Privacy Policy
Last updated: June 2026
Privacy at a Glance
General Information
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any information relating to an identified or identifiable natural person (Art. 4(1) GDPR).
Data Collection on This Website
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. You can find their contact details in the "Controller" section of this privacy policy.
How do we collect your data?
Your data is collected in part by you providing it to us. This may include data you enter into a contact form or when registering a user account.
Other data is collected automatically or with your consent when you visit the website by our IT systems. This is primarily technical data (e.g., internet browser, operating system, or time of page access).
What do we use your data for?
Part of the data is collected to ensure the error-free provision of the website.
Contact and Guest Responses (RSVP)
If you contact us (e.g. by email), we process the information you provide in order to handle your request. If you respond to an invitation as an invited guest (RSVP), we process the data you provide (e.g. name, acceptance or decline, accompanying guests, and meal preference) in order to make it available to the creator of the invitation. The legal basis for processing RSVP responses is our legitimate interest, or the legitimate interest of the invitation creator, in enabling invited persons to respond and in making those responses available to the creator (Art. 6(1)(f) GDPR); a balancing of interests shows that this processing does not override your interests, as you provide the information voluntarily and for a defined purpose. For mere contact, we likewise rely on our legitimate interest pursuant to Art. 6(1)(f) GDPR.
Where you provide a meal preference with your response, it may in individual cases reveal information about your health (e.g. allergies or intolerances) or your religious beliefs (e.g. halal or kosher) and thereby concern special categories of personal data within the meaning of Art. 9(1) GDPR. Providing it is always optional. Where such processing takes place, we rely on your explicit consent pursuant to Art. 9(2)(a) GDPR, which you give separately before submitting your response. You may withdraw this consent at any time with effect for the future by contacting us at the address given in the "Controller" section, stating your name and the date of your response.
Invitation content you create
As a logged-in user, you create invitations containing content you enter yourself (e.g. names, event venues, photos, text). By publishing, you make this content publicly accessible via a shareable link. We process this content in order to provide your invitation and display it via the link; the legal basis is the performance of the user agreement pursuant to Art. 6(1)(b) GDPR.
Such content may in individual cases reveal special categories of personal data within the meaning of Art. 9(1) GDPR, for example where an event venue allows an inference about religious belief or a photo reveals ethnic origin. Where such data concerns you, we rely on your explicit consent pursuant to Art. 9(2)(a) GDPR, which you give separately before publishing, and additionally on the fact that you have manifestly made this data public yourself by publishing it (Art. 9(2)(e) GDPR). You may withdraw your consent at any time with effect for the future by setting the invitation back to private or deleting it.
Where content you add relates to other people (e.g. third parties depicted or named), you are responsible under data protection law for that content and ensure that you have an appropriate legal basis or the consent of the data subjects concerned. We process such content solely to provide and display your invitation as you have requested.
Controller
The controller within the meaning of Art. 4(7) GDPR for data processing on this website is:
Cem Deniz Kabakci
[ADRESSE]
[POSTLEITZAHL]
Germany
Email: withthislink@gmail.com
We have not appointed a data protection officer, as the conditions of Art. 37(1) GDPR are not met.
As the controller, we observe the principles of Art. 5(1) GDPR and are able to demonstrate compliance with them (accountability pursuant to Art. 5(2) GDPR). We maintain a record of processing activities pursuant to Art. 30 GDPR.
Third-party data in invitation content (Art. 14 GDPR)
Through the invitation content created by users, we store personal data of third parties (i.e. persons named or depicted in invitation content) that the respective creator provides and that is not collected directly from those persons. As we have no contact details for these persons, individually informing them under Art. 14 GDPR would be impossible or involve a disproportionate effort (Art. 14(5)(b) GDPR).
As compensating measures, the creator warrants that they have an appropriate legal basis or the consent of the data subjects concerned (see the "Invitation content you create" section and our Terms and Conditions). Affected persons may contact us at any time via the contact address stated in the "Controller" section in order to exercise their rights or request the removal of content concerning them.
Storage Duration
Unless a more specific storage period has been stated within this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. If you assert a legitimate request for deletion or revoke consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing it.
Specifically:
- Account and invitation data: Your user account, your invitations, and uploaded images are deleted as soon as you delete your account or the respective invitation. The image files you uploaded are deleted from our object storage (Cloudflare R2); as images are delivered via a CDN (cdn.withthislink.com) with a cache lifetime capped at 24 hours, copies already cached at CDN edges may remain accessible for up to 24 hours. The RSVP responses submitted for an invitation are deleted when the invitation or the account is deleted; at the latest, they are deleted automatically twelve months after the event date. If you have consented to product analytics or have since withdrawn that consent, your PostHog analytics profile and all associated events are also deleted on a best-effort basis when you delete your account. If the automatic deletion fails, this is logged internally and the deletion is carried out manually.
- Payment and order data: For tax and commercial-law reasons we are required to retain invoices and accounting records for eight years (Section 147 AO, Section 257 HGB). This data is therefore stored even after an account deletion, until the statutory retention period expires (Art. 6(1)(c) GDPR).
- Contact enquiries: Messages you send via the contact form (name, email address, message) are deleted automatically at the latest after twelve months, or when your account is deleted, unless statutory retention obligations apply (Art. 6(1)(f) GDPR).
- Premium support chat: Paying customers have access to a direct support chat inside the editor. We process the content of your messages and our replies, any images you upload, and read timestamps (when a message was read). The purpose is handling your support request as part of our contractual relationship (legal basis: Art. 6(1)(b) GDPR). The conversation is stored for the life of the associated invitation and is deleted with it, and with your account. Recipients are solely the processors listed below (hosting, database, image storage); no other disclosure takes place. So that we can respond promptly, we receive a notification via a messenger service when a new message arrives. That notification contains only a notice that a new message exists plus an internal reference id — never message content, names, email addresses, or any other personal data. The messenger service therefore does not process any personal data of our customers.
- Consent records: We store records of consent given or withdrawn (e.g. for analytics) for as long as necessary to meet our accountability obligation under Art. 7(1) GDPR and to establish or defend legal claims (legal basis: Art. 6(1)(c) GDPR).
Legal Basis for Processing
We only process personal data if one of the following legal bases applies:
- Art. 6(1)(a) GDPR: You have given your consent to the processing.
- Art. 6(1)(b) GDPR: The processing is necessary for the performance of a contract.
- Art. 6(1)(c) GDPR: The processing is necessary for compliance with a legal obligation.
- Art. 6(1)(f) GDPR: The processing is necessary for the purposes of our legitimate interests.
Your Rights
Under the GDPR, you have various rights regarding your personal data:
- Right of Access (Art. 15 GDPR): Right to obtain information about your stored data.
- Right to Rectification (Art. 16 GDPR): Right to have incorrect data corrected.
- Right to Erasure (Art. 17 GDPR): Right to have your data deleted. Exempt from this is data we are required to retain under statutory retention obligations (Art. 17(3)(b) GDPR), in particular payment and order data (see Storage Duration).
- Right to Restriction (Art. 18 GDPR): Right to restrict the processing where (a) you contest the accuracy of the data, (b) the processing is unlawful and you request restriction instead of erasure, (c) we no longer need the data but you require it for the establishment, exercise or defence of legal claims, or (d) you have objected pursuant to Art. 21(1) GDPR and it is not yet established whether our legitimate grounds override yours.
- Right to Data Portability (Art. 20 GDPR): Right to receive data you have provided to us on the basis of consent or for the performance of a contract in a machine-readable format. You can download your data at any time as a JSON file from your account settings (the export also includes all other data we hold about you pursuant to Art. 15 GDPR).
- Right to Object (Art. 21 GDPR): Right to object to the processing.
- Right to Complain (Art. 77 GDPR): Right to lodge a complaint with a supervisory authority.
- Withdrawal of Consent (Art. 7(3) GDPR): Where processing is based on your consent, you may withdraw it at any time with effect for the future. The withdrawal of consent does not affect the lawfulness of processing carried out on the basis of the consent prior to its withdrawal.
- Notification Obligation (Art. 19 GDPR): We communicate any rectification, erasure or restriction of processing to each recipient to whom your data has been disclosed, unless this proves impossible or involves disproportionate effort. Upon request, we will inform you about the recipients to whom we have made such a notification.
- Right to Compensation (Art. 82 GDPR): If you have suffered material or non-material damage as a result of an infringement of the GDPR, you have the right to compensation from the controller or processor.
We respond to your request within one month. In complex cases, we may extend this period by a further two months and will inform you accordingly (Art. 12(3) GDPR). Processing your request is generally free of charge (Art. 12(5) GDPR).
Automated Decision-Making
We do not use automated decision-making, including profiling, within the meaning of Art. 22(1) and (4) GDPR that produces legal effects concerning you or similarly significantly affects you.
Complaint to the Supervisory Authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority. The authority responsible for us is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59-61
10555 Berlin, Germany
https://www.datenschutz-berlin.de
Right to Object
You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you that is carried out on the basis of Art. 6(1)(f) GDPR (legitimate interest) (Art. 21(1) GDPR). This concerns the following processing activities: server log files, the delivery of images via the CDN, reach measurement (view counting), the processing of RSVP responses, the display of maps (OpenStreetMap and Stadia Maps), and error and security monitoring (Sentry). If you object, we will no longer process the personal data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims. You can address your objection to the contact address stated in the "Controller" section.
External Services and Data Transfer
To provide our service we use the following providers (processors or independent controllers). Where personal data is transferred to countries outside the EU/EEA (in particular the USA), this is done on the basis of appropriate safeguards, namely the EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR and – where the recipient is correspondingly certified – on the basis of an adequacy decision (EU-US Data Privacy Framework) pursuant to Art. 45(1) GDPR.
Hosting and Server Log Files
Our website is hosted with an infrastructure provider. When the website is accessed, information transmitted by your browser is automatically processed in so-called server log files. This includes in particular the IP address, the date and time of access, the requested file, the browser used, and the operating system. This data is technically required to deliver the website and to ensure its stability and security, and is deleted after a short period. The legal basis is our legitimate interest in the secure and stable operation of the website pursuant to Art. 6(1)(f) GDPR.
Provider: ProHosting24
Server location: Germany
Authentication (Clerk)
We use Clerk for user authentication. During registration and login, your data (e.g. email address, name) is transmitted to and processed by Clerk. The provider is Clerk, Inc., 660 King Street, Unit 345, San Francisco, CA 94107, USA. Its representative in the EU pursuant to Art. 27 GDPR is VeraSafe Ireland Ltd., Unit 3D North Point House, North Point Business Park, New Mallow Road, Cork T23 AT2P, Ireland. The legal basis is the performance of the user agreement pursuant to Art. 6(1)(b) GDPR.
As Clerk is based in the USA, personal data may be transferred to the USA. Clerk is certified under the EU-US Data Privacy Framework; the transfer therefore takes place on the basis of an adequacy decision pursuant to Art. 45(1) GDPR. In addition, we base the transfer on the EU Standard Contractual Clauses (Module 2) pursuant to Art. 46(2)(c) GDPR.
Privacy Policy: https://clerk.com/legal/privacy
Database and Backend (Convex)
The content you enter (including account and invitation data, names, your guests' RSVP responses) and references to uploaded images are stored and processed in our backend and database platform Convex. The provider is Convex, Inc., 444 DeHaro Street, Suite 218, San Francisco, CA 94107, USA. The provider offers an EU contact point for data subjects via GDPR Local (convex.gdprlocal.com/eu). The data is hosted on Amazon Web Services (AWS) infrastructure within the European Union (Ireland region). The legal basis is the performance of the user agreement pursuant to Art. 6(1)(b) GDPR.
We have concluded a Data Processing Agreement (DPA) pursuant to Art. 28 GDPR with the provider, based on the Convex Data Processing Addendum (available at convex.dev/legal/dpa). While the data is stored within the EU, the provider is a US-incorporated company and individual sub-processors (e.g. for support and operational monitoring) are located in the USA, so access to or a transfer of data to the USA cannot be ruled out. Any such access or transfer is safeguarded by the EU Standard Contractual Clauses (Module 2) pursuant to Art. 46(2)(c) GDPR, which form part of the DPA.
To provide the service, Convex engages further sub-processors (including Amazon Web Services for infrastructure). The provider maintains a current list of sub-processors at convex.dev/legal/subprocessors.
Privacy Policy: https://www.convex.dev/legal/privacy
Payment Processing (Polar)
For payment processing we use Polar, which acts as Merchant of Record (reseller). When you make a payment, your payment data is transmitted directly to and processed by Polar; complete credit card data is not stored on our servers. During checkout, in particular your name and email address are transmitted to Polar. The provider is Polar Software, Inc., 3500 South DuPont Highway, Dover, DE 19901, USA. The legal basis is the performance of the contract pursuant to Art. 6(1)(b) GDPR and compliance with tax and commercial retention obligations pursuant to Art. 6(1)(c) GDPR.
As Polar is based in the USA, personal data may be transferred to the USA. This transfer is safeguarded by the EU Standard Contractual Clauses (Module 2) pursuant to Art. 46(2)(c) GDPR. As Merchant of Record (seller of record), Polar additionally acts as an independent controller toward the buyer with respect to payment and tax records.
Privacy Policy: https://polar.sh/legal/privacy
Image Storage and Delivery (CDN)
Images you upload are stored in the Cloudflare R2 object storage operated by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Before storage, the images are re-encoded to the WebP format server-side using the sharp library. This removes metadata including EXIF/GPS location information. The legal basis is the performance of the user agreement pursuant to Art. 6(1)(b) GDPR.
Images are delivered via a content delivery network (CDN) under the domain cdn.withthislink.com, operated by Cloudflare, Inc. (EU contact: Cloudflare Germany GmbH, Rosenheimer Straße 143C, 81671 Munich, Germany). Cloudflare accelerates and secures the delivery of content; in doing so, your IP address is processed. The legal basis is our legitimate interest in secure and performant delivery pursuant to Art. 6(1)(f) GDPR.
As Cloudflare is based in the USA, personal data may be transferred to the USA. Cloudflare is certified under the EU-US Data Privacy Framework; the transfer therefore takes place on the basis of an adequacy decision pursuant to Art. 45(1) GDPR. In addition, we base the transfer on the EU Standard Contractual Clauses (Module 2) pursuant to Art. 46(2)(c) GDPR.
Cloudflare also provides bot protection (Turnstile) during authentication (Clerk) to defend against abusive sign-in attempts. In doing so, technical characteristics of your device and browser as well as your IP address are processed. The legal basis is our legitimate interest in protecting our services against automated attacks pursuant to Art. 6(1)(f) GDPR.
Privacy Policy: https://www.cloudflare.com/privacypolicy/
Reach Measurement (View Counting)
When a public invitation is accessed, we count the views to measure reach. For this purpose your IP address is pseudonymised using HMAC-SHA256 with a rotating salt (renewed every 24 hours) and stored together with a counter in our Redis store. The hash is used solely to detect repeat views within 24 hours and avoid counting them twice. No profiling takes place and no personal profiles are created. The legal basis is our legitimate interest in reach measurement pursuant to Art. 6(1)(f) GDPR.
Maps (OpenStreetMap and Stadia Maps)
To display event locations and for address search we use OpenStreetMap. When map tiles are loaded (the "standard" map style) and when an address is searched, your IP address is transmitted to the OpenStreetMap Foundation. This feature is only loaded when an invitation contains a location section. The legal basis is our legitimate interest in displaying event locations and a functioning address search pursuant to Art. 6(1)(f) GDPR. The OpenStreetMap Foundation is based in the United Kingdom; the transfer takes place on the basis of the European Commission's adequacy decision pursuant to Art. 45(1) GDPR.
Privacy Policy: https://wiki.osmfoundation.org/wiki/Privacy_Policy
Where the creator of an invitation has selected an alternative map style for its location section ("light", "dark", or "watercolor"), the map tiles are loaded from Stadia Maps instead of OpenStreetMap. When these tiles are loaded, your IP address is transmitted to Stadia Maps. We use Stadia Maps' EU endpoint exclusively, so the tiles are served solely from servers within the EU (Frankfurt, Germany, and Paris, France). The provider is Stadia Maps, Inc., 1690 Watertower Place, Ste 100 #216, East Lansing, MI 48823, USA. The legal basis is our legitimate interest in displaying event locations pursuant to Art. 6(1)(f) GDPR.
Although the map tiles are served exclusively from servers within the EU, because the provider is a US company, access to or a transfer of data to the USA cannot be excluded. Any such access or transfer is safeguarded by the EU Standard Contractual Clauses (Module 2) pursuant to Art. 46(2)(c) GDPR.
Privacy Policy: https://stadiamaps.com/privacy/privacy-policy/
Product Analytics (PostHog)
Where you have given your consent, we use PostHog for pseudonymous product analytics in order to understand how the application is used, to debug issues, and to improve the app. The provider is PostHog, Inc., 2261 Market St., #4008, San Francisco, CA 94114, USA. Processing takes place via the PostHog EU Cloud; the data is hosted on servers within the EU (Frankfurt, Germany).
In doing so, a pseudonymous identifier (distinct id) is assigned to your device and stored in your browser's local storage (localStorage) as well as partially in a cookie, both named ph_[token]_posthog (retention approx. 1 year). This is not anonymous but pseudonymous data, which may constitute personal data under the GDPR. Your consent decision itself is stored in your browser's local storage (localStorage) under the key __ph_opt_in_out_<token>. We also store, in your browser's local storage under the keys wtl_consent_meta and wtl_consent_id, the time and version of your decision and a device-level identifier; these serve solely to record and demonstrate your decision per device, are necessary for that purpose (Section 25(2) TDDDG), and remain until you clear them. If you are logged in, we additionally store your consent decision on our servers (the decision, the version of this privacy notice it relates to, the time it was made, and a device identifier so each device's choice is recorded separately) in order to demonstrate your consent pursuant to Art. 7(1) GDPR.
If you are logged in and have consented, analytics events are associated with your user account: in this case your account identifier (account id) is used as the distinct id. This creates a user-level profile in PostHog that we use for per-user usage analysis (e.g. to understand feature usage across sessions and devices). No further contact data (such as your email address or name) is transmitted as analytics data; only the account identifier is used for the association, and the text content of pages is masked. If you are not logged in, the identifier remains a pseudonymous cookie id.
The legal basis for the processing is your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG for the access to and storage of information on your device.
As the provider is a US-incorporated company, a transfer of personal data to the USA may occur. We have concluded a Data Processing Agreement (DPA) with PostHog pursuant to Art. 28 GDPR. PostHog is certified under the EU-US Data Privacy Framework; the transfer therefore takes place on the basis of an adequacy decision pursuant to Art. 45(1) GDPR. In addition, we base the transfer on the EU Standard Contractual Clauses (Module 2) pursuant to Art. 46(2)(c) GDPR.
You can withdraw your consent at any time with effect for the future by opening the "Cookie settings" link in the site footer.
Privacy Policy: https://posthog.com/privacy
Error and Security Monitoring (Sentry)
For the technical monitoring of our service we use Sentry to detect software errors and crashes and to detect security incidents or personal data breaches at an early stage so that we can handle them in line with our obligations under Art. 32 and Art. 33 and 34 GDPR. The provider is Functional Software, Inc. (Sentry), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA. Processing takes place via Sentry's EU region; the data is hosted on servers within the EU (Frankfurt, Germany). The legal basis is our legitimate interest in the security, stability and integrity of our service pursuant to Art. 6(1)(f) GDPR.
Only technical error and diagnostic data is processed (e.g. error messages, stack traces, the browser, operating system and device used, and the requested route path). We have configured Sentry server-side so that no personal identifiers are transmitted: by means of server-side filters and by disabling the automatic collection of personal data, we remove in particular names, email addresses, IP addresses, request bodies, cookies, request headers, URL query parameters and RSVP data before transmission. No session recording (Session Replay) takes place.
As the provider is a US-incorporated company, access to or a transfer of data to the USA may occur despite the data being held in the EU. We have concluded a Data Processing Agreement (DPA) pursuant to Art. 28 GDPR with the provider. Functional Software, Inc. is certified under the EU-US Data Privacy Framework; the transfer therefore takes place on the basis of an adequacy decision pursuant to Art. 45(1) GDPR. In addition, we base the transfer on the EU Standard Contractual Clauses (Module 2) pursuant to Art. 46(2)(c) GDPR.
Privacy Policy: https://sentry.io/privacy/
Data Security
We use the widely-used SSL (Secure Socket Layer) encryption method in conjunction with the highest level of encryption supported by your browser when you visit our website.
We also employ appropriate technical and organizational security measures to protect your data against accidental or intentional manipulation, loss, destruction, or unauthorized access by third parties.
Changes to This Privacy Policy
We reserve the right to update this privacy policy to ensure it always complies with current legal requirements or to implement changes to our services. The new privacy policy will apply to your next visit.