Privacy Notice
What we collect, why, who sees it, where it is kept and how to get rid of it. Written to be read rather than to be survived.
The short version
- Your wedding is yours. We do not sell it, rent it, or use it to advertise to you.
- We keep it on a database in Frankfurt, Germany, and we say so plainly because you ought to know where your things are.
- Only you and a partner you invite can see your wedding. Not even we can, unless you ask us for help and we deliberately open it — which takes thirty minutes, a written reason, and leaves a permanent record with our name on it.
- You can take everything with you or delete the lot, whenever you like, without asking anybody's permission.
- There are no advertising cookies, no tracking pixels and no analytics company watching you. There is nothing to opt out of because there is nothing switched on.
That summary is here to be useful, not to replace what follows. Where the two differ, what follows is what counts.
1. Who we are
, registration number , trading as , is the responsible party for the personal information described in this notice. We operate an online wedding planning service at .
| Information Officer | |
|---|---|
| Address | |
| Telephone | |
| Email about your information | |
| General email |
"We", "us" and "BrideHub" mean that company. "You" means whoever is reading this — a couple using the service, a partner who has joined one, a guest at somebody's wedding, or a supplier.
2. One thing to understand first: whose information is whose
Two quite different things happen on BrideHub, and nearly every question about privacy has a different answer depending on which one you mean.
Your own account. Your email address, your names, your wedding date, the venue, what you spend. We decide how that is handled, so for this we are the responsible party and this notice tells you what we do with it.
Your guests. When a couple types a guest list, uploads a document or records that somebody cannot eat shellfish, the couple decides what goes in and why. We hold it and keep it safe on their instruction. For that information the couple is the responsible party and we are their operator, and a guest who wants their details changed or removed should normally ask the couple. If a guest cannot reach the couple, or would rather not, they can write to us at and we will deal with it.
This is not a way of passing the buck. It means that if you are planning a wedding, the people on your guest list are your responsibility as well as ours — and section 11 below says plainly what that asks of you.
3. What we collect, and why
If you have an account
| Your email address and password | To make the account, sign you in, and email you about the service. The password is stored only as a salted one-way hash, which means nobody — including us — can read it. If you forget it, we cannot tell you what it was; we can only help you set a new one. |
|---|---|
| Your names, your wedding date, venue, town and province | They are the wedding. Without them there is nothing to plan. |
| Everything you enter while planning | Your checklist, budget, guest list, seating chart, floor plan, running order, suppliers, registry, inspiration boards, documents and photos. We hold it so it is there when you come back. |
| Your wedding website, if you make one | The words, pictures and settings you choose. Nothing is visible to anybody until you publish it, and you can unpublish it again. |
| When you signed up and when you last signed in | To run the service, to see whether an account is still in use, and to apply the deletion rule in section 8. |
| A record that you agreed to the Terms of Use and this notice | The date and the version. It is the only way either of us can later show what was agreed. |
If you are a guest at somebody's wedding
| Your name, and which household you belong to | Typed by the couple, so they can invite you and seat you. |
|---|---|
| Your RSVP, and any answer you give to a question the couple asks | So the couple knows who is coming. |
| Dietary requirements and allergies | So the caterer can feed you. Section 4 is about this, because it needs more care than the rest. |
| Your table | So somebody can find their seat. |
| Photos you add to a couple's album, and the name you give when you add them | So the couple has the photos and knows who to thank. |
We deliberately do not collect guests' phone numbers or email addresses. A wedding does not need a database of everybody's contact details, and every field we do not have is a field that cannot be lost, leaked or misused.
Everyone, including people who are only passing through
| Your internet address, browser and the pages you asked for | Recorded in our providers' server logs, which is how any website on earth works. Used to keep the service running and to investigate abuse, and nothing else. |
|---|
4. Dietary needs, allergies, and children
A dietary requirement is information about somebody's health, and POPIA treats health information as special personal information under section 26. It can also give away a religious belief — "no pork" and "kosher" say something about a person that they may not have meant to publish. We take that seriously.
We hold it only because a guest gave it, or a couple recorded it with the guest's knowledge, for the single purpose of feeding that person at that wedding. It is used for nothing else. It is not shown to other guests. It does not appear in any list our own administrators can see — when we look at how much a wedding is being used, we are shown counts and nothing more, and the one screen that can look inside an account deliberately leaves dietary requirements out altogether, because no support question has ever needed them.
Children. A guest list very often includes children, and POPIA section 34 protects a child's personal information particularly strictly. We process it only where a competent person — usually the child's parent, who is normally the guest doing the replying — has consented, or where another ground in section 35 applies. We do not knowingly let anybody under 18 open an account. If you believe we hold a child's information that we should not, write to and we will remove it.
5. What allows us to hold it at all
POPIA section 11 sets out the grounds. We rely on these:
| You asked us to | Running your account and your wedding is the contract between us. We cannot provide the service without holding what the service is made of. |
|---|---|
| You consented | For anything optional — publishing your wedding website, opening your album to guests, a guest handing over a dietary requirement. Consent given can be taken back, and taking it back is a button rather than a letter. |
| Our legitimate interests | Keeping the service secure, preventing abuse, and knowing how many people use it. Balanced against your rights, and never used as an excuse for anything you would object to. |
| The law requires it | Tax and company records, and anything a court or the Information Regulator properly orders. |
6. Who else ever sees it
| Your partner | If you invite them and they accept, they see the whole wedding and can change it. That is the point of inviting them. Either of you can end it. |
|---|---|
| Your guests | Only what you publish on your wedding website, and the registry items still unclaimed. A guest is never shown another guest's details. |
| The companies that run the machinery | Our hosting, database and email providers, listed in section 7. They act on our written instruction and may not use anything for their own purposes. |
| Us, and only deliberately | Section 9. |
| Professional advisers | Accountants and attorneys where genuinely necessary, under a duty of confidence. |
| Regulators, courts and the police | Where the law obliges us, or to establish or defend a legal claim. Not on an informal request. |
| A buyer of the business | If BrideHub is ever sold or merged, on condition that the buyer is bound to protect it exactly as this notice says. |
We do not sell your personal information. We do not rent it, share it for anybody else's advertising, or hand it to a data broker. There is no arrangement of that kind and there is not going to be one.
7. Where it is kept
Outside South Africa, and we would rather tell you than have you find out.
| Germany — Frankfurt | The database and every file you upload. There is no South African region available from our hosting provider; if one becomes available we will move and say so. |
|---|---|
| Ireland | Service email — password resets, RSVP notifications and the like. |
| Wherever you are | Pages and images are served from the point nearest whoever is looking, which is why the service is quick in Cape Town and quick in London. |
POPIA section 72 allows a transfer out of the Republic where the receiving country's law upholds principles substantially similar to POPIA, or where there is a binding agreement that does. Germany and Ireland are both in the European Union and subject to the GDPR. We hold written agreements with each provider, and we satisfy ourselves that section 72 is met before we appoint one.
If you travel, you will necessarily reach your own wedding from wherever you are. That is you moving, not us transferring.
8. How long we keep it
Not forever. POPIA section 14 says personal information goes when the reason for holding it has gone, and a wedding that happened years ago is exactly that.
| A wedding with a date | Deleted one year after the wedding day. |
|---|---|
| If you want longer | Extend by another twelve months from your account, as often as you like. Each extension resets the clock. |
| No date set, or the account is abandoned | Deleted one year after you last signed in. Signing in resets the year. |
| If you want it gone sooner | Delete it yourself, any time, no reason needed. |
| Before anything is deleted | We write to you sixty days before, fourteen days before, and on the morning of the day itself. Every one of those carries two links: one that adds another year in a single press, and one that takes you to the download — the whole wedding as a single file, your photos at the size you uploaded them, your guest list and budget as spreadsheets, and everything else on one readable page. It is yours to keep, and it needs nothing from us to open. The download asks you to sign in first, because it is your whole wedding and an emailed link can be forwarded. |
| If the warning does not reach you | Nothing is deleted. The rule is built so that an account is only ever removed once its last warning has actually gone out — if our email is failing, weddings sit where they are and we are shown that something is wrong. Holding your information a little longer than we meant to is a small fault; deleting it without the warning we promised is not. |
| Accounting and tax records | Kept for the five to seven years the law requires, whatever else this table says. |
| Once it is deleted | Gone from the live service that day. Encrypted backup copies expire within thirty days. After that not even we can bring it back, which is the point of deleting something properly. |
| What survives, if you close it yourself | Nothing. No line, no record, no address. You asked us to go away and we have. |
| What survives, if we removed it | One line in our own administration log: the date, that an account was removed, why, and the email address it belonged to. Nothing of the wedding itself. We keep that because it is the record that we did what we said we would — it is what we would show you, or the Information Regulator, if anybody ever asked whether a deletion actually happened. Section 14 of POPIA allows a record kept for a purpose like that one. |
9. How it is kept safe, and how we keep ourselves honest
POPIA section 19 asks for appropriate and reasonable measures. Ours:
- Everything between your device and the service is encrypted with current TLS, and an insecure connection is refused rather than downgraded.
- Stored data and backups are encrypted at rest.
- Passwords are stored only as salted one-way hashes.
- The rules about who may see what are enforced by the database itself, not by the app asking nicely. A couple can reach their own wedding and nothing else, and that is true even if somebody finds a fault in the website.
- Documents you upload sit in private storage and are reachable only through a link that we generate for you and that expires within minutes.
- Written agreements with every provider, obliging each to keep the information secure and to tell us at once if anything goes wrong.
What our own staff can see. Day to day, nobody at BrideHub can read your wedding. Our administration screen shows counts — how many guests, how many photos, how much space — and never a guest's name or a figure from your budget. To look inside one account we have to open it deliberately, type a reason first, and it closes itself after thirty minutes. Every one of those is written into a log that records who looked, when, at whose account and why — and that log is built so that nobody signed in to BrideHub can edit a line of it or delete one, including us. A record the operator can quietly tidy is not a record of anything.
If something does go wrong. If there are reasonable grounds to believe your personal information has been accessed or taken by somebody who should not have it, POPIA section 22 requires us to notify the Information Regulator and you. We will, as soon as reasonably possible, in writing, telling you what happened, what it means for you and what to do about it. We will not wait until we have a tidy story.
10. Cookies, and what this site does not do
BrideHub sets no advertising cookies and no tracking cookies. There is no analytics company, no advertising pixel, no social media tracker and no data broker anywhere in it. We have not given you a banner to click away because there is nothing to consent to.
What the service does keep, in your own browser's storage and nowhere else:
| Your sign-in session | So you are not asked for your password on every page. Cleared when you sign out. |
|---|---|
| Which screen you were last on | So the app opens where you left it. |
| If you are a guest: a random string | Invented by your own browser so you can undo a gift you claimed by mistake, or remove a photo you have just uploaded. It is not a name, an email or an account, and nobody — including the couple — can turn it back into a person. |
Our providers' server logs record internet addresses in the ordinary way. We do not combine those with anything to build a profile of you.
11. If you publish a wedding website or open an album
Both are optional, both are off until you switch them on, and both do exactly what they say.
- A published wedding website is on the public internet. Anybody with the address can read it. We ask search engines not to index it, but a request is not a guarantee, and anybody you send the link to can send it on.
- A guest album photo can be opened by anybody who has the exact link to that photo. The addresses are long and unguessable, and the album itself can be hidden — but hiding the album is not a lock on each picture. Nothing genuinely private belongs in there, and we say so on the screen as well as here.
- What you put in about other people is your responsibility. If you type a guest's name, their dietary requirement or their child's name, you are the one who decided to. Tell your guests what you are doing — a line on your invitation is enough — and do not record more about somebody than the wedding actually needs.
12. Your rights, and how to use them
POPIA gives you these. Using one costs nothing and we do not ask why.
| To know what we hold | Section 23. Ask, and we will tell you, and give you a copy. |
|---|---|
| To correct it | Section 24. Most of it you can simply edit yourself. |
| To have it deleted | Section 24. You can delete your whole account yourself from inside the app, without asking us. |
| To take it with you | One button on your profile, marked Download everything. It gives you a single file: your photos at the size you uploaded them, your guest list and budget as spreadsheets, and one page with the rest of it on. Nothing in it needs BrideHub to open, and nothing in it stops working if you close your account. |
| To object | Section 11(3). If you object to processing we base on legitimate interests, we stop unless there is a lawful reason we may not. |
| To withdraw consent | Section 11(2). Unpublish the website, close the album, stop the emails. Withdrawing it does not undo what was lawful before. |
| Not to be marketed at electronically | Section 69. We send service email because you have an account with us. We do not send marketing email, and if that ever changes it will be something you switch on rather than something you have to switch off. |
| To complain | Section 13. |
How. Write to . We answer within 30 days. For a formal access request under PAIA there is a prescribed form (Form 2), and our PAIA Manual explains it — but you do not need a form to ask us a question, and we would rather you just asked. We may need to check you are who you say you are before handing over somebody's wedding, which is a protection for you rather than an obstacle.
13. If we get it wrong
Tell us first, at . If we do not fix it, you have every right to go to the Regulator, and you do not need our permission or our agreement to do so.
Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
P.O. Box 31533, Braamfontein, Johannesburg, 2017
Telephone 010 023 5200 · Toll free 0800 017 160
enquiries@inforegulator.org.za ·
inforegulator.org.za
14. If this notice changes
We will put the new version here with a new version number and date. If the change actually affects what happens to your information — as opposed to fixing a comma — we will tell you by email and ask you to read it before you carry on using the service. We will not change what we do with information we already hold, and then tell you afterwards.