Privacy Notice

This page is maintained by RSVPath to answer common questions about RSVPath. Last updated: July 2026.

1. Who we are

RSVPath is operated by RSVPath, trading as RSVPath. RSVPath is the data controller for personal data processed through RSVPath accounts, the website, and support channels. For personal data that organizers upload about their guests, the organizer is the controller and RSVPath acts as processor on their behalf.

Contact: hello@rsvpath.com.

2. What we collect and why

  • Account data (name, email, password credentials, organization, profile photo) — to create and secure your account. Legal basis: performance of a contract.
  • Event and guest data (event details and venue or virtual meeting information, guest names, emails, phone numbers, invitation groups, plus-one (+1) details, RSVP status, attendance preference for hybrid events, guest communications, check-in records and QR tokens) — to deliver invitations, RSVPs, guest management and check-in. Legal basis: performance of a contract with the organizer; organizers are responsible for their own lawful basis for contacting guests and for having the right to provide guest information to us.
  • Event team data (event owners, celebrants and event staff, their roles, permissions and activity such as check-in scans or reveals of masked guest contact details) — to operate role-based access on an event. Legal basis: performance of a contract and legitimate interests in securing the platform.
  • Calendar actions — when a guest chooses “Add to calendar”, we generate a calendar link or .ics file from the event details you entered. We do not connect to, read or store anyone's personal calendar, and there is no two-way calendar synchronization.
  • Support messages and attachments — to answer your questions. Legal basis: legitimate interests in supporting customers.
  • Usage, telemetry, device identifiers, and IP address — for security, fraud and abuse prevention, diagnostics, and product improvement. Legal basis: legitimate interests.
  • Billing records (plan, invoices, subscription status) — to administer your subscription. Card details are never collected or stored by us; they are handled by Paddle. Legal basis: contract and legal obligation.
  • Marketing preferences — to send product updates where you have opted in. Legal basis: consent, which you may withdraw at any time.

3. Who we share data with

  • Paddle.com — our reseller and Merchant of Record. Paddle processes orders, payments, subscription management, tax compliance, invoicing, and refunds, and acts as controller for that transaction data under its own privacy notice.
  • Service providers and subprocessors — cloud hosting and database infrastructure, email and SMS delivery, mapping and venue lookup, analytics, and support tooling, each bound by confidentiality and data protection terms.
  • Professional advisers — legal, accounting, and insurance advisers where necessary.
  • Authorities — where required by law or to protect legal rights.

We do not sell personal data.

4. International transfers

Our infrastructure and service providers may process data outside your country, including in Canada, the United States, and the European Union. Where data leaves the UK/EEA we rely on adequacy decisions or Standard Contractual Clauses with appropriate supplementary safeguards.

5. How long we keep data

  • Account data: for the life of the account, then deleted within 90 days of closure.
  • Event and guest data: until the organizer deletes it, or 90 days after account closure.
  • Support correspondence: up to 24 months.
  • Billing and tax records: as required by law (typically 6–7 years), held by us and by Paddle.
  • Security and audit logs: up to 12 months.

When data is no longer needed it is deleted or irreversibly anonymised.

6. Your rights

Subject to applicable law, you may request access to your personal data, correction of inaccurate data, deletion, restriction of processing, portability of data you provided, and you may object to processing based on legitimate interests or withdraw consent at any time. Email hello@rsvpath.com and we will respond within one month. You also have the right to complain to your local data protection authority — in Canada, the Office of the Privacy Commissioner; in the UK, the ICO; in the EEA, your national supervisory authority.

7. Security

We apply appropriate technical and organisational measures, including encryption in transit and at rest, row-level access controls scoped to each organization, role-based permissions, masked display of sensitive guest contact details for check-in staff, audit logging of sensitive reveals, and least-privilege access for our staff. No system is perfectly secure, but we review these measures regularly.

8. Cookies

We use essential cookies to keep you signed in and secure your session, and limited analytics cookies to understand how the product is used. We do not use advertising cookies. You can manage or delete cookies through your browser settings; disabling essential cookies will prevent sign-in. See our Cookie Policy for details.

9. Changes

We may update this notice and will post the revised version on this page with a new "last updated" date.