Privacy policy
We collect only what we need to help you plan your wedding. Nothing more, and we never sell your data for money. Our data is hosted in Europe (payment is handled by Link, which may transfer data outside the European Union).
1. Data controller
The controller of your personal data is:
- EI Meidy BAFFOU
- 58 rue de Monceau, 75008 Paris, France
- SIRET (French business registration number): 804 732 683 00052
- Contact: contact@makeitglobal-agency.com
We have not appointed a data protection officer (DPO), because our processing does not reach the thresholds of Article 37 of the GDPR.
We are established in France, so the GDPR applies to the processing described here whatever your country of residence, and the French authority, the CNIL, is our lead supervisory authority. Where the laws of the United Kingdom or of a US state also apply to you, section 10 explains how.
2. Data we collect
a) Data collected in the personalization questionnaire (steps 1 to 8)
During the first eight steps of the personalization questionnaire, before you enter your email address, we collect the following information as pre-contractual measures (Art. 6(1)(b) GDPR):
- The couple’s first names and, if you give them, your last names and your children’s first names (to create your household in the guest list)
- Planned wedding date
- Location of the ceremony or reception (city, state or region, or address; the geographic coordinates are calculated from the address)
- Estimated number of guests
- Estimated maximum budget
- Type of wedding (civil, religious, non-religious, and so on)
- Key moments you plan for the wedding (chosen from a closed list of suggestions, such as a civil ceremony, a religious ceremony, a non-religious ceremony, cocktail hour, dinner, dancing, or a brunch, plus up to 5 additions in free text of 60 characters maximum). Some suggestions are ticked by default depending on the type of wedding you indicate above; each suggestion can be changed. “Religious ceremony” only repeats, as an event title, the religious wedding type already given above (it is not a new category of sensitive data), and this choice stays separate from the religious or philosophical belief below, which is the only item subject to your explicit consent. These key moments become the titles of the events of your wedding in your space, including for your guests’ answers (see sections 2.b and 2.d).
- Religious or philosophical belief (optional; processing based on your explicit consent, Art. 9(2)(a) GDPR; you can leave this field empty with no effect on the service)
- Your 3 priorities for organizing the wedding (chosen from a closed list of 11 suggestions: the venue, food and drinks, flowers and decoration, music and party, photos and video, and so on)
For security and to prevent automated submissions, we also record the IP address, the browser type (user agent), and the UTM parameters tied to the session. This data is processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) and is not used for advertising.
Separately from this session data, your arrival on the home page is recorded in a distinct, minimal way for audience measurement (click rate, acquisition source): IP address truncated at collection (never the full address), user agent, referring page, and, where applicable, an advertising click identifier (gclid). This data is anonymized no later than 13 months after your visit, whether or not the visit led to an account being created (retention details in section 6, related cookie in section 5).
If the questionnaire leads neither to an account nor to a payment, this provisional data is anonymized automatically no later than 31 days after the start of the questionnaire (not after your last visit: this period is never extended). It is not deleted, but made non-identifying in our database. If the journey reached the payment page without a payment, it is instead deleted entirely, within the same period.
The following is then erased: email, first names, last names and children’s first names, wedding date, venue (name, address, postal code, and geographic coordinates), religious belief, any key moment added in free text, IP address, user agent, referring page, advertising click identifiers (utm_content, utm_term), the timestamp of your consent, the pre-computed content of your space, the identifier of any scheduled reminder, and the technical token that identified your journey (replaced with a random value); your consent choices (marketing communications, waiver of the withdrawal period) are reset to “no”. On the record of your home page visit linked to this questionnaire, the IP address, user agent, referring page, Google Ads click identifier (gclid), and advertising click identifiers are erased in the same way, and the visit cookie identifier is replaced with a random value; that record is no longer linked to the questionnaire. If an abandoned payment attempt had been recorded in our technical logs, the email and the session identifiers it contained are erased in the same way.
The following is kept, for statistical purposes only and in a way that cannot identify you: the step reached in the questionnaire, the start date of the questionnaire and the dates of its key steps (end of the questionnaire, email entry), the dates of the home page visit, the acquisition source (utm_source, utm_medium, utm_campaign), the language, the state or region, the estimated number of guests, the estimated budget, the wedding type or types selected, the key moments selected from the closed catalog (excluding any free-text addition, erased above), and the 3 priorities chosen, as well as a technical flag showing whether the questionnaire was filled in from an app’s built-in browser (computed before the user agent is erased).
If the questionnaire leads to the creation of an account (see section 2.b), this data is not anonymized: it is kept with your account, including the IP address and user agent collected during the questionnaire, for the periods described in section 6.
b) Creation of the trial account, step 9 (email entry)
At step 9 of the questionnaire, you enter your email address. As soon as you complete this step, we immediately create:
- A user account (an entry in the Supabase authentication database, with no password: access is by magic link)
- A pre-filled planning space(an event with the data entered in the earlier steps: first names, date, venue, budget, wedding type; the key moments you chose, which become events in your space and are visible to your guests when they reply on the wedding website; your 3 priorities; a starter set of tasks, budget lines, and timeline steps, and up to 2 guests representing the couple, grouped together as the couple’s family)
A login link (an evergreen magic link) is sent immediately to the address you entered, giving access to the planning space in trial mode (all features are available, with quantity caps on some resources: guests, vendors, budget lines, and tasks; the photo gallery, publication of the public wedding website, and the public sharing link for the seating chart are reserved for accounts that have completed payment). Payment does not create new data by default: it lifts these caps and opens these three features.
This processing is based on pre-contractual measures and performance of the contract (Art. 6(1)(b) GDPR): creating the account and sending the login link are necessary to give you access to the service you asked for.
If you used a login email address different from the one you gave Stripe at payment (the billing email), the two addresses may coexist in our systems. The billing email is processed by Stripe for the payment confirmation; the login email is your identifier on MyWedding Planner. Both addresses are kept for the periods described in section 6.
c) Account data (you, the organizer)
- Email address (login identifier, used for the magic link)
- First names and, where applicable, last names of the couple, your children’s first names, wedding date, venue (address and geographic coordinates)
- Preferences entered in the questionnaire (budget, number of guests, wedding types, key moments, priorities)
- Technical identifiers (Supabase ID, Stripe session ID in case of payment)
- Account status: trial mode (
trial) or paid account (paid) - Date of first access after payment (where applicable), used for invoicing
d) Data you enter about your guests
When you add guests to your event, you may give us their first name, last name, email, phone number, allergies, choice of sub-events, and plus-one. You are the controller of this data towards your guests, and we act as a processor for this account. You must make sure you have a legal basis (for example consent, or performance of the invitation) to collect it and pass it to us.
e) Data entered by your guests through the wedding website
- RSVP answers (attendance, dietary restrictions, message)
- Photos and an optional author name when the collaborative gallery is open
f) Technical data (automatic)
- IP address truncated at collection for home page audience measurement (never the full address; see sections 5 and 6)
- Full IP address, collected during the personalization questionnaire for security (see section 2.a)
- Browser type and operating system
- Anonymous view counter for the wedding website (no individual identification)
g) Payment data
Payments (a one-time payment per event for couples, a monthly subscription for MyWedding Pro, at the prices in force shown in the terms of sale) go through Stripe Managed Payments: payment is processed by Link (shown as “Sold through Link, LLC”), a Stripe service that collects payment on our behalf. Link directly collects and processes your payment data (name, email address, billing address, country, payment method, transaction data, connection data) as an independent controller (section 7). We neither receive nor store any card number.
Through the payment confirmation webhook, we receive and keep:
- The Stripe session identifier and the payment identifier (accounting reconciliation)
- The email address entered at payment
- The amount paid, its currency (euro or US dollar), and the tax included in that amount
- The payment mode (direct or through Link) and, when Stripe passes it to us, the billing country
This data is kept for ten (10) years to meet French accounting obligations (Art. L.123-22 of the French Commercial Code). It is used only for invoicing and accounting reconciliation. Link keeps its own data under its own privacy policy.
h) Professional accounts (wedding planners) and the projects they manage
Some accounts are created by wedding professionals who subscribe to our professional offer MyWedding Pro. For these accounts, we collect the name of the business or the professional, a professional email address, and the business registration number where it is given (for a sole trader, that number can identify an individual: it is then personal data and is treated as such). We process this professional account data as controller, on the same terms as the other account data described in section 2.c.
A wedding planner can create, for their own clients, wedding projects containing the data covered by sections 2.d and 2.e above (information about the couple, their guests, their RSVP answers, the budget, the seating chart, gallery photos). For that data, the wedding planner is the controller towards their own clients (the couple and their guests), and we act as a processor on their behalf, within the meaning of Article 28 of the GDPR. The precise terms of this processing relationship (duration, nature and purpose of the processing, security obligations, sub-processors, assistance, breach notification, fate of the data at the end of the contract, audit rights) are set out in the data processing agreement annexed to the terms of sale of MyWedding Pro. The couple and their guests keep, in every case, all the rights described in section 9 of this policy; they can exercise them directly with their wedding planner (the controller of their data) or with us at the address given in section 9, and we will pass the request on if needed.
i) B2B prospecting data (wedding planners we contact)
As part of developing our professional offer MyWedding Pro, we build a database of wedding planners based in France who may be interested, from public sources: the business name, the first name where it can be identified, a professional email address (generic or personal), the website, the city. This data is collected through the Google Places API and then, where applicable, from the public pages of the professional’s website (legal notice, contact page). It is stored in our internal prospecting database (table pro_prospects), with the status, the history of messages sent and answers received, and any objection.
This processing is based on our legitimate interestin developing our professional clientele (Art. 6(1)(f) GDPR). French law (Article L. 34-5 of the Postal and Electronic Communications Code) in principle requires prior consent for email prospecting; the CNIL accepts, however, that prospecting aimed at a professional can rely on legitimate interest when the message relates to their profession, provided they are informed and can object simply. We rely on that position: messages are sent to a professional address, directly related to the recipient’s activity as a wedding planner, and every email includes a simple, free way to object. No data from existing couple accounts (in particular the “helpers” they enter) is used for this purpose. A wedding planner we contact can exercise all the rights described in section 9, including by replying “STOP” to the email they received. Contact details of professionals who have not replied are kept for 3 years from the last contact (see section 6); those of professionals who asked not to be contacted again are kept without time limit in a suppression list, solely to avoid contacting them again.
j) Bank details (IBAN) published at your initiative on the wedding website
In the “gifts” section of your wedding website, you can choose to enter an IBAN and the account holder’s name so that your guests can send you a transfer. This field is optional. If you fill it in, the IBAN and the holder’s name are published on your wedding website and visible to anyone with the link, even if the wedding website is not indexed by search engines. This is also reminded to you in the editor, when you enter it.
We only check that the IBAN entered is well formed (format and check digits); we do not check that it matches the right account, or who holds it: this entry is your responsibility, like the other content you publish on your wedding website (see the terms of sale, Article 8). We store no other bank data: no card number, and no credentials for your bank.
k) Display currency of the price (country inferred from the IP address)
To show the price in the right currency (the euro in Europe, the US dollar elsewhere, including the United Kingdom), our server reads the country associated with your IP address, supplied by our host (the x-vercel-ip-country header added by Vercel). This reading is instantaneous: to display the price, we keep neither the IP address nor the country. Only two traces remain: a mwp_curcookie, which contains only the currency (“eur” or “usd”) and lasts 1 day (see section 5), and the currency chosen for your account when it was created, kept with the account because it determines the amount you pay. The country read in the same way is also used to pick the rule of the cookie banner and is recorded with your choice (see section 5.e).
This processing is based on our legitimate interest (Art. 6(1)(f) GDPR): showing a clear price in the currency that will actually be charged.
3. Purposes of the processing
- Create your account and your pre-filled planning space as soon as you enter your email at step 9 of the questionnaire (pre-contractual measures, Art. 6(1)(b) GDPR)
- Send you the login link (magic link) immediately after the account is created, so you can reach your space in trial mode without delay (performance of the contract and pre-contractual measures, Art. 6(1)(b) GDPR)
- Provide the service in trial mode and, where applicable, with full access after payment (creating and managing your event, wedding website, RSVP, seating chart, and so on)
- Communicate with you (account access email, payment confirmation, support)
- Deliver your wedding website to the recipients you invite (full access only after payment)
- Handle invoicing, technical security, and fraud prevention
- Improve the service (from aggregated, anonymized technical logs)
- Analyze browsing behavior in the sign-up funnel to identify UX friction and improve the conversion rate (with your consent in the European Union, the European Economic Area, the United Kingdom, and Switzerland; elsewhere, legitimate interest, Art. 6(1)(f) GDPR, with the possibility to reject at any time; see section 5)
- Measure the conversions of our advertising campaigns (pixels and sendings from our servers) and optimize them, under the same choice rules as audience measurement (see section 5.e)
- Record your choice about cookies, apply it, and be able to prove it (see section 5.e)
- Manage the professional accounts of our MyWedding Pro offer (creating the wedding planner’s account, managing their subscription, providing the wedding projects they manage) and provide the service for their own clients (performance of the contract, Art. 6(1)(b) GDPR)
- Build a database of professional wedding planners and offer them MyWedding Pro by email, in compliance with Article L. 34-5 of the French Postal and Electronic Communications Code (legitimate interest, Art. 6(1)(f) GDPR; see section 2.i)
4. Legal bases
In this policy, references to the GDPR also cover the UK GDPR for people in the United Kingdom (section 10).
- Pre-contractual measures / performance of the contract(Art. 6(1)(b) GDPR): collecting data in the questionnaire (email, couple’s first and last names, children’s first names, date, venue, number of guests, budget, wedding type, key moments, priorities); creating the user account and the planning space at step 9; sending the login link (the trial-account-ready email) immediately after the account is created.
- Performance of the contract (Art. 6(1)(b) GDPR): managing the account after payment, providing the service with full access, processing the payment (including passing to Link the information needed for payment), sending the payment confirmation.
- Explicit consent (Art. 9(2)(a) GDPR): processing of religious or philosophical belief, sensitive data under Article 9 of the GDPR, collected only if you ticked the optional box provided for that purpose in the questionnaire.
- Consent(Art. 6(1)(a)): publication on the wedding website (including, where applicable, the IBAN and the holder’s name entered in the gifts section), opening the collaborative photo gallery.
- Legitimate interest (Art. 6(1)(f)): technical security, fraud prevention, aggregated improvement of the service, short-lived processing of the IP address to limit automated submissions, keeping the proof of your choice about cookies (Art. 7(1) GDPR).
- Consent(Art. 6(1)(a) GDPR, and Article 82 of the French Data Protection Act for trackers) in the European Union, the European Economic Area, the United Kingdom, and Switzerland: audience measurement (PostHog, Google Analytics, home page visit measurement; see sections 5, 7, and 8), advertising measurement (Google, Meta, and TikTok pixels, conversions sent by our servers; see sections 5 and 7), and the Google Maps map embedded in the wedding website. You can withdraw this consent at any time with “Manage cookies”.
- Legitimate interest, with the possibility to reject at any time(Art. 6(1)(f) GDPR) in the rest of the world: the same processing, active from your arrival until you reject it with “Reject” or “Manage cookies” (right to object, Art. 21 GDPR).
- Legitimate interest (Art. 6(1)(f) GDPR): keeping, for 12 months, the send log and the clicks of the former activation email sequence (discontinued on September 30, 2026), so we can show what was sent; keeping the email suppression list without time limit, to respect your right to object (Art. 21 GDPR) to emails that are not essential to the service on a lasting basis. You can exercise this right through the unsubscribe link in the email that contains your login link, independently of deleting your account (see section 9).
- Legitimate interest, B2B prospecting(Art. 6(1)(f) GDPR, in light of Article L. 34-5 of the French Postal and Electronic Communications Code and the CNIL’s position on prospecting between professionals, see section 2.i): emailing professional wedding planners in France at their professional address, in connection with their activity, with a simple, free way to object in every message
- Legitimate interest (Art. 6(1)(f) GDPR): inferring the display currency of the price from the country of your IP address (see sections 2.k and 5).
- Legal obligation (Art. 6(1)(c)): keeping accounting and invoicing data as required by the French Commercial Code.
5. Cookies, trackers, and your choice
On your first visit, a banner lets you choose about the cookies and trackers that are not essential to the service. The rule depends on the country you are in, which our host infers from your IP address:
- European Union, European Economic Area, United Kingdom, and Switzerland: prior consent. No audience measurement or advertising tracker is set, and no script from those services is loaded, until you click “Accept” or switch on a category under “Customize”. “Reject” is as visible and as easy as “Accept”. If we cannot determine your country, this rule applies.
- Rest of the world: opt-out.Audience measurement and advertising trackers are active as soon as you arrive. The banner tells you so, and “Reject” switches them off right away.
In both cases the choice covers three categories: necessary cookies (always on), audience measurement, and advertising. It applies to the browser you are using and is remembered for 6 months in the prior-consent zone and 12 months elsewhere, after which the banner asks again.
a) Necessary (always on, exempt from consent)
They make the service you ask for work and are used neither for audience measurement nor for advertising (Article 82 of the French Data Protection Act):
sb-*-auth-token(Supabase): signing in to your account, up to 400 days, renewed at every signed-in visit.mwp_funnel_token: resuming the personalization questionnaire, 30 days.mwp_email_proof: proof that the login link was received by email, 15 minutes.mwp_active_event: the wedding shown in the signed-in space (useful if you follow several), 1 year.NEXT_LOCALE: the language you chose, for the length of the session.mwp_consent: remembers your choice about cookies (6 or 12 months, see above).mwp_region: which cookie rule applies to you (“optin” for prior consent, “optout” for the right to object), inferred from the country of your IP address, 1 day. It contains no identifier.mwp_cur(1 day), set when you arrive on the site. It contains only the currency of the price displayed (“eur” or “usd”), inferred from the country of your IP address (section 2.k), so that public pages show the price in the currency that will be charged. It contains no identifier, is not linked to any other data, is not set for search-engine crawlers, and is used neither for audience measurement nor for advertising. We consider it strictly necessary to show the price you are looking at and, as such, exempt from consent. This characterization has not been formally validated by counsel or by the CNIL.- Browser local storage (
localStorage,sessionStorage): a local copy of your questionnaire answers, the language you already declined when we suggested a switch, the paper size chosen for printing, a dismissed activation card, the name you enter to upload photos on a wedding website, and a flag that avoids counting the same wedding website view several times in the same tab. None of this is sent to a measurement or advertising service. - Payment: Stripe and Link set their own cookies on their payment pages, outside our site; see their policies (section 7).
b) Audience measurement (subject to your choice)
It helps us understand what works and what gets stuck on the site, with no advertising targeting:
- PostHog (
ph_*, cookie and local storage, 365 days): a persistent identifier links the page views, clicks, and session recordings of one browser, and can be tied to your email address once your account is created. The text shown and what you type are masked in the recordings (see sections 7 and 8). - Google Analytics 4 (
_ga,_ga_*, 13 months): page views and journeys. - Home page visit measurement (
mwp_landing_session, httpOnly, 90 days): links the visit to any draft of the questionnaire, then to an account, for our funnel statistics (click rate, questionnaire start rate, acquisition source, Google Ads click identifier). IP address truncated at collection, anonymized at 13 months (section 6). It is not used for any advertising targeting. - Anti-duplicate flags in local storage (
mwp_first_resource_*,mwp_trial_started_*): they avoid sending the same event twice.
We do not rely on the audience measurement exemption from consent for PostHog (individual sessions, which can be tied to an email address) or for mwp_landing_session (it links the visit to an account and keeps the advertising origin of the visit): these trackers are subject to your choice.
c) Advertising (subject to your choice)
It measures the conversions of our campaigns (sign-up, first use of the product, payment) and helps us optimize them, nothing else:
- Google Ads (gtag tag):
_gcl_au,_gcl_aw(90 days) and, depending on how our Google Ads account is set up, Google cookies on thedoubleclick.netdomain. - Meta pixel:
_fbp,_fbc(90 days). - TikTok pixel:
_ttp,ttclid(up to 13 months). - Anti-duplicate flags in local storage (
mwp_lead_activated_*,mwp_purchase_tracked_*).
These services may also write to the browser’s local storage; the exact list and the durations are those of their publishers (see section 7).
d) Google Consent Mode v2
Google’s tags follow your choice: the analytics_storage signal matches audience measurement; ad_storage, ad_user_data, and ad_personalizationmatch advertising. In the prior-consent zone they are denied by default and the Google tag is loaded only after you agree. Elsewhere they are granted by default and switch to “denied” as soon as you reject.
e) Conversions sent by our servers, and recording your choice
When your couple starts using the product on trial and when you pay, our servers may tell Meta (Conversions API) and TikTok (Events API) about the conversion, with a hashed email address and, depending on the case, cookie identifiers, the IP address, and the browser (see section 7). This sending follows your “Advertising” choice: in the prior-consent zone, nothing is sent without your agreement; elsewhere, nothing is sent if you have rejected.
To apply your choice on the server side and to be able to prove it, we record it with your questionnaire, then with your account: your advertising choice (accepted or rejected), its date, and the zone that applies (Europe or the rest of the world, inferred from your IP address; the country itself is not stored). The record is deleted with the questionnaire or the account (see section 6).
f) Google Maps map on the wedding website
A wedding website can show a Google Maps map. When it is shown, Google receives the visitor’s IP address and browser and may set its own cookies. In the prior-consent zone, the map is loaded only after a click on “Show the map”, and without that click a link opens Google Maps in a new tab. Elsewhere it is shown directly.
g) Where trackers are not loaded
Google Analytics, Google Ads, and the Meta and TikTok pixels are not loaded on projects managed by a wedding planner (signed-in space and public wedding website), nor on pages reached through a personal link (a guest’s reply, a shared plan, an invitation, a login link), nor on the administration area. PostHog is active across the whole site, including projects managed by a wedding planner, except on the administration area and on pages reached through a personal link. Sentry (technical error tracking, with no session recording) sets no cookie; see section 7.
h) Changing your choice
The “Manage cookies” link, in the footer of the public pages and in the application’s settings, reopens the choice at any time, as easily as it was given. Withdrawing an agreement stops the trackers concerned and, for conversions sent by our servers, applies to later sendings. Rejecting has no effect on what you can do on the site, or on the price. You can also block trackers in your browser settings, or write to us at the address in section 9.
6. Retention periods
- Questionnaire that led neither to an account nor to a payment: automatic anonymization, or deletion if the journey reached the payment page, no later than 31 days after the start of the questionnaire (a period never extended, including if the questionnaire is resumed). The detail of what is erased and what is kept for statistics is in section 2.a.
- Questionnaire that led to an account (email step completed): the answers to the questionnaire, including the IP address and user agent collected while it was filled in, are not anonymized: they are kept with your account, for the periods in the next two bullets (trial mode or paid account).
- Trial mode account not converted to a paid account: 12 months from the last login. If no activity is recorded during that period, the account and all the associated data (planning space, tasks, budget, timeline, guests) may be deleted. You can ask at any time for early deletion of your account and data through the contact address (see section 9).
- Paid account and associated event:for as long as your account exists. Access to the Service is granted with no time limit after payment (“lifetime access”). You can ask at any time for your account and all your data to be deleted through the contact address (see section 9).
- Guest data: kept for as long as your account exists; deleted when the account is deleted.
- MyWedding Pro professional account and the wedding projects it manages: kept for as long as the professional account exists. If the subscription is canceled, the projects switch to read-only (nothing is deleted, and wedding websites already published stay published for guests). Unlike a Couple Plan account, deleting a professional account is not offered as self-servicein the application: because a professional account owns projects that belong to its own clients (the couples), we handle its deletion manually, on written request, to avoid any accidental loss of those third parties’ data. The wedding planner can ask for the export or permanent deletion of their account and the associated projects by writing to us (see section 9); see also the data processing agreement annexed to the terms of sale of MyWedding Pro.
- Collaborative gallery photos: until you delete the gallery or your account.
- IBAN and holder’s name (gifts section of the wedding website): kept and published for as long as you leave them in the editor; deleted as soon as you empty the field, or when your account is deleted, according to the periods above.
- Technical logs: 12 months maximum.
- Choice about cookies: the
mwp_consentcookie lasts 6 months in the European Union, the European Economic Area, the United Kingdom, and Switzerland, and 12 months elsewhere. The record of your choice (advertising accepted or rejected, date, zone) is kept with your questionnaire, then with your account, and deleted with them. - Home page visits (audience measurement): the identifying data of your visit (truncated IP address, user agent, referring page, Google Ads click identifier
gclid,utm_content, andutm_term) is anonymized automatically 13 months after it was recorded, and the visit cookie identifier is replaced with a random value: this period applies whether or not the visit led to an account. If it is linked to a questionnaire that led neither to an account nor to a payment, it is anonymized earlier, together with that draft (see section 2.a, 31 days at the latest); when your account, or your questionnaire at your request, is deleted, it is anonymized immediately. The following are kept, for statistical purposes only and with no time limit: the date of the visit, the click on the call-to-action button, the start of the questionnaire, the sourcesutm_source,utm_medium, andutm_campaign, and a flag, fixed before thegclidis erased, showing whether the visit came from a Google Ads advertisement. If your questionnaire led to an account, the statistical link between your visit and that account (with no IP address or click identifier) is kept for as long as the account exists. - Technical log of payment incidents:kept 12 months, except duplicate payments (two successful payments recorded for the same wedding), which are kept for as long as the account concerned exists: if one of the two payments is refunded, this trace lets us link it to the right wedding and correctly decide whether to keep or withdraw access. This log may contain Stripe technical identifiers, the questionnaire token, the internal identifier of the wedding and, if the email in the questionnaire and the one used for payment do not match, both addresses. When your account, or your questionnaire at your request, is deleted, the entries about you (including any duplicate payments) are deleted immediately, except a payment inconsistency report that also concerns another person’s wedding: it is kept until its 12-month term ends, for payment security and the defense of our rights.
- Send logs of the former activation email sequence, discontinued on September 30, 2026 (
email_sequence_log): 12 months from sending, then automatic deletion. - Click logs on those emails (
email_sequence_click): 12 months from the click, then automatic deletion. - Email suppression list (
email_suppression): kept with no time limit, so your objection is respected on a lasting basis, even if you later sign up again. Your address is added to it if you click an unsubscribe link, if our sending provider reports a permanent bounce or a spam complaint, or if your account is deleted. This list never prevents your login link or the emails necessary to the service from being sent. You can ask for your address to be removed from this list at any time (see section 9): your objection will then no longer be recorded. - Professional prospects (table
pro_prospects) with no reply: 3 years from the last contact. Prospects who asked not to be contacted again: kept with no time limit in a dedicated suppression list. - PostHog analytics data (browsing events, page views, custom events): 12 months from collection.
- PostHog session recordings: 1 month from recording.
- Invoicing data: 10 years (accounting obligation, Art. L.123-22 of the French Commercial Code).
- Currency cookie
mwp_cur: 1 day. The currency chosen for your account is kept for as long as the account exists. - Payment data held by Link:according to Link’s privacy policy (see section 7), whose retention periods we do not control.
- Support requests: 3 years from the last exchange.
7. Processors and recipients
We do not sell your personal data for money. We share it only with the following technical processors and recipients, for the purposes described in this policy: running the service, measuring and optimizing our advertising, and meeting our legal obligations.
Transfers outside Europe.Several of these providers are US companies, and some process data outside the European Economic Area. Where personal data is transferred outside the European Economic Area, the transfer is covered by the standard contractual clauses adopted by the European Commission (SCCs), or by another mechanism recognized by the GDPR. For data about people in the United Kingdom, equivalent safeguards recognized by UK law apply (section 10). We host our own data in Europe where the provider allows it (Vercel in Paris, Supabase in Paris, Sentry in Germany, PostHog in the EU), which does not rule out access from the United States by a US provider’s staff.
- Vercel Inc. (United States, application hosting). Transfer covered by the standard contractual clauses adopted by the European Commission. Execution region: Europe (cdg1, Paris).
- Supabase Inc. (Singapore, database and storage). Data physically stored in Europe (Paris). Transfer covered by the standard contractual clauses.
- Stripe Payments Europe Ltd (Ireland, payment processing) and Stripe Inc. (United States, for certain technical processing). Covered by the standard contractual clauses. For payments processed by Link, see the next entry.
- Link (Stripe). When payment goes through Stripe Managed Payments, it is processed by Link (shown as “Sold through Link, LLC”), a Stripe service that collects payment on our behalf (the charge appears on your statement as “LINK.COM* WEDDING PLAN”). Link then acts as an independent controllerfor the data needed for payment, invoicing, fraud prevention, disputes, and support on the transaction: name, email address, billing address, country, payment method, transaction data, connection data (including the IP address) and, if you create one, a Link account. This data is processed under Link’s privacy policy, which sets out in particular the transfers outside the European Union (the United States in particular) and the safeguards that cover them. On our side, to create the payment session we send Stripe your email address, internal technical identifiers (event or professional account) and, for the advertising measurement described in section 5, the advertising cookie identifiers (
_fbp,_fbc,_ttp,ttclid), only if your advertising choice allows it (section 5.e); we do not send it the couple’s first names or the wedding framing information. Legal basis for our transmission: performance of the contract (Art. 6(1)(b) GDPR) and, for the advertising identifiers, your consent or, outside the prior-consent zone, our legitimate interest (section 5). You can exercise your rights over the data Link holds directly with Link (section 9). Link privacy policy. - Resend, Inc. (United States, email sending). Covered by the standard contractual clauses. Purpose: transactional emails tied to the service (magic link login link, payment confirmation, support). Data transmitted: the recipient’s email address and the content of the email. No payment data or sensitive data is sent to Resend.
- PostHog, Inc. (a US company; data hosted in Europe through PostHog EU Cloud, Amsterdam / Frankfurt region, entry point
eu.i.posthog.com). Transfer to the US parent company covered by the standard contractual clauses adopted by the European Commission (SCCs). A data processing agreement (DPA) is in force with PostHog. Purpose: behavioral analysis of the sign-up funnel and the product journey, improving the user experience, UX debugging. Data transmitted:- page views and navigation (addresses visited, duration, transitions between the steps of the questionnaire); the tokens of personal links are replaced before sending
- journey events, including:
email_collected,generate_lead,view_paywall,begin_checkout,redirect_to_stripe,purchase,trial_started,first_resource_created,tool_limit_hit,upgrade_modal_opened - clicks and form submissions, the element concerned being recorded without its text or its attributes, except the destination address of a link you click (email addresses and phone numbers are removed from it before sending)
- session recordings: page layout, pointer position, clicks, and scrolling; the text shown on screen and the input fields are masked before sending (
maskAllInputs,maskTextSelector), and the body and headers of network requests are never recorded (see section 8) - email address when you complete step 9 of the questionnaire (your email is used as a session identifier in PostHog to allow UX debugging; it is sent to PostHog through the
identifyfunction when your account is created) - IP address (received by PostHog with every send, to infer an approximate location), user agent, device type
- Google LLC(United States). Services used: Google Analytics 4 and Google Ads; the Google Places API, used for the discovery of professional prospects described in section 2.i; and Google Workspace / Gmail (sending prospecting emails from the address chloe@pro.weddingplanner-app.com, and reading, in the associated mailbox, only the replies received to prospecting emails (headers and a short excerpt), to record replies, automatic messages, undelivered emails, and objections). Transfer covered by the standard contractual clauses. Purpose: audience measurement and performance of advertising campaigns; the B2B prospecting described in section 2.i. Data transmitted: cookie identifiers, browsing data, anonymized conversion events; for B2B prospecting, the professional contact details of the wedding planners we contact, the content of the email sent and, where applicable, the reply received. We do not use Google to suggest addresses on accounts using the English version of the service: the venue address is typed freely (see the end of this section). Google Maps map on the wedding website: when it is shown, Google receives the visitor’s IP address and browser and may set its own cookies (see section 5.f). Legal basis: consent (Art. 6(1)(a) GDPR) for the Google trackers and the map in the European Union, the European Economic Area, the United Kingdom, and Switzerland, legitimate interest (Art. 6(1)(f) GDPR) with the possibility to reject elsewhere (see section 5); legitimate interest (Art. 6(1)(f) GDPR) for B2B prospecting. Google privacy policy.
- Meta Platforms Ireland Ltd (Ireland, for European users) and Meta Platforms, Inc. (United States). Meta pixel and Conversions API (server-side, through the Stripe webhook). Transfer covered by the standard contractual clauses. Purpose: measuring advertising conversions, optimizing campaigns. Data transmitted: cookie identifiers (
_fbp,_fbc), conversion events (lead generation, checkout start, purchase) and, through the server-side Conversions API, a hashed email address (when the account is activated, meaning at the first real use of the product on trial, and when a payment is confirmed) and the IP address and user agent (at activation), for deduplication and matching. Legal basis: your consent (Art. 6(1)(a) GDPR) in the European Union, the European Economic Area, the United Kingdom, and Switzerland; elsewhere, our legitimate interest (Art. 6(1)(f) GDPR), with the possibility to reject at any time (section 5). Meta privacy policy. - TikTok Technology Limited (Ireland, for European users) and TikTok Inc. (United States). TikTok pixel (client-side, loaded on the pages described in section 5) and TikTok Events API (server-side, through the Stripe webhook). Transfer to TikTok Inc. covered by the standard contractual clauses adopted by the European Commission. Purpose: measuring advertising conversions, optimizing campaigns. Data transmitted through the client-side pixel: cookie identifiers (
_ttp,ttclid) and the eventsPageView(when you arrive on a page),ViewContent,SubmitForm,InitiateCheckout,ClickButton(when you leave for the Stripe payment page), andCompletePayment. The pixel is not loaded on projects managed by a wedding planner (signed-in space and public wedding website), nor on pages reached through a personal link, nor on the administration area. The pixel’s automatic collection features (automatic events, automatic advanced matching, expanded data sharing) are switched off in our TikTok advertising account: the pixel sends only the events listed above. Data transmitted through the server-side Events API: email address hashed with SHA-256, deduplication parameters (_ttp,ttclid), and the transaction amount, sent when the account is activated (first real use of the product on trial) and when a payment is confirmed (Stripe webhook), with the IP address and user agent at activation. Legal basis: your consent (Art. 6(1)(a) GDPR) in the European Union, the European Economic Area, the United Kingdom, and Switzerland; elsewhere, our legitimate interest (Art. 6(1)(f) GDPR), with the possibility to reject at any time (section 5). TikTok privacy policy. - Functional Software, Inc. (“Sentry”)(45 Fremont Street, San Francisco, CA 94105, United States; technical error tracking and application observability). Sentry is SOC 2 Type II certified. The data of our project is hosted in the European Union, in Sentry’s German region (Germany); since Sentry is a US company, access from the United States (operations, support) cannot be ruled out, and any such transfer is covered by the standard contractual clauses adopted by the European Commission. A data processing agreement (DPA) is in force with Sentry. Purpose: detect and diagnose technical errors to keep the service reliable. Data transmitted: technical error events (error type, route / URL concerned, timestamp, browser and device type, pseudonymous technical identifiers in the form of UUIDs:
user_idandevent_id). No direct personal data is sent to Sentry: abeforeSendfilter systematically removes, before anything is sent, the email addresses, names, phone numbers, postal addresses, tokens, and authentication headers present in error events. Sentry’s session recordings (session replay) are switched off. Legal basis: legitimate interest (Art. 6(1)(f) GDPR): reliability and continuity of the service. Sentry privacy policy · Sentry data processing agreement (DPA). - Telegram (companies of the Telegram group, in particular Telegram Messenger Inc. and Telegram FZ-LLC, located outside the European Union: the British Virgin Islands and Dubai, United Arab Emirates; a messaging channel used internally by our team). Purpose: receiving real-time internal notifications about the activity and security of the service: new sales, sign-ups and changes in the status of the MyWedding Pro subscription, technical and security alerts (payment, login, abnormal influx of replies on a wedding), follow-up of the B2B prospecting described in section 2.i. Data transmitted:
- on a sale: the couple’s first names (for example “Emma & James”)
- on a sign-up or a change to a MyWedding Pro subscription: the name of the business or the professional, the professional email address and, where given, the business registration number
- on a technical alert about payment, login, or abuse: internal technical identifiers (Stripe session or payment identifier, internal identifier of the wedding concerned) and amounts; the associated error message is filtered to automatically remove any email address before sending
- on a reply to a B2B prospecting email: the name of the business and the city of the wedding planner contacted, and a short excerpt of their reply
To turn a venue address into geographic coordinates, we query OpenStreetMap (Nominatim, United Kingdom) for accounts using the English version of the service, anywhere in the world, since weddings can take place abroad. For French accounts, we query the Base Adresse Nationale (api-adresse.data.gouv.fr, run by the French government) and, as a fallback, OpenStreetMap. To calculate the golden hour, we send sunrisesunset.iothe venue’s coordinates and the date. Beyond the data described above, no personal data is sent to these services.
8. Session replays
To understand where people run into difficulty, we use PostHog’s session recording feature (session replay). It records the way a page is used (pointer movements, clicks, scrolling, transitions between pages) and lets us replay it.
What is masked: the text shown on screen and everything typed into form fields (email, first names, budget, venue, and so on) are masked before being sent to PostHog. PostHog receives the layout and the gestures, not the text displayed. Some technical attributes of page elements (accessibility label, tooltip, link address) are not masked and may contain a name or an email address; the most sensitive areas are excluded from them (see below). The areas that show your wedding type, your key moments, your belief, or your priorities are also excluded: their content is never sent, and clicks that happen there give rise to no event. The body and headers of exchanges with our servers (network requests) are never recorded.
What is recorded: gestures (clicks, scrolling, movements), the structure of pages, transitions between steps, and any navigation errors. We use this data exclusively to improve the user experience.
Scope: these recordings cover the pages of our site (weddingplanner-app.com), including the signed-in space and the public wedding website, but not the administration area or pages reached through a personal link. As soon as you are redirected to the payment page hosted by Stripe (under the Link brand), you leave our scope and PostHog records nothing more.
To rejectthe recording of your sessions, use the banner or “Manage cookies” (the “Audience measurement” category): in the European Union, the European Economic Area, the United Kingdom, and Switzerland, nothing is recorded before you agree; elsewhere, recording stops as soon as you reject. To ask for the deletion of the recordings about you, contact us at contact@makeitglobal-agency.com. We will handle your request within one month and delete the corresponding data in PostHog.
9. Your rights
Under the GDPR and the French Data Protection Act (loi Informatique et Libertés), and where they apply the UK GDPR and the other laws described in section 10, you have the following rights over your personal data:
- Right of access
- Right to rectification
- Right to erasure (“right to be forgotten”)
- Right to restriction of processing
- Right to data portability
- Right to object
- Right to withdraw your consent at any time, where the processing is based on consent
- Right to set instructions about what happens to your data after your death (French law)
If you completed the questionnaire up to step 9 (email entry), an account was created automatically. Even if you did not complete a payment, you have a trial mode account and can exercise all your rights (access, erasure, objection, and so on) by writing to us at the address below, stating the email address you used. We will handle your request within one month at the most.
If your questionnaire led neither to an account nor to a payment, you can contact us, giving the approximate date of your visit, to ask for the questionnaire data to be deleted before it is anonymized automatically; no later than 31 days after the start of the questionnaire it is anonymized or deleted anyway and no longer identifies you (details in section 2.a).
To exercise these rights, write to us at contact@makeitglobal-agency.com. We will reply within one month.
Objecting to emails that are not essential to the service. The unsubscribe link in the email that contains your login link lets you object, without having to sign in or delete your account, to any email from us that is not essential to the running of the service. Your address is then recorded in our suppression list. This right to object is independent of your right to have your account erased: your planning space stays accessible, and the emails necessary to the service (login link, payment confirmation, replies to your requests) continue to be sent to you. Until September 30, 2026, this link also ended the sequence of 4 activation emails, which no longer exists.
Data held by Link. Since Link is an independent controller of the payment data it collects, you can exercise your rights over that data directly with it (link.com, privacy section), and with us for the data we hold. A deletion request sent to Link erases the transaction data present in our Stripe objects (customer, invoice, payment, subscription) and ends any subscription whose payment Link processes; Stripe informs us by email. It does not delete your MyWedding Planner account, which you can ask for separately by writing to us.
If, after contacting us, you believe your rights are not being respected, you can lodge a complaint with the CNIL (3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07), our lead supervisory authority since we are established in France, or with the data protection authority of the country where you live (for example the Information Commissioner’s Office in the United Kingdom; for the European Union, the list of national authorities is published by the European Data Protection Board).
10. Information for specific regions
United Kingdom
Because we offer the service to people in the United Kingdom, the UK GDPR and the Data Protection Act 2018 apply to our processing of their data alongside the GDPR. The purposes, legal bases, retention periods, and rights described in this policy apply in the same way. You can lodge a complaint with the Information Commissioner’s Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom (ico.org.uk).
Cookies.In the United Kingdom, the use of cookies and similar technologies is governed by the Privacy and Electronic Communications Regulations 2003 (PECR). As explained in section 5, the United Kingdom is in the prior-consent zone: we set no analytics or advertising tracker until you accept, and you can change your choice at any time with “Manage cookies”.
Transfers. We process your data in Europe, and some of our providers are US companies (section 7). For data about people in the United Kingdom, those transfers are covered by safeguards recognized under UK law, such as the UK addendum to the standard contractual clauses or the UK extension to the EU-US Data Privacy Framework, depending on the provider.
United States
We are a small business based in France. At our current size, we do not believe we are a “business” subject to the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA), or to the privacy laws of other US states that apply only above certain thresholds (for example Virginia, Colorado, Connecticut). We still want US residents to know where they stand:
- Your rights. We apply the rights in section 9 (access, correction, deletion, portability, objection) to everyone, wherever they live, including US residents. Write to us at the address in section 9; we reply within one month. We may ask you to confirm your identity (for example by answering from the email address of your account), and you can use an authorized agent. If we refuse a request, you can appeal by replying to our message, and you can then contact your state attorney general. We do not treat you differently for exercising your rights.
- No sale for money.We do not sell your personal data for money. Our advertising partners (Google, Meta, and TikTok) receive cookie identifiers and conversion events when you use the public pages, the questionnaire, or your signed-in space (sections 5 and 7). Some US state laws treat this kind of disclosure as a “sale” or as “sharing” for cross-context behavioral advertising or “targeted advertising”, and give you the right to opt out of it. To opt out, click “Reject” in the cookie banner or “Manage cookies” at any time (section 5); you can also block these trackers in your browser settings or write to us at the address in section 9.
- Browser signals. We do not currently respond to Do Not Track or Global Privacy Control signals.
- Sensitive data. In the questionnaire, the only sensitive item we ask for is your religious or philosophical belief. It is optional, collected only with your explicit consent (section 2.a), and not sent to our analytics, advertising, or error-monitoring providers. Dietary needs and allergies entered in guest lists and RSVP answers (sections 2.d and 2.e) can reveal health or religious information: they are used only to run your event and are not sent to those providers either.
- What we collect and why. The categories of data we collect, the purposes, the retention periods, and the recipients are described in sections 2, 3, 6, and 7.
Elsewhere
If you live in another country (for example Canada or Australia), you may have additional rights under your local law. Contact us at the address in section 9 and we will handle your request within one month. You can also contact the data protection authority of your country.
Children
The service is for adults planning a wedding. It is not directed to children under 16, and we do not knowingly collect data directly from children. Children’s first names can appear in the service because the organizer enters them (sections 2.a and 2.d), and the organizer is responsible for that data. If you believe a child has given us personal data directly, contact us and we will delete it.
11. Security
All communications with the site and the application are encrypted over HTTPS (TLS). The databases are protected by Supabase’s Row Level Security (RLS) mechanisms: each user can reach only their own events. Passwords are stored as hashes by Supabase Auth; the service also supports magic link authentication (no password).
12. Changes
This policy may be updated to reflect technical, legal, or regulatory developments. The date of the last update is shown below. For any substantial change, we will inform you by email.
Last updated: October 5, 2026.