← amm.ar parties

Privacy

What we store, why, for how long, and how to make it go away.

Last updated 1 September 2026

The short version: we store the party details you type, the RSVPs your guests send, the photos you upload, and a log of who unlocked the album. We do not run analytics, advertising or tracking of any kind. We never sell anything to anyone. Ask us and we delete the lot.

What we store about you, the host

Your email addressIt is your login — we email you a one-time code instead of keeping a password. It also receives RSVP notifications and album-view alerts.
The party details you typeThe child's first name or nickname, the age, the date, time, venue, a map link, and any note or tagline. All of it is shown on the invite page you publish.
Photos and videoThe files you upload for the album, plus the thumbnails we generate from them.
Payment recordStripe's session and payment reference, the amount, the currency and the status. Not your card number — that is entered on Stripe's own page and never reaches us.

What we store about your guests

RSVP repliesThe name they type, whether they are coming, how many children, and the optional message and contact detail they choose to add. Visible to you, the host.
Album access logEmail address, IP address and timestamp, each time someone unlocks the album. This exists so you can see who has looked at photographs of your child, which is the whole reason the album is gated.
One-time codesStored as a keyed hash, never as the digits themselves, and deleted the moment they are used or expire (ten minutes).
Session cookieA signed cookie that says "this address unlocked this album", valid for 48 hours. It is not a tracking cookie: it identifies nothing outside the album it was issued for, and there is no cookie at all until someone signs in.

Children

The pages are about children, and that shapes how this works. Nobody under 18 has an account, and we collect nothing directly from a child — every field is filled in by an adult host or an adult guest. Photographs of children are uploaded by the host under section 4 of the terms, which requires the other parents' consent. Invite pages are served with a noindex instruction so they stay out of search results, and album media is never reachable without a verified email session. If you are a parent who wants a photograph of your child removed from someone's album, email us and we will remove it — you do not have to be the customer to ask.

Who else processes it

We use two sub-processors, and no others:

Both are US companies, so data is processed in the United States. We do not share your data with anyone else, and there is no analytics provider, ad network, social pixel or third-party font-tracking script on any page — the only external request an invite page makes is for its web fonts.

How long we keep things

Invite content, RSVPs, photosFor the twelve-month term, plus the archive period afterwards, until you ask us to delete them.
Album access logTwelve months, then deleted.
One-time codesTen minutes, or until used.
Payment recordsSeven years. We are required to keep proof of a sale for tax and accounting; this is the one category a deletion request cannot clear, and it is a reference number and an amount, not your content.

Deleting your data

Email rsvp@qaffaf.com from the address you signed up with, with the link to the page. We will delete the page, the RSVPs, every photo and video, the thumbnails and the access log within seven days, and reply to confirm it is done. Deletion is permanent — export anything you want to keep first. You can also ask us for a copy of everything we hold about you, or to correct something that is wrong, using the same address.

Security

Everything is served over HTTPS. Album files are not public: each request is checked against the album it belongs to and the session that asked for it, so no guessed or copied URL reaches another family's photos. Login codes are hashed, sessions are signed and expire, and album sessions can be revoked in one action from your dashboard if you ever need to lock everyone out.

Breach

If something is exposed that should not have been, we will email every affected host within 72 hours of finding out, with what happened and what to do. We would rather send an embarrassing email than a quiet one.

Changes

If this policy changes in a way that affects data we already hold, we will email you before it takes effect.