Privacy Policy
Effective Date: June 16, 2023
Last Updated: July 20, 2026
Invitio (Invitio Events brand) is committed to protecting the privacy and security of the personal data we process. This notice describes what information we collect, how we use it, with whom we share it, how long we keep it, and what rights you have, in connection with our digital invitation platform, the website https://invitio.events, related applications, and optional connectors (including ChatGPT / MCP) (together, the "Platform").
1. Data controller and contact
The data controller is Invitio (Invitio Events). To exercise ARCO rights (access, rectification, cancellation, and objection), ask privacy questions, or request information about how we process your data, email invitio.soporte@gmail.com.
2. Scope
This notice applies to use of the Platform, including: account creation and management; digital invitations and events; guest lists and RSVPs; Planner features and Pics albums; WhatsApp or other enabled messaging; payments and subscriptions; analytics and cookies; and the optional Invitio connector for ChatGPT or other MCP clients you authorize.
3. Personal data we collect
We collect data you provide directly, data generated through use of the Platform, and data we receive from providers when needed to deliver the service. The main categories are:
3.1 Account and authentication
- Name and profile details
- Email address
- Phone number (for example, for OTP sign-in)
- Identity-provider profile data (for example, Google OAuth)
- Language/locale preferences and user type
- Push notification tokens (when you use mobile apps)
3.2 Events and invitations
- Event name, date, time, type, and plan
- Invitation content and design (copy, colors, blocks, media)
- Venue or location details (including coordinates when configured)
- Optional links or integrations (for example, music or gift registries)
- Invitation portal passwords, when you configure them
3.3 Guests and attendance
- Guest display name
- Phone number and country code (when captured for contact or messaging)
- RSVP status (Confirmado, Pendiente, NoAsistira, or equivalents)
- Adult and children counts, check-in status, and table assignments
- Guest passwords, tags, guestbook messages, and public RSVP data
- Technical identifiers related to guests and Pics albums (for example, public tokens)
3.4 Messaging (WhatsApp and related channels)
- Phone numbers used for sending or verification
- Template and message metadata (delivery status, integration identifiers)
- Connection data for Meta WhatsApp Cloud API or other messaging providers you enable
3.5 Payments and billing
- Purchase and subscription records (amount, currency, product, payment source, event/invitation identifiers)
- Customer identifiers at payment gateways (for example, Stripe)
- Card or payment-instrument details are processed by payment providers; Invitio does not store full card numbers in its database
3.6 Analytics, device, and marketing
- Device/browser identifiers, operating system, and product events
- IP address and user-agent (for example, for ad attribution and security)
- Cookies, local storage, and measurement pixels (see the cookies section)
- Contact details for commercial communications or reminders, where applicable
3.7 Support and feedback
- Messages sent to support, complaints, suggestions, and satisfaction surveys
4. Purposes of processing
We use personal data for the following purposes:
- Provide, operate, and maintain the Platform (accounts, events, invitations, collaborators)
- Manage guest lists, RSVPs, check-in, seating, and Pics albums
- Send transactional notifications and reminders related to your account or events
- Send WhatsApp or other channel messages when you or your organization request it
- Process payments, subscriptions, refunds, and fraud prevention
- Provide customer support and resolve disputes
- Improve, personalize, and secure the Platform (product analytics, error diagnosis)
- Advertising measurement and marketing, in accordance with applicable law and, where relevant, your consent or legitimate interest
- Comply with legal obligations and respond to lawful requests from authorities
- Enable optional connectors (including ChatGPT/MCP) that you expressly authorize
5. ChatGPT / MCP connector (OpenAI and compatible clients)
If you connect Invitio to ChatGPT or another MCP client, you authorize access via OAuth 2.1. The scopes requested for this connector are openid, email, and profile (phone and offline_access are not requested for MCP). Consent is shown on Invitio’s authorization screen.
MCP tools operate only on events and guests your account can access (owner or collaborator), subject to access controls (including row-level security / roles). Read tools retrieve data; write tools may create or update allowed fields. No MCP tool deletes events or guests or sends messages to third parties (email, WhatsApp, etc.).
Tool responses are returned to the MCP client (for example, ChatGPT) as JSON, both as text content and as structured content (structuredContent). They may include nested objects (for example, event together with guests, rsvp, checkin, or tables).
Fields that may be sent or returned through MCP (including internal identifiers and nested data):
5.1 Events
- id (event UUID)
- name (event name)
- date (date)
- time (time)
- type (event type)
- plan (event plan or tier)
5.2 Guests
- id (guest UUID)
- name (display name)
- status (Confirmado, Pendiente, or NoAsistira)
- adults (number of adults)
- children (number of children)
- checked_in (attendance / check-in)
- table_id (assigned table, if any)
5.3 Aggregates and tables
- RSVP counts: confirmed, pending, declined, total_parties, total_adults, total_children, total_guests
- Check-in counts: checked_in_parties, not_checked_in_parties, total_parties
- Tables: id, name, capacity, occupied
5.4 Typical tool inputs
- evento_id, guest_id, mesa_id
- Optional filters (for example, status, limit, name search query)
- Update fields: name, status, adults, children, checked_in, date, time
Invitio does not expose through MCP: guest phone numbers, guest passwords, collaborator emails, full database dumps, or internal debug fields.
Additional effects of write tools: they update data in your Invitio account; some updates may refresh associated Apple Wallet passes. Invitio does not operate a separate analytics store of MCP request/response bodies; errors may be recorded in server logs for operations and security.
You can revoke access by disconnecting the connector in ChatGPT (or another client) and/or revoking sessions/authorizations associated with your Invitio account.
6. Recipients and processors
We share personal data with providers that help us operate the Platform, only as needed for each purpose, and when required by law or authorized by you (for example, when you connect ChatGPT). Recipient categories include:
- Infrastructure and database: Supabase (authentication, database, and storage)
- Payments: Stripe, PayPal, Mercado Pago, RevenueCat / app stores (Apple, Google), depending on the method chosen
- Messaging: Meta (WhatsApp Cloud API), Twilio, and related providers
- Email: Amazon SES (transactional) and Resend (communications and operational marketing)
- Marketing and CRM: Klaviyo
- Google: OAuth authentication, Maps, reCAPTCHA, advertising/analytics (including Tag Manager / Analytics), BigQuery (when configured), and Google Wallet
- Apple Wallet (guest access passes)
- Microsoft Clarity (on-site behavior analytics)
- Background job orchestration: Inngest
- OpenAI / ChatGPT or other MCP clients, only when you connect the connector
- CDN and static asset delivery (for example, CloudFront)
- Auxiliary attribution or approximate IP-based geolocation services, when used for advertising or security
- Competent authorities, when required by law
7. Cookies and similar technologies
We use cookies and similar technologies for authentication, security, preferences, analytics, and advertising measurement.
- Essential cookies: session and authentication (for example, Supabase Auth cookies)
- Analytics and marketing: Google Tag Manager / Google Analytics, Meta Pixel and Conversions API, Microsoft Clarity, Klaviyo onsite scripts, when active
- Google ads click identifiers (for example, gclid / wbraid / gbraid) retained for approximately 90 days
- Browser local storage: cookie-consent preference, public RSVP continuity, and product-analytics identifiers
- reCAPTCHA and related security cookies on forms
You can manage cookies in your browser settings. Some Platform features may not work correctly if you block essential cookies. We display a cookie notice on the site; purposes are detailed in this notice.
8. International transfers
Some providers may process data outside Mexico. When that occurs, we adopt reasonable contractual and organizational measures available under applicable law to protect your personal data.
9. Data retention
We retain personal data while you maintain an account or service relationship with Invitio, or while it remains necessary for the purposes described. After account deletion or a cancellation request, we delete or anonymize information within a reasonable operational period, except where we must retain it for legal, accounting, billing, fraud-prevention, or dispute-resolution obligations.
The advertising click identifiers referenced above are retained for approximately 90 days. Signed storage URLs are typically short-lived. Payment, messaging, and marketing providers may retain data under their own policies.
10. Your rights and controls
Under applicable Mexican law (including the LFPDPPP), you may request access, rectification, cancellation, or objection (ARCO rights), and limit use or disclosure where applicable, by writing to invitio.soporte@gmail.com. You may also:
- Update account details in the Platform, when the feature is available
- Request account deletion from your profile (subject to technical and legal limitations)
- Unsubscribe from marketing emails via unsubscribe links or by contacting us
- Disconnect the ChatGPT/MCP connector in the relevant client
- Manage cookies and permissions in your browser or device
11. Children
The Platform is not directed to children under 13. We do not knowingly collect personal data from children under that age. If you believe a child has provided us with data, contact us so we can delete it where appropriate.
12. Security measures
We implement reasonable technical and organizational measures to protect personal data against unauthorized access, loss, alteration, or improper disclosure (including access controls, encryption in transit where applicable, and account isolation). No system is completely secure; we cannot guarantee absolute security.
13. Visibility of digital invitations
You control how each invitation is shared. Invitations with a public or shareable link may be viewed by anyone who has the URL. Password-protected portals or other restrictions limit access according to the settings you choose. Collaborators you invite to an event may access event and guest data according to their role. Invitio does not deliberately publish your invitations to unrelated third parties, except as described in this notice (providers, connectors you authorize, or legal requirements).
14. Changes to this notice
We may update this privacy notice periodically. The “Last Updated” date indicates the current version. Continued use of the Platform after changes are posted means you are aware of the updated version. For material changes, we will try to provide reasonable notice through the Platform or by email when feasible.
15. Governing law
This notice is governed by the laws of Mexico. Disputes related to personal data protection may be brought before the Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI) or other competent authorities, without prejudice to your rights before Mexican courts.
16. Contact
For any questions about this notice or how we process your personal data:
- Controller: Invitio (Invitio Events)
- Email: invitio.soporte@gmail.com
- Website: https://invitio.events

