Legal

Privacy Policy

Last updated: October 2026

This Privacy Policy explains how Avently, a sole proprietorship registered in Ontario, Canada (“Avently”, “we”, “us”), handles information when you use the Avently RSVP service (the “Service”). It covers two groups of people: hosts, who create an account and send invitations, and guests, who receive those invitations on WhatsApp. If you are a guest, the section “If you received an invitation” below is written for you.

Who is responsible for what

When a host sends invitations through the Service, the host decides who to invite, what the invitation says, and what questions to ask. Avently processes guest information on the host’s instructions to deliver those messages and collect the replies. In privacy-law terms, the host is the organisation (or person) accountable for the guest list, and Avently is a service provider processing it on their behalf. Under PIPEDA, a transfer to a service provider for processing is a use by the host rather than a disclosure, and the host remains accountable for the information while we hold it. It is the host’s responsibility, not ours, to give their guests notice and to have a lawful basis for contacting them; our Terms of Service require it. Avently is responsible for the host’s own account information, for how the Service operates, and for the limited purposes described in the next paragraph.

Two things we do for our own purposes, not a host’s. We keep a record of every phone number that has opted out, and we apply it across all hosts, so that an opt-out given to one host is honoured by every other. We also keep the right to hold, decline or cancel any launch. Both exist to protect guests and the shared WhatsApp sender number, and we are accountable for them.

Information we collect from hosts

  • Account information. Your email address and the identifiers your sign-in provider (Google or email link) gives us, plus a sign-in cookie.
  • Event content. Event names, dates, your organiser name, the welcome message and follow-up questions you write, and any invitation image you upload.
  • Guest list data. Guest names, phone numbers, and seat counts, read from a Google Sheet you connect to an event.
  • Google account connection (optional).If you connect your Google account so we can create guest sheets for you, we store the email address of the connected account and a Google refresh token that lets us create spreadsheets in your Google Drive on your behalf. See “Your Google account” below.
  • Launch records. When you submit an event to be sent, we keep a copy of the guest list, invitation, and image link as they were at that moment, together with whether it was sent, held or declined.

Payment information

When you pay for an event, the payment is taken by Stripe on a page hosted by Stripe. Your card details go to Stripe, not to us, and we never see or store them. We keep a record of the transaction — the amount, the currency, the date, and Stripe’s identifiers for the payment — against the launch it paid for, so we can match payments to events, issue refunds, and meet our tax and bookkeeping obligations.

Information we collect about guests

  • From the host:the guest’s name, WhatsApp phone number, and seat allocation, as entered by the host.
  • From the guest: replies sent to the invitation, including the answer to the RSVP and to any follow-up questions the host asked, and the WhatsApp delivery and read status of each message.
  • Opt-outs. If a guest replies STOP (or a similar keyword), we record their phone number so that no host can message them through the Service again.

How we use information

  • Send WhatsApp invitations, reminders, and follow-up questions on the host’s behalf.
  • Write RSVP responses back to the host’s connected Google Sheet and show them in the host’s dashboard.
  • Send you occasional emails about your account and your events, such as a reminder about an event you haven’t sent. Each one has a link to stop them.
  • Hold, decline or cancel a launch where we see a risk to guests or to the shared sender number (see the next section).
  • Honour opt-outs, detect abuse, keep the Service secure, and comply with law.
  • Tell hosts about material changes to the Service or these terms.

We do not use host or guest information for advertising, and we do not sell it.

Launch requests

Each launch is stored as a request containing the guest list (names and phone numbers), the invitation text, the invitation image, the host’s email address, and the event name, and that information is visible to us. Most launches go out automatically. We may hold or decline one, and if we do we tell the host why.

We are not obliged to examine the contents of any guest list or message, and sending a launch does not mean we have checked it. Responsibility for the list stays with the host who submitted it.

Your Google account

Connecting your Google account is optional. If you do, we ask Google for permission to create and manage files that Avently itself creates in your Google Drive (Google’s drive.file scope) and to see the email address of the connected account. We use this to:

  • create a blank guest-list spreadsheet in your Drive when you ask us to, and
  • share that spreadsheet with our service account so the Service can read and update it.

We cannot see, open, or change any other file in your Drive. We do not use Google account data for advertising, do not sell it, and do not share it with anyone except as needed to run this feature. Our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

You can disconnect at any time from your Avently account page, which deletes the stored refresh token immediately, or by removing Avently under “Third-party apps & services” in your Google Account settings. Spreadsheets already created stay in your Drive and remain yours.

Separately from this connection, the Service reads and writes any Google Sheet you have shared with our service account email address, whether or not your Google account is connected. Removing that share stops our access.

Website analytics

On our public pages (the home page, pricing, and guides) we use PostHog to see how visitors use the website. PostHog records where you click, how your mouse moves, how far you scroll, how long you stay on a page, and when you leave, and it can build a replay of your visit from those actions. Replays hide anything typed into a form field. PostHog also receives your IP address, approximate location, and browser and device type.

PostHog does not run on the dashboard, sign-in pages, or event pages, so it never sees guest lists, RSVP replies, or your account details. It sets no cookies and stores nothing on your device, so we cannot recognise you on a later visit. Across the whole website, Vercel Web Analytics also counts page views, without cookies. We use this information only to improve the website, and we keep it no longer than PostHog’s standard retention period.

Invitation images are publicly accessible

WhatsApp fetches invitation images from a public web address, so any image you upload is hosted at a link that does not require a login. The link is not listed anywhere, but anyone who has it can view the image. Do not upload images you would not be comfortable being seen by anyone who obtains the link.

Who we share information with

We share information only with the providers we need to operate the Service:

  • Twilio— guest phone numbers and message content, to deliver messages over the WhatsApp Business Platform.
  • Meta (WhatsApp)— the platform the messages travel over. Meta also receives the invitation image link.
  • Google— the Sheets and Drive APIs, for the spreadsheets described above.
  • Supabase— database, file storage, and sign-in.
  • Vercel— hosting for the website, dashboard, and API, and cookieless page-view counts.
  • PostHog— website analytics on our public pages, as described above. PostHog does not receive host or guest information.
  • DigitalOcean— hosting for the background service that sends and receives messages.
  • Upstash— the message queue between those two systems.
  • Stripe— payment processing for paid events. Stripe receives your email address and the amount charged, and handles your card details directly under its own terms. We never receive or store card numbers.
  • Resend— delivers the emails we send. Resend receives the recipient’s email address and the content of the email.

We may also disclose information if required by law, to enforce our Terms of Service, or to protect the rights, safety, or property of Avently, our hosts, or guests. We do not sell personal information.

Where information is stored

Avently operates from Ontario, Canada. The providers above store and process information in the United States and possibly other countries. Information we hold may therefore be subject to the laws of those countries and accessible to their authorities. By using the Service, hosts consent to these transfers on behalf of themselves and the guests they invite.

How long we keep information

  • Host account, event, and guest datais kept for as long as the host’s account exists.
  • Conversation records and RSVP responsesare kept for as long as the event’s host account exists, so the host can refer back to them.
  • Opt-out records are kept indefinitely, even after the host who sent the message deletes their account, so that the opt-out continues to be honoured.
  • Google refresh tokens are deleted immediately when you disconnect.
  • Account deletionis by request to the address below. We remove the host’s account and the data listed above within 30 days, except opt-out records and anything we are required by law to keep.

If you received an invitation

The person or organisation named in the message is the one inviting you. They chose to contact you, supplied your name and phone number, and decided what to ask. Avently delivered the message on their behalf and records your replies so they can be shared with that host.

  • To stop receiving messages, reply STOP. We will block further messages to your number from every host who uses the Service.
  • To ask what a host holds about you, or to have it corrected or removed, contact the host directly. They are responsible for that data.
  • To reach us, email info@avently.studio. We can confirm which host sent a message, remove your replies from our systems, and add your number to the opt-out list.

Your rights

Hosts may ask us for a copy of their personal information, ask us to correct it, or ask us to delete their account, by emailing info@avently.studio. We respond within 30 days. Guests should contact the host who invited them for their own data, or us for the limited purposes described above.

Residents of Canada may complain to the Office of the Privacy Commissioner of Canada. Residents of Quebec have additional rights under Quebec’s Law 25, including rights of access, correction, de-indexing, and portability, and may complain to the Commission d’accès à l’information. Residents of other jurisdictions may have equivalent rights under local law.

Cookies

The Service sets one cookie, used to keep you signed in. We do not use advertising or analytics cookies, and our website analytics store nothing on your device.

Security

Information travels between your browser, our systems, and our providers over encrypted connections. Access to guest data is limited to the systems that need it and to the person who operates the Service. No system is perfectly secure, and we cannot guarantee that information will never be accessed without authorisation.

Children

Hosts must be at least 18 years old. Hosts are responsible for deciding whether it is appropriate to invite guests under 18 and for having the authority to share their information.

Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated to hosts by email or a prominent dashboard notice, and the date at the top of this page will change.

Contact

Questions about this policy or your data: info@avently.studio