Legal

Privacy Policy

Last updated: July 2026. invitepe is powered by Purics Creation Private Limited. This policy explains what personal information invitepe collects, why we collect it, and how we handle it. By using invitepe you agree to the practices described here.

Information We Collect

Account & Profile

  • Name and email address (required at sign-up)
  • Password — stored as a one-way cryptographic hash; we never see the plain text
  • Optional profile details: display photo, bio, phone number, timezone, public username

Booking & Scheduling Data

  • Invitee name, email address, and timezone
  • Selected meeting date, time, and duration
  • Any custom questions answered during the booking flow
  • Free-text notes provided by the invitee
  • Booking status history (upcoming, completed, cancelled, rescheduled)

Payment Metadata

  • Payment amount, currency, and platform fee for each booking
  • Razorpay order ID and payment ID (references only — no card or bank details)
  • Full card numbers, CVVs, and bank account credentials are handled exclusively by Razorpay and are never stored on invitepe servers

Third-Party Integration Tokens

  • OAuth access and refresh tokens for connected services (Google Calendar, Zoom, Microsoft Teams). These are stored encrypted and used solely to create and manage calendar events and meeting links on your behalf.

Technical & Usage Data

  • Django session cookie (required for authentication — no tracking cookies)
  • Server logs: IP address, request path, HTTP status code, timestamp. Retained for up to 90 days for security and debugging.

How We Use Your Information

  • Providing the service — creating accounts, displaying booking pages, processing reservations
  • Email notifications — booking confirmations, reminders, reschedule and cancellation notices sent via Amazon SES
  • Calendar & meeting sync — creating and updating events in Google Calendar, Zoom, or Microsoft Teams using the OAuth tokens you granted
  • Payment processing — passing order details to Razorpay and routing payouts to host bank accounts via Razorpay Route
  • Security & fraud prevention — rate-limiting, detecting abuse, and protecting accounts
  • Service improvement — aggregate, anonymised usage metrics to understand how features are used. No individual-level behavioural tracking.

We do not sell, rent, or trade your personal data to any third party for marketing purposes.


Third-Party Services

invitepe integrates with the following services. Each operates under its own privacy policy.

Razorpay

Payment processing and host payouts

Privacy Policy →

Amazon SES

Transactional email delivery

Privacy Policy →

Zoom

Video meeting creation (when you connect Zoom)

Privacy Policy →

Google

Calendar sync and Google Meet links (when you connect Google)

Privacy Policy →

Microsoft

Outlook calendar and Teams meetings (when you connect Microsoft)

Privacy Policy →

Data Retention

  • Account data — retained for as long as your account is active. Deleting your account removes your profile, event types, and personal details within 30 days.
  • Booking records — retained for 3 years for accounting and dispute-resolution purposes, then permanently deleted.
  • Payment metadata — retained for 7 years to comply with applicable financial regulations.
  • Server logs — 90 days, then automatically purged.
  • OAuth tokens — deleted immediately when you disconnect an integration or delete your account.

Cookies

invitepe uses one first-party cookie — the Django session cookie (sessionid). This cookie is strictly necessary to keep you logged in between page loads. It contains no personally identifiable information and is deleted when you log out or close your browser (depending on your browser settings).

We do not use advertising cookies, analytics cookies, or any third-party tracking pixels. No cookie consent banner is shown because no non-essential cookies are set.


Your Rights

You have the right to:

  • Access — request a copy of all personal data we hold about you
  • Correction — update inaccurate information via Dashboard → Settings at any time
  • Deletion — request deletion of your account and personal data (subject to legal retention obligations above)
  • Portability — request your booking history and profile data in a machine-readable format
  • Withdraw consent — disconnect any OAuth integration at any time via Dashboard → Integrations

To exercise any of these rights, email privacy@invitepe.com. We will respond within 30 days.


Google API Services — Data Policy

Limited Use Compliance Statement

invitepe's use of information received from Google APIs will adhere to the Google API Services User Data Policy , including the Limited Use requirements.

What Google user data invitepe accesses

  • Basic identity (OpenID Connect) — your Google account email address and display name, read once at connection time to label your linked account in the dashboard.
  • Free/busy calendar data — invitepe queries your Google Calendar's free/busy intervals (via the freeBusy endpoint) to determine which of your time-slots are already taken, preventing double-bookings. No event titles, descriptions, or attendee lists from your existing events are ever read or stored.
  • Calendar events created by invitepe — when an invitee books a slot on a Google Meet event type, invitepe writes a new calendar event to your primary Google Calendar containing the meeting title, start/end time, the invitee's email as an attendee, and a Google Meet conference link. These events are updated when a booking is rescheduled and deleted when a booking is cancelled.

How that data is used

  • Exclusively to operate the scheduling features you have enabled — displaying availability, creating meeting invites, and keeping them in sync with your calendar.
  • Google user data is never used for advertising, marketing profiling, credit scoring, or any purpose unrelated to providing the scheduling service.

Data transfer and sharing

  • Google user data is not sold, rented, or shared with any third party for their independent use.
  • Google Calendar events created by invitepe are sent to Google's servers as part of the Calendar API call — this is inherent to how the Calendar API works and is the only transfer that occurs.
  • Your Google email address is included in booking confirmation emails sent via Amazon SES solely to identify your account as the meeting host.

AI / ML model training

Google user data received via Google APIs is never used to train, fine-tune, or otherwise improve any AI or machine-learning model — whether operated by invitepe or transferred to any third-party AI/ML service.

Data protection

  • OAuth access and refresh tokens are stored encrypted at rest.
  • All API calls to Google are made over HTTPS/TLS.
  • Access tokens are never logged or exposed in responses to end-users.

Data retention & deletion

  • OAuth tokens are immediately and permanently deleted when you disconnect the Google integration (Dashboard → Integrations → Disconnect) or when you delete your invitepe account.
  • Calendar events previously created by invitepe are deleted from Google Calendar when the corresponding booking is cancelled within invitepe.
  • No cached copies of your Google Calendar event data are retained by invitepe beyond what is needed to manage the current booking lifecycle.

The short version

  • We collect only what's needed to run the scheduling service.
  • We never sell your data. We never track you across the web.
  • One session cookie. No ad trackers, no analytics pixels.
  • Your OAuth tokens are used only to create meetings on your behalf and deleted the moment you disconnect.
  • Questions? privacy@invitepe.com

Privacy questions: privacy@invitepe.com  ·  Terms & Refund Policy  ·  Support