Table of Contents
- Introduction
- Information We Collect
- How We Use Your Information
- Automated Decision-Making
- How We Share Your Information
- Cookies and Tracking Technologies
- Your Rights and Choices
- Data Retention
- Data Security
- Children's Privacy
- International Data Transfers
- California Privacy Rights (CCPA/CPRA)
- European Privacy Rights (GDPR)
- Canadian Privacy Rights (PIPEDA)
- Third-Party Services
- Changes to This Policy
- Contact Us
1. Introduction
1.1 About This Policy
This Privacy Policy ("Policy") describes how the operator of invitation.codes ("Company," "we," "us," or "our") collects, uses, shares, and protects your personal information when you use the invitation.codes website, mobile applications, browser extensions, and related services (collectively, the "Service").
1.2 Scope
This Policy applies to all users of the Service, including visitors, registered users, and participants in our rewards and affiliate programs. By using the Service, you consent to the practices described in this Policy.
1.3 Key Terms
- Personal Information: Information that identifies, relates to, or could reasonably be linked to you
- Processing: Any operation performed on personal information, including collection, storage, use, and disclosure
- Data Controller: The entity that determines the purposes and means of processing personal information (that's us)
2. Information We Collect
2.1 Information You Provide
Account Information
- Email address
- Password (stored in encrypted form)
- Username/handle
- Display name
Profile Information
- Profile picture and cover image
- Bio and introduction
- Website and social media links
- Location (city, country)
- Social profile connections
Payment and Financial Information
- Payment method details (processed by third-party providers)
- Payout information (PayPal email, bank details)
- Billing address
- Transaction history
Tax Information (for Affiliate Program participants)
- Tax identification number (last 4 digits stored)
- W-9 or W-8BEN forms (for U.S. tax reporting)
- VAT number (for applicable jurisdictions)
User Content
- Referral codes and links you share
- Posts, comments, and discussions
- Messages sent through the Service
- Program suggestions and submissions
- Support requests and communications
Survey and Research Data
- Responses to surveys
- Feedback you provide
- Research participation data
2.2 Information Collected Automatically
Device and Browser Information
- Device type and model
- Operating system and version
- Browser type and version
- Screen resolution
- Language preferences
- Time zone
Network Information
- IP address
- Internet service provider
- Approximate geographic location (derived from IP)
Usage Information
- Pages and features accessed
- Links clicked
- Search queries
- Time spent on pages
- Referral source (how you arrived at our Service)
- Session duration and frequency
Device Identifiers and Fingerprinting
While you are signed in, we collect device identifiers and browser fingerprints for fraud prevention and security purposes. We do not create them for signed-out visitors. This includes:
- Browser fingerprint data (canvas, WebGL, audio context)
- Hardware identifiers
- Font enumeration
- Plugin information
- Screen and color depth information
The resulting identifier is kept in your browser's local storage as invt_fp_id. This information is used solely for fraud prevention, security, and abuse detection. See Section 4 for more information about automated decision-making.
Cookie and Tracking Data
- Cookies (see Section 6)
- Pixel tags and web beacons
- Local storage data
2.3 Information from Third Parties
Authentication Providers
- Google (Sign in with Google): Name, email, profile picture
Payment Processors
- Paddle and Stripe: Transaction status, payment confirmation
Affiliate Networks
- Conversion data
- Commission information
- Click and referral attribution
Analytics Providers
- PostHog, only after you accept optional cookies
- Our self-hosted Rybbit analytics, only after you accept optional cookies
- Cloudflare Web Analytics: aggregated page-load statistics
2.4 Browser Extension Data
If you install our browser extension, we may collect:
- URLs of pages you visit (for detecting applicable offers)
- Shopping cart and checkout information (for applying deals)
- Click data on our affiliate links
- Order confirmation data (for attributing conversions)
You can control what the extension collects through extension settings, and you can uninstall the extension at any time.
3. How We Use Your Information
3.1 Service Provision
We use your information to:
- Create and manage your account
- Provide our core services and features
- Process transactions and payouts
- Deliver personalized content and recommendations
- Enable communication between users
- Provide customer support
3.2 Rewards and Affiliate Programs
We use your information to:
- Track and credit Coin earnings
- Process redemptions
- Calculate and pay commissions
- Verify qualifying activities
- Prevent fraud and abuse
- Comply with tax reporting requirements
3.3 Communications
We use your information to:
- Send transactional emails (account, orders, payouts)
- Send service announcements and updates
- Send marketing communications (with your consent)
- Respond to support requests
- Send push notifications (if enabled)
3.4 Improvement and Analytics
We use your information to:
- Analyze usage patterns and trends
- Improve our Service and user experience
- Develop new features and products
- Conduct research and analysis
- Generate aggregated, anonymized insights
3.5 Security and Fraud Prevention
We use your information to:
- Detect and prevent fraud, abuse, and security threats
- Verify user identity
- Enforce our Terms of Service
- Protect our users and the platform
- Investigate suspicious activity
3.6 Legal Compliance
We use your information to:
- Comply with legal obligations
- Respond to legal process
- Protect our legal rights
- Fulfill tax reporting requirements
4. Automated Decision-Making
4.1 Overview
We use automated systems to help operate the Service, including for fraud detection, content moderation, and security. Some automated processes may affect your account or access to features.
4.2 Fraud Detection and Risk Scoring
We use automated systems to detect and prevent fraud. These systems analyze:
- Device and browser characteristics
- IP address and reputation
- Account activity patterns
- Transaction velocity
- Historical behavior
Based on this analysis, accounts may receive a risk score that affects:
- Payout processing times
- Account verification requirements
- Access to certain features
- Redemption eligibility
4.3 Content Moderation
We use automated systems to:
- Detect potential policy violations in user content
- Flag content for human review
- Apply visibility restrictions to flagged content
- Identify spam and abusive content
4.4 Account Actions
Automated systems may result in:
- Account restrictions or limitations
- Temporary suspensions pending review
- Content visibility changes
- Verification requirements
4.5 Your Rights Regarding Automated Decisions
You have the right to:
- Request human review of any automated decision that significantly affects you
- Provide additional information to contest a decision
- Receive an explanation of the factors considered
- Appeal decisions through our support process
To request human review of an automated decision, contact us at [email protected] with details about the decision you wish to contest.
4.6 Human Oversight
Automated decisions that may significantly affect your account are subject to human review upon request. Account terminations and significant restrictions are reviewed by our team before implementation, except in cases of clear fraud or security threats requiring immediate action.
5. How We Share Your Information
5.1 Public Information
The following information may be publicly visible:
- Your username/handle
- Profile information you choose to make public
- Referral codes you share
- Posts and comments
- Public activity
5.2 Service Providers
We share information with these service providers, who help us operate the Service:
| Provider | What it does | Where | When it runs |
|---|---|---|---|
| Netcup | Hosting of our application servers and primary database | Germany | Every visit, whatever you choose in the cookie banner |
| Cloudflare | DNS, content delivery and security for every request; storage of uploaded images (R2); our email service (Tinbox) runs on Cloudflare Workers | Global network, United States | Every visit, whatever you choose in the cookie banner |
| Cloudflare Web Analytics | Aggregate page-load and performance measurement. It sets no cookies. | Global network, United States | Every visit, whatever you choose in the cookie banner |
| Rybbit (self-hosted by us) | First-party page-view analytics. It does not count views of the legal pages. | Our own infrastructure | Only after you accept optional cookies |
| PostHog | Product analytics and error reports | United States | Browser analytics: only after you accept optional cookies. Error reports from our servers: always |
| Sentry | Error monitoring | United States | Browser errors: only after you accept optional cookies. Errors on our servers: always |
| Google (Sign in with Google) | Signing in with a Google account, including the One Tap prompt shown to signed-out visitors | United States | When you sign in, or see the sign-in prompt |
| Google Firebase Cloud Messaging | Delivering browser push notifications you turn on | United States | Only if you turn on push notifications |
| Ezoic | Display advertising on magazine articles, for signed-out visitors | United States | Only after you accept optional cookies |
| Paddle | Subscription checkout and billing | United Kingdom, United States | Only when you make a payment |
| Stripe | Payment processing | United States | Only when you make a payment |
Customer support is handled by our own team inside the Service. We do not use a third-party fraud-scoring service.
Service providers are contractually obligated to use your information only for providing services to us.
5.3 Affiliate Partners and Networks
When you earn commissions or participate in affiliate programs, we share:
- Click and conversion data with affiliate networks
- Necessary information for attribution and payment
- Transaction data required for commission calculation
5.4 Business Partners
We may share aggregated, anonymized data with business partners for:
- Market research
- Trend analysis
- Product development
This data cannot be used to identify you individually.
5.5 Legal Requirements
We may disclose information when required by:
- Law, regulation, or legal process
- Government requests
- Court orders or subpoenas
- To protect our rights, property, or safety
- To protect the rights, property, or safety of others
5.6 Business Transfers
In the event of a merger, acquisition, bankruptcy, or sale of assets, your information may be transferred to the acquiring entity. We will notify you of any such change and your choices regarding your information.
5.7 With Your Consent
We may share information for other purposes with your explicit consent.
5.8 We Do Not Sell Your Personal Information
We do not sell your personal information for monetary consideration. However, some sharing of information for targeted advertising may be considered a "sale" or "sharing" under California law. See Section 12 for your California rights, including the right to opt out.
6. Cookies and Tracking Technologies
6.1 What Are Cookies
Cookies are small text files stored on your device when you visit websites. We use cookies and similar technologies to operate our Service.
6.2 Types of Cookies We Use
Essential Cookies
- Required for basic functionality
- Enable login and session management
- Cannot be disabled
Functional Cookies
- Remember your preferences
- Enable personalized features
- Can be disabled (may affect functionality)
Analytics Cookies
- Help us understand how users interact with the Service
- Collect aggregated usage statistics
- Used to improve the Service
Advertising Cookies
- Set by Ezoic and its partners when magazine articles show display ads
- Only for signed-out visitors, and only after you accept optional cookies
6.3 Third-Party Cookies
Our Cookie Policy lists every cookie and storage key the site sets, who sets it and when. In short:
- Cloudflare Web Analytics: Aggregate page-load and performance measurement. It sets no cookies. (Global network, United States). Every visit, whatever you choose in the cookie banner.
- Rybbit (self-hosted by us): First-party page-view analytics. It does not count views of the legal pages. (Our own infrastructure). Only after you accept optional cookies.
- PostHog: Product analytics and error reports (United States). Browser analytics: only after you accept optional cookies. Error reports from our servers: always.
- Sentry: Error monitoring (United States). Browser errors: only after you accept optional cookies. Errors on our servers: always.
- Google (Sign in with Google) sets a
g_statecookie when the sign-in prompt is shown to signed-out visitors. - Ezoic sets advertising cookies on magazine articles for signed-out visitors, only after you accept optional cookies.
6.4 Browser Extension Tracking
Our browser extension uses tracking technologies to:
- Detect when you visit merchant sites
- Identify applicable offers and deals
- Track clicks and conversions
- Attribute referrals for rewards
6.5 Email Tracking
Our emails may contain:
- Pixel tags to track open rates
- Click tracking for links
- Information to personalize content
You can disable email tracking by blocking images in your email client or using our unsubscribe link.
6.6 Managing Cookies
You can manage cookies through:
- Browser settings: Most browsers allow you to block or delete cookies
- Our cookie preferences: reopens the cookie banner so you can accept or reject optional cookies again. It is also in the footer of every page. Our Cookie Policy describes each cookie.
- Opt-out tools: NAI opt-out (networkadvertising.org/choices)
Note that blocking cookies may affect functionality.
6.7 Do Not Track and Global Privacy Control
Our Service does not respond to Do Not Track signals. If your browser sends a Global Privacy Control (GPC) signal, we treat it as a rejection of optional cookies and, for California residents, as a request to opt out of the sale or sharing of personal information (see Section 12.8).
7. Your Rights and Choices
7.1 Account Settings
You can manage your information through account settings:
- Update profile information
- Change notification preferences
- Manage connected accounts
- Delete your account
7.2 Communication Preferences
You can control communications:
- Email: Use unsubscribe links or email preferences in settings
- Push notifications: Manage in your device or browser settings
- Marketing: Opt out in account settings
Note: You cannot opt out of transactional communications about your account.
7.3 Access and Portability
You can request:
- A copy of your personal information
- Information about how we use your data
- Export of your data in a portable format
7.4 Correction
You can request correction of inaccurate personal information by:
- Updating information in your account settings
- Contacting our support team
7.5 Deletion
You can request deletion of your personal information. Note that:
- Some information may be retained for legal or business purposes
- Aggregated or anonymized data may be retained
- Public content you posted may remain visible
- We may retain records of the deletion request
7.6 How to Exercise Your Rights
To exercise your privacy rights:
- Self-service: When signed in, download your data or delete your account at Privacy & data settings
- Email: Contact [email protected]
We will verify your identity before processing requests. We will respond within the timeframes required by applicable law.
8. Data Retention
8.1 General Retention Periods
| Data Type | Retention Period |
|---|---|
| Account information | Duration of account + 3 years |
| Transaction records | 7 years |
| User content | Duration of account |
| Usage logs | 2 years |
| Support communications | 3 years |
| Marketing data | Until opt-out + 30 days |
8.2 Factors Affecting Retention
We consider the following when determining retention:
- Legal and regulatory requirements
- Business necessity
- User expectations
- Data sensitivity
- Security considerations
8.3 Deletion and Anonymization
When retention periods expire, we:
- Delete personal information, or
- Anonymize data so it can no longer identify you
Some aggregated data may be retained indefinitely for analytics.
9. Data Security
9.1 Security Measures
We implement appropriate technical and organizational measures to protect your information:
Technical Measures
- Encryption in transit (TLS/SSL)
- Encryption at rest for sensitive data
- Secure password hashing
- Regular security assessments
- Intrusion detection systems
Organizational Measures
- Access controls and authentication
- Employee security training
- Vendor security assessments
- Incident response procedures
- Regular security audits
9.2 Your Role in Security
You can help protect your information by:
- Using strong, unique passwords
- Enabling two-factor authentication
- Keeping your login credentials confidential
- Reporting suspicious activity
- Keeping your devices secure
9.3 Security Incidents
If we discover a security breach affecting your personal information, we will:
- Notify you as required by applicable law
- Take steps to mitigate harm
- Cooperate with authorities as appropriate
- Implement measures to prevent future incidents
9.4 No Guarantee
Despite our efforts, no security measures are perfect. We cannot guarantee absolute security of your information.
10. Children's Privacy
10.1 Age Requirement
The Service is not intended for children under 18 years of age. We do not knowingly collect personal information from children under 18.
10.2 Discovery of Child Data
If we learn that we have collected personal information from a child under 18, we will:
- Delete the information promptly
- Terminate the associated account
- Take steps to prevent future collection
10.3 Reporting
If you believe we have collected information from a child under 18, please contact us immediately at [email protected].
11. International Data Transfers
11.1 Data Location
Our application servers and primary database are in Germany. Some of the service providers listed in Section 5.2 process data in the United States or on Cloudflare's global network, so your information may be transferred to and processed in countries other than your country of residence.
11.2 Transfer Safeguards
When transferring data internationally, we use appropriate safeguards:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Other legally recognized transfer mechanisms
11.3 Your Consent
By using the Service, you consent to the transfer of your information to countries that may have different data protection laws than your country of residence.
12. California Privacy Rights (CCPA/CPRA)
This section applies to California residents and supplements our general Privacy Policy.
12.1 Categories of Personal Information
In the past 12 months, we have collected the following categories of personal information:
| Category | Examples | Collected | Sold/Shared |
|---|---|---|---|
| Identifiers | Name, email, username, IP address | Yes | No/Yes* |
| Personal records | Payment information, address | Yes | No |
| Protected characteristics | Age (for eligibility) | Yes | No |
| Commercial information | Transaction history, preferences | Yes | No |
| Internet activity | Browsing history, clicks, usage | Yes | Yes* |
| Geolocation | Approximate location from IP | Yes | No |
| Professional information | Affiliate/business information | Yes | No |
| Inferences | Preferences, characteristics | Yes | Yes* |
*Information may be "shared" for cross-context behavioral advertising under CPRA.
12.2 Sources of Information
We collect information from:
- Directly from you
- Automatically through the Service
- Third-party services (OAuth, analytics, affiliate networks)
- Publicly available sources
12.3 Purposes for Collection
We collect information for purposes described in Section 3, including:
- Providing the Service
- Processing transactions
- Marketing and advertising
- Security and fraud prevention
- Legal compliance
12.4 Your California Rights
Right to Know: You can request information about:
- Categories of personal information collected
- Sources of personal information
- Business purposes for collection
- Categories of third parties we share with
- Specific pieces of personal information we hold
Right to Delete: You can request deletion of your personal information, subject to exceptions.
Right to Correct: You can request correction of inaccurate personal information.
Right to Opt-Out of Sale/Sharing: You can opt out of the "sale" or "sharing" of your personal information for cross-context behavioral advertising.
Right to Limit Sensitive Information: You can limit our use of sensitive personal information to purposes necessary for providing the Service.
Right to Non-Discrimination: We will not discriminate against you for exercising your rights.
12.5 How to Exercise Your Rights
- Online: https://v3.invitation.app/legal/do-not-sell
- Email: [email protected]
12.6 Verification
We will verify your identity before processing requests by:
- Matching information you provide with our records
- Requiring account login for account-related requests
- Using a third-party verification service if necessary
12.7 Authorized Agents
You may designate an authorized agent to submit requests on your behalf. Agents must provide:
- Written authorization signed by you
- Proof of the agent's identity
- Verification of your identity
12.8 Opt-Out Preference Signals
We honor Global Privacy Control (GPC) signals. When your browser sends a GPC signal, we treat it as a request to opt out of sale/sharing and as a rejection of optional cookies, so advertising and optional analytics do not load in that browser.
12.9 Shine the Light
California residents may request information about disclosure of personal information to third parties for direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes.
12.10 Financial Incentives
Our Coin rewards program may be considered a "financial incentive" under CPRA. Participation is voluntary. The value of the program is reasonably related to the value of data provided. You can opt out at any time by closing your account.
13. European Privacy Rights (GDPR)
This section applies to residents of the European Economic Area (EEA), United Kingdom, and Switzerland.
13.1 Data Controller
The data controller for your personal information is the operator of invitation.codes.
Contact: [email protected]
13.2 Legal Bases for Processing
We process your personal information based on:
| Purpose | Legal Basis |
|---|---|
| Account management | Performance of contract |
| Transaction processing | Performance of contract |
| Customer support | Performance of contract |
| Security and fraud prevention | Legitimate interest |
| Analytics and improvement | Legitimate interest |
| Marketing (with consent) | Consent |
| Legal compliance | Legal obligation |
13.3 Your GDPR Rights
Right of Access: Request a copy of your personal data.
Right to Rectification: Request correction of inaccurate data.
Right to Erasure: Request deletion of your data ("right to be forgotten").
Right to Restrict Processing: Request limitation of processing in certain circumstances.
Right to Data Portability: Receive your data in a structured, machine-readable format.
Right to Object: Object to processing based on legitimate interests.
Right to Withdraw Consent: Withdraw consent at any time (for consent-based processing).
Right Regarding Automated Decisions: Not be subject to decisions based solely on automated processing (see Section 4).
13.4 Exercising Your Rights
To exercise your GDPR rights:
- Email: [email protected]
- We will respond within one month (extendable by two months for complex requests)
- We may need to verify your identity
13.5 Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority in your country of residence. A list of EU supervisory authorities is available at: https://edpb.europa.eu/about-edpb/board/members_en
13.6 International Transfers
When we transfer your data outside the EEA, we use:
- Standard Contractual Clauses (SCCs)
- Adequacy decisions
- Your explicit consent where appropriate
13.7 Data Protection Impact Assessments
We conduct Data Protection Impact Assessments (DPIAs) for high-risk processing activities, including our automated fraud detection systems.
14. Canadian Privacy Rights (PIPEDA)
This section applies to residents of Canada.
14.1 Consent
We collect, use, and disclose your personal information with your knowledge and consent, except where permitted by law.
14.2 Your Rights Under PIPEDA
Right to Access: Request access to your personal information.
Right to Correct: Request correction of inaccurate information.
Right to Withdraw Consent: Withdraw consent subject to legal or contractual restrictions.
Right to Complain: File a complaint with the Office of the Privacy Commissioner of Canada.
14.3 Exercising Your Rights
To exercise your rights, contact us at [email protected]. We will respond within 30 days.
14.4 Privacy Commissioner
Office of the Privacy Commissioner of Canada 30 Victoria Street Gatineau, Quebec K1A 1H3 Toll-free: 1-800-282-1376 Website: www.priv.gc.ca
15. Third-Party Services
15.1 Third-Party Links
The Service contains links to third-party websites. We are not responsible for their privacy practices. We encourage you to review their privacy policies.
15.2 Social Media
If you connect social media accounts or share content on social media, those platforms may collect information according to their privacy policies.
15.3 Payment Processors
Payment information is processed by:
- Paddle: paddle.com/legal/privacy
- Stripe: stripe.com/privacy
We do not store complete payment card numbers.
15.4 Analytics
We use these analytics and error-monitoring services:
- Cloudflare Web Analytics: Aggregate page-load and performance measurement. It sets no cookies. (Global network, United States). Every visit, whatever you choose in the cookie banner.
- Rybbit (self-hosted by us): First-party page-view analytics. It does not count views of the legal pages. (Our own infrastructure). Only after you accept optional cookies.
- PostHog: Product analytics and error reports (United States). Browser analytics: only after you accept optional cookies. Error reports from our servers: always.
- Sentry: Error monitoring (United States). Browser errors: only after you accept optional cookies. Errors on our servers: always.
You can reject optional cookies in the cookie banner, or send a Global Privacy Control signal, to stop PostHog, Rybbit and browser error reporting from loading.
15.5 Affiliate Networks
When you interact with affiliate links, third-party affiliate networks may collect information including:
- Click data
- Conversion information
- Device identifiers
The network or merchant that receives the click collects this information under its own privacy policy.
16. Changes to This Policy
16.1 Updates
We may update this Policy from time to time. We will notify you of material changes by:
- Posting the updated Policy with a new "Last Updated" date
- Sending an email notification
- Displaying a notice on the Service
16.2 Review
We encourage you to review this Policy periodically to stay informed about our practices.
16.3 Continued Use
Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
17. Contact Us
17.1 Privacy Questions
For questions about this Policy or our privacy practices:
Email: [email protected]
17.2 Data Subject Requests
To exercise your privacy rights:
- Self-service (signed in): Privacy & data settings
- Email: [email protected]
17.3 DMCA Agent
For copyright concerns, see our Terms of Service or contact: [email protected]
17.4 Response Times
We aim to respond to privacy inquiries within:
- General inquiries: 5 business days
- Data subject requests: 30 days (or as required by law)
- Urgent matters: 48 hours
End of Privacy Policy