Privacy Policy

Last updated 14 August 2026

Your wedding is personal, and so is the information you trust us with. This page explains exactly what we collect, why, and what you can do about it — in plain English, with no small print.

1. Who we are

wed.cards runs the website and app at wed.cards. We are an Indian company, based in India, and we follow India's data protection law in full.

We go further than we have to. Europe's privacy rules are the strictest in the world, and we apply that same standard to everyone who uses wed.cards, wherever you live — not because a regulator makes us, but because we would rather run one high standard than a different one per country. In practice that means you can download or delete your data yourself at any time, turn off analytics with one switch, see exactly how long we keep everything, and read the name of every company that touches your information.

One important exception. When you upload a guest list, those details belong to you, not to us. You decide whose information goes in and what it is used for; we simply hold it and act on your instructions. The terms for that are in our guest data terms.

Address: HQ — Pune, India 411057
Privacy contact: support@wed.cards

2. What we collect

WhatDetailsWhere it comes from
Your accountName, email, mobile number, your password (scrambled so even we cannot read it), and a postal address if you order printed cardsYou
Your invitationCouple names, event dates, venues, messages, photos, your love storyYou
Your guest listGuest names, contact details, addresses, RSVPs, meal preferences, personal notesYou (see section 1)
Guestbook entriesNames, wishes and photos left by your visitorsYour guests
PaymentsAmount, currency, plan, receipt referenceYou and Razorpay
Technical bitsYour country (see below), device and browser type, pages viewedYour device
Your choicesWhat you agreed to and whenSaved when you act

How we work out your country — and why nobody else finds out. We need to know your country so we can show you the right currency, so that visitors in India see rupees and UPI rather than euros. We work this out on our own servers, using a lookup file stored inside the application. Your IP address is used for that check and then thrown away. It is never sent to an outside service, never saved against your account, and never written down in full.

We don't build profiles of you, we don't follow you around other websites, and no computer makes important decisions about you on its own.

3. Why we use it

We only use your information for things you would expect, and for nothing else. Analytics runs by default so we can see which pages help — you can switch it off whenever you like, and it stops straight away. Marketing emails only ever go out if you asked for them.

What we doWhy we can
Create and protect your accountYou asked us to — it is part of providing the service
Build, host and share your invitationYou asked us to
Manage your guest list and RSVPsYou asked us to, and we act on your instructions
Take payment and issue receiptsYou asked us to, and tax law requires us to keep records
Email you about your account and eventsYou asked us to
Keep the service safe and stop abuseNecessary to run the service securely
Count visits with Google Analytics and Microsoft ClarityOn by default — you can turn them off at any time
Show non-personalised ads so the free plan can stay freeNecessary to fund the service — ad personalisation is switched off
Send you tips and offersOnly with your permission
Plant a tree for your weddingYou asked us to

You can turn analytics off, or unsubscribe from marketing, at any time from Profile → Privacy & Data — or from our Cookie Policy page if you're not signed in. Either takes effect immediately.

4. Who we share it with

We never sell your information, and we never share it so that someone else can market to you. We do share it with the companies we need to run the platform. Here is every single one, what they get, and where they are. They may only use your information to do the job we hired them for, never for their own purposes.

CompanyWhat they doWhat they getWhere
Google Cloud / FirebaseRuns the app and stores your uploaded photosEverything the app holdsEU / India / US
MongoDB AtlasOur main databaseEverything the app holdsEU / India
RazorpayTakes payments and issues receiptsName, email, mobile, amount. Never your card number — we never see it.India
Google (Gemini AI)Writes invitation wording when you use the AI helperOnly what you typed in: couple names, date, venue. No account details, no guest list.US
Email deliverySends account, RSVP and reminder emailsRecipient name, email address, the email itselfEU / US
Google AnalyticsCounts visits, unless you turn it offShortened IP, pages viewed, device and browser typeEU / US
Microsoft ClarityShows us how pages are used — clicks and scrolling — unless you turn it offPages viewed, clicks and scrolling, device and browser type. Text you type into forms is masked.EU / US
Google AdSenseShows the ads that keep wed.cards free to startThe page the ad appears on, device and browser type, approximate location. Ad personalisation is switched off, so your browsing is not used to target ads.EU / US
OpenStreetMapTurns venue coordinates into a country nameVenue coordinates only. Nothing that identifies a person.EU (Germany)
Courier partnersDelivers printed and NFC cards you orderRecipient name, postal address, phone numberIndia and destination

Adding to this list. If we ever bring in a new company that handles your information, we update this section at least 30 days beforehand. If you have a genuine concern about one of them, write to support@wed.cards and we will work it out with you.

How we work out your country, and why nobody else is involved. We used to send every visitor's IP address to an outside geolocation service just to decide which currency to show. We stopped. The app now carries its own lookup file and does that on our own servers. The company that publishes the file is deliberately not on the list above — we download it from them, and they get nothing back from us: not your IP address, not even the fact that you visited.

We will also hand over information if the law genuinely requires it — a valid court order, for example — and we will tell you when we are allowed to.

Your invitation page is public by default. Anyone with the link can open it, and search engines may find it, unless you set an access code. Please keep that in mind when adding photos or personal details.

5. Where your information goes

We are based in India, and our systems are hosted in India and Europe. A few of our providers are in the United States, so some information moves between countries.

Whenever that happens, we put the strongest protection agreements available in place with the company receiving it — the same ones European businesses are required to use — and we apply them to everyone's information, not just to users in Europe. If the Indian government ever restricts transfers to a country we use, we will move or stop that processing.

You can ask us what protections apply to any particular transfer by writing to support@wed.cards.

6. How long we keep it

We delete things once the reason we collected them has passed. A wedding has an end date, which makes that unusually easy for us to know, so we act on it rather than quietly hanging on. Your guests' names, phone numbers and addresses are the most sensitive information we hold, and those people never signed up with us, so we don't keep their details a year after they could possibly be needed.

WhatHow long we keep itThen what
Your invitation and guest list12 months after the wedding datePermanently deleted, photos included
Guestbook entries and photos12 months after the wedding dateDeleted with the invitation
Your accountWhile you use itSee the next row
Accounts with no sign-in24 monthsAccount and everything in it permanently deleted
Accounts you delete yourself30-day grace periodPermanently deleted — you can cancel until then
Payment and tax records8 yearsKept for tax and audit, with your personal details stripped out once your account is gone
Contact form messages90 daysDeleted from the support inbox
System and security logs90 daysRotated and deleted
Records of what you agreed toWhile it applies, plus 3 yearsDeleted — kept this long as proof we asked properly
Marketing email listUntil you unsubscribeYour address is removed

You always get warned first. Nothing is deleted on a schedule without telling you. We email you at least 30 days beforehand when your wedding data or an unused account is coming up for deletion, so you can save a copy — or simply log in to keep the account going.

The one thing we keep. When you delete your account we erase everything except payment records. Indian tax law requires us to keep those for eight years, and that obligation overrides your deletion request. It is the one exception, and we would rather point it out plainly than bury it. Those records are stripped of anything identifying the moment your account goes: we remove your name, email, phone number and address, and keep only the amount, date and receipt reference. An auditor can confirm a payment happened; nobody can tell it was you.

Deleting sooner. You don't have to wait for any of these timings. Delete an archived invitation from your dashboard, or your whole account from Profile → Privacy & Data. If a guest asks you to remove their details, you can delete them from your guest list straight away.

7. What you can do

Everything below is available to everyone, wherever you live. Most of it you can do yourself right now in Profile → Privacy & Data. None of it costs anything, and we reply within 30 days.

What you can doWhat it meansHow
Get a copyDownload everything we hold about youProfile → Download my data
Take it elsewhereThe download is a standard file any other service can readSame button
Fix somethingCorrect anything wrong or incompleteProfile, or email us
Delete everythingRemove your account and data for goodProfile → Delete my account
Change your mindTurn analytics or marketing emails offProfile → Privacy & Data
Ask us to pauseStop us using your information a particular wayEmail support@wed.cards
ComplainRaise a problem and get a proper answerSee section 8 below
Appoint someoneName a person to act for you if you die or become seriously illEmail support@wed.cards

8. If you're unhappy with us

If something has gone wrong, or even just feels wrong, please tell us. We would far rather hear about it than have you leave quietly — we will look into it properly, and if we have made a mistake we will say so and fix it.

Who handles it. We are required to name the person responsible for answering your questions and complaints, and to publish how to reach them:

To be appointed

Grievance Officer & Data Protection Contact

Email: support@wed.cards

Post: HQ — Pune, India 411057

What happens, and when:

  • Within 72 hours — we acknowledge your message and give you a reference number.
  • Within 30 days — you get a written answer explaining what we found, what we have done, and what happens next. We hold ourselves to this strictly.
  • If it is genuinely complicated — we may need longer, but we will tell you inside the first 30 days, explain why, and keep you updated. We will not just go quiet.

To help us sort it out quickly, include the email address on your account, what happened, and what you would like us to do about it.

If we still don't resolve it. Please come to us first — it is the fastest route, and what the law expects. If our answer doesn't satisfy you, or we fail to reply in time, you can escalate to the Data Protection Board of India, the authority that oversees us. Please quote your reference number.

If you are in Europe or the UK you may also contact your local privacy regulator. We should be straight with you about what that achieves: we have no European office, so no European authority supervises us directly and their powers over us are more limited than over a local company. That is exactly why we commit to the same 30-day answer and the same standard of care for you as for anyone else — what you get from us doesn't depend on who can force us.

9. Children

wed.cards is for adults. You need to be 18 or over to create an account, and we ask you to confirm that when you sign up. We do not knowingly collect information about children, and we never track or advertise to them.

If your guest list or photos include a child, you are confirming you have the right to share those details with us — which for a child means their parent or guardian is happy with it. If you think a child's information has reached us when it shouldn't have, tell us at support@wed.cards and we will remove it promptly.

10. Cookies

We use a small number of cookies to keep you signed in and the site secure — those are essential and can't be turned off while you use the service.

We also use Google Analytics and Microsoft Clarity, both on by default. They count visits and show us which parts of a page people actually use. Neither builds a profile of you: Google Analytics is set to shorten your IP address before Google ever sees it, and Clarity masks the text you type so form entries are not captured. You can switch both off with the single switch on our Cookie Policy page, or in Profile → Privacy & Data — either way they stop immediately.

We also show ads, through Google AdSense. They fund the free plan. They are not personalised: ad storage, advertising data and ad personalisation are switched off permanently in our setup, so your browsing is never used to target ads at you and we run no retargeting. Ads appear at the foot of a page, and never on a payment screen. The analytics switch does not remove them — an ad-blocker or your browser settings will, and we don't work around either.

The full list — what each cookie does and how long it lasts — is on the Cookie Policy page.

11. How we protect it

We take security seriously and we work at it continuously. Passwords are stored scrambled and can never be read back, not even by us. Everything travels over an encrypted connection and is stored encrypted. Only the few people who genuinely need access to live data have it. We run automated security testing against our own systems and keep everything patched and up to date.

What we can honestly promise. We will always take every reasonable step to keep your information safe, and we will never cut corners on it. What no service on the internet can promise — and we would rather tell you plainly than pretend otherwise — is that nothing will ever go wrong. Software has flaws, suppliers have outages, and determined attackers exist.

So: we don't guarantee the service will always be available or completely free of faults, and where something goes wrong despite our precautions, or because of an event genuinely outside our control, our responsibility is limited as set out in our Terms of Service. That is not us stepping away from our duty to look after your information — we remain fully accountable for that — it is simply an honest statement of what can and cannot be promised.

You have a part to play too. Choose a strong password, keep it to yourself, and tell us straight away if you think someone else has got into your account. In practice that is the most common way information gets exposed, and it is the one thing only you can prevent.

12. If there is a security incident

If your information is ever caught up in a security incident, we will tell you. Not just the regulator — you, directly. We hold ourselves to the strictest standard here: there is no “too small to mention” category, and we would rather over-inform you than quietly hope you don't notice.

We aim to notify the authorities within 72 hours of finding out, and to tell affected people as soon as we understand what happened. Alongside that we will explain what we are doing about it and what, if anything, you should do.

13. Which law applies

We are based in India. Indian law applies to this policy, and any dispute would be handled by the courts of Sangli, Maharashtra, India.

That doesn't take away rights you have where you live. Nothing here overrides the consumer protections of your own country. We're not trying to use our location to give you less — the promises on this page are made to you directly, wherever you are.

14. Changes to this policy

We keep a dated record of every meaningful change. If something changes that materially affects how we use your information, we will tell you by email or in the app before it takes effect — and where your permission is needed, we will ask again rather than assume.

14 August 2026

We now show ads, through Google AdSense. They are what lets us keep a genuinely free plan rather than putting the whole service behind a payment. Two things about how we have done it: the ads are not personalised — ad storage, advertising data and ad personalisation are switched off permanently in our setup, so your browsing is never used to target ads at you and we run no retargeting — and they are kept out of your way, appearing at the foot of a page and never on a payment screen, an error screen, or in the middle of something you are doing. Google is now listed in our service-provider table for advertising as well as analytics, and the cookies AdSense sets are listed on the Cookie Policy page. To be straight about one thing: the analytics switch turns off measurement, not ads. An ad-blocker or your browser settings will stop the ads, and we do not try to work around either.

14 August 2026

Added Microsoft Clarity alongside Google Analytics. It shows us how a page is actually used — where people click and how far they scroll — so we can fix the parts that confuse people. It masks the text you type, so nothing you enter into a form is captured, and it never sees your account details or your guest list. It is covered by the same single analytics switch you already had: turning analytics off on the Cookie Policy page or in Profile → Privacy & Data stops Clarity too, immediately, and if you had already turned analytics off then Clarity has never loaded for you at all. Microsoft is now listed in our service-provider table, and the cookies it sets are listed in full on the Cookie Policy page. We still run no advertising and build no profiles.

31 July 2026

Merged four separate pages into the documents they belonged in, so there is less to hunt through. Our full list of service providers, how long we keep everything, and how to raise a complaint are now sections of this Privacy Policy; the guest data terms are now part of the Terms of Service. The old links still work and take you straight to the right section. Nothing was removed in the move — every commitment, timing and contact detail carried across in full.

30 July 2026

Removed the cookie banner. Google Analytics now runs by default rather than waiting for you to accept it, so we have updated every page that previously said otherwise. In its place there is a switch on the Cookie Policy page and in Profile → Privacy & Data that turns analytics off instantly, for anyone, signed in or not — and if you turned analytics off under the old banner, that choice is still being honoured. Advertising and profiling remain switched off entirely.

29 July 2026

Rewrote every policy in plain English. We removed the legal section numbers and jargon so you can actually read what we do with your information, and renamed several pages to say what they are. Nothing about how we handle your data changed — no right, protection or retention period was reduced. We also set out more clearly what we can and cannot promise: we commit to genuine care over your information and remain fully accountable for it, while being honest that no online service can guarantee it will never have a fault or an outage.

28 July 2026

Consolidated our contact points: privacy, grievance and all other legal correspondence now goes to a single monitored address (support@wed.cards) so a rights request cannot be lost in an unmonitored alias, with hello@wed.cards for general enquiries. Our full registered office is published where payment-gateway and consumer-law rules require a complete postal address; other pages show our operating HQ. Telephone contact has been withdrawn in favour of email, which gives both sides a written record.

27 July 2026

Clarified our regulatory position: wed.cards is established in India and governed by the Digital Personal Data Protection Act, 2023, with no EU establishment. We apply GDPR-level protections to every user worldwide as a voluntary standard rather than a jurisdictional obligation, and where the two frameworks differ we follow the stricter. Also explained how we determine your country: the lookup now runs entirely on our own servers against a local database, so your IP address is no longer disclosed to any geolocation service. No user-facing right, retention period or safeguard was reduced by these changes.

26 July 2026

Full rewrite for the GDPR and India's Digital Personal Data Protection Act, 2023. Added legal-basis and retention tables, the sub-processor list, international-transfer disclosures, data-principal and data-subject rights (including the DPDPA right to nominate), a named Grievance Officer, children's-data terms, and cookie-consent controls. Introduced self-service data export and account deletion.

Contact us

Anything about this policy, your information, or a formal complaint: support@wed.cards — see Privacy Policy for how complaints are handled and how quickly. For anything else, write to hello@wed.cards.

Post: HQ — Pune, India 411057