Ah - I had not considered SendGrid.
From an absolute security perspective, using some sort of hash or similar unique ID then referencing a database seems like the strongest solution.
But you are right, at large scale encoding the data in the URL plus some sort of HMAC would provide strong security with no database overhead, which I'm sure becomes significant at scale.
Might be interesting to try and reverse engineer their approach. Hash algorithms have a rather long history of being proven weaker than hoped... Especially down the road this could lead to some interesting possible exploits, mostly if the link was related to some kind of account a little more sensitive than meetup.com
Thanks for clarifying my thinking on this matter...