Privacy Policy
Last updated 14 August 2026
Your wedding is personal, and so is the information you trust us with. This page explains exactly what we collect, why, and what you can do about it — in plain English, with no small print.
1. Who we are
wed.cards runs the website and app at wed.cards. We are an Indian company, based in India, and we follow India's data protection law in full.
We go further than we have to. Europe's privacy rules are the strictest in the world, and we apply that same standard to everyone who uses wed.cards, wherever you live — not because a regulator makes us, but because we would rather run one high standard than a different one per country. In practice that means you can download or delete your data yourself at any time, turn off analytics with one switch, see exactly how long we keep everything, and read the name of every company that touches your information.
One important exception. When you upload a guest list, those details belong to you, not to us. You decide whose information goes in and what it is used for; we simply hold it and act on your instructions. The terms for that are in our guest data terms.
Address: HQ — Pune, India 411057
Privacy contact: support@wed.cards
2. What we collect
| What | Details | Where it comes from |
|---|---|---|
| Your account | Name, email, mobile number, your password (scrambled so even we cannot read it), and a postal address if you order printed cards | You |
| Your invitation | Couple names, event dates, venues, messages, photos, your love story | You |
| Your guest list | Guest names, contact details, addresses, RSVPs, meal preferences, personal notes | You (see section 1) |
| Guestbook entries | Names, wishes and photos left by your visitors | Your guests |
| Payments | Amount, currency, plan, receipt reference | You and Razorpay |
| Technical bits | Your country (see below), device and browser type, pages viewed | Your device |
| Your choices | What you agreed to and when | Saved when you act |
How we work out your country — and why nobody else finds out. We need to know your country so we can show you the right currency, so that visitors in India see rupees and UPI rather than euros. We work this out on our own servers, using a lookup file stored inside the application. Your IP address is used for that check and then thrown away. It is never sent to an outside service, never saved against your account, and never written down in full.
We don't build profiles of you, we don't follow you around other websites, and no computer makes important decisions about you on its own.
3. Why we use it
We only use your information for things you would expect, and for nothing else. Analytics runs by default so we can see which pages help — you can switch it off whenever you like, and it stops straight away. Marketing emails only ever go out if you asked for them.
| What we do | Why we can |
|---|---|
| Create and protect your account | You asked us to — it is part of providing the service |
| Build, host and share your invitation | You asked us to |
| Manage your guest list and RSVPs | You asked us to, and we act on your instructions |
| Take payment and issue receipts | You asked us to, and tax law requires us to keep records |
| Email you about your account and events | You asked us to |
| Keep the service safe and stop abuse | Necessary to run the service securely |
| Count visits with Google Analytics and Microsoft Clarity | On by default — you can turn them off at any time |
| Show non-personalised ads so the free plan can stay free | Necessary to fund the service — ad personalisation is switched off |
| Send you tips and offers | Only with your permission |
| Plant a tree for your wedding | You asked us to |
You can turn analytics off, or unsubscribe from marketing, at any time from Profile → Privacy & Data — or from our Cookie Policy page if you're not signed in. Either takes effect immediately.
4. Who we share it with
We never sell your information, and we never share it so that someone else can market to you. We do share it with the companies we need to run the platform. Here is every single one, what they get, and where they are. They may only use your information to do the job we hired them for, never for their own purposes.
| Company | What they do | What they get | Where |
|---|---|---|---|
| Google Cloud / Firebase | Runs the app and stores your uploaded photos | Everything the app holds | EU / India / US |
| MongoDB Atlas | Our main database | Everything the app holds | EU / India |
| Razorpay | Takes payments and issues receipts | Name, email, mobile, amount. Never your card number — we never see it. | India |
| Google (Gemini AI) | Writes invitation wording when you use the AI helper | Only what you typed in: couple names, date, venue. No account details, no guest list. | US |
| Email delivery | Sends account, RSVP and reminder emails | Recipient name, email address, the email itself | EU / US |
| Google Analytics | Counts visits, unless you turn it off | Shortened IP, pages viewed, device and browser type | EU / US |
| Microsoft Clarity | Shows us how pages are used — clicks and scrolling — unless you turn it off | Pages viewed, clicks and scrolling, device and browser type. Text you type into forms is masked. | EU / US |
| Google AdSense | Shows the ads that keep wed.cards free to start | The page the ad appears on, device and browser type, approximate location. Ad personalisation is switched off, so your browsing is not used to target ads. | EU / US |
| OpenStreetMap | Turns venue coordinates into a country name | Venue coordinates only. Nothing that identifies a person. | EU (Germany) |
| Courier partners | Delivers printed and NFC cards you order | Recipient name, postal address, phone number | India and destination |
Adding to this list. If we ever bring in a new company that handles your information, we update this section at least 30 days beforehand. If you have a genuine concern about one of them, write to support@wed.cards and we will work it out with you.
How we work out your country, and why nobody else is involved. We used to send every visitor's IP address to an outside geolocation service just to decide which currency to show. We stopped. The app now carries its own lookup file and does that on our own servers. The company that publishes the file is deliberately not on the list above — we download it from them, and they get nothing back from us: not your IP address, not even the fact that you visited.
We will also hand over information if the law genuinely requires it — a valid court order, for example — and we will tell you when we are allowed to.
Your invitation page is public by default. Anyone with the link can open it, and search engines may find it, unless you set an access code. Please keep that in mind when adding photos or personal details.
5. Where your information goes
We are based in India, and our systems are hosted in India and Europe. A few of our providers are in the United States, so some information moves between countries.
Whenever that happens, we put the strongest protection agreements available in place with the company receiving it — the same ones European businesses are required to use — and we apply them to everyone's information, not just to users in Europe. If the Indian government ever restricts transfers to a country we use, we will move or stop that processing.
You can ask us what protections apply to any particular transfer by writing to support@wed.cards.
6. How long we keep it
We delete things once the reason we collected them has passed. A wedding has an end date, which makes that unusually easy for us to know, so we act on it rather than quietly hanging on. Your guests' names, phone numbers and addresses are the most sensitive information we hold, and those people never signed up with us, so we don't keep their details a year after they could possibly be needed.
| What | How long we keep it | Then what |
|---|---|---|
| Your invitation and guest list | 12 months after the wedding date | Permanently deleted, photos included |
| Guestbook entries and photos | 12 months after the wedding date | Deleted with the invitation |
| Your account | While you use it | See the next row |
| Accounts with no sign-in | 24 months | Account and everything in it permanently deleted |
| Accounts you delete yourself | 30-day grace period | Permanently deleted — you can cancel until then |
| Payment and tax records | 8 years | Kept for tax and audit, with your personal details stripped out once your account is gone |
| Contact form messages | 90 days | Deleted from the support inbox |
| System and security logs | 90 days | Rotated and deleted |
| Records of what you agreed to | While it applies, plus 3 years | Deleted — kept this long as proof we asked properly |
| Marketing email list | Until you unsubscribe | Your address is removed |
You always get warned first. Nothing is deleted on a schedule without telling you. We email you at least 30 days beforehand when your wedding data or an unused account is coming up for deletion, so you can save a copy — or simply log in to keep the account going.
The one thing we keep. When you delete your account we erase everything except payment records. Indian tax law requires us to keep those for eight years, and that obligation overrides your deletion request. It is the one exception, and we would rather point it out plainly than bury it. Those records are stripped of anything identifying the moment your account goes: we remove your name, email, phone number and address, and keep only the amount, date and receipt reference. An auditor can confirm a payment happened; nobody can tell it was you.
Deleting sooner. You don't have to wait for any of these timings. Delete an archived invitation from your dashboard, or your whole account from Profile → Privacy & Data. If a guest asks you to remove their details, you can delete them from your guest list straight away.
7. What you can do
Everything below is available to everyone, wherever you live. Most of it you can do yourself right now in Profile → Privacy & Data. None of it costs anything, and we reply within 30 days.
| What you can do | What it means | How |
|---|---|---|
| Get a copy | Download everything we hold about you | Profile → Download my data |
| Take it elsewhere | The download is a standard file any other service can read | Same button |
| Fix something | Correct anything wrong or incomplete | Profile, or email us |
| Delete everything | Remove your account and data for good | Profile → Delete my account |
| Change your mind | Turn analytics or marketing emails off | Profile → Privacy & Data |
| Ask us to pause | Stop us using your information a particular way | Email support@wed.cards |
| Complain | Raise a problem and get a proper answer | See section 8 below |
| Appoint someone | Name a person to act for you if you die or become seriously ill | Email support@wed.cards |
8. If you're unhappy with us
If something has gone wrong, or even just feels wrong, please tell us. We would far rather hear about it than have you leave quietly — we will look into it properly, and if we have made a mistake we will say so and fix it.
Who handles it. We are required to name the person responsible for answering your questions and complaints, and to publish how to reach them:
To be appointed
Grievance Officer & Data Protection Contact
Email: support@wed.cards
Post: HQ — Pune, India 411057
What happens, and when:
- Within 72 hours — we acknowledge your message and give you a reference number.
- Within 30 days — you get a written answer explaining what we found, what we have done, and what happens next. We hold ourselves to this strictly.
- If it is genuinely complicated — we may need longer, but we will tell you inside the first 30 days, explain why, and keep you updated. We will not just go quiet.
To help us sort it out quickly, include the email address on your account, what happened, and what you would like us to do about it.
If we still don't resolve it. Please come to us first — it is the fastest route, and what the law expects. If our answer doesn't satisfy you, or we fail to reply in time, you can escalate to the Data Protection Board of India, the authority that oversees us. Please quote your reference number.
If you are in Europe or the UK you may also contact your local privacy regulator. We should be straight with you about what that achieves: we have no European office, so no European authority supervises us directly and their powers over us are more limited than over a local company. That is exactly why we commit to the same 30-day answer and the same standard of care for you as for anyone else — what you get from us doesn't depend on who can force us.
9. Children
wed.cards is for adults. You need to be 18 or over to create an account, and we ask you to confirm that when you sign up. We do not knowingly collect information about children, and we never track or advertise to them.
If your guest list or photos include a child, you are confirming you have the right to share those details with us — which for a child means their parent or guardian is happy with it. If you think a child's information has reached us when it shouldn't have, tell us at support@wed.cards and we will remove it promptly.
10. Cookies
We use a small number of cookies to keep you signed in and the site secure — those are essential and can't be turned off while you use the service.
We also use Google Analytics and Microsoft Clarity, both on by default. They count visits and show us which parts of a page people actually use. Neither builds a profile of you: Google Analytics is set to shorten your IP address before Google ever sees it, and Clarity masks the text you type so form entries are not captured. You can switch both off with the single switch on our Cookie Policy page, or in Profile → Privacy & Data — either way they stop immediately.
We also show ads, through Google AdSense. They fund the free plan. They are not personalised: ad storage, advertising data and ad personalisation are switched off permanently in our setup, so your browsing is never used to target ads at you and we run no retargeting. Ads appear at the foot of a page, and never on a payment screen. The analytics switch does not remove them — an ad-blocker or your browser settings will, and we don't work around either.
The full list — what each cookie does and how long it lasts — is on the Cookie Policy page.
11. How we protect it
We take security seriously and we work at it continuously. Passwords are stored scrambled and can never be read back, not even by us. Everything travels over an encrypted connection and is stored encrypted. Only the few people who genuinely need access to live data have it. We run automated security testing against our own systems and keep everything patched and up to date.
What we can honestly promise. We will always take every reasonable step to keep your information safe, and we will never cut corners on it. What no service on the internet can promise — and we would rather tell you plainly than pretend otherwise — is that nothing will ever go wrong. Software has flaws, suppliers have outages, and determined attackers exist.
So: we don't guarantee the service will always be available or completely free of faults, and where something goes wrong despite our precautions, or because of an event genuinely outside our control, our responsibility is limited as set out in our Terms of Service. That is not us stepping away from our duty to look after your information — we remain fully accountable for that — it is simply an honest statement of what can and cannot be promised.
You have a part to play too. Choose a strong password, keep it to yourself, and tell us straight away if you think someone else has got into your account. In practice that is the most common way information gets exposed, and it is the one thing only you can prevent.
12. If there is a security incident
If your information is ever caught up in a security incident, we will tell you. Not just the regulator — you, directly. We hold ourselves to the strictest standard here: there is no “too small to mention” category, and we would rather over-inform you than quietly hope you don't notice.
We aim to notify the authorities within 72 hours of finding out, and to tell affected people as soon as we understand what happened. Alongside that we will explain what we are doing about it and what, if anything, you should do.
13. Which law applies
We are based in India. Indian law applies to this policy, and any dispute would be handled by the courts of Sangli, Maharashtra, India.
That doesn't take away rights you have where you live. Nothing here overrides the consumer protections of your own country. We're not trying to use our location to give you less — the promises on this page are made to you directly, wherever you are.
14. Changes to this policy
We keep a dated record of every meaningful change. If something changes that materially affects how we use your information, we will tell you by email or in the app before it takes effect — and where your permission is needed, we will ask again rather than assume.
14 August 2026
We now show ads, through Google AdSense. They are what lets us keep a genuinely free plan rather than putting the whole service behind a payment. Two things about how we have done it: the ads are not personalised — ad storage, advertising data and ad personalisation are switched off permanently in our setup, so your browsing is never used to target ads at you and we run no retargeting — and they are kept out of your way, appearing at the foot of a page and never on a payment screen, an error screen, or in the middle of something you are doing. Google is now listed in our service-provider table for advertising as well as analytics, and the cookies AdSense sets are listed on the Cookie Policy page. To be straight about one thing: the analytics switch turns off measurement, not ads. An ad-blocker or your browser settings will stop the ads, and we do not try to work around either.
14 August 2026
Added Microsoft Clarity alongside Google Analytics. It shows us how a page is actually used — where people click and how far they scroll — so we can fix the parts that confuse people. It masks the text you type, so nothing you enter into a form is captured, and it never sees your account details or your guest list. It is covered by the same single analytics switch you already had: turning analytics off on the Cookie Policy page or in Profile → Privacy & Data stops Clarity too, immediately, and if you had already turned analytics off then Clarity has never loaded for you at all. Microsoft is now listed in our service-provider table, and the cookies it sets are listed in full on the Cookie Policy page. We still run no advertising and build no profiles.
31 July 2026
Merged four separate pages into the documents they belonged in, so there is less to hunt through. Our full list of service providers, how long we keep everything, and how to raise a complaint are now sections of this Privacy Policy; the guest data terms are now part of the Terms of Service. The old links still work and take you straight to the right section. Nothing was removed in the move — every commitment, timing and contact detail carried across in full.
30 July 2026
Removed the cookie banner. Google Analytics now runs by default rather than waiting for you to accept it, so we have updated every page that previously said otherwise. In its place there is a switch on the Cookie Policy page and in Profile → Privacy & Data that turns analytics off instantly, for anyone, signed in or not — and if you turned analytics off under the old banner, that choice is still being honoured. Advertising and profiling remain switched off entirely.
29 July 2026
Rewrote every policy in plain English. We removed the legal section numbers and jargon so you can actually read what we do with your information, and renamed several pages to say what they are. Nothing about how we handle your data changed — no right, protection or retention period was reduced. We also set out more clearly what we can and cannot promise: we commit to genuine care over your information and remain fully accountable for it, while being honest that no online service can guarantee it will never have a fault or an outage.
28 July 2026
Consolidated our contact points: privacy, grievance and all other legal correspondence now goes to a single monitored address (support@wed.cards) so a rights request cannot be lost in an unmonitored alias, with hello@wed.cards for general enquiries. Our full registered office is published where payment-gateway and consumer-law rules require a complete postal address; other pages show our operating HQ. Telephone contact has been withdrawn in favour of email, which gives both sides a written record.
27 July 2026
Clarified our regulatory position: wed.cards is established in India and governed by the Digital Personal Data Protection Act, 2023, with no EU establishment. We apply GDPR-level protections to every user worldwide as a voluntary standard rather than a jurisdictional obligation, and where the two frameworks differ we follow the stricter. Also explained how we determine your country: the lookup now runs entirely on our own servers against a local database, so your IP address is no longer disclosed to any geolocation service. No user-facing right, retention period or safeguard was reduced by these changes.
26 July 2026
Full rewrite for the GDPR and India's Digital Personal Data Protection Act, 2023. Added legal-basis and retention tables, the sub-processor list, international-transfer disclosures, data-principal and data-subject rights (including the DPDPA right to nominate), a named Grievance Officer, children's-data terms, and cookie-consent controls. Introduced self-service data export and account deletion.
Contact us
Anything about this policy, your information, or a formal complaint: support@wed.cards — see Privacy Policy for how complaints are handled and how quickly. For anything else, write to hello@wed.cards.
Post: HQ — Pune, India 411057