Privacy Policy
Last updated 29 July 2026
Your wedding is personal, and so is the information you trust us with. This page explains exactly what we collect, why, and what you can do about it — in plain English, with no small print.
1. Who we are
wed.cards runs the website and app at wed.cards. We are an Indian company, based in India, and we follow India's data protection law in full.
We go further than we have to. Europe's privacy rules are the strictest in the world, and we apply that same standard to everyone who uses wed.cards, wherever you live — not because a regulator makes us, but because we would rather run one high standard than a different one per country. In practice that means we ask before we track anything, you can download or delete your data yourself at any time, we publish how long we keep things, and we name every company that touches your information.
One important exception. When you upload a guest list, those details belong to you, not to us. You decide whose information goes in and what it is used for; we simply hold it and act on your instructions. The terms for that are in our Guest Data Agreement.
Address: HQ — Pune, India 411057
Privacy contact: support@wed.cards
2. What we collect
| What | Details | Where it comes from |
|---|---|---|
| Your account | Name, email, mobile number, your password (scrambled so even we cannot read it), and a postal address if you order printed cards | You |
| Your invitation | Couple names, event dates, venues, messages, photos, your love story | You |
| Your guest list | Guest names, contact details, addresses, RSVPs, meal preferences, personal notes | You (see section 1) |
| Guestbook entries | Names, wishes and photos left by your visitors | Your guests |
| Payments | Amount, currency, plan, receipt reference | You and Razorpay |
| Technical bits | Your country (see below), device and browser type, pages viewed | Your device |
| Your choices | What you agreed to and when | Saved when you act |
How we work out your country — and why nobody else finds out. We need to know your country so we can show you the right currency, so that visitors in India see rupees and UPI rather than euros. We work this out on our own servers, using a lookup file stored inside the application. Your IP address is used for that check and then thrown away. It is never sent to an outside service, never saved against your account, and never written down in full.
We don't build profiles of you, we don't follow you around other websites, and no computer makes important decisions about you on its own.
3. Why we use it
We only use your information for things you would expect, and for nothing else. Anything that isn't strictly needed to run the service — analytics, marketing — happens only if you say yes, and you can change your mind whenever you like.
| What we do | Why we can |
|---|---|
| Create and protect your account | You asked us to — it is part of providing the service |
| Build, host and share your invitation | You asked us to |
| Manage your guest list and RSVPs | You asked us to, and we act on your instructions |
| Take payment and issue receipts | You asked us to, and tax law requires us to keep records |
| Email you about your account and events | You asked us to |
| Keep the service safe and stop abuse | Necessary to run the service securely |
| Count visits with Google Analytics | Only with your permission |
| Send you tips and offers | Only with your permission |
| Plant a tree for your wedding | You asked us to |
Where we rely on your permission, you can withdraw it at any time from Profile → Privacy & Data. That won't undo anything we already did properly beforehand, but it stops immediately from that point on.
4. Who we share it with
We never sell your information, and we never share it so that someone else can market to you. We do share it with the companies we need to run the platform — payment processing, hosting, email delivery, analytics if you allow it, and couriers when you order printed cards. Every one of them is named on our Service providers page, along with what they receive and where they are. They may only use your information to do the job we hired them for.
We will also hand over information if the law genuinely requires it — a valid court order, for example — and we will tell you when we are allowed to.
Your invitation page is public by default. Anyone with the link can open it, and search engines may find it, unless you set an access code. Please keep that in mind when adding photos or personal details.
5. Where your information goes
We are based in India, and our systems are hosted in India and Europe. A few of our providers are in the United States, so some information moves between countries.
Whenever that happens, we put the strongest protection agreements available in place with the company receiving it — the same ones European businesses are required to use — and we apply them to everyone's information, not just to users in Europe. If the Indian government ever restricts transfers to a country we use, we will move or stop that processing.
You can ask us what protections apply to any particular transfer by writing to support@wed.cards.
6. How long we keep it
We delete things once the reason we collected them has passed. Holding on to your guests' names, phone numbers and addresses forever would be a risk to them and to us, so we don't. The full schedule, and the warning you get before anything is deleted, is on the How long we keep things page. In short:
| What | How long |
|---|---|
| Your invitation and guest list | 12 months after the wedding date |
| Your account | While you use it — 24 months of no sign-in ends it |
| Deleted accounts | Erased 30 days after you ask |
| Payment and tax records | 8 years, with your personal details stripped out once your account is gone |
| Contact form messages and system logs | 90 days |
| Records of what you agreed to | While it applies, plus 3 years |
7. What you can do
Everything below is available to everyone, wherever you live. Most of it you can do yourself right now in Profile → Privacy & Data. None of it costs anything, and we reply within 30 days.
| What you can do | What it means | How |
|---|---|---|
| Get a copy | Download everything we hold about you | Profile → Download my data |
| Take it elsewhere | The download is a standard file any other service can read | Same button |
| Fix something | Correct anything wrong or incomplete | Profile, or email us |
| Delete everything | Remove your account and data for good | Profile → Delete my account |
| Change your mind | Turn analytics or marketing emails off | Profile → Privacy & Data |
| Ask us to pause | Stop us using your information a particular way | Email support@wed.cards |
| Complain | Raise a problem and get a proper answer | Raise a concern |
| Appoint someone | Name a person to act for you if you die or become seriously ill | Email support@wed.cards |
If we get it wrong. Come to us first — it is the fastest way to fix it, and we take it seriously. If our answer doesn't satisfy you, you can escalate to the Data Protection Board of India, which is the authority that oversees us. If you live in Europe or the UK you may also contact your local privacy regulator.
8. Children
wed.cards is for adults. You need to be 18 or over to create an account, and we ask you to confirm that when you sign up. We do not knowingly collect information about children, and we never track or advertise to them.
If your guest list or photos include a child, you are confirming you have the right to share those details with us — which for a child means their parent or guardian is happy with it. If you think a child's information has reached us when it shouldn't have, tell us at support@wed.cards and we will remove it promptly.
9. Cookies
We use a small number of cookies to keep you signed in and the site secure — those are essential and can't be turned off while you use the service. Everything else waits for your permission. Google Analytics stores nothing at all unless you accept it in the banner, and switching it off in Profile → Privacy & Data stops it straight away.
The full list — what each cookie does and how long it lasts — is on the Cookie Policy page.
10. How we protect it
We take security seriously and we work at it continuously. Passwords are stored scrambled and can never be read back, not even by us. Everything travels over an encrypted connection and is stored encrypted. Only the few people who genuinely need access to live data have it. We run automated security testing against our own systems and keep everything patched and up to date.
What we can honestly promise. We will always take every reasonable step to keep your information safe, and we will never cut corners on it. What no service on the internet can promise — and we would rather tell you plainly than pretend otherwise — is that nothing will ever go wrong. Software has flaws, suppliers have outages, and determined attackers exist.
So: we don't guarantee the service will always be available or completely free of faults, and where something goes wrong despite our precautions, or because of an event genuinely outside our control, our responsibility is limited as set out in our Terms of Service. That is not us stepping away from our duty to look after your information — we remain fully accountable for that — it is simply an honest statement of what can and cannot be promised.
You have a part to play too. Choose a strong password, keep it to yourself, and tell us straight away if you think someone else has got into your account. In practice that is the most common way information gets exposed, and it is the one thing only you can prevent.
11. If something goes wrong
If your information is ever caught up in a security incident, we will tell you. Not just the regulator — you, directly. We hold ourselves to the strictest standard here: there is no “too small to mention” category, and we would rather over-inform you than quietly hope you don't notice.
We aim to notify the authorities within 72 hours of finding out, and to tell affected people as soon as we understand what happened. Alongside that we will explain what we are doing about it and what, if anything, you should do.
12. Which law applies
We are based in India. Indian law applies to this policy, and any dispute would be handled by the courts of Sangli, Maharashtra, India.
That doesn't take away rights you have where you live. Nothing here overrides the consumer protections of your own country. We're not trying to use our location to give you less — the promises on this page are made to you directly, wherever you are.
13. Changes to this policy
We keep a dated record of every meaningful change. If something changes that materially affects how we use your information, we will tell you by email or in the app before it takes effect — and where your permission is needed, we will ask again rather than assume.
29 July 2026
Rewrote every policy in plain English. We removed the legal section numbers and jargon so you can actually read what we do with your information, and renamed several pages to say what they are. Nothing about how we handle your data changed — no right, protection or retention period was reduced. We also set out more clearly what we can and cannot promise: we commit to genuine care over your information and remain fully accountable for it, while being honest that no online service can guarantee it will never have a fault or an outage.
28 July 2026
Consolidated our contact points: privacy, grievance and all other legal correspondence now goes to a single monitored address (support@wed.cards) so a rights request cannot be lost in an unmonitored alias, with hello@wed.cards for general enquiries. Our full registered office is published where payment-gateway and consumer-law rules require a complete postal address; other pages show our operating HQ. Telephone contact has been withdrawn in favour of email, which gives both sides a written record.
27 July 2026
Clarified our regulatory position: wed.cards is established in India and governed by the Digital Personal Data Protection Act, 2023, with no EU establishment. We apply GDPR-level protections to every user worldwide as a voluntary standard rather than a jurisdictional obligation, and where the two frameworks differ we follow the stricter. Also explained how we determine your country: the lookup now runs entirely on our own servers against a local database, so your IP address is no longer disclosed to any geolocation service. No user-facing right, retention period or safeguard was reduced by these changes.
26 July 2026
Full rewrite for the GDPR and India's Digital Personal Data Protection Act, 2023. Added legal-basis and retention tables, the sub-processor list, international-transfer disclosures, data-principal and data-subject rights (including the DPDPA right to nominate), a named Grievance Officer, children's-data terms, and cookie-consent controls. Introduced self-service data export and account deletion.
Contact us
Anything about this policy, your information, or a formal complaint: support@wed.cards — see Raise a concern for how complaints are handled and how quickly. For anything else, write to hello@wed.cards.
Post: HQ — Pune, India 411057