Privacy Policy
Effective date: 14 July 2026 · Version: 1.1
Wedder helps couples plan their wedding — build a public wedding website and RSVP page, manage a guest list, plan seating, create a gift registry, and email guests. This Privacy Policy explains what personal data we process, why, and the rights you have under the GDPR (Regulation (EU) 2016/679). It applies alongside our Terms of Service and our Data Processing Agreement.
1. Who we are (the controller)
Wedder is operated by Maciej Besler, a sole proprietor (jednoosobowa działalność gospodarcza, "JDG") established in Poland, trading as "Wedder."
- Address: Poznań, Poland
- NIP / VAT: PL7772880973
- Contact: admin@wedder.eu
- Website: wedder.eu
For account and analytics data we are the data controller. For the guest data a couple enters, the couple is the controller and Wedder acts as a processor on their behalf (see our Data Processing Agreement).
2. What we process
- Account holders (the buyer and their partner): name, email, hashed password (via our authentication provider — we never see your plaintext password), profile locale, an optional avatar, and purchase / code-redemption records.
- Wedding content the couple uploads: photos and written content, stored in the EU. We do not host guest photo or video uploads — those are external links only. Gift-registry images are hot-linked from the source shop and are not copied onto our servers.
- Guest data (entered by the couple, or by the guest at RSVP): name, email, phone, language, RSVP status and plus-ones. Dietary or allergy information is collected only with the guest's explicit consent at the point of entry; without that consent, the fields stay empty. Guests do not create an account — they use a private, signed link.
- Payments: handled entirely by our Merchant of Record (Lemon Squeezy) or the relevant marketplace. We do not receive or store card or payment details.
3. Why we process it, and our legal bases
- To create and operate your account and provide the service you bought — Art. 6(1)(b) (contract).
- To host and display your wedding website, RSVP, seating and registry, and to send the emails you choose to send to your guests — Art. 6(1)(b), and processed on the couple's behalf for guest data.
- To collect a guest's dietary or allergy information, where the guest chooses to give it — Art. 9(2)(a) explicit consent.
- To keep the service secure, prevent abuse, and understand how the product is used — Art. 6(1)(f) (legitimate interest).
- To meet tax, accounting and other legal obligations — Art. 6(1)(c).
4. Cookies and analytics
We use only strictly necessary cookies — those required to log you in and keep your session secure. We do not use advertising or cross-site tracking cookies, and we do not load third-party tracking scripts. Our product analytics are collected server-side and do not set cookies in your browser or track you across other sites. Because we set no non-essential cookies, no cookie-consent banner is required.
5. Who we share data with
We use the service providers listed on our Data & GDPR page (our sub-processors). Guest and account data is hosted in the EU; where a provider is US-parented, it operates in an EU region under appropriate safeguards (its own Standard Contractual Clauses / Data Processing Agreement and, where applicable, EU-U.S. Data Privacy Framework certification). We may also disclose data where required by law or to protect rights, property or safety.
6. International transfers
Data is hosted in the EU. Some providers are US-parented, so limited transfers outside the EEA may occur; where they do, we rely on appropriate safeguards under Chapter V of the GDPR (Standard Contractual Clauses, adequacy decisions, or Data Privacy Framework certification). We do not claim that no US-headquartered company is ever involved.
7. How long we keep data
We keep your data while your account and wedding are active. After your access period ends, we may delete the associated data. You can ask us to delete your data, or to provide a copy of it, at any time by emailing admin@wedder.eu.
8. Your rights
Under the GDPR you have the rights of access, rectification, erasure, restriction, portability, objection, and to withdraw consent (which does not affect processing already carried out). To exercise any of these, email admin@wedder.eu; we handle requests directly. For guest data — where the couple is the controller — we will refer or assist your request to the couple, or act on their instructions. You may also lodge a complaint with the Polish supervisory authority (Urząd Ochrony Danych Osobowych, UODO, ul. Stawki 2, 00-193 Warsaw).
If you are in California, we do not sell your personal information; email admin@wedder.eu to exercise applicable rights. If you are in Brazil, the rights in Article 18 of the LGPD apply; contact the same address.
9. Children
Wedder is intended for adults planning a wedding and is not directed at children. In Poland, the age of digital consent is 16; we do not knowingly collect data from children below that age.
10. Security
We use technical and organisational measures including EU data residency, encryption in transit, hashed passwords, access controls, and vetted providers bound by data-processing agreements. No system is perfectly secure, but we work to protect your data and to notify you and the authorities of a personal data breach where the law requires.
11. Do we need a DPO or an EU representative?
No. A Data Protection Officer is required only for large-scale monitoring or large-scale special-category processing, which does not describe Wedder's small-scale, consent-gated activity; and an Article 27 EU representative applies only to controllers not established in the EU, whereas Wedder is established in Poland. We may revisit this as the business grows.
12. Changes
We may update this Privacy Policy from time to time. We will post the updated version here and revise the effective date; where changes are material, we will bring them to your attention.