Last updated: September 17, 2026
This Privacy Policy describes how Envite by RAW Digital ("we," "us," "our") collects, uses, stores, and protects personal data through our event RSVP and management platform (the "Service"). The Service is used by event organizers ("Organizers") to manage guest lists, RSVPs, check-ins, and event media, and by guests, crew, and other invitees who interact with events hosted through it.
1. Who This Policy Covers
- Organizers and their team members (owners, managers, crew, media contributors) who create accounts to manage events.
- Guests and invitees who receive an invitation, RSVP, check in, or view an event hub/gallery — typically without creating an account.
Each Organizer's event data is logically isolated from other Organizers' data within our system; Organizers cannot access another Organizer's guest lists, media, or account information.
2. Information We Collect
2.1 Guest / RSVP Information
When you are invited to or RSVP to an event, we may collect:
- Name and salutation
- Email address(es), including additional emails an Organizer chooses to copy on invitations
- Phone number
- Household or party grouping and party size
- RSVP status (attending, declined, etc.) and check-in timestamps
- Custom responses the Organizer configures for their event form (which may include details such as dietary preferences, plus-one names, or other event-specific questions)
- Preferred language
- How you were added to the guest list (e.g., invited directly, public sign-up, walk-in)
2.2 Staff / Team Member Account Information
For individuals who log in to manage events, we collect:
- Name, email address, and password (stored in encrypted/hashed form; we never store or transmit plain-text passwords)
- Role and permissions (e.g., organization owner, event manager, crew, media contributor)
- Profile picture, if uploaded
- Login session tokens (see Section 2.4)
2.3 Photos, Videos, and Files
Guests, crew, and media contributors may upload photos, videos, or documents to an event's gallery or library (e.g., event photos, floor plans, cover images). Uploaded files are stored as submitted; we do not currently strip embedded metadata (such as EXIF data, which can include the time and, on some devices, the location a photo was taken) from uploaded images. Files are associated internally with the account or guest record that uploaded them.
2.4 Access Tokens
- Guest access tokens (QR tokens): Guests may access their personal RSVP status, digital pass, or an event hub without creating an account, using a unique QR code/token tied to their invitation. This token acts as a credential — anyone with the link or code can access the associated guest's information — so guests should treat it as they would a password and avoid sharing it publicly.
- Staff login tokens: When staff log in, we issue access and refresh tokens (JSON Web Tokens) stored in your browser's local storage. These expire automatically after a configured period and are used solely to keep you logged in and authorize your actions.
2.5 Usage and Analytics Data
We use Google Analytics 4 (GA4) to understand how the Service is used. This includes:
- Page views and navigation within the guest hub and staff dashboard
- Interaction events such as starting or completing an RSVP, adding an event to a calendar, viewing hub tabs, importing/adding/reminding invitees, and scanning a check-in QR code
We configure these events to send only functional labels (e.g., which tab was viewed, which action occurred) — we do not intentionally send guest names, email addresses, or other direct identifiers as part of these events. However, Google Analytics independently collects standard technical information from your browser or device (such as IP address, approximate location, device type, and browser), subject to Google's own privacy practices. You can review Google's privacy policy at policies.google.com/privacy.
Analytics tracking can be disabled entirely at the platform configuration level; if disabled for a given deployment, no data is sent to Google Analytics.
3. How We Use Information
We use the information described above to:
- Create, manage, and process event invitations and RSVPs
- Enable check-in at events and issue digital passes
- Allow guests and staff to view and contribute to event galleries, agendas, and related content
- Authenticate staff accounts and enforce role-based access controls
- Send invitations, confirmations, and reminder communications related to an event
- Monitor and improve the performance, usability, and reliability of the Service
- Maintain the security and integrity of the Service, including preventing unauthorized access
We do not sell personal data, and we do not use guest or staff data for advertising or marketing unrelated to the event(s) they are associated with.
4. Legal Basis for Processing (where applicable)
Where data protection laws such as the GDPR apply, we process personal data on the following bases:
- Performance of a contract — to provide RSVP and event management services requested by the Organizer or guest.
- Legitimate interests — to secure the platform, improve functionality, and analyze aggregate usage.
- Consent — where required, such as certain analytics or optional communications.
- Legal obligation — where retention or disclosure is required by law.
5. Third Parties We Share Data With
We share data only as necessary to operate the Service:
- Cloud storage providers (S3-compatible object storage) — to store uploaded media, documents, and images.
- Google Analytics (GA4) — to collect usage/interaction data as described in Section 2.5.
- Email delivery providers — to send invitations, confirmations, and reminder emails on behalf of Organizers.
- Event Organizers — guest RSVP and contact information is visible to the Organizer and their authorized team members (managers, crew, media, as assigned) for the event(s) the guest is invited to.
We do not share personal data with third parties for their own independent marketing purposes.
6. Data Retention
We retain guest and event data for as long as the associated Organizer account remains active, or as needed to fulfill the purposes described in this policy, unless a longer retention period is required by law. Organizers may request deletion of their event data; guests may request deletion or correction of their personal information by contacting the relevant Organizer or us directly (see Section 10).
7. Data Security
We apply reasonable technical and organizational safeguards to protect personal data, including encrypted password storage, token-based authentication with expiry, tenant-level data isolation between Organizers, and access controls based on assigned roles. However, no system is completely secure, and we cannot guarantee absolute security of information transmitted or stored.
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict certain processing
- Request a copy of your data in a portable format
To exercise these rights, contact us using the details in Section 10, or contact the Organizer of the event you are associated with, as they may be the primary controller of your RSVP data.
9. Children's Privacy
The Service is not directed at children, and we do not knowingly collect personal data from children without appropriate consent from a parent, guardian, or the responsible Organizer (e.g., where an event guest list includes a minor added by a parent or guardian).
10. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact:
Envite by RAW Digital
support@envite.rawdigital.asia
18-1, Silk Residence, Jalan Sutera, Lebuh Raya Silk
Balakong, 43200 Cheras, Selangor, Malaysia.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.