Legal
Privacy Policy
Planning a wedding creates a lot of data - and most of it does not belong to you, it belongs to your guests. This policy provides the information required by Art. 12, 13 and 14 GDPR: what we do with that data, why we are allowed to, and how you can stop us.
1. Controller and contact
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
- Company
- Efficient Operations GmbH
- Address
- Schürenbruch 13, 32479 Hille, Germany
- Represented by
- Daniel Fischer
- daniel@wedtab.com
- Phone
- +49 151 74269061
No data protection officer has been appointed at this time.
This policy covers visits to wedtab.com, registering and using a WedTab account, and every page you publish through WedTab for your guests - your wedding website, your RSVP page and your photo gallery.
2. The short version
- We do not sell data. To anyone.
- We do not use your photos for advertising or to train AI systems.
- We measure how our Google ads perform. That sets cookies - only with your consent.
- You can delete your account yourself at any time, along with all guest data and photos.
- Your guests need no account and no app to reply or upload photos.
3. Data you give us
Account
At registration we process your email address, your name and a password stored only as a hash, in order to provide your account and sign you in. The legal basis is Art. 6(1)(b) GDPR.
Wedding data
Everything you create in the app: wedding date, tasks, budget items, seating plans and the text of your wedding website.
Guest data
Names, postal addresses, email addresses, mobile numbers, acceptances and declines, plus-ones, and information about dietary preferences and allergies. See sections 5 and 6 for detail.
Payment data
When you buy a paid add-on, payment is handled by Paddle as Merchant of Record. Paddle processes your payment data as an independent controller; Paddle's own privacy information applies in addition. We do not store full card or bank details ourselves - only the fact of payment, the amount and a transaction reference for our accounts.
4. Data created automatically
When you open our pages, your browser transmits technically necessary data that is recorded in server logs: IP address, date and time, the address requested, the volume of data transferred, browser type and operating system.
The purpose is secure, stable operation and defence against attacks such as denial-of-service attempts. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the secure operation of our service. Recipients of this data are in particular Cloudflare and Vercel as providers for delivery, security and hosting.
We delete these logs after 30 days, unless we exceptionally need them longer to investigate a specific security incident.
5. Guest data: who is responsible
This is the most important section of this policy, so here it is in full.
When you build your guest list, you decide what data goes in it and what it is used for. We only provide the tool and act on your instructions. In relation to your guests you are therefore normally the controller, and we are a processor under Art. 28 GDPR.
For a purely private wedding, the household exemption in Art. 2(2)(c) GDPR will often apply to you: planning your own celebration among family and friends is a personal activity. That does not excuse you from being considerate, but it does spare you a company's formal obligations.
Either way, on our side: we process guest data solely to provide the service to you. We do not analyse it, do not use it for our own purposes and do not pass it on, other than to the processors listed in section 10.
What guests enter themselves
When a guest scans your QR code, they enter their details with us directly. At that point we tell them which wedding they are replying to, which fields are optional, and who can see their answers - namely you as the couple.
6. Allergies and dietary preferences
Entries such as "peanut allergy", "coeliac" or "gluten-free" can reveal information about a person's health. Such data enjoys special protection under Art. 9 GDPR and may only be processed on narrow grounds.
So in WedTab:
- The field is always optional for guests. A guest can accept without it.
- We obtain explicit consent under Art. 9(2)(a) GDPR in the RSVP form.
- Guests can change or withdraw their entry at any time through the same link. Withdrawal takes effect for the future.
- We show these entries only to you as the couple, never to other guests.
- We delete them sooner than the rest of the guest data - see section 12.
Please pass this information to your caterer only as far as the kitchen needs it - ideally without names, as a count per table.
7. Photos from your guests
When a guest uploads a photo through the QR code, we store the image file and the time of upload, plus their name if they choose to give it. The files are stored with Supabase, see section 10.
Photos often carry embedded metadata such as capture location and device model. We strip location data on upload before storing the file.
The gallery is not public. It is reachable only through your link and is not indexed by search engines. You can delete individual photos at any time.
Photos show people who were never asked whether they wanted to be photographed. If someone pictured asks for an image to be removed, they will usually approach you, and you can remove it from your gallery yourself. If they approach us, we pass the request on to you and delete the image unless you object within a reasonable period.
8. Email reminders
At your request we remind guests who have not yet replied. For that we process the email address the guest provided themselves, or that you entered from your address book.
Every reminder explains how the guest can opt out of further messages. We send at most two reminders per guest. There is no SMS delivery.
The legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in organising a private celebration to which the guest has already been invited.
Mobile number for verification
When replying, a guest enters their mobile number. It serves only to prevent duplicate or impersonated replies. We send no messages to that number - neither by SMS nor by any other route - and we do not pass it on. It is visible only to you as the couple and is deleted together with the rest of the guest data. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest lies in a reliable guest list.
9. Legal bases
| Processing | Legal basis |
|---|---|
| Account and provision of features | Art. 6(1)(b) GDPR - performance of a contract |
| Paid purchases and invoices | Art. 6(1)(b) and (c) GDPR |
| Server logs and attack defence | Art. 6(1)(f) GDPR - legitimate interest in secure operation |
| Guest data on your behalf | Art. 28 GDPR - processing on behalf of a controller |
| Allergies and dietary preferences | Art. 9(2)(a) GDPR - explicit consent of the guest |
| Email reminders to guests | Art. 6(1)(f) GDPR - legitimate interest in organising the celebration |
| Retention of invoices | Art. 6(1)(c) GDPR - commercial and tax law obligations |
10. Recipients and processors
We pass personal data on only where it is necessary to run the service, where there is a legal basis, or where you have consented. The recipients are:
| Provider | Purpose | Role |
|---|---|---|
| Cloudflare, Inc. (USA) | Website delivery, DNS, protection against attacks, caching | Processor |
| Vercel Inc. (USA) | Hosting and operation of the application | Processor |
| Supabase, Inc. (USA) | Database, authentication and storage of your photos and files | Processor |
| Google Ireland Limited (Ireland) | Google Tag Manager: technical management of embedded tools | Processor |
| Paddle.com Market Ltd. (United Kingdom) | Payment, sales tax, invoicing and refunds | Independent controller (Merchant of Record) |
We have data processing agreements under Art. 28 GDPR with every processor listed. Paddle processes payment data as an independent controller within its own service.
Beyond that we disclose data to tax advisers, legal advisers, banks and authorities where necessary or where we are legally required to.
11. Transfers outside the EU
Personal data may be transferred to, or processed by, recipients outside the European Union or the European Economic Area, in particular in the United States and the United Kingdom. This concerns Cloudflare, Vercel, Supabase, Paddle and Google.
An adequacy decision of the European Commission exists for the United Kingdom. Where no adequacy decision exists for a third country, transfers take place on the basis of appropriate safeguards under Art. 44 et seq. GDPR, in particular the EU Standard Contractual Clauses, supplementary measures, or certification under the EU-U.S. Data Privacy Framework.
Where our providers offer European data centre regions, we select them.
12. Retention and deletion
We retain personal data only as long as necessary for the relevant purpose or as long as statutory retention periods require. In detail:
| Data | Deleted |
|---|---|
| Account data | when you delete your account |
| Wedding and guest data | 12 months after the wedding date, or sooner on request |
| Allergies and dietary preferences | 30 days after the wedding date |
| Photos | 6 months after the wedding date, extendable at your request as often as you like, with advance notice by email |
| Server logs | after 30 days |
| Invoices and accounting records | once statutory retention periods expire, normally 10 years |
Before your photos and guest data are finally deleted, we write to you in good time so you can download everything.
13. Data security
We take technical and organisational measures under Art. 32 GDPR to protect your data. These include in particular:
- encrypted transmission of every page and upload over TLS (HTTPS)
- encryption of stored data and files at our providers
- passwords stored only as hashes, never in plain text
- access to production data limited to the people who need it for maintenance
- protection against overload and attack attempts through Cloudflare
- randomly generated, unlisted addresses for galleries and RSVP pages
Nobody can promise complete security against every conceivable attack. Should a personal data breach occur despite our measures, we notify the supervisory authority and - where the risk is high - the people affected, as Art. 33 and 34 GDPR require.
14. Minors
Only adults may create a WedTab account.
Wedding guests can be any age. Where children under 16 are involved - because they are accepting an invitation or uploading a photo - the entry must be made or approved by a person with parental responsibility. As the couple, please keep this in mind when you add children to your guest list.
If we learn that a child's data is held with us without the necessary approval, we delete it.
15. No automated decisions
We use no automated decision-making within the meaning of Art. 22 GDPR and we build no profiles. Neither your entries nor those of your guests are analysed to predict characteristics or behaviour.
Do you have to give us this data?
The account and wedding details are necessary for us to perform the contract - without them WedTab cannot be used. Everything else, in particular allergies, dietary preferences, mobile numbers and photos, is voluntary. Withholding them has no consequence other than the relevant feature being unavailable.
17. Your rights
You have the right at any time to:
- access the data we hold about you (Art. 15 GDPR)
- rectification of inaccurate data (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability in a common format (Art. 20 GDPR)
- object to processing based on legitimate interests (Art. 21 GDPR)
- withdraw consent with effect for the future (Art. 7(3) GDPR)
Write to daniel@wedtab.com. We respond within one month.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.
Are you a wedding guest wanting your data deleted? The couple manages the list, so contacting them directly is usually quickest - but you can also come to us and we will help.
18. Changes to this policy
When we add features or change providers, we update this policy. The current version is always on this page, and the date at the top shows when it was last changed.
For significant changes we also notify you by email.