What we collect
- Account: email, name, locale.
- Wedding data: couple names, country, phone, religion, expected size and budget.
- Planning data: events, groups, families, guests, RSVP responses, dietary needs, messages from guests, expenses, payments.
- Photos and other media you upload (stored in Cloudflare R2).
- Billing identifiers from Stripe (we never store full card numbers).
Why we collect it
To provide the service you signed up for: a wedding planning platform with a guest-facing website, RSVP tracking and budgeting. We do not sell or share your data with third parties for marketing.
Your rights (GDPR)
- Access + portability: export your account data as JSON via Account → Danger zone (your wedding, events, guests, RSVPs, expenses).
- Erasure: Account → Danger zone → "Delete my account" wipes everything immediately, cascading through related rows.
- Rectification: edit your profile from Account; edit wedding details from each wedding's Settings tab.
- Restriction / objection: email privacy@festela.app.
Sub-processors
We use the following processors, all bound by a DPA: Neon (Postgres, EU), Vercel (web hosting), Cloudflare R2 (object storage for photos), Stripe (billing), Resend (transactional email). Our standard sub-processor DPA is available at /dpa.
Retention
Audit log entries are kept for 90 days. Wedding data is kept for as long as your account is active; deletion removes it immediately.