Privacy Policy
Last updated: June 2026
1. Data controller
The data controller is Stefano Frediani (a private individual).
For any request regarding your data, write to info@sponsalia.app.
2. What data we collect
We process different categories of data depending on how you use the service:
- Account data (customers): name and email, handled through our authentication provider.
- Invitation content: the couple’s names, date, schedule, texts, FAQs and the guest list (names) you enter.
- RSVP data, provided by guests: attendance, any dietary needs or notes, whether children attend, and an optional message.
- Payment data: handled directly by the payment provider; Sponsalia does not store your card details.
- Technical data: the minimum needed to operate the service securely (e.g. a session cookie and a language-preference cookie).
3. Why we process data and on what legal basis
- To provide the service (create, publish and manage the invite, collect RSVPs): performance of the contract (Art. 6.1.b GDPR).
- To handle payment: performance of the contract and legal obligations (Art. 6.1.b and 6.1.c).
- To send service communications (e.g. confirmations, account notices): performance of the contract.
- To ensure security and prevent abuse: legitimate interest (Art. 6.1.f).
As a customer you decide which guest data to enter: for that data Sponsalia acts as a technical provider and you are responsible for processing it lawfully.
4. Providers that process data on our behalf
To run the service we rely on trusted providers (data processors), including:
- Clerk — authentication and account management.
- Supabase — database and storage of service data.
- Vercel — application hosting.
- Stripe — payment processing.
- Resend — transactional email delivery.
Some providers may process data outside the European Union: where they do, the transfer is based on appropriate safeguards (e.g. the EU Commission’s standard contractual clauses).
5. How long we keep data
We keep data for as long as needed to provide the service. Invitation content and RSVPs remain available while your account or invite is active; they are deleted on your request or after a period of inactivity. Payment-related data is kept for as long as required by tax and accounting obligations.
6. Your rights
At any time you can exercise your GDPR rights:
- access, rectification and erasure of your data;
- restriction of and objection to processing;
- data portability;
- withdrawal of consent, where processing is based on it.
To exercise them, write to info@sponsalia.app. You also have the right to lodge a complaint with a supervisory authority (in Italy, the Garante per la protezione dei dati personali).
7. Changes to this policy
We may update this policy over time. The version published on this page, with its date, is the one in force.