Privacy policy
What we collect, why, who else sees it, how long we keep it and what your rights are.
Last updated: 17 August 2026
This document is available in Croatian, Bosnian, English and German. In case of discrepancies, the German version prevails.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is Marko Stjepanović, trading as xtwo.dev (Einzelunternehmer, small business under section 19 UStG).
Address: Gerhart-Hauptmann-Straße 3, 78112 St. Georgen im Schwarzwald, Germany. Email: kontakt@xtwo.dev. Telephone: +49 176 277 981 89.
No data protection officer has been appointed. Under section 38 of the German Federal Data Protection Act (BDSG) an appointment is only mandatory where at least 20 people are constantly engaged in automated processing, which is not the case here. All data protection enquiries go directly to the email address above.
Supervisory authority: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Heilbronner Straße 35, 70191 Stuttgart (https://www.baden-wuerttemberg.datenschutz.de). You may lodge a complaint with that authority or with the supervisory authority where you habitually reside.
2. Who is responsible for what
For your account data, payment data, security records and anonymous visit statistics we are the controller. This policy describes that processing.
For everything you as a host put into your event (guests, invitations, gifts, seating plans, photos uploaded by your guests) YOU are the controller and we are a processor acting solely on your instructions. That relationship is governed by the Data Processing Agreement, which forms part of our terms.
The practical consequence: if a guest has asked for their photo or their data to be deleted, contact the host of the event first. We can only carry out such a request on the host's instruction, unless the law requires us to act otherwise.
3. What data we process
The list is grouped by whose data it is and how it reaches us.
- Account data (host)
- Name, email address, interface language, user identifier. If you register with email, your password is stored by Supabase Auth as a cryptographic hash only; we never see it. If you sign in with Google, we receive your email address and display name from your Google profile.
- Event data (host)
- Event title, date, location, settings, checklist, budget and notes. Title and location usually contain personal data, because they are names and places.
- Guest data (entered by the host, or by the guest)
- First and last name, phone number, table number, tags, accommodation requirement, RSVP status and a free-text message which is stored in the dietary notes field. This data comes from the host's own entry, an Excel import, or a guest's reply on the public invitation.
- Song suggestions and gift reservations (guest)
- The name the guest types in, song title, artist and an optional link. On a gift list, the name of the person reserving is visible to other visitors of that list unless the guest chooses to reserve anonymously.
- Photos and media files (guest)
- The file itself, plus a technical record of it: storage path, file type, size and upload time. We do NOT store the name, email address or IP address of the person who uploaded it, which is why not even the host can see who uploaded what.
- Payment data
- Payment is carried out by Stripe. We store only a Stripe customer identifier and a payment identifier. Card details never pass through or rest in our systems.
- Technical data
- Server and platform logs kept by Vercel and Supabase, including IP address, browser type and the date and time of access. Gift reservations create an action record; see the retention section.
- Anonymous visit statistics
- Vercel Web Analytics records the time, page address, referrer, approximate location at country or city level, device type and browser. It uses no cookies, stores nothing on your device, and identifies a visitor only through a hash derived from the incoming request that is discarded after 24 hours.
4. Special categories of data
The dietary notes field attached to a guest also serves as the free-text message field on the RSVP form. Guests write whatever they like into it. Information about allergies, coeliac disease or diabetes is health data and falls within the special categories under Article 9 GDPR.
The controller for that data is the host of the event. The host must ensure a valid legal basis, normally the guest's explicit consent under Article 9(2)(a) GDPR, and should not invite health information beyond what is necessary.
We do not analyse this data, do not disclose it to third parties, and use it for no purpose other than storing it and displaying it to the host.
5. Photographs
Event photographs are personal data of every identifiable person in them, not only of the person who uploaded them. They may also reveal special-category data, for example religious belief in the case of a wedding in a place of worship.
We store original files exactly as uploaded. That means they may still contain EXIF metadata, including GPS coordinates, capture time and the device model and settings. The thumbnails and preview versions we generate on the server do not contain that metadata, because the image is re-encoded.
The host must obtain the consent of the people shown in photographs in line with the right to one's own image (sections 22 and 23 of the German Act on Copyright in Works of Fine Art and Photography, KUG) and must inform guests about the processing before they start uploading.
Files are stored in Supabase Storage. Each file address contains a random identifier that cannot be guessed, but the address itself is not protected by a login: anyone holding the link can open the file. Do not share gallery links more widely than you intend.
6. Purposes and legal bases
- Providing the service and managing your account
- Article 6(1)(b) GDPR, performance of a contract with you. The platform cannot function without this data.
- Processing payment and issuing confirmation
- Article 6(1)(b) GDPR for performing the purchase and Article 6(1)(c) for meeting tax and accounting obligations.
- Security, abuse prevention and rate limiting
- Article 6(1)(f) GDPR. Our legitimate interest is protecting the platform and our users' data from automated abuse, unwanted submissions and overload. The interest of guests and hosts in a stable, secure service points the same way.
- Anonymous visit statistics
- Article 6(1)(f) GDPR. Our legitimate interest is understanding which pages people use so we can improve them. The measurement is cookieless and does not follow you across sites, so the intrusion is minimal.
- Legal obligations
- Article 6(1)(c) GDPR, principally the retention periods in section 147 of the German Fiscal Code (AO) and section 257 of the Commercial Code (HGB).
- Processing guest data on behalf of the host
- Here we do not act on a legal basis of our own. We act on the host's instructions under Article 28 GDPR. The legal basis towards guests must be provided by the host.
7. Recipients of personal data
This is the complete list of external providers that receive personal data. We have no advertising partners and we do not sell data.
Supabase Pte. Ltd
- Role
- Processor (Article 28 GDPR)
- Purpose
- Authentication, database, file storage, realtime notifications and the transactional emails that confirm an account.
- Established in
- 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513
- Transfer
- European Commission Standard Contractual Clauses. Supabase is not certified under the EU-US Data Privacy Framework.
Vercel Inc.
- Role
- Processor (Article 28 GDPR)
- Purpose
- Hosting of the web platform and cookieless anonymous visit statistics.
- Established in
- 440 N Barranca Ave #4133, Covina, CA 91723, USA
- Transfer
- Certified under the EU-US Data Privacy Framework, including the UK Extension and the Swiss-US DPF, alongside Standard Contractual Clauses.
Stripe Payments Europe, Ltd.
- Role
- Independent controller for payment data, together with the affiliated Stripe entities.
- Purpose
- Processing the one-time Premium payment, fraud prevention and regulatory compliance.
- Established in
- The One Building, 1 Grand Canal Street Lower, Dublin 2, Ireland. EU main establishment: Stripe Technology Company, Ltd. (Ireland).
- Transfer
- Standard Contractual Clauses and EU-US Data Privacy Framework certification for Stripe, LLC in the United States.
Google Ireland Limited (Google sign-in)
- Role
- Independent controller. Google does not process this data on our instructions.
- Purpose
- Signing in with a Google account, if you choose it. Your email address and display name are transmitted.
- Established in
- Gordon House, Barrow Street, Dublin 4, Ireland
- Transfer
- Under Google's own terms; Google LLC is certified under the EU-US Data Privacy Framework.
Resend
- Role
- Processor (Plus Five Five, Inc.).
- Purpose
- Sending the order confirmation carrying the withdrawal instruction after a purchase. Your email address and the content of that message are transmitted.
- Established in
- 2261 Market Street #5039, San Francisco, CA 94114, USA
- Note
- Processing takes place primarily in the United States. Open and click tracking are switched off, so the links in the message point straight at our own pages.
YouTube (tutorial videos)
- Role
- Independent controller
- Purpose
- Tutorial videos in the dashboard. A video loads only after you open it yourself, and privacy-enhanced mode (youtube-nocookie.com) is used. No connection to Google is made before your click.
- Established in
- Gordon House, Barrow Street, Dublin 4, Ireland
- Transfer
- Under Google's own terms; Google LLC is certified under the EU-US Data Privacy Framework.
A current list of sub-processors with addresses and transfer mechanisms is maintained at /subprocessors. We also disclose data where required by law, court order or a request from a competent authority.
8. Transfers outside the European Economic Area
Some of our providers are established outside the European Economic Area. Supabase Pte. Ltd is established in Singapore, for which there is no European Commission adequacy decision; the transfer rests on the Standard Contractual Clauses in Implementing Decision (EU) 2021/914. Vercel Inc. and Stripe, LLC are established in the United States; both are certified under the EU-US Data Privacy Framework and additionally apply Standard Contractual Clauses.
Plus Five Five, Inc. (Resend) is established in the United States, sends the order confirmation on our behalf and is certified under the EU-US Data Privacy Framework, with Standard Contractual Clauses applying in addition. Typefaces are served exclusively from our own domain; no transfer to Google occurs for them any longer.
A copy of the Standard Contractual Clauses in use can be requested at the email address above.
10. How long we keep data
Plainly: there is currently no automated deletion. Nothing disappears by itself, not even when a Premium plan expires. Deletion is triggered by your request or by an action in the app.
- Account data
- Kept while your account exists. Request account deletion by email to kontakt@xtwo.dev; we carry it out within 30 days.
- Event content and photographs
- Kept until you delete them or request deletion of your account. When you delete a photo in the gallery we remove the stored file and the database record.
- Media of expired events
- We reserve the right to delete photos and other media belonging to events whose Premium plan or trial expired more than 12 months ago. We notify you by email at least 30 days beforehand. We have not exercised this right to date and it is not automated.
- Payment data and invoices
- Transaction records are held by Stripe and subject to Stripe's retention periods. Documentation needed to meet German tax and accounting obligations is kept for up to 10 years under section 147 AO and section 257 HGB.
- Server and platform logs
- Kept by Vercel and Supabase under their own retention settings. We do not collect these logs separately and do not use them for profiling.
- Gift reservation records
- The record of a reservation and its cancellation is stored with the event and deleted together with it.
11. Your rights
Under the GDPR you have the following rights regarding your data:
- The right of access to the data we process about you (Article 15).
- The right to rectification of inaccurate or incomplete data (Article 16).
- The right to erasure (Article 17).
- The right to restriction of processing (Article 18).
- The right to data portability in a machine-readable format (Article 20).
- The right to object to processing based on legitimate interests (Article 21).
- The right to withdraw consent at any time, without affecting the lawfulness of processing before withdrawal (Article 7(3)).
- The right to lodge a complaint with a supervisory authority (Article 77).
Send your request to kontakt@xtwo.dev. We respond within one month. If you are a guest at someone else's event, the controller is the host: contact them, and we will help them carry out your request. Guests have no user account, so there is no self-service route for exercising rights; every such request is handled manually.
12. Users outside the European Union
We provide the service outside the European Union as well. We extend the rights described above to all users, wherever they are.
California: we do not sell personal information and we do not share it for cross-context behavioural advertising within the meaning of the CCPA/CPRA. The revenue and volume thresholds of that statute are not met in our case, so we honour those rights voluntarily rather than because we are subject to them. We respect the Global Privacy Control signal, although we operate no processing it would need to switch off.
We do not respond to Do Not Track signals, because we operate no cross-site tracking that such a signal could disable.
United Kingdom and Switzerland: we extend the same rights to users in those countries. Our marketing is not directed at the United Kingdom, so no representative under Article 27 of the UK GDPR has been appointed.
13. Minors
The service is not directed at children. Only persons aged 18 or over may open an account.
Under Article 8 GDPR and German implementing law, processing a child's data below the age of 16 on the basis of consent requires the authorisation of the holder of parental responsibility. We operate no technical age verification. If children are expected at your event, for example at a children's birthday party, you as the host must obtain the necessary authorisations before their data or photographs are entered into the platform.
If we learn that we have received a child's data without the required authorisation, we delete it without undue delay. Reports can be sent to kontakt@xtwo.dev.
14. Automated decision-making and artificial intelligence
We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR.
We do not carry out profiling. We do not use artificial intelligence or machine learning to process your data, your event content or your guests' photographs. We do not analyse photographs, do not perform face recognition and do not create biometric templates.
15. Changes to this policy
We update this policy from time to time to keep it aligned with changes to the service or the law. The date of the last change is shown at the top of the page.
We announce material changes by an in-app notice at least 14 days before they take effect. Continuing to use the service after the changes take effect counts as acceptance of the amended policy; your statutory rights are unaffected.