What a trip page stores, who can see it, and how long it is kept.
Last updated 6 September 2026
| The organiser | Your email address, used to sign you in with a one-time code. No password is ever stored. |
|---|---|
| The trip | Everything you type into the builder: title, start, meeting point, route, difficulty, distances, cost, what to bring, notes. |
| RSVPs | The name a guest gives, their answer, their seat count, the contact they leave, the optional emergency contact, and a message. Guests past the seat limit are recorded as waitlisted. |
| The album | The photos and video you upload, and a log of which email addresses opened the album, when and from which IP address — shown to you so you know who saw your group's photographs. |
| Codes and limits | Hashed one-time codes and rate-limit counters, which expire on their own. |
Delete the trip from your dashboard, or email rsvp@qaffaf.com from the address you signed up with. We delete the page, every RSVP including emergency contacts, every photo and video, the thumbnails and the access log within seven days, and reply to confirm. A guest who wants their own RSVP removed can ask the organiser or email us.
The page runs on Cloudflare's network; the database and photos are stored on Cloudflare (D1 and R2). Emails are sent through Cloudflare from rsvp@qaffaf.com.