Privacy policy

Effective from 19 September 2026.

This policy explains what personal data we process in connection with the Veilly service, why we process it, and what rights you have. It covers the veilly.online website (including the blog and newsletter), the organiser panel at app.veilly.online, and the individual wedding pages published on veilly.online subdomains.

1. Data controller and contact

The controller of your personal data is the operator of the Veilly service ("Veilly", "we"). For any matter concerning personal data, contact us at kontakt@veilly.online.

For wedding-guest data entered into the service by the couple or wedding organiser, the couple (organiser) is the data controller and Veilly processes that data on their behalf as a processor — see section 4.

2. What data we process

  • Organiser account data: the couple's first names, e-mail address, Google account identifier (when signing in with Google), the wedding date and basic wedding parameters, page settings.
  • Wedding content: schedule, descriptions, locations, photos and other materials added to the wedding page.
  • Guest data: first and last names, contact details (e-mail, phone number), RSVP responses, dietary preferences, accommodation and transport information, messages and content added by guests (e.g. gallery photos, music suggestions).
  • Newsletter and contact: your e-mail address and the content of our correspondence when you join the list or write to us.
  • Technical and analytics data: IP address, device and browser identifiers, product usage events (e.g. pages visited) — as described in section 9.

Providing data is voluntary but necessary to use the relevant features (e.g. you cannot create an account without an e-mail address).

3. Purposes and legal bases

  • Providing the service (creating and running the account, publishing the wedding page, handling RSVP and guest communication) — art. 6(1)(b) GDPR (performance of a contract).
  • Billing and tax/accounting obligations related to the publication fee — art. 6(1)(c) GDPR.
  • Newsletter and launch updates — art. 6(1)(a) GDPR (consent, which you can withdraw at any time).
  • Analytics, product development and security (usage statistics, abuse prevention, error diagnostics) — art. 6(1)(f) GDPR (our legitimate interest).
  • Marketing and remarketing (measuring ad performance, remarketing lists) — art. 6(1)(a) GDPR (consent given in the cookie banner, which you can withdraw at any time).
  • Handling enquiries and complaints — art. 6(1)(b) or (f) GDPR.

We do not make decisions based solely on automated processing that would produce legal effects concerning you, nor do we profile you for such purposes.

4. Wedding-guest data — roles of the parties

A wedding page is a tool the couple (organiser) uses to communicate with their guests. Guest data — entered by the couple or provided by guests themselves (e.g. in the RSVP form) — is processed on the couple's behalf and under their instructions; the couple decides on its scope and purpose. In this respect Veilly acts as a processor within the meaning of art. 28 GDPR: it stores the data, makes it available to the couple and their guests within the wedding page, and sends communications requested by the couple.

If you are a wedding guest and want to exercise your rights (e.g. correct or delete your data), the simplest route is to contact the couple directly. You can also write to us at kontakt@veilly.online — we will help handle the request and inform the organiser.

5. Sign in with Google

You can sign in to the organiser panel with a Google account or with a link sent to your e-mail address. When you sign in with Google, we receive only basic profile data: your name, e-mail address and account identifier. We do not access your messages, contacts, calendar or files.

Veilly's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google data solely to create and operate your account; we do not sell it or use it for advertising.

6. Recipients of data

We process data in the European Union, using established infrastructure providers (sub-processors):

  • Vercel — website hosting and CDN,
  • Supabase — database and authentication (servers in Frankfurt, EU),
  • Cloudinary — photo storage and processing,
  • Brevo — e-mail delivery (EU),
  • PostHog — product analytics (EU-hosted instance),
  • Google — Google sign-in,
  • Cookiebot (Cybot A/S) — cookie consent management (EU),
  • Google Ads and Meta Platforms — ad performance measurement and remarketing; activated only after you consent to the marketing category.

Some providers may process limited data outside the European Economic Area; in that case the transfer relies on Standard Contractual Clauses approved by the European Commission or other mechanisms provided for by the GDPR. Beyond that, we do not share personal data with third parties unless required by law.

7. How long we keep data

  • A wedding page together with its guest data is archived 180 days after the wedding date and permanently deleted 12 months after archiving. We warn the organiser 30, 7 and 1 day before deletion.
  • The organiser account is kept until deleted at the user's request.
  • Newsletter e-mail addresses are kept until you unsubscribe.
  • Billing data is kept for the period required by law (as a rule, 5 tax years).
  • Technical and analytics data is kept for a limited time, no longer than needed for statistics and security.

The organiser can delete the wedding page or specific data earlier at any time — directly in the panel or by writing to us.

8. Your rights

You have the right to access your data, rectify it, erase it, restrict processing, data portability, object to processing based on legitimate interest, and withdraw consent at any time (without affecting the lawfulness of processing carried out before withdrawal). To exercise these rights, write to kontakt@veilly.online.

You also have the right to lodge a complaint with a supervisory authority — in Poland, the President of the Personal Data Protection Office (UODO, ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl).

9. Cookies and consent

The service uses cookies and similar technologies grouped into categories:

  • **Necessary** — required for the service to work (e.g. maintaining your sign-in session, remembering your language, security). No consent needed.
  • **Statistics** — PostHog product analytics on an EU-hosted instance, which helps us understand how the service is used (e.g. which pages are visited) and improve the interface. Until you consent, it runs without storing data on your device (cookieless).
  • **Marketing** — Google Ads and Meta (Pixel) tools for measuring ad performance and remarketing. We activate them only after you consent.

We manage consent through the Cookiebot platform (consent banner) together with Google Consent Mode v2, which passes your choice to the analytics and advertising tools. You can change or withdraw consent at any time via the banner or the "Cookie settings" link in the footer. You can also limit or block cookies in your browser settings — the service will remain functional to a basic extent.

10. Security

Data in transit is encrypted (TLS). Each wedding's data is isolated at the database level, and access to production data is limited to those who need it. We keep the service's components up to date and monitor it for abuse.

11. Changes to this policy

We may update this policy, e.g. when the service's features or the law change. We will announce material changes in the service or by e-mail. The current version is always available at veilly.online/legal/privacy.

Privacy policy