Privacy Policy
Last updated: 1 October 2026
WeddingHome ("we," "us") provides Template and Bespoke wedding websites at weddinghome.co and its subdomains. This policy explains what personal information we collect, why, and what your rights are. It is written to comply with the Philippine Data Privacy Act of 2012 (RA 10173) and its implementing rules.
Questions or requests: hello@weddinghome.co.
Who this policy covers
We handle information about three groups of people:
- Couples — people who try, personalize or commission a wedding website.
- Guests — people whose names and replies appear on a couple's website or RSVP list.
- Visitors — anyone browsing weddinghome.co or a wedding site.
What we collect, and why
From couples. Names, contact details, wedding details (date, venues, schedule), photographs and other content you submit, style references, messages you send us, login records, and payment records (amount, date, reference — we do not store card numbers). We use these to design your website, publish and host it, run your dashboard, and invoice you.
About guests. When a guest replies on a wedding website, we store the name they enter, whether they accept or decline, the number of seats, and any message they write. When a couple adds a guest or an invitation themselves, we store the details the couple enters. We use this only to show the couple their responses and display what the couple chooses to publish (for example, an entourage list). We never use guest information for marketing and never contact guests.
Important note for couples: you are responsible for having the right to share the guest details and photographs you give us, including photos that show other people. If someone in your photos or on your lists asks us to remove their information, we will, and we will let you know.
Template drafts. We store the invitation content you edit, a browser visitor credential and save revisions before you create an account. A verified email connects your draft to a recoverable account. The editor keeps a device backup of edits, and host-only cookies provide access. Private share links give read-only access to the selected invitation and media for 14 days and can be revoked or replaced. Anyone with an active share link can view that preview; it does not grant editing access.
From visitors. Basic technical logs (IP address, browser, pages viewed) for security and troubleshooting. On weddinghome.co we use the Meta Pixel to measure our advertising; you can limit ad tracking in your browser and in your Meta settings. Wedding websites themselves are set to be excluded from search engines.
Reliability, anonymous visits and optional usage analytics
When monitoring is enabled, PostHog helps us diagnose technical failures using limited error reports, operation names, and software release information. Checkly checks availability with synthetic visits. Our error-reporting integration removes form contents, email addresses, private links, credentials, and provider response bodies before transmission. Error reports do not include photographs or guest lists.
We count visits and basic interactions on public marketing pages and editor designs using PostHog's cookieless mode before you make a choice or when you decline optional usage tracking. This includes pageviews, page leaves with time on page, button or link clicks, scroll depth, page-speed measurements, that a first edit happened (not what was edited), and whether a draft save, photo upload, verification code, checklist check, payment step or inquiry form succeeded or failed (a status code, timing or count, never the content, email address or names). PostHog calculates anonymous counts on its servers using a daily salted hash of the project, request IP address, browser user agent and website host, then strips the raw IP and user agent from those events. These daily counts cannot identify returning visitors across days. We do not send our browser journey identifier, account identity, or a browser session identifier with those visits. These events contain a public page path without query strings or fragments, referring domain, campaign labels, device category and software information, such as the operating system, whether the page is open in the Facebook or Instagram in-app browser, and screen width. Campaign labels and the referring domain are kept in the browser tab's session storage, which ends when the tab closes, so later pages in the same visit keep the ad source; they are not an identifier. They do not include invitation contents, email addresses or verification codes. Private access, checkout, shared-preview and dashboard pages are excluded from anonymous pageview counting. Supported browser privacy signals remain respected; blocked analytics requests cannot be counted.
You can choose whether to allow optional usage analytics through Usage privacy on our marketing site, editor, and dashboard. Allowing it lets us measure steps such as starting an invitation, scrolling, saving, uploading, and entering checkout. We also record masked session replays on public marketing and design editor pages so we can see where visitors get stuck. Input values, visible wedding details, photos, media, and embedded previews are hidden from those replays. We do not record replays on access, checkout, or private invitation pages. Usage events use a random journey identifier, campaign labels, public page paths, and the referring domain without its path or query. Pageview URLs omit query strings and fragments. The choice is shared across these WeddingHome applications. With your consent, the random journey identifier and attribution labels are retained in a first-party cookie for up to 30 days so a return visit or dashboard handoff can be connected. When an invitation is saved, these limited labels may also be retained with its private workspace to connect confirmed payment and publication to the earlier visit. Declining removes the journey cookie; access cookies remain separate. Internal and QA visits may retain a traffic-class cookie without a journey identifier so test sales can be excluded. You can change your choice there at any time. Refusing it does not prevent editing or payment. We also respect supported browser Do Not Track and Global Privacy Control signals for this integration. These controls govern our PostHog usage analytics; Meta advertising controls are described above.
Server payment, publication, and email-delivery records are maintained to operate the service and investigate failures. A recorded email delivery means the recipient's mail server accepted it, not that the message was read. Our selected PostHog project is hosted in the United States. Optional analytics use its configured retention period; we review access and retention as part of monitoring setup. Questions or deletion requests can be sent to hello@weddinghome.co.
AI processing
For Bespoke design concepts, the photographs and details you submit are processed by Anthropic's Claude, an AI service. This processing is for generating your designs only. Our agreement with the provider does not permit them to use your content to train their models.
Template personalization uses our existing designs and does not send your content to a design-generation AI service.
If you choose to ask WeddingHome AI a question, the question and a limited part of the current chat are sent to Anthropic’s Claude to prepare an answer using our product guide. We do not automatically attach your invitation, photographs, guest list, account records, or page access links. Please do not include private information in your messages. We remove recognized email addresses, web links, and long credential-like strings before sending, but this cannot detect every kind of personal information. The chat stays in browser memory until cleared or the page is closed; we do not save chat transcripts in our database or analytics. The provider processes these questions under its applicable API data-handling terms. We use structured responses and do not create a stored chat session with the provider. Optional usage analytics record help outcomes such as whether an answer helped, without message contents. Quick answers and external contact options remain available without sending a question to AI.
Where your data lives, and who helps us
Your data is stored on servers in Singapore (DigitalOcean) and passes through Cloudflare. Emails are delivered by Resend. Advertising measurement uses Meta. Each provider processes data only to provide its service to us. Because our servers are in Singapore, your information is stored outside the Philippines with these safeguards in place.
How long we keep things
Template free drafts remain accessible for 90 days anonymously or 180 days after email verification, renewed by successful saves. Confirmed payments awaiting first publication protect the draft. Unused uploads may be removed after 24 hours; interrupted uploads after one hour. Up to 30 selected photographs (20MB each) and one 15MB music track fit within a 200MB storage allowance.
Published Template invitations stay public for two years from first publication. Private editing and dashboard access remain available for 180 days after hosting ends. Expired drafts then become unavailable; selected media is scheduled for removal after a further 30 days. Removal requests for personal information can be made through the contact below. Retained published versions protect their referenced media while the account remains available.
Bespoke hosting and data follow the period included in your package (two years unless agreed otherwise), with the existing 90-day post-hosting deletion period. Export your RSVP list while dashboard access is available. We retain basic invoice, payment and correspondence records as required for business, tax and accounting purposes. Encrypted backups follow their normal retention cycle.
Your rights
Under the Data Privacy Act you may ask us to: tell you what information we hold about you, correct it, delete it, give you a copy, or stop a particular use. Guests have these rights too — if your name appears on a wedding site and you want it removed, email us and we will handle it. Write to hello@weddinghome.co; we respond within 15 business days. You may also complain to the National Privacy Commission (privacy.gov.ph).
Security
Access to your data is limited and protected by encrypted connections, hashed credentials, and two-factor authentication on administrative access. Backups are encrypted. No system is perfectly secure; if a breach affects you, we will notify you and the National Privacy Commission as the law requires.
Changes
If we change this policy in a way that matters, we will note it here with a new date, and tell active clients by email.