Privacy Policy

Last updated: 30 August 2026

This policy explains what data we collect, why, how we store it and who we share it with. It follows the Personal Data Protection Law of the Kingdom of Saudi Arabia and its implementing regulations.

What we collect from you

  • Account data: name, mobile number, and a hashed password.
  • Event data: title, type, date, venue, invitation wording and the chosen design.
  • Payment data: from the payment provider we receive the transaction status, its reference, and the last four digits of the card only. We never store a full card number or security code.
  • Technical data: IP address, browser type and usage logs, for security and fault diagnosis.

Guest data

When a host uploads a guest list we process guests' names, mobile numbers, RSVPs, companion counts and check-in times.

For this data the host is the controller and we are the processor: we process it to run the service on their behalf, we do not use it for any marketing of our own, and we do not sell it.

A guest who wants their data corrected or deleted can contact the host directly, or contact us and we will pass the request on.

Legal basis

We process your data to perform our contract with you in providing the service, to comply with Saudi law on invoicing and record-keeping, and for a legitimate interest in the platform's security and the prevention of abuse.

How we use data

  • Running the service: creating invitations and their links, collecting RSVPs, checking guests in, and producing the host's reports.
  • Operational messages: SMS to verify a number, or notices about your event.
  • Security: detecting unauthorised access attempts and limiting abuse.
  • Billing: issuing and retaining invoices as required.

We never send marketing messages to guests.

Sharing

We do not sell personal data. We share it, as narrowly as possible, with:

  • The payment gateway, to complete a transaction.
  • The SMS provider, to deliver verification codes.
  • The hosting provider, as the place the platform runs.
  • Competent authorities, where required by law or court order.

Where data is kept, and for how long

Data is held on servers at a hosting provider and travels over an encrypted connection.

We keep event and guest data for as long as the host's account exists, and a host may delete an event and its guest list at any time. Invoice records are kept for the period Saudi accounting and tax rules require.

Cookies

We use strictly necessary cookies only: keeping your session open, remembering your chosen language, and protecting forms. We use no advertising or tracking cookies.

Your rights

You have the right to be informed about your data, to access it and obtain a copy, to have it corrected, to request its destruction, and to withdraw consent where processing rests on it. To exercise any of these write to [support email]; we respond within thirty days.

If you are not satisfied with our response you may complain to the competent data protection authority in the Kingdom.

Security

Passwords are stored hashed and cannot be reversed, invitation links and check-in codes are signed so they cannot be guessed or forged, and administrative access is restricted and logged. No system, however, can promise absolute security.

Children

The service is intended for those aged eighteen and over. Where a child's details appear in a guest list, that is the host's responsibility and we use them only to issue that invitation.

Changes to this policy

We may update this policy; the date of the last update appears at the foot of this page. Where a change is material we notify account holders.

Contact

For any question or request about your data: yahlainvite@gmail.com