What we store, why, for how long, and how to make it go away.
Last updated 1 September 2026
The short version: we store the party details you type, the RSVPs your guests send, the photos you upload, and a log of who unlocked the album. We do not run analytics, advertising or tracking of any kind. We never sell anything to anyone. Ask us and we delete the lot.
| Your email address | It is your login — we email you a one-time code instead of keeping a password. It also receives RSVP notifications and album-view alerts. |
|---|---|
| The party details you type | The child's first name or nickname, the age, the date, time, venue, a map link, and any note or tagline. All of it is shown on the invite page you publish. |
| Photos and video | The files you upload for the album, plus the thumbnails we generate from them. |
| Payment record | Stripe's session and payment reference, the amount, the currency and the status. Not your card number — that is entered on Stripe's own page and never reaches us. |
| RSVP replies | The name they type, whether they are coming, how many children, and the optional message and contact detail they choose to add. Visible to you, the host. |
|---|---|
| Album access log | Email address, IP address and timestamp, each time someone unlocks the album. This exists so you can see who has looked at photographs of your child, which is the whole reason the album is gated. |
| One-time codes | Stored as a keyed hash, never as the digits themselves, and deleted the moment they are used or expire (ten minutes). |
| Session cookie | A signed cookie that says "this address unlocked this album", valid for 48 hours. It is not a tracking cookie: it identifies nothing outside the album it was issued for, and there is no cookie at all until someone signs in. |
The pages are about children, and that shapes how this works. Nobody under 18 has an account, and we collect nothing directly from a child — every field is filled in by an adult host or an adult guest. Photographs of children are uploaded by the host under section 4 of the terms, which requires the other parents' consent. Invite pages are served with a noindex instruction so they stay out of search results, and album media is never reachable without a verified email session. If you are a parent who wants a photograph of your child removed from someone's album, email us and we will remove it — you do not have to be the customer to ask.
We use two sub-processors, and no others:
Both are US companies, so data is processed in the United States. We do not share your data with anyone else, and there is no analytics provider, ad network, social pixel or third-party font-tracking script on any page — the only external request an invite page makes is for its web fonts.
| Invite content, RSVPs, photos | For the twelve-month term, plus the archive period afterwards, until you ask us to delete them. |
|---|---|
| Album access log | Twelve months, then deleted. |
| One-time codes | Ten minutes, or until used. |
| Payment records | Seven years. We are required to keep proof of a sale for tax and accounting; this is the one category a deletion request cannot clear, and it is a reference number and an amount, not your content. |
Email rsvp@qaffaf.com from the address you signed up with, with the link to the page. We will delete the page, the RSVPs, every photo and video, the thumbnails and the access log within seven days, and reply to confirm it is done. Deletion is permanent — export anything you want to keep first. You can also ask us for a copy of everything we hold about you, or to correct something that is wrong, using the same address.
Everything is served over HTTPS. Album files are not public: each request is checked against the album it belongs to and the session that asked for it, so no guessed or copied URL reaches another family's photos. Login codes are hashed, sessions are signed and expire, and album sessions can be revoked in one action from your dashboard if you ever need to lock everyone out.
If something is exposed that should not have been, we will email every affected host within 72 hours of finding out, with what happened and what to do. We would rather send an embarrassing email than a quiet one.
If this policy changes in a way that affects data we already hold, we will email you before it takes effect.