The short version
Cut the Cake is event software. Hosts use it to invite people and collect RSVPs; guests use it to answer. We collect what’s needed to do that and not much else. We do not sell personal information. We do not put advertising on invitations. You can ask us to delete your data and we will.
Who is responsible for your data
When you are a host or venue using Cut the Cake, we are the data controller for your account.
When you are a guest, the host or venue who invited you decides what to ask you and what to do with your answers. They are the controller of that guest list; we process it on their behalf. If you want your details removed from a particular event, the fastest route is to ask that host — but you can always ask us and we will help.
What we collect
From hosts and venues
- Name, email address, and password or sign-in method.
- Billing details. Payments are processed by our payment provider; we store a customer reference and the last four digits of the card, never the full number.
- The events you create and their settings.
- Basic product analytics — which pages were used and when — so we can find what’s broken.
From guests
- Whatever the host puts on their guest list, typically name and an email address or phone number.
- Your RSVP and anything you choose to add to it: meal choice, plus-ones, dietary notes, a message to the host.
- Content you contribute to an event — photos, guestbook entries, song requests — if the host has enabled those.
- Whether you opted in to hearing from the host or venue about future events.
Why we use it
- To show you the invitation and record your answer.
- To send the messages described in our messaging policy and the equivalent emails.
- To give the host an accurate headcount and guest list.
- To take payment from hosts and venues.
- To keep the service working and secure, spam prevention, abuse detection, debugging.
Who can see your information
- The host of the event. They see your RSVP, your contact details, and anything you submitted.
- Other guests, only where the host has turned on a shared feature such as the photo gallery or guestbook, and only for that event.
- Our service providers — hosting, database, email delivery, text delivery, payment processing, and error monitoring — who are contractually limited to processing data on our instructions.
- Nobody else. We do not sell personal information, and we do not share it with third parties for their own advertising.
Guests invited to one event cannot see the guests, content, or details of any other event. That separation is enforced in the database itself, not only in the interface.
What is on a guest page, and who can open it
A published guest page is unlisted rather than private. It has no password: anyone holding the link can open it. We ask search engines not to index it and it appears in no sitemap, so it should not turn up in a search result — but the link itself is the key, and a link that gets forwarded works for whoever receives it.
Everyone who opens the page sees the event’s title, its date and time, the name the host has given the place, and whatever else the host has written there. The street address and the map link to it are held back until a guest answers yes or maybe.
There is one exception, and it is the host’s own doing. A host may name the place, give its address, or both — only one of the two is required, because a party at somebody’s house has an address and often no name worth inventing. When a host leaves the name blank, the address is what the page prints for where the event is, so it is public along with the rest of the page, and so is its map link. Giving the place a name of its own puts the address back behind the RSVP.
Content moderation
Where a host enables guest-contributed content, we may use automated systems to screen submissions for abusive material before they appear. Flagged content is held for the host to review.
How long we keep it
Event data is kept while the host’s account is active, so they can look back at what they hosted. When a host deletes an event or closes their account, we delete the associated guest data within 30 days, except where we must keep records for tax or legal reasons.
Your rights
You can ask us to give you a copy of your data, correct it, or delete it. Depending on where you live you may also have the right to object to certain processing or to lodge a complaint with your local data protection authority. Ask us through our contact form and we will respond within 30 days.
Security
Data is encrypted in transit and at rest. Access to production systems is limited and logged. No system is perfect; if we ever have a breach that affects you, we will tell you promptly and tell you what to do about it.
Children
Cut the Cake is not intended for children under 13, and we do not knowingly collect their personal information. A host may of course invite a family to an event; in that case the responsible adult provides the details.
Changes
If we change this policy materially we will update the date at the top and notify account holders by email before the change takes effect.
Contact
Write to us through our contact form, or by post at the address in the footer of this site. A person reads every message.