, purchase status, Stripe customer and transaction identifiers, subscription status, refunds, and disputes. Stripe receives payment-card details directly; we do not receive or store full card numbers.
- Device, security, and log information: IP address, browser and device details, timestamps, requested pages, security events, error reports, and bot-check results. We do not intentionally place names, Guest responses, private links, or message bodies in error-monitoring reports.
- Private-beta information: the information submitted with an access request and whether the request was approved, declined, or withdrawn.
We collect information from you, from a couple or collaborator who adds you, from a Guest who replies, automatically from the service and its security systems, and from providers such as Stripe and Resend when they report transaction or delivery status.
How we use information
- Provide, personalize, publish, maintain, and support the service.
- Authenticate users and preserve requested setup or RSVP state.
- Send account, invitation, RSVP, service, and support communications.
- Process purchases, subscriptions, refunds, disputes, and entitlements.
- Protect accounts and Guests, prevent abuse, debug failures, and enforce terms.
- Comply with legal obligations and establish or defend legal claims.
- Improve the product using feedback and limited operational information. We do not use Guest lists, RSVP answers, photos, or private Wedding content to train generative AI models.
Sensitive details
Dietary, accessibility, and other open-text RSVP answers can reveal health, disability, religious, or other sensitive information. Couples should request only what they need, make optional questions clearly optional, restrict access to people who need it, and remove the information when it is no longer needed. Guests should avoid including unrelated sensitive information in open-text answers.
How we disclose information
We disclose information only as needed for the following purposes:
- Couples and collaborators: Wedding owners and authorized collaborators can see the Wedding and Guest information allowed by their role.
- Guests and site visitors: content a couple publishes is available through the Wedding address, subject to any site password or private event controls.
- Service providers: Supabase for database, authentication, and file storage; Vercel for hosting; Resend for email delivery; Cloudflare Turnstile for bot protection; Sentry for limited error monitoring when enabled; and Stripe for payment processing and billing management.
- Legal and safety: authorities, advisers, or other parties when reasonably necessary to comply with law, protect rights and safety, investigate abuse, or establish and defend legal claims.
- Business changes: a buyer, successor, or adviser in connection with a financing, merger, acquisition, reorganization, or sale, subject to appropriate confidentiality and legal protections.
We do not sell personal information or disclose it for targeted advertising. We do not disclose Guest information to data brokers.
Cookies and similar technology
We currently use cookies and similar technology only for requested setup choices, authentication, security, site-password access, and RSVP sessions. Optional analytics, advertising pixels, and cross-site behavioral tracking are disabled. Our Cookie Notice lists the purposes and retention periods.
Because we do not sell personal information or use it for targeted advertising, browser-based opt-out signals such as Global Privacy Control do not change the current service behavior. We will honor applicable signals before activating any use to which they apply.
Retention and deletion
Retention depends on the type of information, the Wedding lifecycle, security and delivery needs, and legal obligations. Couples can export Wedding information and initiate Wedding deletion. A deletion request first takes the site offline and enters a 30-day reversal period before permanent removal. Provider, backup, billing, suppression, fraud-prevention, and legal records may remain longer where necessary. Details are in our Data Retention and Deletion Policy.
Your choices and privacy requests
Couples can correct much of their information in the Dashboard, export Wedding data, remove Guests, and initiate Wedding deletion. Guests should usually contact the couple first because the couple controls the roster and RSVP questions. Anyone may also contact us to request access, correction, deletion, or a portable copy of personal information we control.
Email hello@craftedkit.io with the subject “Privacy request.” We may need to verify your identity and authority before acting. We will respond within the period required by applicable law, generally 45 days under state privacy laws that apply to a request. If we deny a request, reply with the subject “Privacy appeal” and explain why you believe the decision should be reviewed. You may also have the right to contact your state attorney general or local data protection authority.
We will not discriminate against you for exercising an applicable privacy right. An authorized agent may submit a request where law permits, but we will verify the request and the agent's authority.
Security
We use access controls, tenant-level database policies, encrypted transport, restricted administrative access, abuse controls, and operational monitoring designed to protect personal information. No online service can promise perfect security. If you believe a Wedding, invitation link, or account has been compromised, contact us promptly and do not include sensitive Guest details in the first email.
International processing
We and our providers are based in the United States and may process information in the United States and other countries where they operate. Those countries may have different privacy laws. Where applicable law requires transfer safeguards, we rely on provider contractual protections and other lawful transfer mechanisms.
Children
The service is intended for adults and is not directed to children under 13. A couple may list a child Guest's name, household, meal, or seating details. Adults should provide only what is reasonably needed and should not provide a child's direct contact details or sensitive information unless necessary and authorized. Contact us if you believe a child provided information directly without appropriate permission.
Changes and contact
We will post updates here and revise the effective date. We will provide additional notice to account holders before a material change takes effect when appropriate. Questions and privacy requests can be sent to hello@craftedkit.io.