Skip to content
← Back to home

Privacy Policy

Last updated: July 2026

Who We Are

Strawberry Invites is an Ontario sole proprietorship operated by Kyle Czernuszka. This policy explains what information we collect when you use the service and how we handle it.

What We Collect

When you use Strawberry Invites, we collect the minimum information needed to provide the service:

  • Your email address — used for sign-in (magic links) and as the reply-to address on invitations you send.
  • Your name — if you sign in with Google, we receive your name and email address to set up your account. We do not keep your Google profile photo or OAuth access tokens. If you sign in by magic link, we store the name you choose to enter. Your name may appear as the host on invitations you send.
  • Event content — title, date, time, location, messages, schedule, details, survey questions, and any photos you upload for your event page.
  • Guest information — names and email addresses you provide for your guest list, plus RSVP responses, notes, party details, companion names, survey answers submitted by guests, and private notes the host adds for event management.
  • Email activity — whether an event email was sent, delivered, bounced, or reported as spam. Open and click tracking are disabled.
  • Payment information — if you upgrade an event to Premium ($9 CAD), payment is processed securely by Stripe. We do not store your card details ourselves.
  • Pseudonymous usage analytics — a random identifier that lasts only for the current browser tab, funnel steps, which public product or guide page was viewed, date and time, referring site hostname, campaign tags, selected design or tier, and guest-list size. We do not attach this data to your account or email address.

How We Use Your Data

  • To create and deliver your event invitations via email.
  • To track RSVPs, survey answers, and email delivery for the event host.
  • To send reminders to guests who haven't responded.
  • To show guest names and RSVP status on an event page when the host enables an attendee or invitee list.
  • To improve the service through pseudonymous usage analytics and aggregate trends.

Third-Party Services

We use the following services to operate:

  • Microsoft Azure — stores event, guest, and uploaded image data and hosts the service.
  • Resend — sends event emails and reports delivery, bounce, and spam-complaint events back to us. Email clients and their image proxies may receive and cache image URLs containing the text needed to render each invitation section. RSVP and unsubscribe tokens are not included in those image parameters.
  • Stripe — processes payments for the optional Premium Event upgrade. We do not store card details.
  • Google Sign-In— if you choose to sign in with Google, Google verifies your identity and shares your basic profile (name and email address) with us. This is optional; you can sign in by magic link instead. Google’s handling of your data is governed by Google’s own privacy policy.
  • Sentry — receives filtered technical error reports and sampled performance traces so we can diagnose problems. We remove URL query strings, known token/internal-ID path segments, and contact, credential, payment, and internal-ID fields before sending error or performance context.
  • Microsoft Outlook and ImprovMX — receive or forward messages sent to our support, security, and feedback addresses.
  • GitHub — hosts our source repository and runs deployment and scheduled-job logs. We do not intentionally place event exports or raw guest data in GitHub.

We do not sell, rent, or share your personal information with any other third parties except as needed to operate the service or when required by law.

Some service providers may process information outside Canada. Their records may therefore be subject to the laws and lawful-access rules of the countries where they operate. We remain responsible for selecting and overseeing processors that protect information used on our behalf.

Information Shared With Hosts and Guests

RSVP responses, notes, party details, companion names, and survey answers are shared with the host of the event you are responding to. If a host enables a public attendee or invitee list, a guest’s first name, last initial, RSVP status, and the similarly shortened names of companions they provide may appear to anyone with the event link. These lists are off by default and controlled by the host. Event pages are accessible to anyone who has their link.

Data Retention

Drafts more than 30 days old are deleted. For sent events, guest information, notifications, and uploaded images are removed 30 days after the event date. For cancelled events, this removal occurs no later than 30 days after cancellation and may happen sooner based on the original event date. We then keep a minimal dashboard record: technical identifiers, status, title, event date, and creation date. No guest names, email addresses, RSVP responses, messages, or photos remain in that active event record. Minimal records and the host account remain until the account is deleted.

Private daily recovery backups are stored in a separate locked Canadian storage account for up to 30 days. Deleted backup versions may remain recoverable for approximately seven additional days before automatic removal. Backups are used only to recover from data loss or service incidents, not for ordinary product use.

Deleted image blobs may remain recoverable through Azure soft delete for approximately seven days. Unused magic-link records expire within 24 hours, and per-host email-volume counters are removed after about 90 days.

Pseudonymous usage analytics (which public product or guide pages are viewed and which steps visitors reach when creating an invitation, e.g. viewed the site, started creating, sent invitations) are recorded against a random tab-session identifier, not your account or email. Referrer hostnames, campaign tags, design/tier, and guest count may also be included. These records are kept for about one year and then deleted after aggregate rollup. We also keep a permanent, aggregate-only summary (a daily count per step, with no session, referrer, or other identifying detail) indefinitely, so we can track long-term usage trends without retaining individual visitor records.

Abuse Prevention

To protect the service from spam and abuse, the application briefly processes IP addresses for rate limiting and does not write them to its account or analytics tables. Hosting, security, and network providers may process ordinary request-log information under their own retention controls.

Feedback

If you send us feedback through the in-app feedback tool, we receive your message, reply email address, current page path, and timestamp so we can respond and improve the service. Feedback is delivered to our operator mailbox through Resend.

Your Rights

In accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable Canadian privacy legislation, you have the right to:

  • Access the personal information we hold about you.
  • Request correction of inaccurate information.
  • Request deletion of personal data that we are not required or permitted to retain.
  • Withdraw consent, subject to legal or contractual restrictions.

To exercise any of these rights, contact us at support@strawberryinvites.com. We aim to respond within 30 days. We may need to verify your identity, clarify scope, protect another person’s information, or retain a limited record for legal, security, transaction, complaint, or email suppression purposes. Active deletion does not erase copies already held in recipient mailboxes or another person’s browser; recovery copies expire under the schedule above.

Age Requirement

Account holders must be at least 18. Event invitees and companions may include minors. Hosts must be authorized to provide invitee data and should not ask a child to submit information without appropriate parent or guardian involvement. Contact us if information about a child needs review or deletion.

Cookies and Browser Storage

We use essential cookies for authentication only — they keep you signed in and protect sign-in requests. We do not use advertising cookies or third-party tracking cookies.

We also store a short, random analytics identifier in your browser’s session storage. It exists only while your tab is open, cannot identify you personally, and is used to group anonymous usage events (e.g. so we can tell that 10 page views came from one visitor versus ten visitors). It is cleared when you close the tab.

After an RSVP, we may keep only the attendance result in that tab’s session storage so the confirmation state survives a refresh. We do not store the guest name or RSVP token there, and it clears when the tab closes.

While you build an invitation, we save your draft locally in your browser’s storage so you don’t lose your work before signing in. This stays on your device and is cleared when your event is saved or you clear it yourself.

Changes to This Policy

We may update this privacy policy from time to time. Changes will be posted on this page with an updated date.