Privacy Policy
You are trusting us with your wedding, and with the names and details of everyone you love. This page explains exactly what we hold, why we hold it, who helps us run the service, and how to get it all back or deleted. We do not sell anything to anyone.
Last updated 3 September 2026
Who we are
The Wedding Suite is an online wedding planning suite run by Mel in Australia. In this policy, we and us mean The Wedding Suite. For the information you put into your wedding, you are the one who decides what is collected, and we hold and process it on your behalf.
What we collect and why
Your account
Your email address, a securely hashed version of your password, your name if you give one, and the dates your account was created and last used. We need this to let you in, to keep your wedding attached to you, and to send you the handful of emails the service depends on, such as a password reset.
Your wedding
Everything you enter into the planners: your guest list, budget, timeline, seating, vendors, checklists, registry, schedule, notes, vows, the copy and photos of your wedding website, and any files you upload. This is the product. We hold it so it is there when you come back, on any device, and so the people you invite can work on it with you.
Your guests
Whatever you choose to record about them, and whatever they type into your RSVP form: names, attendance, meal choices, dietary notes, song requests, messages, and email addresses or postal addresses if you ask for them. We hold this for you. We never contact your guests for our own purposes.
Payment
If you subscribe, Stripe collects and holds your card details on its own hosted checkout page. Card numbers are never sent to or stored on our servers. What we keep is the Stripe customer and subscription identifier, the plan status, the trial end and the next renewal date.
Messages you send us
If you write to us through the contact page or the in-app feedback box, we keep your message, the email address you gave, and the page you were on, so we can reply and so we can fix what you told us about.
Technical logs
Our hosting keeps ordinary server logs: the request, the time, an IP address and a browser user agent. They exist to keep the service up and to stop abuse, they expire on their own, and we do not build profiles from them.
How long we keep it
- Your wedding data: for as long as your account exists. Weddings do not expire, and neither does the album of what you planned.
- After you cancel: your data stays in your account so you can come back to it. Ask us to delete it and we will, permanently, within 30 days.
- Guest data: as long as you keep it. You can delete any guest, or your whole guest list, from inside the Suite at any time.
- Billing records: Stripe keeps payment records for as long as tax and financial law requires, typically seven years in Australia.
- Support messages: up to two years, so we can pick up a conversation where it left off.
- Server logs: short-lived, kept by our hosting provider for its own operational window.
Who we share it with
We do not sell your data, and we never will. We do not share it with advertisers, data brokers or anyone else who wants to market to you. Four companies help us run the service, and each one sees only the part it needs:
- Neon stores the database: your account, your wedding, your guest list, and the photos you upload, which are held as image data in that same database rather than on a separate media host.
- Vercel runs and serves the application itself, including your published wedding website.
- Stripe handles payments, cards and subscriptions.
- Resend delivers our transactional email, such as password resets and the notes the Suite sends you.
Beyond those, we would only disclose data if the law required it, and we would tell you unless we were forbidden from doing so. If the business is ever sold, your data would move with it under this same policy, and you would be told first.
Some of these providers operate servers outside Australia, so your data may be stored or processed overseas. Each of them is contractually bound to protect it and to use it only to provide their service to us.
Cookies and tracking
The Wedding Suite sets one cookie. It is called cs_session, it holds a signed token that says you are logged in, it is HTTP-only and sent only over HTTPS, and it lasts up to 180 days so you are not asked to sign in every week. Signing out clears it.
That is the entire list. There are no advertising cookies, no third-party trackers, no pixels, no session recording and no cross-site profiling on this site or on your published wedding website. Because the only cookie we set is the one that keeps you signed in, there is no consent banner to click through.
Your rights as a couple
You can, at any time:
- See it: everything we hold about your wedding is visible in the Suite itself.
- Correct it: edit anything, including your account email.
- Take it with you: every planner exports, and the offline edition of your planner is yours to keep.
- Delete it: remove individual items yourself, or ask us to delete your account and everything in it.
- Unpublish: take your wedding website offline in one click, which stops it being reachable at its address.
- Complain: write to us first, and if we have not put it right, you can contact the Office of the Australian Information Commissioner.
Your guests and their rights
Guest information belongs to the couple, and we process it under their instructions. If you are a guest and you want to know what a couple holds about you, corrected or removed, the fastest route is to ask them, since they can edit it directly.
You can also write to us at hello@theweddingsuite.co and we will pass the request on to the couple and help them action it. We will not hand a guest list to anyone other than the couple who owns it.
A published wedding website and its RSVP link are public to anyone who has the address. They are not listed in search engines by default, but a link that has been shared can be shared again. Keep anything sensitive, such as home addresses, in the planner rather than on the public page.
How we protect it
- Every connection to the Suite is encrypted with HTTPS.
- Passwords are stored only as bcrypt hashes, so nobody, including us, can read them back.
- The session cookie is HTTP-only and signed, so it cannot be read or forged by a script in your browser.
- The database is managed, access-controlled and backed up by Neon.
- Card data never reaches our servers, so there is nothing there for anyone to take.
- Access to production data is limited to the people who maintain the service.
No system is perfect. If a breach ever affected your data, we would tell you promptly and tell you plainly what happened, as the Notifiable Data Breaches scheme requires.
Children
The Wedding Suite is for adults planning a wedding. We do not knowingly collect information from children under 18, and we have no interest in doing so. A child’s name may appear on a guest list because the couple put it there, and that entry is treated like every other piece of the couple’s data. If you believe a child has created an account, tell us and we will remove it.
Changes to this policy
If we change what we collect, who we share it with, or how long we keep it, this page changes with it and the date at the top is updated. A change that materially affects your privacy is emailed to you before it takes effect.
How to reach us
Privacy questions, access requests and deletion requests all go to hello@theweddingsuite.co, or through the contact page. A person reads every one, and couples usually hear back within one business day.
See also our Terms of Service and our Refund and Cancellation Policy.