Privacy Policy
Version 6 · Effective August 8, 2026
Version 6 — see the end of this document for what changed since Version 5.
1. What we collect
- Account data: name, email, hashed password (we never store your password in readable form), account role (couple, vendor, planner, admin, support), and, if you set one, a hashed PIN used only to quickly resume an already-authenticated session.
- Guest data: names, RSVP status, meal/dietary notes, seating assignments, and — for adult guests only — contact information (email, phone number), which is encrypted at rest using field-level encryption, separate from ordinary database access. We do not collect direct contact information for guests marked as children; see "Children's data" below.
- Vendor data: business details, service category, portfolio media, and pricing/package information. Payment for your services happens directly with the Couple, off the Platform — we don't collect or store your bank details or payment information for that.
- Planner data: business name and the specific couples who have linked their account to you, scoped individually per couple.
- Payment data: for Platform subscription fees only, handled by Stripe; we store references to those transactions (amounts, status, Stripe identifiers), never raw card numbers. We don't process or store payment data for Vendor/Planner services — see "Vendor data" above.
- Communications data: the content of guest messages you send through the Platform (email and, where enabled, SMS), and metadata about whether they were delivered.
- Usage and device data: pages visited, actions taken, IP address, browser/device information, and timestamps, collected to secure the Platform and understand feature usage. We do not use third-party advertising trackers.
- AI feature inputs: if you use the AI concierge or AI venue-visualization features, the questions or images you submit are sent to our third-party AI provider(s) to generate a response (see "AI features" below).
2. How we use it
To operate core features (guest ledger, vendor matching, payments, wedding websites, AI-assisted planning, support); to secure accounts (fraud/abuse prevention, rate limiting, and the security measures described on our Security page); to communicate with you (confirmations, receipts, service notices, and — only where you've opted in or as reasonably necessary to the service — product updates); to comply with legal obligations; and to improve the Platform. We do not use your data to make any fully automated decision that produces a legal or similarly significant effect on you without human involvement.
3. Legal basis for processing (EEA/UK users)
Where the GDPR or UK GDPR applies, we process your personal data on one or more of these legal bases: performance of a contract with you (operating your account and the features you use); our legitimate interests (securing the Platform, preventing abuse, improving the service) balanced against your rights; your consent (for example, opting in to marketing communications, or a Couple choosing to send SMS to a guest); and compliance with a legal obligation (for example, tax records).
4. Children's data (COPPA)
A couple's guest list often includes children. For any guest marked as a child, the Platform is structurally prevented — at the database level, not just in the application code — from storing that child's direct email or phone number; a child guest record must instead be linked to a parent/guardian guest record for any contact purposes. We do not knowingly collect personal information directly from children, and the Platform is not directed at, and account holders must be at least 18 years old to use it directly.
5. Marketing communications
If you provide an email address or phone number, we may send you service communications necessary to operate your account (confirmations, security alerts, receipts) regardless of marketing preferences, since these are not marketing. Any promotional communications are sent only with your consent where required, and every marketing email includes an unsubscribe mechanism consistent with CAN-SPAM. If you use the Platform's own guest-messaging features to contact your guests, you — not Vows & Volts — are responsible for having a lawful basis to do so; see our Terms of Service, Section 5.
6. Sharing and sub-processors
We share data with: Vendors and Planners you engage with or grant access to (only the information needed for that relationship — e.g., a Vendor sees your event details relevant to their booking, a Planner sees whatever scope you've granted them, and either can be revoked by you at any time); and a limited set of service providers (sub-processors) who process data on our behalf strictly to operate the Platform, which may include: a payment processor (Stripe) for payments, billing, and tax calculation; an email delivery provider for transactional and guest email; an SMS delivery provider for guest text messaging (only where that feature is enabled for your account); AI providers for the concierge and venue-visualization features (only when you actively use those features, and only with the specific input you provide — not your full account data); a cloud storage provider for uploaded photos and files; and our application and database hosting providers. Not every sub-processor above is necessarily active for every account — some features activate only once the underlying integration is configured. We do not sell personal data, and we do not share personal data with third parties for their own independent marketing purposes.
We may also disclose data where required by law, to protect the rights, safety, or property of Vows & Volts or others, or in connection with a merger, acquisition, or sale of assets (with notice to affected users where required).
7. AI features
If you use the AI concierge or AI venue-visualization tools, the specific question, prompt, or image you submit is sent to our third-party AI provider(s) to generate a response. We do not send your entire account or guest database to these providers — only the input relevant to the specific request you make, plus the minimum context needed to answer it (for example, your budget summary if you ask a budget question). We do not permit these providers to use your data to train their general-purpose models, to the extent we can contractually restrict that. These features are optional; the Platform's core functionality does not require using them.
8. International transfers
Where data is transferred outside your region (for example, to a service provider located in another country), we rely on appropriate safeguards — such as standard contractual clauses — as detailed in our Data Processing Addendum.
9. Retention
We retain account and guest data for as long as your account is active, plus a limited period afterward for legal, tax, and accounting purposes, or to resolve disputes. If you request deletion, we begin a 30-day grace period (in case the request was made in error, or to allow you to reconsider) before permanent removal; you can cancel a pending deletion request within that window from your account.
10. Your rights
Depending on your location, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing.
If you are in the EEA or UK, you additionally have the right to lodge a complaint with your local data protection supervisory authority — see our dedicated GDPR Addendum, linked below and from the main Legal index, for a consolidated summary of these rights, the legal bases we rely on, and how international transfers are safeguarded.
If you are a California resident, the CCPA/CPRA gives you the right to know what personal information we collect and how we use it, to delete it, to correct inaccurate information, and to opt out of the "sale" or "sharing" of personal information — we do not sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of in that respect, but you can still exercise your other rights through the mechanism below. We do not discriminate against you for exercising any privacy right.
You can request deletion from your account settings, which creates a trackable deletion request; you can cancel it within the 30-day grace window. For other requests, contact us through the in-app support system.
11. Cookies
See our Cookie Policy for details on the cookies we use and how to manage your preferences, including how EEA/UK visitors are asked for consent before non-essential cookies are set.
12. Do Not Track
Because there is no common industry standard for responding to browser "Do Not Track" signals, the Platform does not currently respond to them differently than described in this Policy and our Cookie Policy.
13. Security
We use field-level encryption for sensitive guest contact data, role-based access control enforced independently at both the page and API layers, rate limiting on authentication and public-facing endpoints, and the broader set of protections described on our public Security page — including, honestly, which of those protections have actually been tested and which are still in progress, not just designed. No system is perfectly secure, and we encourage good-faith security research reported through our support system rather than public disclosure — see our Acceptable Use Policy.
14. Internal staff access and support tools
Authorized Vows & Volts staff (admin and support roles) can access account data as needed to provide support, investigate abuse or security issues, and operate the Platform — always role-based, and every sensitive administrative action is logged with who performed it, when, and what it targeted.
One specific tool works this way: when you contact support with an issue you can't resolve yourself, an authorized admin can start a time-limited, logged session that lets them view and act within your account exactly as you would — for example, to fix a guest-list issue you're stuck on before your wedding. These sessions expire automatically (currently within 30 minutes), are visibly indicated with a banner for the duration, can only be started or ended by the admin who initiated them, and can never be used against another staff member's account. We don't store your payment card details in the first place (see Section 1), so there's nothing of that kind for this access to expose.
If you'd like more detail about access to your specific account, contact us through the in-app support system — see "Contact" below.
15. Third-party links
The Platform may link to third-party websites (for example, a Vendor's own website, or a payment page hosted by Stripe). We are not responsible for the privacy practices of sites we don't control.
16. Changes to this Policy
We may update this Policy as the Platform evolves. Material changes will prompt a re-acceptance flow before you can continue using your account, consistent with our Terms of Service.
What changed in Version 6: added a cross-reference in Section 10 to our new, dedicated GDPR Addendum — a consolidated summary of EEA/UK data subject rights, legal bases, and international-transfer safeguards; no change to what data we collect or how we process it.
What changed in Version 5: removed the AI-drafted/attorney-review notice that previously appeared at the end of this document.
What changed in Version 4: added Section 14, "Internal staff access and support tools" — disclosing that authorized staff can access account data for support and security purposes, and describing the new time-limited, logged "view and act as you" support tool specifically. Sections previously numbered 14–16 shifted down by one to make room.
What changed in Version 3: corrected the "Vendor data" and "Payment data" entries in Section 1 — we don't collect Stripe Connect account status or any Vendor/Planner payment data, since that payment happens directly between you and the Vendor/Planner off the Platform (previous wording assumed a Stripe Connect integration that was never actually implemented).
What changed in Version 2: added sections on legal basis for EEA/UK processing, marketing communications, AI feature data handling, Do Not Track, and California (CCPA/CPRA) rights; named the categories of sub-processors we actually use (payments, email, SMS, AI, storage, hosting) rather than describing them only generically; clarified that not every listed integration is necessarily active for every account.
17. Contact
Privacy requests and questions can be submitted through the in-app support system, or to the contact listed in your account region's data protection notice once published.