WedTab
DE EN
Back to homepage

Contents

  1. 1. Controller and contact
  2. 2. The short version
  3. 3. Data you give us
  4. 4. Data created automatically
  5. 5. Guest data: who is responsible
  6. 6. Allergies and dietary preferences
  7. 7. Photos from your guests
  8. 8. Email reminders
  9. 9. Legal bases
  10. 10. Recipients and processors
  11. 11. Transfers outside the EU
  12. 12. Retention and deletion
  13. 13. Data security
  14. 14. Minors
  15. 15. No automated decisions
  16. 16. Cookies and analytics
  17. 17. Your rights
  18. 18. Changes to this policy

Legal

Privacy Policy

Last updated: 23 August 2026 · Auf Deutsch lesen

Planning a wedding creates a lot of data - and most of it does not belong to you, it belongs to your guests. This policy provides the information required by Art. 12, 13 and 14 GDPR: what we do with that data, why we are allowed to, and how you can stop us.

1. Controller and contact

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Company
Efficient Operations GmbH
Address
Schürenbruch 13, 32479 Hille, Germany
Represented by
Daniel Fischer
Email
daniel@wedtab.com
Phone
+49 151 74269061

No data protection officer has been appointed at this time.

This policy covers visits to wedtab.com, registering and using a WedTab account, and every page you publish through WedTab for your guests - your wedding website, your RSVP page and your photo gallery.

2. The short version

  • We do not sell data. To anyone.
  • We do not use your photos for advertising or to train AI systems.
  • We measure how our Google ads perform. That sets cookies - only with your consent.
  • You can delete your account yourself at any time, along with all guest data and photos.
  • Your guests need no account and no app to reply or upload photos.

3. Data you give us

Account

At registration we process your email address, your name and a password stored only as a hash, in order to provide your account and sign you in. The legal basis is Art. 6(1)(b) GDPR.

Wedding data

Everything you create in the app: wedding date, tasks, budget items, seating plans and the text of your wedding website.

Guest data

Names, postal addresses, email addresses, mobile numbers, acceptances and declines, plus-ones, and information about dietary preferences and allergies. See sections 5 and 6 for detail.

Payment data

When you buy a paid add-on, payment is handled by Paddle as Merchant of Record. Paddle processes your payment data as an independent controller; Paddle's own privacy information applies in addition. We do not store full card or bank details ourselves - only the fact of payment, the amount and a transaction reference for our accounts.

4. Data created automatically

When you open our pages, your browser transmits technically necessary data that is recorded in server logs: IP address, date and time, the address requested, the volume of data transferred, browser type and operating system.

The purpose is secure, stable operation and defence against attacks such as denial-of-service attempts. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the secure operation of our service. Recipients of this data are in particular Cloudflare and Vercel as providers for delivery, security and hosting.

We delete these logs after 30 days, unless we exceptionally need them longer to investigate a specific security incident.

5. Guest data: who is responsible

This is the most important section of this policy, so here it is in full.

When you build your guest list, you decide what data goes in it and what it is used for. We only provide the tool and act on your instructions. In relation to your guests you are therefore normally the controller, and we are a processor under Art. 28 GDPR.

For a purely private wedding, the household exemption in Art. 2(2)(c) GDPR will often apply to you: planning your own celebration among family and friends is a personal activity. That does not excuse you from being considerate, but it does spare you a company's formal obligations.

Either way, on our side: we process guest data solely to provide the service to you. We do not analyse it, do not use it for our own purposes and do not pass it on, other than to the processors listed in section 10.

What guests enter themselves

When a guest scans your QR code, they enter their details with us directly. At that point we tell them which wedding they are replying to, which fields are optional, and who can see their answers - namely you as the couple.

6. Allergies and dietary preferences

Entries such as "peanut allergy", "coeliac" or "gluten-free" can reveal information about a person's health. Such data enjoys special protection under Art. 9 GDPR and may only be processed on narrow grounds.

So in WedTab:

  • The field is always optional for guests. A guest can accept without it.
  • We obtain explicit consent under Art. 9(2)(a) GDPR in the RSVP form.
  • Guests can change or withdraw their entry at any time through the same link. Withdrawal takes effect for the future.
  • We show these entries only to you as the couple, never to other guests.
  • We delete them sooner than the rest of the guest data - see section 12.

Please pass this information to your caterer only as far as the kitchen needs it - ideally without names, as a count per table.

7. Photos from your guests

When a guest uploads a photo through the QR code, we store the image file and the time of upload, plus their name if they choose to give it. The files are stored with Supabase, see section 10.

Photos often carry embedded metadata such as capture location and device model. We strip location data on upload before storing the file.

The gallery is not public. It is reachable only through your link and is not indexed by search engines. You can delete individual photos at any time.

Photos show people who were never asked whether they wanted to be photographed. If someone pictured asks for an image to be removed, they will usually approach you, and you can remove it from your gallery yourself. If they approach us, we pass the request on to you and delete the image unless you object within a reasonable period.

8. Email reminders

At your request we remind guests who have not yet replied. For that we process the email address the guest provided themselves, or that you entered from your address book.

Every reminder explains how the guest can opt out of further messages. We send at most two reminders per guest. There is no SMS delivery.

The legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in organising a private celebration to which the guest has already been invited.

Mobile number for verification

When replying, a guest enters their mobile number. It serves only to prevent duplicate or impersonated replies. We send no messages to that number - neither by SMS nor by any other route - and we do not pass it on. It is visible only to you as the couple and is deleted together with the rest of the guest data. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest lies in a reliable guest list.

9. Legal bases

ProcessingLegal basis
Account and provision of featuresArt. 6(1)(b) GDPR - performance of a contract
Paid purchases and invoicesArt. 6(1)(b) and (c) GDPR
Server logs and attack defenceArt. 6(1)(f) GDPR - legitimate interest in secure operation
Guest data on your behalfArt. 28 GDPR - processing on behalf of a controller
Allergies and dietary preferencesArt. 9(2)(a) GDPR - explicit consent of the guest
Email reminders to guestsArt. 6(1)(f) GDPR - legitimate interest in organising the celebration
Retention of invoicesArt. 6(1)(c) GDPR - commercial and tax law obligations

10. Recipients and processors

We pass personal data on only where it is necessary to run the service, where there is a legal basis, or where you have consented. The recipients are:

ProviderPurposeRole
Cloudflare, Inc. (USA) Website delivery, DNS, protection against attacks, caching Processor
Vercel Inc. (USA) Hosting and operation of the application Processor
Supabase, Inc. (USA) Database, authentication and storage of your photos and files Processor
Google Ireland Limited (Ireland) Google Tag Manager: technical management of embedded tools Processor
Paddle.com Market Ltd. (United Kingdom) Payment, sales tax, invoicing and refunds Independent controller (Merchant of Record)

We have data processing agreements under Art. 28 GDPR with every processor listed. Paddle processes payment data as an independent controller within its own service.

Beyond that we disclose data to tax advisers, legal advisers, banks and authorities where necessary or where we are legally required to.

11. Transfers outside the EU

Personal data may be transferred to, or processed by, recipients outside the European Union or the European Economic Area, in particular in the United States and the United Kingdom. This concerns Cloudflare, Vercel, Supabase, Paddle and Google.

An adequacy decision of the European Commission exists for the United Kingdom. Where no adequacy decision exists for a third country, transfers take place on the basis of appropriate safeguards under Art. 44 et seq. GDPR, in particular the EU Standard Contractual Clauses, supplementary measures, or certification under the EU-U.S. Data Privacy Framework.

Where our providers offer European data centre regions, we select them.

12. Retention and deletion

We retain personal data only as long as necessary for the relevant purpose or as long as statutory retention periods require. In detail:

DataDeleted
Account datawhen you delete your account
Wedding and guest data12 months after the wedding date, or sooner on request
Allergies and dietary preferences30 days after the wedding date
Photos6 months after the wedding date, extendable at your request as often as you like, with advance notice by email
Server logsafter 30 days
Invoices and accounting recordsonce statutory retention periods expire, normally 10 years

Before your photos and guest data are finally deleted, we write to you in good time so you can download everything.

13. Data security

We take technical and organisational measures under Art. 32 GDPR to protect your data. These include in particular:

  • encrypted transmission of every page and upload over TLS (HTTPS)
  • encryption of stored data and files at our providers
  • passwords stored only as hashes, never in plain text
  • access to production data limited to the people who need it for maintenance
  • protection against overload and attack attempts through Cloudflare
  • randomly generated, unlisted addresses for galleries and RSVP pages

Nobody can promise complete security against every conceivable attack. Should a personal data breach occur despite our measures, we notify the supervisory authority and - where the risk is high - the people affected, as Art. 33 and 34 GDPR require.

14. Minors

Only adults may create a WedTab account.

Wedding guests can be any age. Where children under 16 are involved - because they are accepting an invitation or uploading a photo - the entry must be made or approved by a person with parental responsibility. As the couple, please keep this in mind when you add children to your guest list.

If we learn that a child's data is held with us without the necessary approval, we delete it.

15. No automated decisions

We use no automated decision-making within the meaning of Art. 22 GDPR and we build no profiles. Neither your entries nor those of your guests are analysed to predict characteristics or behaviour.

Do you have to give us this data?

The account and wedding details are necessary for us to perform the contract - without them WedTab cannot be used. Everything else, in particular allergies, dietary preferences, mobile numbers and photos, is voluntary. Withholding them has no consequence other than the relevant feature being unavailable.

16. Cookies and analytics

We use strictly necessary cookies only, in particular for sign-in and session security. The legal basis is § 25(2) no. 2 TDDDG; no consent is required for these.

We also store your choice between the light and dark theme locally in your browser. That setting never leaves your device.

NameTypePurposeDurationBasis
wedtab-langcookieremembers your language choice1 yearstrictly necessary
wedtab-themelocal storageremembers light or dark themeuntil you clear itstrictly necessary
wedtab-consentlocal storageremembers your decision on this noticeuntil you clear itstrictly necessary
_gcl_aucookieGoogle Ads: attributes a sign-up to the ad you came from90 daysconsent

Only the last row requires consent - and that cookie is created only once you have agreed in the notice. If you decline, the list stops at the first three entries.

Google Tag Manager

We use Google Tag Manager. It is not an analytics tool in itself: it sets no cookies and stores no personal data, it only manages other tools in one place.

Loading Tag Manager transmits your IP address to Google. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; transfer to the United States cannot be ruled out.

That is why we only load it once you have agreed. Tag Manager is not part of our pages' source code. If you open wedtab.com without agreeing to the notice, not a single request goes to Google - not even your IP address. The legal bases are § 25(1) TDDDG and Art. 6(1)(a) GDPR.

We store your decision locally in your browser under wedtab-consent. That entry never leaves your device and is technically necessary under § 25(2) no. 2 TDDDG. You can withdraw your consent at any time with effect for the future, through “Cookie settings” at the bottom of every page.

Google Ads conversion tracking

We advertise on Google and measure which ads lead to a sign-up. For that we load the Google Ads tag (ID AW-18215625433) through the Tag Manager described in section 16.

What we measure is the click on “Start for free”, meaning the move into our application - not the completion of a registration. What is transmitted is that such a click happened, not who clicked. Without your consent this report does not take place; the click simply takes you to the application.

The tag sets cookies, in particular _gcl_au, and in doing so transmits your IP address, details of the device you use and the page you opened to Google. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; transfer to the United States cannot be ruled out.

The legal bases are § 25(1) TDDDG and Art. 6(1)(a) GDPR - that is, your consent. You can withdraw it at any time with effect for the future. We do not combine this data with your WedTab account.

Beyond that we use no profiling and no further third-party marketing services.

17. Your rights

You have the right at any time to:

  • access the data we hold about you (Art. 15 GDPR)
  • rectification of inaccurate data (Art. 16 GDPR)
  • erasure (Art. 17 GDPR)
  • restriction of processing (Art. 18 GDPR)
  • data portability in a common format (Art. 20 GDPR)
  • object to processing based on legitimate interests (Art. 21 GDPR)
  • withdraw consent with effect for the future (Art. 7(3) GDPR)

Write to daniel@wedtab.com. We respond within one month.

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.

Are you a wedding guest wanting your data deleted? The couple manages the list, so contacting them directly is usually quickest - but you can also come to us and we will help.

18. Changes to this policy

When we add features or change providers, we update this policy. The current version is always on this page, and the date at the top shows when it was last changed.

For significant changes we also notify you by email.

WedTab
Legal notice Privacy Terms Home
© 2026 Efficient Operations GmbH · WedTab – everything for your wedding in one place.