Privacy Policy
Last updated September 29, 2026
This policy explains what Evnts (evnts.rsvp) collects, how we use it, and your choices. We collect only what we need to run your event and send the messages you ask for.
Information we collect
From hosts and guests: your name, mobile number, and (optionally) email address — on a paid event, the email address you enter on Stripe's checkout page is attached to your RSVP so we can send your confirmation there. From hosts: the event details you enter (title, description, date, place, images, questions). From guests: your RSVP response and anything you choose to add, such as a note or party size. If you run a community: its name, link, description and cover. If you follow one: your number and which community, with the consent record below. If a host puts you on a member list: your name and number as the host gave them, used only for that host's Members only tickets and member perks — never to message you. If you join a community's membership (free or paid): your number, the tier and plan, whether it's active and when it renews (from Stripe, for a paid one), and that joining made you a follower, with its consent record; we text you when you join and if a paid membership ends. On a host's event, your RSVP keeps the tier it was priced with and what it included, and the host and their co-hosts see it. At events with door check-in, the host's records show when you arrived. For hosts and co-hosts, each check-in records which number did it and a random id for the browser used. Deleting your data removes your number and that id from those records. If you join a students-only tier: the school email address you type is used once, to email you a code, and is not stored; we keep only its domain (for example “school.edu”) and the date it was checked, on your membership. Your data download shows the lists you are on (by name), and deleting your data removes you from every list. We also process limited technical data, such as your IP address, to prevent abuse and rate-limit requests, and we keep aggregate, non-identifying usage counts. See “Cookies & tracking” below for the cookies and device storage we use and the choices you have.
How we use it
To operate the service: to publish and manage the event, to show hosts their guest list, and to send the messages you opted into, including verification codes, RSVP confirmations, reminders, event updates, and the host management link. We do not show third-party ads on the service and we do not sell your data. If you accept ad measurement (see “Cookies & tracking”), we use the ad click identifier only to measure which of our own ad campaigns brought you here.
Cookies & tracking
We keep cookies and device storage to a minimum, and we do not use third-party advertising cookies or cross-site tracking cookies.
Essential. One first-party cookie keeps a host signed in. It is required for the service to work, so it does not need consent. It is not used for advertising.
Analytics. We use Cloudflare Web Analytics, which is cookieless and privacy-first: it counts aggregate, non-identifying page traffic and does not track you across other sites or build a profile of you.
Ad measurement (optional). If you arrive from one of our ads, we can store the ad campaign and click identifier in your browser's local storage for up to 30 days and count it in our own aggregate numbers, so we can see which ads work. Today nothing is sent back to the ad platform; if that changes, this policy will say so first. This is off until you choose Accept in the cookie banner — choosing Essential only, or ignoring the banner, leaves it off. You can change your choice anytime with “Cookie preferences” in the footer. We never share your name, mobile number, or email for this.
We also use your browser's local storage for basic functionality, such as remembering your own RSVP on your device and saving an in-progress invite draft. That stays on your device, except the random door id a host's browser sends with each check-in.
Bot protection. To keep automated abuse off the create, RSVP, host sign-in and support forms, we use Cloudflare Turnstile — a privacy-preserving alternative to CAPTCHAs that runs a lightweight check in your browser and does not track you across sites. Your use of it is subject to Cloudflare's Turnstile Privacy Addendum.
Text messaging
You opt in to text messages by providing your mobile number and checking the consent box on our form. You may receive a verification code, an RSVP confirmation, a reminder, event updates, (for hosts) a management link and a day-after note asking how the event went, and, if you follow a community, a text when it posts a new event — at most four a month from one community; tap Unfollow on its page, or reply STOP, to end them. Message frequency varies and message and data rates may apply. Reply STOP to cancel and HELP for help.
If a host added you. A host who knows you can add you to their guest list and give us your number. In that case you receive one message from that host through us (a text in the US and Canada, WhatsApp elsewhere) — their name, the event and your RSVP link — under the consent the host gave on your behalf, and nothing more unless you confirm your number from that link. Ignore it and nothing else follows; reply STOP to a text and we will not text that number again.
Consent record. Each time you opt in — the checkbox on the RSVP or publish form, the “Text me a code” tap when signing in, or Follow on a community page — we store a record of it: your number, the time, your IP address and browser, the exact wording you agreed to, and when you confirmed the code we texted. It is the proof that we had your permission to text you. You can see every record in “Your data”. We keep these records for four years, including after you delete everything else about your number, because a dispute about a text can be raised for that long.
We do not sell your information. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text-messaging opt-in data and consent are not shared with any third party.
Who we share it with
The host. A host sees the RSVPs to their events, as described on the invite. If you follow a community, its host sees that you follow and your number (it is in their data download), so the audience stays theirs if they leave; nobody else sees who follows.
We share information only with the service providers that help us deliver the product, each solely to operate the service: our hosting and infrastructure provider (Cloudflare); our messaging provider (Telnyx, and for WhatsApp messages Meta's WhatsApp Business Platform, which sees your number and the message); our email provider (Resend); and — for paid events — our payments provider (Stripe). When you pay for a paid event, your card details go to Stripe on a Stripe-hosted page and never reach us; we store only that the RSVP was paid, the amount (and any optional tip to us), and Stripe's reference for it. Stripe also receives the guest's name and the tickets bought, so the host's own Stripe Dashboard shows who paid, and the email address the guest gave us (if any) to fill in the checkout page — never the guest's mobile number. For a community membership, Stripe holds the subscription on the host's account (with the email and card entered on its page); we send it only the community and the plan, never the member's number.
AI drafting. When a host uses the invite assistant or “rewrite”, the text they typed (the prompt, and the event's title and description) goes to our AI provider, Anthropic, to produce the draft, through Cloudflare's AI Gateway. Nothing else about the host or any guest is sent, and the text is not used to train models. The gateway keeps a log of each prompt and draft, which we use to troubleshoot drafting and clear periodically; it is not tied to your mobile number. Cover images are generated on Cloudflare's own infrastructure.
Address suggestions. When a host types in the Place field while making an invite, what they type goes to Google (the Google Maps Platform Places API) to suggest matching places. After an AI draft that names a place, the place name — and the address, unless the host chose to hide it until RSVP — goes to Google the same way, to offer a match the host can pin. Each request carries the rough area of the host's internet connection (city level, to rank nearby places first — not a precise location). Nothing else about the host or any guest is sent. If the host picks a suggestion, we keep Google's id for that place so Directions opens the exact spot; like the address, it is shown only to guests allowed to see the address. Google handles the request under Google's privacy policy.
Weather. The invite can show a forecast for the day. For that, the event's public place name — never the address — goes to Open-Meteo, a free weather service.
Hosts who take payments connect their own Stripe account, so the identity details Stripe collects from them are held by Stripe under Stripe's privacy policy. When you RSVP, the host of that event can see the information you submit. We do not sell your information or share it for others' marketing.
Retention and your choices
We keep event and RSVP data while the event is active so it can function; events are deleted a year after their date (cancelled ones after 30 days). Messages you send to Support, replies to “How did it go?”, and email you send us are kept for two years, then deleted. A host's member lists are kept until the host deletes them or their data; anyone on a list can remove themselves by deleting their data below — which also stops any membership they pay for from renewing. Guests can remove their own RSVP at any time, and texting STOP opts you out of future texts. To see or erase everything we hold against your mobile number — events you host, RSVPs you made as a guest, co-host access, your community and its followers, the communities you follow, member lists you keep or are on — sign in at evnts.rsvp/host and use “Your data”: download a copy, or delete it all in one step. Support messages you sent stay for their two years, but your number and contact details are removed from them, so they can no longer be tied to you. Anything we can't key on a number, contact us at the address below.
Security and children
We use reasonable measures to protect your information, including encrypted transport and access controlled by secret tokens. The service is intended for adults arranging events and is not directed to children under 13.
Changes to this policy
We may update this policy from time to time; the "last updated" date above will change when we do.
Questions? Email support@evnts.rsvp.