Privacy Policy

Last updated 29 July 2026

Your wedding is personal, and so is the information you trust us with. This page explains exactly what we collect, why, and what you can do about it — in plain English, with no small print.

1. Who we are

wed.cards runs the website and app at wed.cards. We are an Indian company, based in India, and we follow India's data protection law in full.

We go further than we have to. Europe's privacy rules are the strictest in the world, and we apply that same standard to everyone who uses wed.cards, wherever you live — not because a regulator makes us, but because we would rather run one high standard than a different one per country. In practice that means we ask before we track anything, you can download or delete your data yourself at any time, we publish how long we keep things, and we name every company that touches your information.

One important exception. When you upload a guest list, those details belong to you, not to us. You decide whose information goes in and what it is used for; we simply hold it and act on your instructions. The terms for that are in our Guest Data Agreement.

Address: HQ — Pune, India 411057
Privacy contact: support@wed.cards

2. What we collect

WhatDetailsWhere it comes from
Your accountName, email, mobile number, your password (scrambled so even we cannot read it), and a postal address if you order printed cardsYou
Your invitationCouple names, event dates, venues, messages, photos, your love storyYou
Your guest listGuest names, contact details, addresses, RSVPs, meal preferences, personal notesYou (see section 1)
Guestbook entriesNames, wishes and photos left by your visitorsYour guests
PaymentsAmount, currency, plan, receipt referenceYou and Razorpay
Technical bitsYour country (see below), device and browser type, pages viewedYour device
Your choicesWhat you agreed to and whenSaved when you act

How we work out your country — and why nobody else finds out. We need to know your country so we can show you the right currency, so that visitors in India see rupees and UPI rather than euros. We work this out on our own servers, using a lookup file stored inside the application. Your IP address is used for that check and then thrown away. It is never sent to an outside service, never saved against your account, and never written down in full.

We don't build profiles of you, we don't follow you around other websites, and no computer makes important decisions about you on its own.

3. Why we use it

We only use your information for things you would expect, and for nothing else. Anything that isn't strictly needed to run the service — analytics, marketing — happens only if you say yes, and you can change your mind whenever you like.

What we doWhy we can
Create and protect your accountYou asked us to — it is part of providing the service
Build, host and share your invitationYou asked us to
Manage your guest list and RSVPsYou asked us to, and we act on your instructions
Take payment and issue receiptsYou asked us to, and tax law requires us to keep records
Email you about your account and eventsYou asked us to
Keep the service safe and stop abuseNecessary to run the service securely
Count visits with Google AnalyticsOnly with your permission
Send you tips and offersOnly with your permission
Plant a tree for your weddingYou asked us to

Where we rely on your permission, you can withdraw it at any time from Profile → Privacy & Data. That won't undo anything we already did properly beforehand, but it stops immediately from that point on.

4. Who we share it with

We never sell your information, and we never share it so that someone else can market to you. We do share it with the companies we need to run the platform — payment processing, hosting, email delivery, analytics if you allow it, and couriers when you order printed cards. Every one of them is named on our Service providers page, along with what they receive and where they are. They may only use your information to do the job we hired them for.

We will also hand over information if the law genuinely requires it — a valid court order, for example — and we will tell you when we are allowed to.

Your invitation page is public by default. Anyone with the link can open it, and search engines may find it, unless you set an access code. Please keep that in mind when adding photos or personal details.

5. Where your information goes

We are based in India, and our systems are hosted in India and Europe. A few of our providers are in the United States, so some information moves between countries.

Whenever that happens, we put the strongest protection agreements available in place with the company receiving it — the same ones European businesses are required to use — and we apply them to everyone's information, not just to users in Europe. If the Indian government ever restricts transfers to a country we use, we will move or stop that processing.

You can ask us what protections apply to any particular transfer by writing to support@wed.cards.

6. How long we keep it

We delete things once the reason we collected them has passed. Holding on to your guests' names, phone numbers and addresses forever would be a risk to them and to us, so we don't. The full schedule, and the warning you get before anything is deleted, is on the How long we keep things page. In short:

WhatHow long
Your invitation and guest list12 months after the wedding date
Your accountWhile you use it — 24 months of no sign-in ends it
Deleted accountsErased 30 days after you ask
Payment and tax records8 years, with your personal details stripped out once your account is gone
Contact form messages and system logs90 days
Records of what you agreed toWhile it applies, plus 3 years

7. What you can do

Everything below is available to everyone, wherever you live. Most of it you can do yourself right now in Profile → Privacy & Data. None of it costs anything, and we reply within 30 days.

What you can doWhat it meansHow
Get a copyDownload everything we hold about youProfile → Download my data
Take it elsewhereThe download is a standard file any other service can readSame button
Fix somethingCorrect anything wrong or incompleteProfile, or email us
Delete everythingRemove your account and data for goodProfile → Delete my account
Change your mindTurn analytics or marketing emails offProfile → Privacy & Data
Ask us to pauseStop us using your information a particular wayEmail support@wed.cards
ComplainRaise a problem and get a proper answerRaise a concern
Appoint someoneName a person to act for you if you die or become seriously illEmail support@wed.cards

If we get it wrong. Come to us first — it is the fastest way to fix it, and we take it seriously. If our answer doesn't satisfy you, you can escalate to the Data Protection Board of India, which is the authority that oversees us. If you live in Europe or the UK you may also contact your local privacy regulator.

8. Children

wed.cards is for adults. You need to be 18 or over to create an account, and we ask you to confirm that when you sign up. We do not knowingly collect information about children, and we never track or advertise to them.

If your guest list or photos include a child, you are confirming you have the right to share those details with us — which for a child means their parent or guardian is happy with it. If you think a child's information has reached us when it shouldn't have, tell us at support@wed.cards and we will remove it promptly.

9. Cookies

We use a small number of cookies to keep you signed in and the site secure — those are essential and can't be turned off while you use the service. Everything else waits for your permission. Google Analytics stores nothing at all unless you accept it in the banner, and switching it off in Profile → Privacy & Data stops it straight away.

The full list — what each cookie does and how long it lasts — is on the Cookie Policy page.

10. How we protect it

We take security seriously and we work at it continuously. Passwords are stored scrambled and can never be read back, not even by us. Everything travels over an encrypted connection and is stored encrypted. Only the few people who genuinely need access to live data have it. We run automated security testing against our own systems and keep everything patched and up to date.

What we can honestly promise. We will always take every reasonable step to keep your information safe, and we will never cut corners on it. What no service on the internet can promise — and we would rather tell you plainly than pretend otherwise — is that nothing will ever go wrong. Software has flaws, suppliers have outages, and determined attackers exist.

So: we don't guarantee the service will always be available or completely free of faults, and where something goes wrong despite our precautions, or because of an event genuinely outside our control, our responsibility is limited as set out in our Terms of Service. That is not us stepping away from our duty to look after your information — we remain fully accountable for that — it is simply an honest statement of what can and cannot be promised.

You have a part to play too. Choose a strong password, keep it to yourself, and tell us straight away if you think someone else has got into your account. In practice that is the most common way information gets exposed, and it is the one thing only you can prevent.

11. If something goes wrong

If your information is ever caught up in a security incident, we will tell you. Not just the regulator — you, directly. We hold ourselves to the strictest standard here: there is no “too small to mention” category, and we would rather over-inform you than quietly hope you don't notice.

We aim to notify the authorities within 72 hours of finding out, and to tell affected people as soon as we understand what happened. Alongside that we will explain what we are doing about it and what, if anything, you should do.

12. Which law applies

We are based in India. Indian law applies to this policy, and any dispute would be handled by the courts of Sangli, Maharashtra, India.

That doesn't take away rights you have where you live. Nothing here overrides the consumer protections of your own country. We're not trying to use our location to give you less — the promises on this page are made to you directly, wherever you are.

13. Changes to this policy

We keep a dated record of every meaningful change. If something changes that materially affects how we use your information, we will tell you by email or in the app before it takes effect — and where your permission is needed, we will ask again rather than assume.

29 July 2026

Rewrote every policy in plain English. We removed the legal section numbers and jargon so you can actually read what we do with your information, and renamed several pages to say what they are. Nothing about how we handle your data changed — no right, protection or retention period was reduced. We also set out more clearly what we can and cannot promise: we commit to genuine care over your information and remain fully accountable for it, while being honest that no online service can guarantee it will never have a fault or an outage.

28 July 2026

Consolidated our contact points: privacy, grievance and all other legal correspondence now goes to a single monitored address (support@wed.cards) so a rights request cannot be lost in an unmonitored alias, with hello@wed.cards for general enquiries. Our full registered office is published where payment-gateway and consumer-law rules require a complete postal address; other pages show our operating HQ. Telephone contact has been withdrawn in favour of email, which gives both sides a written record.

27 July 2026

Clarified our regulatory position: wed.cards is established in India and governed by the Digital Personal Data Protection Act, 2023, with no EU establishment. We apply GDPR-level protections to every user worldwide as a voluntary standard rather than a jurisdictional obligation, and where the two frameworks differ we follow the stricter. Also explained how we determine your country: the lookup now runs entirely on our own servers against a local database, so your IP address is no longer disclosed to any geolocation service. No user-facing right, retention period or safeguard was reduced by these changes.

26 July 2026

Full rewrite for the GDPR and India's Digital Personal Data Protection Act, 2023. Added legal-basis and retention tables, the sub-processor list, international-transfer disclosures, data-principal and data-subject rights (including the DPDPA right to nominate), a named Grievance Officer, children's-data terms, and cookie-consent controls. Introduced self-service data export and account deletion.

Contact us

Anything about this policy, your information, or a formal complaint: support@wed.cards — see Raise a concern for how complaints are handled and how quickly. For anything else, write to hello@wed.cards.

Post: HQ — Pune, India 411057