Privacy Policy
Legal text, written to be read. Three documents, the same honesty.
On this page
This translation is provided for convenience; the French version prevails in case of discrepancy. Read the French version
1. Data we collect
Tov.events collects the following data:
- Organizer account: name, email, password (hashed, never readable), profile photo if you sign in with Google, language, time zone and username (shown in the address of your invitations).
- Sign-in sessions: IP address and browser of each open session, shown in your settings so that you can revoke them.
- Events: title, date, place, description, ceremonies, uploaded photos and, if you fill them in, your family memory (relatives, yahrzeit dates).
- Guests: name, Hebrew name, phone, email, notes and language, entered by the organizer (by hand, as a pasted list, from a file or from their contacts).
- Guest replies: attendance, number of people, children, companions, message and answers to custom questions. If the form asks for them, the guest can also indicate a kosher diet and food allergies: these are sensitive data (religious beliefs, health), entered voluntarily by the guest to plan the meal. They are visible to the organizer and to their collaborators (owner, editor and viewer, including in the replies export and the caterer page). When a reply is changed, the previous one is kept in an archive. Tov does not record guests’ IP addresses with their reply.
- Imported Google contacts: if you import your Google contacts, they are copied to a temporary area, erased as soon as you see them to make your choice; only the contacts you choose become guests. Tov keeps no Google access token. Details in section 9.
- Invitation opens: Tov counts internally when an invitation is opened (so the organizer can see it has been read), without cookies and without consent, using a pseudonymous identifier; this count is sent to no third party.
- Logs and forms: log of the emails sent (recipient’s domain only), feedback messages (kept without your identity after account deletion) and the waiting list (email, country, browser).
- Audience measurement and error reports: only with your consent for the browser; see section 6.
2. Purposes of processing
The data is used to:
- Provide the online invitation service.
- Manage RSVPs and track confirmations.
- Let the organizer know that an invitation has been opened.
- Send service-related notifications to the organizer and their collaborators (confirmations, reminders, security alerts). Tov never writes to guests directly.
- Keep accounts secure and fix errors in the service.
- With your consent, measure traffic on the public website.
3. Legal basis
Processing is based on the performance of the service contract (account creation, acceptance of the Terms of Use), on the legitimate interest of keeping the service secure, and on your consent for audience measurement and browser error reports. Guest data is entered by the organizer, who decides whom to invite, or by the guest themselves when replying.
4. Retention and deletion
Your celebrations are kept until you delete them. A celebration and its data (guests, replies, messages, gifts…) are kept until its owner deletes it; the owner can do so at any time, and deletion is immediate. Invitation open counts are kept for one year. The temporary copy of imported Google contacts is erased as soon as it is displayed or, if it is never opened, by the next cleanup once an hour has passed (section 9); sign-in sessions last 30 days, then expired sessions are erased. The email log, the waiting list and feedback messages are kept with no set end date for now.
Deleting a celebration erases its page, its moments, its guests and their replies. Its owner can do so at any time.
The recap after the celebration is private by default. For celebrations created since October 1, 2026, the memory page is visible only if the organizer publishes it; it then shows the summary, approved photos and guests’ messages with their names. The organizer can hide it again at any time.
Deleting your account (Settings, Privacy) requires confirmation by email, valid for one hour, then immediately erases the account, its celebrations, its guests and their replies. What remains: feedback messages (without your identity), open counts (pseudonymous), the email log (domain only), the waiting list, and the database’s technical history, which makes it possible to restore the last six hours. If you uploaded photos, their files are not erased automatically (neither with the celebration nor with the account): they can be removed on request; write to us for this.
5. Our service providers and data sharing
Tov never sells your data: it is used only for your celebration and to run the service. It is entrusted to the following providers, each for its own function only:
- Cloudflare: hosting and running the website (global network), photo storage, and Turnstile bot protection on sign-up, password reset and the guest reply form.
- Neon: database (European Union, Frankfurt).
- Resend: sending service emails, to the organizer and their collaborators only.
- Inngest: scheduled tasks (reminders, digests, thank-you notes).
- Google: Sign in with Google, importing your contacts at your request, address entry (Google Maps) and, with your consent, Google Analytics.
- PostHog (European servers): with your consent, measuring site usage.
- Sentry: technical error reports from the server and, with your consent, from the browser.
- Your browser’s notification services: if you turn on notifications.
- UptimeRobot: monitoring the website’s availability (public address only).
- Hostinger: the [email protected] mailbox.
Some of these providers may process data outside the European Union (Google Analytics, in particular, in the United States, under the EU–U.S. Data Privacy Framework). We also disclose data to the competent authorities when legally required. Finally, the Tov team can temporarily open (for two hours) an organizer’s space for technical support.
6. Cookies, local storage and audience measurement
Essential cookies (no consent needed): session cookie (30 days, inaccessible to JavaScript), session cache (1 hour) and, for the Tov team during support, a temporary cookie (2 hours).
Browser local storage (no consent needed): these are not cookies. Tov keeps there your cookie choice, the language of the organizer space, the “signed in” state, the state of the sidebar, the opened envelope of an invitation and your music preference. None of it leaves your device.
Audience measurement (with your consent): the “Audience measurement” category of the banner covers three tools:
- Google Analytics: page views of the public website, with Google’s cookies. Google may process this data in the United States. Google signals and ad personalization are turned off.
- PostHog: use of the website and its flows (European servers), with PostHog’s own storage in your browser.
- Sentry: browser error reports, loaded at the first error, with a screen replay (all text masked, media blocked) for some sessions and for every session with an error.
These three tools never run on invitations, in the organizer space, on sign-in, drafts or collaboration pages, nor on any address containing a personal link. No advertising cookie is used. You can withdraw your consent at any time from the settings of your space or by clearing the site’s data in your browser; the “Cookie settings” banner then appears again.
7. Your rights (GDPR)
Under the GDPR, you have the following rights:
- Right of access: obtain a copy of your personal data.
- Right to rectification: correct inaccurate data.
- Right to erasure: delete a celebration or your account from your settings (see section 4).
- Right to data portability: receive your data in a structured, machine-readable format (JSON export of the celebrations you own, without the photo files, from your settings; CSV export of replies).
- Right to object: object to the processing of your data.
If you are a guest, you can contact the organizer of the celebration or us. To exercise these rights, contact us at [email protected].
8. Security
We apply technical and organizational measures to protect your data: password hashing, signed sessions in a cookie inaccessible to JavaScript, CSRF protection, systematic input validation, rate limiting and the Cloudflare Turnstile bot challenge on sign-up, password recovery and the guest reply form. Guest replies are visible according to the role (owner, editor, viewer) that the organizer gives their collaborators.
9. Google user data
Tov.events offers two features that go through your Google account. They are used only if you choose them.
- Sign in with Google: Tov asks Google for your basic identity only (the “openid,” “email” and “profile” permissions): your name, your email address, your profile photo and your Google account identifier. They are used only to create your Tov account and sign you in. Tov stores no Google access token: the tokens Google sends at sign-in are discarded before anything is saved.
- Importing your Google contacts (“Invite” page, only if you click that button): Tov asks for read-only access to your contacts (the “contacts.readonly” permission) and reads, for each contact, their name, primary phone number and primary email address, nothing else, up to 2,000 contacts. Tov never changes or deletes your contacts at Google. The access token is used only for the duration of this reading: it is never saved, and Tov asks for no lasting access.
Use and storage: your contacts are used only to let you choose whom to invite. The list read from Google is copied to a temporary area of our database, tied to your account and your celebration. It is erased as soon as the selection list is displayed to you, right after you come back from Google; a list that was never opened is erased by the next cleanup once an hour has passed. Only the contacts you check become guests of your celebration; the others are not kept. Those guests are then handled like any guest entered by hand (sections 1 and 4).
Transfer to third parties: data received from Google is never sold, never used for advertising (no targeting, retargeting or personalized ads), never used to assess creditworthiness, and never passed on to advertising platforms or data brokers. It is not used to train any artificial intelligence model. It is transferred to no one, except to the technical providers that run the service (Cloudflare for hosting, Neon for the database; see section 5), when necessary for the security of the service, or when the law requires it.
Human access: no one at Tov reads your Google contacts. The guests you chose are viewed by the Tov team only if you ask the support team for help (section 5), for the security of the service, or to comply with the law.
Revoking access and erasing this data: you can remove Tov.events’ access to your Google account at any time at myaccount.google.com/permissions. Removing access does not erase what you have already chosen in Tov: delete the guests concerned or the celebration in your space, or delete your account (Settings, Privacy) to erase the name, email and photo received from Google (section 4). You can also write to us at [email protected].
Limited Use commitment: Tov.events’ use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Last updated:
What’s next?
An invitation true to your traditions.
In 4 languages, with Hebrew set the way it should be and replies tracked household by household.