Skip to main content

Privacy Policy

Last updated: October 6, 2026

SealSend is run by Cameron Ashley, operating as Ashbi Design, in Ontario, Canada. This page explains what information we collect, why, and what choices you have. Canadian privacy law (PIPEDA) applies to us.

1. What we collect

From hosts (people who make events):

  • Account details: email, name, sign-in codes and sign-in sessions.
  • Event details, images and files you upload, and your branding.
  • Client records, if you use them.
  • Beta participation and feedback, if you join the beta or send feedback: your consent choice, your rating, the area you picked, what you wrote, whether we may contact you, and simple milestones from your events.
  • Your email, if you join a waitlist.
  • Simple product-usage events, so we can see what is used and what breaks. We do not use third-party analytics or tracking scripts.

Guest data that hosts upload or guests give us:

  • Names, emails, phone numbers, notes, tags and plus-ones.
  • RSVP answers, including dietary and accessibility notes. These can be sensitive, so please only share what you are comfortable with.
  • Comments, sign-up board claims and check-in times.
  • Optional guest-name sharing, reactions, poll votes, photos and photo captions. Event activities and albums are available only to verified invited guests and authorised hosts. Names appear only if the guest chooses to share them. Photos require host approval unless the host turns that review off. Image metadata is removed when photos are uploaded.

Technical records:

  • Delivery logs of the emails we send, and opt-out (unsubscribe) records.
  • IP addresses and email addresses in short-lived rate-limit records, which stop abuse.
  • Server error logs.

2. How we use it

We use your information to run SealSend: sign you in, show your events, send invitations and reminders you ask for, learn from beta feedback and milestones, collect RSVPs, keep the Service secure, fix problems, and answer your questions. We do not sell your information, and we do not use it for advertising.

3. Guest data and the host's role

The host decides what guest data to upload and is responsible for having permission to contact those guests. SealSend handles that data on the host's behalf, only to run the Service.

Hosts can also set up webhooks and client review links. These send event data to places the host chooses. We do not control those places.

4. Who we share it with

We use these service providers to run SealSend:

  • Mailgun sends our emails (based in the United States).
  • Hostinger hosts our servers.
  • Cloudflare handles our domain name (DNS).
  • OpenAI is used only when you use AI drafting or chat, and AI cover images (event title, description, chosen style and your note). We send the event details you enter. They are not used to train OpenAI's models.
  • Twilio would send text messages. SMS is turned off for now.
  • Stripe would handle payments. Payments are turned off for now.

Your data may be stored or processed outside Canada, including in the United States. Laws there may differ from Canadian law. We may also share information if the law requires it.

5. Cookies

We use essential cookies to make the site work. We do not use advertising cookies.

  • sealsend_session keeps you signed in. It is not readable by scripts on the page (httpOnly) and lasts 7 days. Guests who use their invite or access link also get it.
  • sealsend_user lets the page show who you are. Scripts on the page can read it. It can include your email, phone, role and event id.
  • sealsend_rsvp_<eventId> lets public respondents update their own RSVP in the same browser. It is a private, httpOnly edit credential sent over HTTPS, scoped to the event’s RSVP endpoint, and lasts up to one year. Clearing it removes that browser’s ability to edit the response.
  • sealsend_social_<eventId> keeps invited guests verified for an event’s private activities and photos. It contains the invitation access token, is not readable by page scripts (httpOnly), is sent over HTTPS and lasts up to 7 days.

6. How long we keep it

We keep your data while your account is active. When you ask to delete your account, we treat it as a deletion request: it is scheduled and finished within 7 days. Backups are kept for up to 30 days, so deleted data can stay in backups for up to about 37 days in total.

We keep opt-out lists so we can keep honouring them.

Deleting an event, guest or album photo also deletes its private album files; interrupted file deletion is queued for retry. Optional automatic cleanup is currently disabled. If cleanup is later turned on, a draft event becomes eligible 90 days after its last update, with a 14-day warning first, and an unreferenced upload that is not attached to an event becomes eligible after 7 days.

7. Your choices and rights

Hosts: you can export your data or delete your account in Settings. You can also email support@sealsend.app.

Guests: every guest email has an unsubscribe link that stops that host's emails. To ask for access, correction or deletion of your information, email support@sealsend.app. We may need to involve the host who invited you.

8. Children

SealSend is for people 16 and older. We do not knowingly collect information from anyone under 16.

9. Security

We use HTTPS to protect data in transit, sign-in codes and sessions to protect accounts, and we limit who can reach production data. No system is perfectly secure, so we cannot promise absolute security.

10. Contact and complaints

Our privacy contact is Cameron Ashley, Ashbi Design, 95 Ellesmere Road Suite 1006, Scarborough, ON M1R 4B7, Canada, support@sealsend.app.

If we have not solved your concern, you can complain to the Office of the Privacy Commissioner of Canada.

11. Changes

We may update this policy. We will change the date at the top and, for important changes, email you or show a notice in the app.