This policy explains how parati handles your personal data under Law No. 29733, Peru's Personal Data Protection Law, and its Regulation approved by Supreme Decree No. 016-2024-JUS. A summary comes first; the detail follows. This is a translation; if it differs from the Spanish version, the Spanish version prevails.
In short
- We use your data so your event, your gift registry and your payments work. We do not sell or rent personal data.
- If you are a guest, the organizer sees what you send them (your RSVP, gift, message, photos). Nothing else.
- We only message you on WhatsApp or send you news and promotions if you expressly agree, and you can withdraw that at any time.
- Some providers (Cloudflare, Google, Meta, Zoho, the payment gateways and the map, font or video services shown in invitations) may process data outside Peru. We tell you which ones and why.
- You can ask for access, correction, deletion or objection by writing to soporte@paratipe.com. If we do not answer properly, you can go to Peru's National Personal Data Protection Authority.
1. Who we are and our role
In short: parati is the controller of the data it needs to provide the service. When the organizer uploads their own guest list, parati processes it on their behalf.
TUSOCIO IA S.A.C. (RUC 20615869580), with its address at Av. Venezuela 1861, Lima, Perú, operates the parati platform (paratipe.com and app.paratipe.com, the "Platform").
When we are the controller
- Your account and profile data, and identity verification for payouts.
- Data of guests who reply to an invitation, buy a gift or agree to receive WhatsApp messages.
- Payment, receipt and payout data.
- Browsing, security and support data and, if you agree, marketing communications.
- Contact lists parati uses to invite people to create an account, with their source and authorization recorded.
When we act on the organizer's behalf
When the organizer enters or imports (for example, from Excel) their guest list, or receives guests' photos in the event album, the organizer decides which data to include and whom to invite. In those cases parati processes that data on the organizer's behalf and only to provide the service they asked for. The organizer must have a legal basis to share that data with us (see the Terms and Conditions).
2. What data we process, why and for how long
In short: This table summarizes each type of data. If something is not here, we do not use it for anything else without telling you first.
| Data | Purpose | Basis | How long | With whom / where |
|---|---|---|---|---|
| Account: name, email, phone, password (or your Google sign-in) | Create and protect your account; send you service notices (confirmations, payments, security) | Contract (the Terms) | While you keep the account. If you ask us to close it, we delete it, or anonymize it if there are payments we must keep | Our identity system on our server; Google if you sign in with Google; Zoho for email |
| Your event: names of the people celebrated, date, venue, schedule, texts, photos, gift list | Publish your invitation and gift registry | Contract | While the event exists. You can delete it at any time if it has no payments | Our server; Cloudflare to deliver the page. Anyone with the link can see it |
| Verification and payouts: legal name, document type and number, photo of your ID (DNI), bank, account number and CCI | Confirm your identity, prevent fraud and transfer your gift money to you | Contract and legal obligations | While the account has a balance or payouts, then for the period required by tax and accounting rules (at least 5 years, or the limitation period if longer — Peruvian Tax Code art. 87.7). Our team deletes the ID photo when it handles your account closure request | Private storage on our server; your bank when the transfer is made |
| Guests who RSVP: name, phone or email, attendance, companions, message or dedication | Record your reply and show it to the organizer | Your decision to reply to the invitation | While the event exists | Our server; the organizer (and their planner, if any) |
| Gifts and payments: name, email, amount, message, payment status. Card data goes to the gateway, not to parati | Charge the gift, notify the organizer, keep the books and prevent fraud | Contract and legal obligations | While the transaction is active, then for the period required by tax and accounting rules (at least 5 years, or the limitation period if longer — Peruvian Tax Code art. 87.7) | MercadoPago or Culqi, through our payment service; the organizer sees name, amount and message |
| Manual payment (Yape or bank transfer): operation number and photo of the receipt | Check that the money arrived and approve the gift | Contract | Same as payments | Private storage; only the parati team reviews it |
| WhatsApp: number and your opt-in (the text you accepted and the date) | Send you event reminders on WhatsApp | Your express consent (checkbox) | Until you withdraw it. We keep the record of your opt-in or opt-out while the event exists | Meta (WhatsApp Business), through our messaging provider |
| Guests' photos and videos | Build the event album | Your decision to upload them, on the organizer's behalf | Until the organizer or you delete them, or the event is deleted | Our server; the organizer's Google Photos if connected |
| The organizer's guest list (name, phone, email; also imported from Excel) | Manage guests and send them the invitation and reminders | On the organizer's behalf | Until the organizer deletes it or the event is deleted | Our server; Zoho for email |
| Google Photos: encrypted access token | Copy the event's photos to your album | Your consent on Google's screen | Until you disconnect the account | Google (see section 5) |
| Planners: profile, assigned events, referral commissions, bank details | Manage their clients' events and pay their commissions | Contract | Same as account and payouts | Our server; the organizer who invited them |
| Support: messages, screenshots, complaints | Handle your question or complaint | Your request; legal obligation for complaints | While it is handled, then the legal period for the Complaints Book | Zoho (email); WhatsApp if you write to us there |
| Browsing and security: IP, device, browser, technical logs | Keep the site secure and working | Necessary to provide the service | Short periods, only as needed for security | Cloudflare; our server |
| Advertising: Meta pixel identifiers on paratipe.com | Measure our ads and show you parati ads | Your consent: it only loads if you accept it in the cookie notice, and you can withdraw it at any time | Up to 90 days (Meta cookies) | Meta (see the Cookie Policy) |
| News and promotions: email, your preference and the record of your answer (the text you accepted or declined, its version and the date) | Send you parati news | Your express consent, separate from the Terms | Until you unsubscribe. We keep the record of your answers as proof | Zoho |
Our server is a private server rented by parati, where we keep the database and files (S3-compatible storage). Only authorized parati staff can access it.
3. If you are a guest
In short: The organizer sent you the invitation. They see what you reply; WhatsApp messages only arrive if you accept them.
- The organizer may have entered your name and your number or email to send you the invitation. If you do not want to be on their list, ask them or write to us.
- When you RSVP, buy a gift or leave a message, the organizer sees your name, your reply, the amount and your message.
- WhatsApp reminders are only sent if you tick the box that allows them. If you change your number, the permission does not move to the new number. You can opt out from the message itself or by writing to us.
- Photos you upload to the album are seen by the organizer and, if they turned it on, copied to their Google Photos.
- If the invitation shows a third-party map, fonts or video (Google Maps, Google Fonts, YouTube or another player chosen by the organizer), that provider receives your browser's request (your IP and browser details) when the invitation loads or when that content scrolls into view, and handles it under its own policy.
4. Who we share data with and transfers outside Peru
In short: Only with the providers we need to operate, and with authorities when the law requires it. Some are outside Peru.
We do not sell or rent personal data. We share it only with:
| Provider | Purpose | Where it processes data |
|---|---|---|
| Cloudflare | Deliver the site, protect it from attacks and measure traffic without cookies | Global network, including the US |
| Sign in with Google and, if you connect it, Google Photos | US and other countries | |
| Meta (WhatsApp Business and pixel) | WhatsApp reminders you accepted and ad measurement | US and other countries |
| Zoho | Sending and receiving email | Outside Peru |
| MercadoPago and Culqi | Processing card and wallet payments | MercadoPago: outside Peru; Culqi: Peru |
| Banks | Transferring payout money | Peru |
| Google Maps, Google Fonts, YouTube or another video player chosen by the organizer | Show the venue map, the design's fonts or a video in invitations. They receive the guest's browser request (IP and browser details) when the invitation loads or when that content scrolls into view, and may set their own cookies | US and other countries |
Payment gateways handle card data under their own policies; parati never receives or stores your full card number. We require our providers to apply appropriate security and confidentiality measures, and we only give them the data they need for the task we assign them.
Other cases
- When a law, a competent authority or a court requires it.
- To protect our users against fraud or abuse.
- If parati merges or sells its business, the data would pass to the new owner, who must respect this policy. We will tell you beforehand.
5. Google Photos and Google user data
In short: If you connect Google Photos, we can only add the event's photos to your library. We cannot see what you already have.
If you are an organizer, you can optionally connect your Google Photos account to your event so that parati saves a copy of the event's photos and videos there, including the ones your guests upload. To do so we request a single Google permission: "Add to your Google Photos library" (photoslibrary.appendonly).
What we do with that permission
- Create an album for the event in your library.
- Upload the event's photos and videos to that album.
What we do not do
- We do not view, list, modify or delete the photos and videos already in your Google Photos: that permission does not allow it.
- We do not use access to your account for any purpose other than the one described in this section.
How we keep the access
Google gives us a token that we store encrypted and use only to keep uploading the event's photos while the connection is active. You can disconnect Google Photos from your event in parati or revoke access in your Google Account permissions; either way we delete the token. Whatever was already uploaded stays in your Google Photos and under your control: disconnecting the account or deleting the event in parati does not remove it from your library.
If you are a guest
If the organizer connected Google Photos, the photos and videos you upload to the event are stored in parati and also copied to the event album in the organizer's Google account.
Limited Use
The following restrictions apply to all data received from Google and take precedence over anything else in this policy:
- We do not sell your Google user data or transfer it to third parties, except as needed to provide this feature, for security purposes, to comply with the law, or as part of a merger or acquisition.
- We do not use your Google user data for advertising.
- We do not use your Google user data to train artificial intelligence or machine learning models.
- No person reads your Google user data, except with your explicit consent, for security purposes or to comply with legal obligations.
parati's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. Messages we send you
In short: Service notices always arrive. News and promotions, and WhatsApp messages, only if you accept them; signing up does not count as accepting.
- Service notices: confirmations, gifts received, payments, payouts, security and changes to these documents. They are part of the service and need no separate permission. You can adjust some of them (for example, the daily digest) from your profile.
- parati news and promotions: only if you expressly tick the corresponding box, which starts unticked. Accepting the Terms or using the Platform does not count as accepting them. We record when you accepted or declined and with which text. You can withdraw at any time from Profile → Notifications (the "News and promotions" switch) or by writing to soporte@paratipe.com. If you created your account before October 8, 2026, we do not send you news until you answer again.
- Getting-started help emails: if you ask for them from your dashboard or authorize us to send them, we send you a short series of emails to create your first event. The unsubscribe link in those emails stops only that series; to stop all news and promotions, use Profile → Notifications or write to us.
- WhatsApp: only for event reminders you accepted, never third-party advertising.
- Commercial email: parati only sends commercial email to people who gave us their consent directly or asked us to contact them. Contacts an organizer enters or imports for their own event receive only that event's invitation, which we send on the organizer's behalf; we do not use them to promote parati.
7. Your rights and how to exercise them
In short: Write to soporte@paratipe.com from your account's email. It is free and we answer within the legal deadlines.
- Information: know what data we process, why and with whom.
- Access: get a copy of your data.
- Rectification: correct inaccurate or incomplete data. You can edit much of it yourself in your profile.
- Cancellation: ask us to delete your data when it is no longer needed, except what the law requires us to keep.
- Objection: object to processing on legitimate grounds, and in any case to advertising.
- Portability: receive your data in a structured, commonly used format, where the regulation recognizes it.
- Withdraw your consent at any time, without affecting what was done before.
- Not to be subject to decisions based solely on automated processing that significantly affect you. parati does not make such decisions today.
How to ask
- Write to soporte@paratipe.com with the subject "ARCO rights", stating your name, the right you want to exercise and, if you are a guest, the event.
- If you write from an email other than your account's, or on behalf of someone else, we may ask you to prove your identity or authority. We will not ask for more data than needed.
- If your data is in an organizer's guest list, you can also ask them; we pass your request on to them.
- We answer within the Regulation's deadlines: up to 8 business days for information, 20 for access and 10 for rectification, cancellation or objection.
If you are not satisfied with our answer, you can file a claim with Peru's National Personal Data Protection Authority (Ministry of Justice and Human Rights).
8. Minors
In short: Only people over 18 can hold an account. At events such as quinceañeras, the adult organizing answers for the minor's data and photos.
- You must be over 18 to create an account and organize an event.
- If the event celebrates a minor (for example, a quinceañera or a child's birthday), the organizer must be their parent or guardian or have their authorization, and decides which name, photos and data of the minor are published.
- Guests under 14 should RSVP, accept messages or upload photos with the help of a parent or guardian.
- We do not use minors' data for advertising or to send them news.
- If you are a parent or guardian and want us to remove a minor's data or photos, write to soporte@paratipe.com and we will handle it as a priority.
9. How we protect your data
In short: Encrypted connections, restricted access and sensitive documents in private storage. If an incident affects you, we will tell you.
- All communication with the Platform is encrypted (HTTPS).
- Passwords are managed by our identity system and stored hashed; never in plain text. If you sign in with Google, we never receive your password.
- ID photos and payment receipts are kept in private storage that only authorized staff can access.
- We keep our systems and dependencies up to date.
No system is infallible. If a security incident affects your data, we will notify the authority and the people affected as the law requires. If you find a vulnerability, report it to soporte@paratipe.com.
10. Cookies
In short: We use technical cookies and, on paratipe.com, Meta's advertising pixel.
Each cookie, its purpose, its duration and how to reject it is described in our Cookie Policy (in Spanish). The Meta pixel is an advertising tool, not anonymous analytics.
11. Changes to this policy
In short: If we change something important, we tell you 30 days in advance. If a change needs your consent, we will ask for it.
When we make substantial changes, we will notify you by email or with a visible notice on the Platform at least 30 days before they take effect. If a change means using your data for a new purpose that requires consent, we will ask you expressly; continuing to use the Platform does not count as consent.
| Version | Date | Changes |
|---|---|---|
| 2.0 | October 8, 2026 | Corrections after review. |
| 2.0 | October 8, 2026 | Opening summary, data table with retention periods, roles of parati and the organizer, guests, minors, WhatsApp, manual payments, identity verification, international transfers, Supreme Decree 016-2024-JUS. Providers we do not use were removed. |
| 1.x | October 4, 2026 | Previous version. |
12. Contact
For any question about this policy or your data: