Privacy Policy

Last updated: August 21, 2026

1. Who we are

Brindis operates brindis.me and app.brindis.me, a platform for creating digital invitations and managing the guests of an event. This policy explains what personal data we process, in which role, for how long, and how to exercise your rights.

Brindis.me is operated by Gabriel Zerbino, RUT 219521720013 (national ID 4.640.662-4), domiciled at Obligado 1131 Bis, Montevideo, Uruguay.

For questions, or to exercise any of the rights in section 8: info@brindis.me.

2. The two roles, and why they matter

Brindis processes personal data under two distinct roles, and which one applies determines who decides about that data.

  • For the data of our users — whoever registers and creates an event — and of our leads, Brindis is the controller: we decide what it is used for.
  • For the data of the guests an organiser uploads to their event, Brindis is the processor. The organiser is the controller. We act only on their instruction and never use that data for any purpose of our own.

In practice: if you are a guest at an event and want your data deleted, the person who decides is the organiser who invited you. You can still write to us — we will help and pass the request along — but the decision is not ours.

3. Data we process as controller

3.1 About users.

Name, email, phone, time zone, language and preferences; the content of the events you create (name, date, venue, invitation design, budget, tasks, seating plan); billing and usage data. Legal basis: performance of the contract between you and Brindis.

3.2 About leads.

If you joined the waitlist or left us your email, we process that email, your country inferred from approximate geolocation, your language and the record of your consent. Legal basis: your consent, which you can withdraw from the unsubscribe link in any email.

3.3 About usage.

Technical browsing data, errors and product usage metrics, as described in section 5.

4. Data we process as processor

4.1 What it is.

When an organiser uploads their guest list, we process name, phone, email, RSVP status, dietary restrictions, family group and table assignment. That data is not ours: it belongs to the organiser, who is the controller.

4.2 What we do with it.

Only what the organiser instructs us to do: display the invitation, record RSVPs, send WhatsApp or email messages on their behalf, and organise the reception. We do not use it for advertising, we do not cross-reference it between organisations, and we do not sell it.

4.3 Persistence across events.

An organisation's contact book persists across events, so that an organiser with recurring events does not have to upload the same list again. While the account is active, those contacts remain under the organiser's control, who can view, export and delete them at any time.

4.4 If you are a guest.

Write to info@brindis.me and we will tell you which organiser holds your data and how to ask them to remove it, or we will pass the request along ourselves. If the organiser instructs us to delete it, we delete it.

5. Third-party tools

We work with providers that process data on our behalf, under contract, and that cannot use it for their own purposes.

5.1 Infrastructure and messaging.

5.2 Analytics.

We use PostHog to understand how the product is used: which screens are visited, which actions are completed and where something fails. We do not record anyone's screen or session. In addition, any link containing an access token is redacted before it leaves your browser. If we enable session recording in the future, we will update this policy and tell you beforehand, as set out in section 10.

5.3 Artificial intelligence.

The invitation design assistant processes your instructions and any reference images you upload through the Google, OpenAI and Anthropic APIs. We contract those services on paid tiers, under which the providers do not use the content to train their models. We do not send guest lists to these services.

5.4 Errors.

We use Sentry to detect failures. The reports include your user identifier so we can reproduce the problem, and not your IP address, your email or the content of your forms.

6. International transfer

Our infrastructure and that of every provider in section 5 is located in the United States. If you access it from outside the United States, your data is transferred there. Each provider is bound by a data processing agreement with contractual clauses requiring an adequate level of protection.

7. How long we keep each thing

7.1 User data.

For as long as your account is active. When you close it, there is a 30-day grace period to reverse the decision; after that, it is permanently deleted along with all its associated content.

7.2 Guest data.

The organiser keeps it for as long as their account is active, or until they delete it. If the organiser closes their account, it is deleted with it.

7.3 Leads.

If you never engaged with our emails and never created an account, we delete your profile after 24 months. If you unsubscribed, we keep an encrypted, irreversible version of your email indefinitely, for the sole purpose of never writing to you again. It is the only way to guarantee the unsubscribe is permanent.

7.4 Technical logs.

Server logs and error reports are kept according to each provider's retention policy, for up to 90 days.

8. Your rights

8.1 As a user.

You have the right to access, rectify, update and delete your data, and to request a portable copy. Account closure and export are available from your profile. For anything else: info@brindis.me.

8.2 As a guest.

Write to info@brindis.me. Since we are the processor and not the controller of that data, we identify the organiser who uploaded it and pass your request on to them, following it through until it is resolved.

8.3 Supervisory authority.

If you believe we did not handle your request properly, you may file a complaint with Uruguay's Unidad Reguladora y de Control de Datos Personales (URCDP), under Law 18.331. If you live elsewhere, you may also turn to the data protection authority of your own jurisdiction.

9. Security

We encrypt communications in transit, store credentials in a secret manager and strip passwords and tokens from every error report before it is stored. Invitation links contain an access token that expires 30 days after the event date; once expired, the invitation becomes read-only and no longer allows RSVPs to be changed.

10. Changes

If we make substantial changes to this policy, we will notify you by email and in the application before they take effect. The last updated date appears at the top.