Last updated: 2026-08-15
This page explains what cookies and data whimsy.cards collects, why, and how long it is kept. We keep our cookie footprint as small as possible.
The controller of whimsy.cards is IOSIF DANIEL-IONEL PERSOANĂ FIZICĂ AUTORIZATĂ, professional office at Municipiul Târgu Mureș, Calea Sighișoarei no. 17, ap. 4, Mureș County, Romania, tax ID 55238922, Trade Register no. F2026035949000.
We process data under the GDPR and Romanian Law no. 190/2018.
We may process identification and contact details; billing and transaction records; technical and usage data; invitation text, images and event details; account data and a password hash held by our authentication provider; and RSVP answers submitted through the general invitation link, such as name, optional email, attendance, guest counts, message and organiser-defined fields. Stripe processes card details; we do not store full card numbers. Facebook/Google Login supplies the profile data you authorise; we do not receive your provider password.
Contract performance: account administration, orders, payments, invitations, transactional notices and support. Legal obligation: accounting records and lawful authority requests; accounting documents are generally kept for 5 years calculated from 1 July of the following year unless a special rule applies. Consent: newsletters, commercial messages and optional audience analytics; consent may be withdrawn at any time. Legitimate interests: security, fraud and abuse prevention, error diagnosis and minimal operational telemetry, subject to your right to object.
We use Stripe (payments), Resend (email), Supabase (database, authentication and storage), Vercel (hosting), Sentry (error monitoring and masked session replay), Upstash (abuse prevention), Cloudflare Turnstile (anti-bot), Cloudinary (media delivery), Railway (scheduled jobs), Google and Meta/Facebook (optional login), and Google Maps and Google Fonts. They receive only data needed for their function. Stripe may be an independent controller for some payment, fraud and compliance activities. We may disclose data where legally required. We do not sell or rent personal data for advertising.
Account/profile: while active, then removed from active systems on deletion, subject to legal exceptions. Digital invitations/media: until deleted; trash is permanently purged within 48 hours. RSVP responses: up to 12 months from submission, or sooner when the invitation/account is deleted. Removing old RSVP responses does not delete the digital invitation or disable new responses while the form is active and its deadline has not passed. Optional analytics: 90 days. Completed email recipient/content and delivery events: 30 days. Security/audit logs: up to 12 months; resolved/ignored error logs: 30 days and all error logs at most 12 months. Marketing preferences: until consent is withdrawn. Accounting records: the applicable legal term, generally 5 years from 1 July of the following year. Claim-related data may be retained for the applicable limitation period. Backups expire through technical rotation.
Subject to GDPR conditions, you have rights to information and access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and complaint to a supervisory authority. We do not use solely automated decisions that produce legal or similarly significant effects. Erasure is not absolute: we may keep accounting records, data required by law, or data needed to establish, exercise or defend legal claims.
Contact us:
Email: contact@etherealstories.com (subject: "GDPR Request")
Response time: Maximum 30 days from receipt of request (Art. 12 GDPR). This period may be extended by 60 days for complex requests — we will inform you within the first 30 days.
Identity verification: Requests sent from the email address registered in your account are processed directly. If you contact us from a different address, we may ask for proof of identity (copy of ID or verification via your existing account) to prevent disclosing data to unauthorised persons.
Costs: Exercising your rights is FREE. For excessive or repetitive requests we may charge a reasonable administrative fee or refuse the request.
Right to complain: You may lodge a complaint with:
The National Supervisory Authority for Personal Data Processing (ANSPDCP)
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest
www.dataprotection.ro | anspdcp@dataprotection.ro | +40 21 252 5599
We apply technical and organisational measures appropriate to risk, including TLS, access controls, password hashing by the authentication provider, rate limiting, monitoring and incident response. No transmission or storage method guarantees absolute security. We notify ANSPDCP without undue delay and, where feasible, within 72 hours of becoming aware of a breach that is likely to pose a risk; affected people are informed when the legal high-risk threshold is met.
The Service is not intended for account creation by children under 16. Invitations may nevertheless contain a child's name or image uploaded by an organiser, who must have a lawful basis and any required permissions. A parent or guardian may contact us so we can assess and, where appropriate, delete the data.
We use cookies for site operation and analytics. For full details please consult the Cookie Policy at /cookies.
We may update this policy to reflect changes to the Service or law. The current version and date are displayed here. We will provide appropriate notice of material changes and request separate consent when a new activity requires it.
For questions about this policy or processing, email contact@etherealstories.com.
The organiser shares the digital invitation through one general link. RSVP data may include name, optional email, attendance, adult/child counts, a message and organiser-defined answers. It is visible to the organiser and our technical providers as needed, not to other guests, and is not used for our marketing. The organiser is ordinarily the controller for RSVP content and purpose, while we act on its instructions as processor. We may be an independent controller for platform security, abuse prevention and our legal duties. Organisers must not request health, religion or other special-category data without a valid legal basis. Guests should contact the organiser first, or contact@etherealstories.com with the invitation link if that is not possible.
Providers may process data in the EU/EEA and, depending on their configuration, in third countries including the United States. For transfers outside the EU/EEA we rely, as applicable, on an adequacy decision (including the EU-US Data Privacy Framework for eligible participants) or safeguards such as Standard Contractual Clauses and supplementary measures where required. Ask contact@etherealstories.com about the applicable mechanism.
Main providers: Supabase — database, authentication and storage; Vercel — hosting and functions; Stripe — payments and fraud prevention; Resend — email; Sentry — error monitoring; Upstash — abuse prevention; Cloudflare Turnstile — anti-bot; Cloudinary — media delivery; Railway — scheduled jobs; Google and Meta/Facebook — optional login; Google Maps and Google Fonts — maps and fonts. Providers are contractually bound where required by their role and applicable law. We will update this policy when a provider change materially affects processing.