Legal
Privacy Policy
This policy explains how Sevidate handles personal data when you use our website, create invitations, respond as a guest, purchase a plan, or contact us.
Effective and last updated: 4 August 2026
Data controller
The controller for Sevidate product data is ФОП Титжинський A.A., Ukraine, ЄДРПОУ 3746400730. Privacy questions and rights requests may be sent through our contact form.
Paddle separately controls personal data it processes as merchant of record. See Paddle's Privacy Notice.
1. Data we collect
- Account data: email address, authentication information, verification status, and optional connected-account identifiers.
- Content: invitations, uploaded assets, published links, guest names, responses, and answers submitted through invitation pages.
- Billing data: Paddle customer, subscription, transaction, product, and price identifiers and subscription status. We do not receive or store full card details.
- Support data: name, email address, topic, and message sent through the contact form.
- Technical data: IP address, request time, browser/device information, security logs, error logs, and approximate country supplied by our network provider.
- Optional integrations: Google account data used for sign-in and Telegram chat identifiers used when you connect notifications.
2. Why we use data
- to create accounts, publish invitations, collect responses, and provide requested features;
- to process subscriptions, provision paid access, send transactional messages, and provide support;
- to secure the service, prevent abuse, enforce limits, diagnose faults, and keep reliable records;
- to comply with tax, accounting, fraud-prevention, and other legal obligations;
- to improve Sevidate using aggregated or appropriately minimized information.
Depending on the situation and applicable law, processing is based on performing our contract with you, taking steps you request, legitimate interests in operating and securing the service, consent, or compliance with a legal obligation.
3. When data is shared
We use service providers only where needed to operate Sevidate. They may process data under their own terms and data-protection commitments:
- Paddle: checkout, payment, tax, invoices, subscriptions, fraud prevention, and buyer support;
- Resend: delivery of contact and transactional email;
- Cloudflare and hosting providers: delivery, TLS, traffic protection, infrastructure, and logs;
- Google: optional OAuth sign-in;
- Telegram: optional response notifications you choose to connect.
We may also disclose information where required by law, to protect rights or safety, in connection with a business transfer, or with your direction. We do not sell personal data.
4. Public invitations and guest information
A published invitation is accessible to anyone with its link. Invitation owners decide what content to publish and why they collect guest responses. Owners must provide any notice or obtain any consent required for their use of guest information. Guests should not submit sensitive information unless it is necessary and expected by the invitation owner.
5. Storage, cookies, and international transfers
Sevidate uses browser storage and technically necessary authentication data to keep you signed in, remember language preferences, and operate requested features. We do not currently use advertising cookies. Paddle Checkout and linked third-party services may use their own necessary or preference technologies under their notices.
Our providers may process information outside Ukraine or your country. Where required, we rely on lawful transfer mechanisms and provider safeguards.
6. Retention and security
We keep account and invitation data while your account is active or as needed to provide the service. Contact-form content is sent to our support inbox and is not intentionally stored in Sevidate's application database. Billing and security records may be kept longer where needed for accounting, fraud prevention, dispute handling, or legal compliance.
We use access controls, HTTPS, restricted server-side credentials, and other reasonable safeguards. No internet service can guarantee absolute security.
7. Your choices and rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent where processing relies on consent. You may also complain to the competent data-protection authority. Ukrainian personal-data rights apply, and EEA/UK rights apply where their laws cover the processing.
Use our contact form and choose “Privacy request.” We may need to verify your identity. Some records cannot be deleted immediately where retention is legally required or needed to establish, exercise, or defend claims.
8. Children and policy changes
Sevidate is not directed to children who cannot lawfully consent to data processing or enter into the service agreement. If you believe a child submitted personal data improperly, contact us.
We may update this policy as the service or legal requirements change. We will post the revised date here and provide additional notice when required.