Privacy Policy
Version 1.0 Last updated 29 July 2026 · applies to savedate.me and every invitation published on it
The short version
- We collect what is needed to run your invitations — nothing is sold, rented or shared with advertisers.
- Guest replies belong to the host who created the invitation. We hold them on that host's behalf and never use them for our own purposes.
- Uploaded photos are re-encoded on our server, which removes hidden metadata such as GPS location.
- A published invitation is a public web page. Anyone with the link can open it, and search engines may index it — so think about what you put on it.
- Delete your account and everything goes: photos, guest replies, the lot. There is a 7-day grace period, then it is gone for good.
1. Who we are
SaveDate is an online invitation maker operated under the name SaveDate ("we", "us"). We are the data controller for your account and for how the service runs. Questions, requests and complaints: support@savedate.me.
An important distinction. For the information guests submit to an invitation — RSVPs and greetings — the person who created that invitation is the controller and decides what happens to it. We act as their processor: we store it, show it to them, and act on their instructions. If you are a guest and want your reply removed, ask the host first; you can also contact us and we will help.
2. What we collect, and why
2.1 Your account Required
| Data | Why we need it | Legal basis |
|---|---|---|
| Name and email address | To create and identify your account, sign you in and send service messages such as password resets. | Performance of a contract |
| Password | Stored only as a one-way hash — we cannot read it, and neither can anyone who obtained the file. | Performance of a contract |
| Google account identifier and profile picture | Only if you choose "Continue with Google". We receive your name, email address and picture from Google — never your Google password. | Performance of a contract |
| Two-factor secret and recovery codes | Only if you switch on two-factor authentication. Recovery codes are stored hashed and each works once. | Legitimate interests (account security) |
| Sign-up IP address and the country derived from it | Fraud and abuse prevention, and to understand where the service is used. | Legitimate interests (security) |
| Record that you accepted the terms, and which version | To show the agreement was entered into. | Legal obligation / contract |
2.2 What you put on an invitation
Everything you type or upload while building an invitation: the celebration's title and date, the names of the people it is about, family members you list, your story text, venue names and addresses, schedule entries, photographs, an optional music track, video links, live-stream links and any social links you add. This content is stored so we can display the invitation, and it is used for nothing else.
Please be thoughtful about other people. If you add a family member's name or a photograph of a friend, you are sharing their information — make sure they would be comfortable with it appearing on a page anyone with the link can open. Do not upload photographs of children unless you are their parent or guardian, or have that person's permission.
2.3 What guests submit
| Data | Why | Who sees it |
|---|---|---|
| RSVP: name, whether they are coming, number of guests, which events, optional phone, email and message | So the host knows who is attending | The host of that invitation, and us only as their processor |
| Greetings: name and message | Wishes for the host, shown on the invitation once the host approves them | The host; and every visitor, once approved |
| IP address attached to the submission | Spam and abuse prevention on public forms | Us only — it is not shown to the host |
| A count of invitation views | So the host sees how many times the page was opened | The host, as a total only — never as a list of individuals |
Guests do not need an account, and we do not build profiles of them. A greeting only becomes visible on the invitation when the host approves it.
2.4 Support, reports and technical records
When you contact support we keep your message, anything you attach, and our replies, so the conversation makes sense and we can prove what was agreed. For security we keep short-lived records of failed sign-in attempts (email address tried and IP address) to stop brute-force attacks, password-reset tokens until they are used or expire, and — if you asked us to trust a device — a hashed token for that browser. Our servers also produce ordinary technical logs.
Sign-in records. Each time you sign in successfully we record the IP address used, the country derived from it and the browser reported, and we set the long-lived security cookie described in the Cookie Policy (sd_dev) so we can recognise a browser that has signed in before. These records exist to protect accounts and to detect one person operating several accounts to abuse the service. They are visible only to our own staff, are never shown to hosts, guests or other users, and are not used for advertising, analytics or profiling.
Abuse reports and contact messages. When anyone uses our public Report Abuse or Contact forms we keep what they submitted together with the connection's IP address, the country derived from that address, basic browser information, the security cookie described above if the browser holds one, and — if they were signed in — a link to their account. We use these records to act on the report, to stop spam and misuse of the forms, and to recognise when separate submissions come from the same connection, which helps us spot repeat abuse. They are visible only to our own staff, are never shown to hosts or other users, and are not used for advertising or profiling. Because these forms can be used maliciously — for example to make false reports — keeping who-sent-what is also how we protect the people reported about.
2.5 What we never collect
We do not ask for or store payment card details. We do not collect precise device location, we do not run advertising or cross-site tracking, and we do not buy personal data from anyone. We do not knowingly create accounts for children under 16 — see section 8.
2.6 Device fingerprinting and identifiers
We do not use browser fingerprinting, canvas or audio hashing, WebGL or font enumeration, or any tracking script to identify or profile visitors. We hold no device fingerprint of you, and we do not buy or receive one from anyone else. Today our collection is limited to what is needed to run the service, keep it secure, prevent abuse of our public forms and understand in broad terms where the service is used; if we ever add measurement, it will be a privacy-friendly tool, described here first, and subject to the choice you set in our cookie banner.
One exception is not ours to make: if a host embeds a video, that player is operated by the company named in our Cookie Policy and applies its own identification once you press play. We use the no-cookie player, so nothing is set until you choose to watch.
3. Published invitations are public
This deserves its own section because it surprises people. When you publish an invitation it gets its own web address. That address is unlisted and hard to guess, but it is not password-protected: anyone you send it to can forward it, and because published pages are not blocked from search engines they may appear in search results. Drafts are never public and are excluded from search engines.
If you would rather a page were not reachable, switch it off from your dashboard — it goes offline immediately — or delete it. Deleting an invitation removes its photos, RSVPs and greetings straight away.
4. Photographs and hidden metadata
Photos are not stored as you uploaded them. Every image is decoded and re-encoded on our server, which strips embedded metadata — including GPS coordinates, camera details and any hidden payload — and is then resized and compressed. Only that cleaned copy is saved. This protects you and your guests from accidentally publishing the location a photo was taken.
5. Who we share information with
We do not sell your personal information, and we do not share it for advertising. Information is disclosed only in these situations:
- People you choose. Anyone you give an invitation link to sees what you published on it.
- The host of an invitation. Guest replies go to the host, which is the whole point of the form.
- Service providers who help us operate. Our hosting provider stores the data; an email provider delivers service messages. They act on our instructions and may not use the data for themselves.
- Services that a page loads. Fonts, map tiles, address search and embedded videos come from other companies, so your browser's request reveals your IP address to them. Each one, and why it is used, is listed in the Cookie Policy.
- Law and safety. If we are legally required to disclose something, or need to act to prevent fraud, abuse or harm, we will — and no further than necessary.
- A change of ownership. If the service were ever transferred to another company, your data would move with it and this policy would continue to apply until you were told otherwise.
6. Where your data is stored
Our servers and providers may be located outside your country, including outside the European Economic Area. Where data leaves the EEA or the UK we rely on the safeguards the law allows for such transfers, such as the European Commission's standard contractual clauses or a transfer to a country recognised as providing adequate protection.
7. How long we keep it
| What | Kept for |
|---|---|
| Your account and its invitations | While your account exists |
| An invitation you delete, with its photos, RSVPs and greetings | Removed immediately |
| A deactivated account | Held, hidden from guests, until you sign back in — signing in reactivates it |
| An account you asked us to delete | 7 days, so you can change your mind by signing in; then permanently erased, including uploaded files |
| Support conversations | While your account exists, so history stays intact |
| Abuse reports and contact-form messages | While we handle them, then up to 24 months after they are closed so repeat misuse can be recognised |
| Failed sign-in records, reset tokens, trusted-device tokens | Short-lived — minutes to a few days |
| Sign-in records (IP history and the security cookie's link to your account) | While your account exists; removed with the account |
| Cookie-consent records | As set out in the Cookie Policy |
Permanent deletion means the account row and everything linked to it — invitations, details, photos on disk, RSVPs and greetings — is destroyed. It cannot be undone and we cannot recover it for you afterwards.
8. Children
SaveDate is for adults organising celebrations. You must be at least 16 to create an account, or older if your country requires it. We do not knowingly collect personal information from children. Invitations for a naming ceremony, baptism or child's birthday will naturally mention a child — that content is yours as parent or guardian to decide on, and the same rule applies: publish only what you are happy for anyone with the link to see. If you believe a child's information has been published without authority, write to us and we will remove it promptly.
9. How we protect it
Passwords are stored only as one-way hashes. Two-factor authentication is available, and repeated failed sign-ins are throttled. Forms are protected against cross-site request forgery, uploads are validated and re-encoded rather than trusted, and access to the administration tools is restricted. No service can promise perfect security, so please use a strong, unique password and turn on two-factor authentication. If we ever discover a breach affecting your rights, we will notify you and the relevant authority as the law requires.
10. Your rights (EU, EEA and UK)
Under the GDPR and UK GDPR you may:
- ask for a copy of the personal data we hold about you;
- have inaccurate details corrected;
- ask us to erase your data — the fastest route is deleting your account in settings;
- ask us to restrict how we use it, or object where we rely on legitimate interests;
- receive your data in a portable, machine-readable form;
- withdraw consent at any time where we relied on it, such as cookie choices;
- complain to your data-protection authority — in Ireland the Data Protection Commission, in the UK the Information Commissioner's Office.
Write to support@savedate.me from the address on your account. We reply within one month, and will tell you if a request needs longer or if we cannot act on it and why. Exercising these rights costs nothing and we will not treat you differently for it.
11. Your rights in California (CCPA / CPRA)
We do not sell personal information and we do not share it for cross-context behavioural advertising — in the twelve months before the date at the top of this page we did neither. You may request to know the categories and specific pieces of personal information we hold, request deletion or correction, and appoint an authorised agent. We verify requests against your account before acting, and we will not discriminate against you for making one.
12. Cookies
We use four strictly necessary cookies and no advertising or analytics cookies. The full picture — every cookie, every third-party service and how to change your choices — is in the Cookie Policy.
13. Changes to this policy
If we change how we handle personal data we will update this page and raise the version number. For a significant change we will tell you in the app or by email before it takes effect, and ask again for consent where consent is what the law requires. The date at the top always shows when this text last changed.
14. Contact
Privacy questions and data requests: support@savedate.me. Account and billing matters: accounts@savedate.me. If you are a guest asking about a reply you sent, tell us which invitation it was and we will put you in touch with the host or act for them.