Privacy policy
Last updated 2026-01
Who we are
Three Sixty operates togetherwe.party ("the platform"), a service for creating event websites and managing invitations and replies. Our registered address is Lisboa, Portugal. For anything in this policy, write to support@invitesyouto.party.
Two kinds of people, two different roles
This distinction matters because it decides who you should contact about your data.
- Organizers — people who create an account and run an event. For their account data we are the controller.
- Guests — people invited to someone's event. The organizer decides who to invite and what to ask them; for guest data we act as a processor on that organizer's behalf. If you are a guest and want your data changed or removed, the fastest route is the privacy page on the event's own website, or the organizer directly.
What we collect
From organizers
- Name, email address, language and timezone.
- A hashed password. We never store it in a form we can read.
- Event details you enter: title, date, venue, website content.
- Sign-in records: time, and a salted hash of the IP address — never the address itself.
- Billing records if you buy a plan. Card details go straight to our payment provider and never reach our servers.
From guests
- Whatever the organizer put on their guest list: usually a name, and an email address if they want to invite you by email.
- Your reply: whether you are coming, and any meal, dietary, allergy, accessibility or custom answers the organizer asked for.
- Whether the invitation was delivered, opened, and whether the page was viewed. This is so the organizer can tell who has not seen it yet.
- Photos you choose to upload to an event gallery.
- Check-in time if the organizer scans you in at the door.
What we do not do
- No advertising, and no selling or sharing of personal data with advertisers.
- No third-party analytics or tracking scripts on event websites or invitations.
- No cross-site tracking, and no profile built about you across different events.
- We do not store raw IP addresses for analytics — only salted hashes, and only where needed for security and abuse prevention.
Special category data
Allergy, dietary and accessibility answers can reveal information about health. We collect them only because an organizer asked for them so they can cater and host safely. They are shown only to people the organizer has explicitly given permission to see them, they are excluded from general exports, and they are deleted with the rest of the event data.
Why we are allowed to hold it
| Data | Basis |
|---|---|
| Running your account and events | Performance of a contract with you |
| Sending an invitation or reply confirmation | The organizer's legitimate interest in inviting their guests |
| Allergy, dietary and accessibility answers | Your explicit consent, given when you answer |
| Marketing email to organizers | Consent, withdrawable at any time |
| Security logging and abuse prevention | Our legitimate interest in keeping the service safe |
| Invoices and payment records | Legal obligation |
Who else sees it
We use a small number of processors, and only for the job named:
- Hosting and database — to run the service.
- An email provider — to deliver invitations and notifications.
- Object storage — to hold uploaded photos.
- A payment provider — to take payments. They receive your card details directly; we receive only a reference and a status.
We do not sell personal data, and we do not share it for anyone else's marketing.
Where it is stored
Data is stored within the European Economic Area. Where a processor operates outside it, that transfer is covered by Standard Contractual Clauses.
How long we keep it
- Account data — until you delete your account.
- Event and guest data — until the organizer deletes the event. A deleted event is recoverable for 30 days, then permanently erased.
- Gallery photos — for the retention period of the event's plan, after which they are deleted.
- Activity records — about 13 months.
- Invoices — as long as tax law requires, typically 10 years.
Deleting your account starts a 14-day grace period, so an accidental or malicious request can be undone. After that it is permanent.
Your rights
You can ask to access, correct, delete, restrict, port or object to the use of your data.
- Organizers: in the dashboard under Account → Privacy. You can download everything we hold in one file, or delete your account.
- Guests: on the event's website, under "Your data". We will email a confirmation link to the address on the guest list, so nobody else can make the request for you.
You also have the right to complain to your data protection authority. In Portugal that is the CNPD.
Security
- Everything is served over HTTPS.
- Passwords are hashed with a slow, salted algorithm.
- Invitation, upload and reset links use long random tokens, and only a hash of each token is stored — a copy of our database will not let anyone open your invitation.
- Sign-in attempts and other sensitive actions are rate limited.
- Every administrative action is written to an audit log.
Cookies
We use only the cookies the site needs to work. There are no advertising or analytics cookies. See the cookie policy.
Children
Accounts are for adults. Children often appear on a guest list — their name and meal choice, entered by a parent or the organizer — and that data is treated with the same care as everyone else's and deleted with the event.
Changes
If we change this policy materially we will tell account holders by email before it takes effect.