Floryn
Privacy Policy
Last updated 3 October 2026
The short version
Floryn has no email sign-up, no passwords to choose, no payments and no advertising. You type the details of a wedding into a form, get a link and login credentials, and share the link. That link is the invitation. Anyone who has the link can read it, so the link is the invitation — treat it as the thing you would hand out at a door.
Invitations are not tied to email or identity. If you find a record containing your name, it did not necessarily come from you. See who can create one. The login credentials (slug and secret) allow you to edit or delete your own invitation.
Every invitation is deleted automatically 90 days after it was created. The couple can also delete it at any moment from the dashboard: it asks once, then removes the record immediately and permanently, with no backup we can restore from and no soft-delete state, so deletion really is deletion.
We do not run analytics of any kind. Nothing on this site tracks you between pages, follows you around the web, or profiles you.
Who is responsible for your data
Floryn is operated by Minosh. Under the Sri Lankan Personal Data Protection Act, No. 9 of 2022 ("PDPA"), the operator of this service is the controller of the personal data described below, and the Data Protection Authority of Sri Lanka is the regulator. This policy is written to meet the transparency duty in section 11 of that Act.
This service is run by one person, not a company. If you need to reach us about anything in this policy, use the address at the bottom. There is no formally appointed Data Protection Officer; the same address is the contact point for data subject requests.
What an invitation actually contains
These are the only fields stored for an invitation. There is no user table, no login table, and no analytics table, because there is no concept of a user.
slug |
The short address in the link, built from the couple's initials plus a short random suffix. It is what makes the link work and is not a secret. |
|---|---|
bride_name |
Name shown on the card. |
groom_name |
Name shown on the card. |
date, time |
Wedding date and time, used for the countdown. |
venue_name |
Venue name shown on the card. |
venue_address |
Street address shown on the card. |
venue_map_url |
A map link you paste in. If you share a Google Maps link, any click-tracking parameters on it are stripped before storage, so we do not keep a per-link campaign identifier. |
message |
Your note, up to 500 characters, shown on the card. |
photo_url |
A URL to an image, if you use one. Floryn does not host photos for you; the image is fetched from wherever you pointed at. |
template, color_theme |
Which card design and color scheme you picked. |
guests |
The guest list you generate on the dashboard, up to 200 names, stored encoded (readable, not encrypted) so the list survives across your devices. Each entry carries that guest's RSVP answer and when they gave it, if any. |
rsvp_enabled |
Whether the card shows RSVP buttons. |
share_message |
The message you type on the dashboard to send with guest links, up to 1000 characters. Copied with the links, never shown on the card. |
created_at |
When you created it. Written by us, not by you, and used to expire the invitation after 90 days. |
active |
Whether the record is still served. |
Who can create an invitation
Invitations are not tied to an email address or an approval step. Floryn does not record who created a record, so we cannot tell you whether a given invitation is yours, and we cannot confirm the identity of whoever made one. Practically that means a name can appear on a Floryn invitation that somebody wrote about you without asking. The login credentials (slug and secret) are randomly generated and shown only once; they allow you to manage an invitation but do not identify you.
We do not moderate content and we cannot review every record as it is created. If a Floryn invitation names you and you did not expect it, write to us with the link and we will look at it. We can delete a record on request, and you can also find a Delete button on any invitation you created yourself.
What is not collected
- No email addresses. Floryn cannot send you anything, by design.
- No phone numbers and no physical addresses of guests.
- No personal identification stored with login credentials. Your slug and secret are randomly generated and used only to prove you can manage a specific invitation; they are not connected to an email, name or other identifier.
- No IP addresses stored by us, no device identifiers, and no advertising, analytics or profiling cookies. The one cookie this site can set is strictly functional, and it is described under what is stored on your device.
- No third-party analytics, advertising pixels, session recording or heat maps.
Guest names, and why the link is the secret
Guest names are not encrypted. When you personalize a link for a guest, their name is included in the URL. The link itself is the secret — anyone who has it can see the guest's name.
The guest list you generate on the dashboard is stored with the invitation, encoded but readable, so it is still there when you sign in from another device. A personalized link itself reveals only the one name it was made for, to anyone who receives that link.
In practice this means: a personalized guest link reveals who it was made for to anyone who receives it. If that matters for your guest list, send the unpersonalized link instead. We cannot make the name private without turning every guest into an account, which would be a worse trade.
Who can see an invitation
- Anyone with the link. There is no password, no login and no per-guest access control on an invitation. This is the intended behavior, not an oversight.
-
Search engines and link previews. Invitation pages ask
crawlers not to index them, but that is a request, not a control. If
you want an invitation to stay unlisted, do not rely on the
noindextag alone. - Anyone you paste the link into. Messaging apps, email and social platforms all handle the link themselves, and several of them will generate a preview of the page.
Other services that handle data on a guest's visit
These services are contacted directly by your browser while loading the page. None of them are used to track anyone across the web.
- Hosting and content delivery — Cloudflare serves the site to you and keeps its own security logs.
- Database — invitation records are stored on a private database.
- Bot protection — creating an invitation or signing in checks a Cloudflare Turnstile challenge, so your browser contacts Cloudflare's challenge servers and they see your IP address. No account or tracking is involved.
- Google Maps — only if a guest taps the venue link on the card. Nothing is sent to Google before that tap.
What is stored on your device
Two things, both strictly functional. Neither is used to track you, and neither is ever sent to us.
| Builder access cookie |
The builder is currently reachable only by people who know a
private access password, and a cookie remembers that a visitor has
entered it so they are not asked again. It is
HttpOnly and SameSite=Strict, so scripts
cannot read it and it is not sent to other sites. Guests
never receive it — only someone opening the builder
does. The password and this cookie are removed when the site opens
to the public.
|
|---|---|
floryn:guest:<slug> |
Local storage on a guest's own device, holding that guest's name so a personalized card still greets them if they reload. It never leaves the device and is never sent to us. Clearing site data removes it. |
How long we keep things
- 90 days. Every invitation is permanently deleted by an automatic sweep once it is 90 days old. There is no archive.
- Any time before that. The dashboard delete button asks once and then removes the record immediately, with no recovery copy.
- After deletion. The record is gone from the live database. Hosting and database providers may keep their own backups for a short period, and copies may persist in log files; we do not control that and cannot give it a fixed end date.
- Your own device. The guest-name entry in local storage stays until the guest clears their browser data.
Because deletion is real and immediate, an invitation is worth recreating if you need to change it after deleting. There is no undo.
Your rights
Under the PDPA you have the right to access your data, to have inaccurate data corrected, to withdraw consent, to object to further processing, and to have data erased in the circumstances the Act allows. You also have the right to ask for a review of any decision made about you by automated processing, and to appeal to the Data Protection Authority of Sri Lanka.
If you are in the EU or UK, the GDPR gives you the same rights plus the right to restriction and to data portability, and the right to complain to your local supervisory authority. Floryn is not established in the EU and is not a GDPR "processor", but we apply the same standard to everybody rather than sorting requests by nationality.
How to make a request
Write to us with the slug from the invitation link — that is the part
after /invite/ — and say what you want. A written request
must be answered within 21 working days under section 17
of the PDPA, extendable only where the Act allows. In practice a
deletion request is actioned in minutes.
One honest limitation: an invitation does not record who created it. We store no email address, so if you never kept the link, we cannot tell you whether a given slug is yours or show you who made it. Keep the link if you want the ability to delete it later.
Security
This service handles a small, low-sensitivity amount of data, and the measures below are real but modest. It is not a bank and should not be treated like one.
- Deletion is a hard delete at the database, not a hidden flag.
- The database is not readable by unauthenticated requests.
- A strict Content-Security-Policy, so injected markup or script cannot run even if it were stored.
- No analytics, so no cross-site tracking surface to abuse.
No system is perfect. If a breach affects personal data, we will tell the affected people and notify the Data Protection Authority as the Act requires. We will not be able to guarantee a particular notification timeline, because the Act's timeline depends on decisions we would have to make under pressure.
Children
Floryn is made for weddings, and weddings involve guests of many ages. We do not knowingly collect information from children, and we collect no information directly from anyone at all — the only person who types anything in is the couple creating the invitation. If a guest is a child, their name is personal data and the same rights above apply on their behalf by a parent or guardian. Nothing on this site is directed at children or built to draw them in.
Data outside Sri Lanka
Parts of the service rely on providers outside Sri Lanka. Your data is processed outside Sri Lanka as a normal part of serving the page, under the PDPA's cross-border provisions.
Changes to this policy
If this policy changes, the date at the top changes with it. Material changes — what we store, who sees it, or how long we keep it — will be reflected here, and because we have no way to email you, that page is the only notice you will get.
Contact
Questions, requests and complaints about this policy: write to [email protected] with the invitation slug in the subject line. For anything involving the data of a guest rather than your own invitation, we will need the slug, since we hold no other identifier.