Legal
Privacy Policy
Your wedding details and your guest list are the most personal data we hold. This policy explains what we process, why, who helps us run the service, and what you can ask us to do with it.
Last updated: September 2026. This document is a placeholder for your legal review. Replace with counsel-approved copy before launch.
1. Data we process
We process information you provide when building invitations (for example names, event details, and messages), guest and RSVP data submitted through secure flows, and technical data needed to run and secure the service.
If you allow analytics, we use bounded UTM campaign fields from public landing pages in public-site events. If you separately allow ad measurement, we can retain approved click attribution for up to 30 days. That record can include Google, Meta, and TikTok click identifiers and the same UTM fields. We do not store arbitrary URLs, private paths, or form content in this record.
2. How we use data, and on what basis
We use data to deliver invitations, authenticate couples, process RSVPs, and send the emails those steps need. This is necessary to perform our contract with you.
We use technical and error data to keep the service reliable and secure. We use bounded UTM campaign fields only after you allow analytics. We store and use click identifiers only after you separately allow ad measurement.
With your consent, we use Google Analytics to understand visits to selected public pages, collection views, demo opens, new launch-list entries, and completed couple account signups. Google Analytics receives a public page path, a fixed title, and technical information about the visit. It uses cookies to distinguish visits. If you also choose Session insights, Microsoft Clarity records clicks, scrolling, and page changes on selected public pages. Recording text is fully masked. You can withdraw either choice in Cookie settings in the footer. Guest invitations and private dashboards are excluded from this setup. PostHog and Vercel Analytics are disabled by default and need a separate approved reporting purpose.
We do not sell personal data, and we do not use guest data for marketing of any kind.
3. Sharing
We use a small number of providers to run the service, each under a data-processing agreement: Vercel (hosting), Convex (database), Clerk (couple sign-in), Stripe (payment), Resend (transactional email), and Sentry (error reporting, with personal details removed before anything is sent). PostHog and Vercel Analytics are optional providers that are disabled by default.
Google provides Google Analytics, loaded through Google Tag Manager, for optional public-site and signup analytics after consent. Microsoft provides Clarity for optional session insights after a separate choice. If you separately allow ad measurement, we can share permitted conversion data and Google click identifiers with our linked Google Ads account. Ad personalization remains off. We do not send names, email addresses, account identifiers, or guest data to Google for this measurement. You can withdraw these permissions in Cookie settings.
Meta Pixel and TikTok Pixel are not active in this release. Purchase reporting to advertising providers is also disabled. We will update this policy before either feature begins.
We may disclose information if required by law.
4. International transfers
Some of the providers above process data outside the United Kingdom. Where they do, transfers are covered by the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, or by an adequacy decision.
5. Retention
We keep data only as long as we need it for the purposes above, or as long as the law requires.
Guest data. Allergy and access notes are deleted 90 days after the wedding. The rest of the guest list, the replies and the seating are deleted 90 days after the wedding, or 12 months after it if the couple chooses to keep them longer. We email the couple before each deletion, and nothing is deleted until at least 14 days after the first email.
A couple can download their guest list, delete it, or delete the whole invitation from their dashboard at any time. If a purchase is refunded, access to the invitation ends at once, and its guest data is deleted 30 days later.
The invitation itself and the couple's photos stay while the couple's account is open. Purchase records are kept for as long as UK tax law requires, normally six years. Copies in our backups are removed when those backups expire.
6. Your rights
You have the right to access, correct, delete, or restrict processing of your personal data, to object to processing based on our legitimate interests, and to request portability. You also have the right to complain to the Information Commissioner's Office.
To exercise any of these, contact hello@everleighhouse.com.
7. Cookies
Cookies and similar technologies are covered separately in our Cookie Policy.