InviteHandle Privacy Policy
Effective date: Aug 13, 2026
هذه الوثيقة القانونية معتمدة ومنشورة باللغة الإنجليزية فقط. لم تُعتمد بعد ترجمة عربية، والنص الإنجليزي أدناه هو النص الملزم.
1. About this Privacy Policy
This Privacy Policy explains how InviteHandle (“InviteHandle”, “we”, “us” or “our”) collects, uses, shares, stores and protects personal data when you visit invitehandle.com, submit an inquiry, use an InviteHandle account or event page, communicate with us, or otherwise use our services.
This policy is intended for users in the United Arab Emirates and the Kingdom of Saudi Arabia. Additional terms may apply where another law applies to a particular user or processing activity.
2. Who this policy applies to
This policy applies to prospective customers who submit inquiries, customers and event hosts who use our services, guests whose information is entered into an InviteHandle event, authorised team or operator users, and visitors to our public website.
If a customer or event host gives us personal data about a guest or another person, that customer or host is responsible for having the authority to provide it and for giving any required notice or obtaining any required consent.
3. Personal data we collect
Information you provide to us may include your name, email address, telephone or WhatsApp number, preferred contact method, event type, event date, event city or location, guest-count range, selected package, referral source, inquiry notes, event content, guest details, account details, communications, support requests, and any other information you choose to provide.
Information collected automatically may include browser and device information, approximate location derived from network information, IP address where received by our service providers, pages viewed, interactions with the booking funnel, timestamps, language, landing page, referrer, and campaign information such as utm_source, utm_medium, utm_campaign, utm_term, utm_content, gclid, gbraid and wbraid when present.
When a booking form starts, we generate a random transaction identifier called tid for that booking journey. The same tid is used across approved booking-funnel events and, if the inquiry is submitted successfully, stored with the inquiry. The tid continues across a refresh in the same browser tab. A new explicit booking action, a successfully completed inquiry, expiry after six hours, or a separate browser tab starts a new journey with a new tid. We do not use tid as Google Analytics user_id, and we do not send names, email addresses, phone numbers, exact addresses, free-text answers or a customer identity lookup linked to tid to Google Analytics.
4. How we collect personal data
We collect personal data directly from you, from a customer or event host acting on your behalf, through your use of the website and services, from communications with us, and from service providers that support website hosting, analytics, advertising, communications, security and customer operations.
During a same-tab booking journey, we use sessionStorage to preserve the random tid and, where supported campaign parameters are present, first-touch attribution while a visitor moves to and uses the booking form. We also use sessionStorage for a bounded, short-lived retry queue containing approved non-identifying booking-funnel event data when delivery to our first-party event ledger is interrupted. The queue holds no more than 12 events, expires events after 30 minutes, and is removed as delivery succeeds. We store only the defined attribution and funnel fields, not arbitrary URL parameters or contact details.
5. Why we use personal data
We use personal data to respond to inquiries; prepare proposals or quotations; take steps requested before entering into a contract; provide, administer and support InviteHandle services; create and manage events, accounts, guest lists, invitations, messages and automations; communicate by email, telephone or WhatsApp about an inquiry or service; verify access and prevent fraud or misuse; maintain security; troubleshoot and improve the website; measure booking-funnel performance and advertising effectiveness; comply with legal and regulatory duties; establish, exercise or defend legal claims; and keep required business records.
Where permitted by applicable law, our processing may be necessary to respond to your request, enter into or perform a contract, comply with a legal obligation, protect legitimate interests that are not overridden by your rights, or protect a person’s vital interests. We rely on consent where applicable law requires it, including for optional future marketing or optional disclosure to event partners.
6. Analytics, advertising and tid
We use Google Analytics 4 to understand how visitors use our website and progress through the booking funnel. Approved funnel events may include a random tid, a random event identifier called event_id, and limited non-contact context such as form name, locale, event category, city category, days until the event, guest-count band, package name and displayed package price. Displayed package price is reporting context and is not treated as confirmed revenue.
We also store a first-party copy of approved booking-funnel events in our Supabase event ledger so we can reconstruct a booking journey, verify delivery and reconcile an event with Google Analytics using event_id. The ledger may contain tid, event_id, event name and time, page path, locale, controlled booking categories, package and price context, referral and campaign attribution, and entry-CTA context. It does not contain contact names, email addresses, telephone or WhatsApp numbers, exact event dates, exact addresses, notes or other unrestricted free text.
After an inquiry is successfully saved, we may send a generate_lead event containing the persisted tid and approved non-identifying reporting context. This event may be imported into Google Ads to measure lead conversions. A failed or unconfirmed inquiry is not intended to generate that confirmed-lead event.
The tid may be sent with approved funnel events regardless of a cookie preference because it is a random identifier limited to one booking attempt and is not used to identify or contact the visitor. Disabling cookies may still limit Google’s ability to recognise a browser, session or advertising source. We do not claim that all measurement stops when cookies are disabled.
7. When we share personal data
We may share personal data with hosting, database, cloud, security, communications, analytics, advertising, payment, professional-adviser and customer-support providers that process information for us or provide services we use. This may include Google for analytics and advertising measurement, and Meta or WhatsApp service providers where WhatsApp communications are used.
We may disclose information to government bodies, regulators, courts, law-enforcement authorities or professional advisers where required by law or reasonably necessary to protect rights, safety or legal interests. We may also transfer information as part of a merger, acquisition, financing, reorganisation or sale of all or part of the business, subject to appropriate safeguards.
We share contact details and event requirements with selected event partners only where the user has given the separate consent required for that sharing. We do not treat submission of an inquiry as consent to unrelated partner marketing.
8. International processing and transfers
InviteHandle and its service providers may process personal data outside the country where it was collected, including in countries where Google, Meta, hosting, database or other technology providers operate. Those countries may have different data-protection laws.
Where applicable law requires it, we use appropriate contractual, organisational and technical safeguards and limit transfers to the personal data reasonably necessary for the relevant service.
9. How long we keep personal data
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including providing services, responding to inquiries, maintaining security, resolving disputes and meeting legal, accounting and regulatory duties. We then delete, anonymise or securely isolate it unless continued retention is required by law.
Retention periods vary according to the type of record, the service provided and applicable legal, accounting, security and operational requirements. Raw events in our first-party booking-funnel ledger are retained for 24 months from the server-recorded receipt time and then deleted. Analytics data held by third-party analytics services follows the retention settings configured for the relevant service. The tid, attribution and retry queue held in sessionStorage normally end when the browser tab or session is closed, with the retry queue additionally limited as described above. We periodically review retained data and delete, anonymise or securely isolate it when it is no longer required.
10. Security
We use reasonable technical and organisational safeguards designed to protect personal data against accidental or unlawful loss, misuse, alteration, unauthorised access or disclosure. No internet service is completely secure, and we cannot guarantee absolute security.
Users are responsible for protecting account credentials and event access codes, using them only with authorised persons, and notifying us promptly if they suspect unauthorised access.
11. Your privacy rights
Subject to applicable law and any lawful exceptions, you may have the right to be informed about our processing; request access to or a copy of your personal data; request correction, completion or updating; request deletion or destruction when the data is no longer required; request restriction or cessation of certain processing; withdraw consent where processing is based on consent; object to certain processing; and complain to the competent data-protection authority.
To exercise a right, submit a request through our website contact form. We may need to verify your identity and authority before acting. Withdrawing consent does not affect processing already carried out lawfully before withdrawal and does not prevent processing that relies on another lawful basis.
12. Marketing and partner sharing
Messages necessary to respond to or manage your inquiry are service communications, not permission for unrelated future marketing. We send optional future InviteHandle marketing only where the required consent has been obtained, and we provide a way to unsubscribe or withdraw consent.
Where you separately consent to event-partner sharing, we may share only the contact and event information reasonably necessary for the relevant offer and record the partner, disclosure time and consent state. Declining an optional consent does not prevent you from submitting an inquiry.
13. Children
InviteHandle is not intended for children to submit inquiries or create accounts independently. If personal data about a child is needed for an event, the responsible customer or host must have the authority required by applicable law. Contact us if you believe a child’s information was provided without proper authority.
14. Third-party links and services
Our website or services may link to third-party websites, platforms or services. Their privacy practices are governed by their own notices, and we are not responsible for those independent practices.
15. Changes to this policy
We may update this Privacy Policy to reflect changes in our services, providers, legal requirements or data practices. We will publish the updated version with a revised effective date and provide additional notice where required.
16. Contact and complaints
For privacy questions, rights requests, consent withdrawal or complaints, submit a request through the contact form on invitehandle.com.
You may also complain to the competent data-protection authority in the jurisdiction that applies to you. We encourage you to contact us first so we can try to resolve the concern.