✦ Privacy Policy
Privacy Policy
Last updated 1 July 2026
This Privacy Policy explains what personal data Ftesa Ime (operated by AmalBryx, "we") collects at ftesa-ime.com, how we use it, and the choices you have.
1. Who we are
Ftesa Ime is a digital-invitation service operated by AmalBryx. For any privacy question, contact privatesia@ftesa-ime.com.
2. Data you provide
We collect the information you give us to run the service:
- Account: your email address, a securely hashed password, and an optional display name. If you sign in with Google instead, we receive the name, email address and profile picture on that Google account and store the sign-in tokens Google issues to us.
- Invitation content: event details, host names, the venue name and address, dress code, and any photos, audio, story text and music you upload.
- Guest list: the names, household names, number of seats and email addresses you add so we can send your invitations.
- RSVP responses your guests submit: their name, email, attendance, party size, an optional dietary note and an optional message. A dietary note can reveal health or religious information, so treat it as sensitive — it is visible to you as the host and can be exported to a spreadsheet. A guest's message stays private unless you approve it for the public wishes wall.
- Holiday planner: if you use the holiday planner, we store the plan under your account — country, year, how many days off you have, the days you mark, and any holiday you add, rename or hide.
3. Data collected automatically
Every page — including a public invitation page a guest opens — loads Vercel Web Analytics, which measures page views plus a few product events (which opening film played, its mood, the invitation's tier). We do not use advertising trackers and we do not sell or share data for advertising.
Your IP address is used but not stored in our database: it is the key of the short-lived counter that rate-limits repeated RSVP submissions and password-reset requests. When the Upstash rate-limit cache is configured, that key — which contains the IP — lives there until the ten-minute window lapses.
If error monitoring (Sentry) is switched on, crash and performance diagnostics including the page URL and browser are sent to it. Session replay is switched off.
4. How we use your data
- Create, host and display your invitations.
- Deliver invitation emails and reminders to the guests you choose.
- Collect and show you RSVP responses.
- Send service messages such as email verification and password reset.
- Keep the service secure and prevent abuse (e.g. rate limiting).
5. Guest data and your responsibility
When you add guests' names and email addresses, you confirm you have a legitimate basis to contact them. We process that data on your behalf solely to deliver your invitation and collect RSVPs.
Sending an invitation is tracked, and you should tell your guests so. For each guest we record whether the email was delivered, opened, bounced or was reported as spam — Resend reports those events back to us — and the moment they first open their personal link. All of it is visible to you on your guest list. Every email carries an unsubscribe link: using it stops further emails about that invitation, while their invitation link keeps working.
6. Service providers (subprocessors)
We share data only with providers that help us run the service, and only for that purpose:
- Resend — sends every email we send: invitations, reminders, sign-in links, email verification and password resets. It also reports back whether each invitation was delivered, opened, bounced or marked as spam.
- Vercel — hosts the application and provides the Web Analytics described above, so it processes every request to the site.
- Contabo — the rented server on which our PostgreSQL database and our MinIO object storage (the photos, audio and video you upload) run. Both are operated by us rather than by a managed third-party service.
- Upstash — Redis rate-limit counters, when configured. The counter key contains the visitor's IP address and expires with the window.
- Sentry — error and performance diagnostics, only when it is configured. Session replay is off.
- Paysera — payment processing. Payments are switched off today; when they are enabled, Paysera receives the order reference, the amount and the payer details entered at checkout. Card details never reach us.
- Google — only if you sign in with Google, which tells us your Google account's name, email and picture; and for two typefaces that the animated card on our home page loads from Google's font CDN, which lets Google's servers see your IP address while that animation renders.
7. Cookies
We set two cookies. One is the sign-in cookie that keeps you logged in. The other is set only when you arrive through a link carrying a partner code (?ref=…): a thirty-day, server-only cookie that credits the partner who referred you if you later buy something. We set no advertising or cross-site tracking cookies.
We also use your browser's own storage, which is not a cookie and never reaches our servers: your light/dark theme choice, a per-tab note that the opening animation has already played, and — in the holiday planner — your notes, favourites and country preference.
A venue's “open in Maps” button is an ordinary link, not an embedded map. Nothing is sent to Google unless a guest taps it, and from there Google's own terms apply.
8. Data retention
Nothing is deleted on a schedule. The service runs no automatic clean-up job, so anything not covered below stays until it is deleted by hand.
Deleting an invitation is immediate and total: the invitation, its guest list, every RSVP with its dietary notes and messages, its schedule, story, gallery and music, any payment records tied to it, and the uploaded files themselves are removed and cannot be recovered.
Sign-in and email-verification links expire after 24 hours and password-reset links after one hour; each is deleted the moment it is used or replaced.
Everything else — your account, your invitations, and the payment-notification records we keep so the same payment is never processed twice — stays until you ask us to delete it. There is no self-serve “delete my account” button yet: write to privatesia@ftesa-ime.com and we will delete the account and its data.
9. Your rights
You may access, correct, export or delete your personal data. Some of it you can already do yourself: any invitation can be deleted from your dashboard, and your RSVP list exports to a spreadsheet in one click. For the rest — a copy of your account data, or deleting your account entirely — contact privatesia@ftesa-ime.com and we will respond within a reasonable time. If you are in the EU/EEA, you have rights under the GDPR, including the right to lodge a complaint with a supervisory authority.
10. Children
The service is not directed to children under 16, and we do not knowingly collect their personal data.
11. Security
Passwords are stored hashed, access is restricted, and data is transmitted over encrypted connections. No method of storage or transmission is 100% secure, but we work to protect your data.
12. Changes to this policy
We may update this policy. Material changes will be posted on this page with a new “last updated” date.
13. Contact
Questions about this policy: privatesia@ftesa-ime.com.