Effective: July 28, 2026 — Last updated: July 28, 2026
1. Who is responsible for the data
بشرى, operating under the Bushra brand, is responsible for personal data processed to operate the website, sell and host invitations, administer orders, secure the service, and provide support. When an invitation owner chooses which guest data to collect and why, that owner also has responsibilities toward guests, while Bushra processes the data to provide the requested invitation service. Current correspondence details are available on the Contact us page.
2. Scope
This policy applies to Bushra's public website, template previews, customer drafts, manual payment coordination, hosted invitation pages, invitation-management portal, RSVP and wish forms, guest links, QR tickets, check-in tools, support requests, and administrative operations.
3. Data we collect about customers
We may collect the customer's name, email address, phone number, order and support communications, selected template, event and invitation settings, uploaded files, portal activity, and preferences. Invitation content may include names, family names, event dates and times, venue and map details, schedules, notes, photographs, audio, video, and other information the customer chooses to provide.
4. Data we collect about guests and visitors
Depending on the enabled features, we may collect a guest's name, phone number or email, attendance response, number of companions, message, wish, guest-link source, ticket details, and check-in status and time. We may also process page views, browser and device information, user agent, approximate request time, security events, an IP address, and an approximate city or country when supplied by the hosting provider. We do not ask guests for payment-card data.
5. Sources of data
We receive data directly from customers, guests, invitation visitors, and Super Admins acting on a customer's instructions. We also generate operational records when the website, invitation, portal, ticket, or check-in features are used.
6. Why and on what basis we process data
We process data to create and deliver invitations; complete orders and payments; provide portal access; publish event details chosen by the customer; manage RSVPs, wishes, guest links, tickets, and check-in; provide support; prevent fraud and abuse; protect links and sessions; troubleshoot and improve reliability; keep accounting and audit records; establish or defend legal claims; and comply with law. Depending on the activity and applicable law, processing is based on performing the customer agreement, steps requested before entering it, consent, compliance with legal obligations, and legitimate interests in operating and securing the service. Where processing is based on consent, it may be withdrawn without affecting processing already carried out lawfully.
7. Payment information
Payments are currently coordinated directly with Bushra through CliQ or Zain Cash. We may receive and retain the transfer reference, amount, currency, sender details needed to match the payment, payment time, and any receipt you choose to share. We do not request or store payment-card numbers, expiry dates, or security codes.
8. Invitation visibility and public content
Invitation links are normally excluded from search indexing unless the owner enables indexing, but an unlisted link is not the same as an encrypted or secret document. Anyone who receives a public invitation link may be able to view its published content and may forward it. Management, guest, and ticket links can grant additional access and must be protected. Approved wishes and the guest name attached to them may be displayed on the invitation when that feature is enabled. Customers should avoid publishing information they do not want recipients to see.
9. Cookies and local storage
Bushra uses cookies or similar browser storage that are necessary to maintain protected administrator, draft, and customer-portal sessions, remember essential interface state, protect forms, and secure access. These technologies are not used to sell personal data. If optional analytics, advertising, or non-essential cookies are introduced, this policy and any required consent control will be updated before they are used.
10. Who we share data with
We may disclose only the data reasonably necessary to hosting, database, file-storage, email or messaging, security, and technical-support providers acting for Bushra; authorized Bushra personnel; invitation owners and their authorized managers; guests who can view published invitation content; professional advisers; and authorities when disclosure is legally required or necessary to protect rights and safety. We do not sell personal data and do not provide it to third parties for their independent advertising.
11. International processing
Some infrastructure, storage, or messaging providers may process data outside Jordan. Where this occurs, Bushra will select appropriate providers and use the contractual, technical, and legal safeguards required for the transfer, taking account of the nature of the data and the protection available in the destination.
12. Retention and deletion
We keep data only for as long as reasonably needed for the purposes described above. Active invitation data is retained while the service is provided and for a reasonable period afterward to support recovery, disputes, and customer requests. Order, payment, accounting, fraud-prevention, consent, and audit records may be retained longer where required by law or needed to establish legal rights. When data is no longer needed, it is deleted, anonymized, or securely isolated from normal use. Backup copies may remain for a limited rotation period before being overwritten.
13. Security and incidents
We use safeguards appropriate to the service, including encrypted transport, protected and HttpOnly sessions where applicable, hashing of authentication secrets and selected network identifiers, role-based permissions, invitation isolation, expiring or revocable access, rate limiting, upload restrictions, and audit logging. No online service can guarantee absolute security. If a personal-data incident occurs, we will investigate, mitigate it, and notify affected people and competent authorities when required by applicable law.
14. Your data-protection rights
Subject to applicable law and identity verification, you may request information about processing, access to your data, a copy, correction or completion, deletion, restriction or concealment, objection to certain processing, and withdrawal of consent. You may also complain about how a request was handled. Some requests may be limited where retention or processing is required by law, needed to protect another person's rights, or necessary for legal claims. Invitation guests may contact the invitation owner first for event-specific details and may also contact Bushra. We will respond according to the procedures and time limits required by applicable law.
15. Children
Bushra's purchasing and management services are not directed to children who cannot lawfully enter the agreement. An event host may include a child's name or companion count for an invitation, but should provide only what is necessary and obtain any legally required parental or guardian authorization. Contact us to request removal of a child's data.
16. Requests, complaints, and updates
To exercise a privacy right or report a concern, use the Contact us page. We may request information needed to verify identity and protect the invitation from unauthorized changes. You may also complain to the competent personal-data-protection authority in Jordan. We may update this policy when the service, providers, or law changes. The effective and last-updated dates appear at the top. Material changes will be highlighted or otherwise communicated where reasonably required.
