Privacy

Privacy policy

What shaadi.diy stores, why it stores it, who can see it, and how to have it deleted. Written to be read, not to be survived.

Last updated 24 July 2026

The short version

  • We store what you type into your wedding: your account details, and the guest, event, vendor, budget and accommodation records you create.
  • Most of that data is about other people — your guests. You are the one who decided to enter it, and you can export or delete all of it at any time.
  • We do not sell data, we take no vendor commission, and we run no advertising or third-party tracking pixels.
  • We do not read your wedding data to train anything.
  • Deleting your wedding deletes its records. Ask us and we will confirm it is gone.

Who we are

shaadi.diy is a free, open source wedding planning service. For the purposes of India’s Digital Personal Data Protection Act 2023 we act as the Data Fiduciary for your account, and as a processor acting on your instructions for the guest records you enter. For GDPR purposes the equivalent roles are controller and processor.

Privacy contact and grievance officer: privacy@shaadi.diy. We aim to answer within 7 days and to resolve requests within 30.

What we store

CategoryWhat it includesWhy
Your accountWhat it includesName, email address, a hashed password, and email verification and password reset tokensWhyTo let you sign in and to recover access
Your weddingsWhat it includesWedding name, dates, the members you invite and what sections each may seeWhyTo run a shared workspace with scoped access
GuestsWhat it includesNames, households, side, phone numbers, meal preferences, RSVP status per event, travel and room needsWhyThe guest list, headcounts and rooming lists you came here for
Planning recordsWhat it includesEvents, venues, vendors, tasks, budgets, expenses, payments, gifts, seating, rituals and accommodationWhyThe planning workspace itself
WhatsApp messagesWhat it includesMessages sent to and received from guests, delivery status, and replies to option listsWhyTo send invitations and record RSVPs against the right guest
Your public siteWhat it includesEverything you publish: story text, event details, photos and gallery uploadsWhyIt is a public web page — that is its purpose
Operational logsWhat it includesServer logs and email/digest send records, retained short-termWhyDebugging, abuse prevention and delivery troubleshooting

We do not ask for and do not want financial account numbers, card details, or government identity numbers. Payment records in the budget are amounts and dates you type, not payment instruments — please do not paste card or account numbers into a note field.

A note about your guests’ data

This is the part most wedding tools skip. When you add a guest, you are entering another person’s name and phone number into our systems, and they never agreed to that with us — they agreed with you, by being your family or your friend. Two consequences follow.

  • You are responsible for having a reason to hold that contact detail, and for honouring a guest who asks you to remove them. We will act on such a request routed through you, or directly if a guest contacts us.
  • We use guest data only to provide the features you invoke — sending an invitation you composed, recording the reply, counting the headcount. We do not message your guests for our own purposes, ever.

WhatsApp

If you connect a WhatsApp Business number, messages to and from your guests pass through Meta’s WhatsApp Business Platform and are subject to Meta’s own terms and privacy policy in addition to this one. We store the message content, its delivery status and the reply, linked to the guest record, so your RSVP counts are auditable. Message templates you submit are reviewed by Meta, not by us.

Who else touches the data

ServiceWhat it handles
SupabaseWhat it handlesDatabase and file storage for everything above
VercelWhat it handlesApplication hosting, serving and server logs
Meta (WhatsApp Business Platform)What it handlesDelivery of WhatsApp invitations and replies
BrevoWhat it handlesTransactional email — verification, password resets, digests
MixpanelWhat it handlesProduct analytics on how the app is used

Each is bound to process data on our instructions. We do not sell personal data to anyone, and we do not share it for anyone else’s advertising.

Cookies and analytics

We set a session cookie so you stay signed in. That one is strictly necessary and cannot be switched off without breaking sign-in. We use product analytics to understand which features get used; we run no advertising cookies, no remarketing pixels and no cross-site trackers. The prerendered guide and tool pages you may have arrived on carry no third-party scripts at all.

How long we keep it

  • Wedding data: for as long as the wedding exists in your account. Delete the wedding and its records go with it.
  • Account data: until you ask us to close the account.
  • Verification and password-reset tokens: hours, then they expire and are cleared.
  • Operational logs: typically 30 days.
  • Backups: deleted data can persist in encrypted backups for a short window before those rotate out.

Your rights

Under the DPDP Act you may access your data, have it corrected, have it erased, nominate someone to exercise these rights on your behalf, and raise a grievance. Under GDPR you additionally have rights to restriction, objection and portability. In practice:

Export

Guest lists and budgets export to a spreadsheet from inside the app. For a full account export, email us.

Deletion

Delete a wedding from its settings, or email privacy@shaadi.diy to have the whole account and everything in it removed. We will confirm when it is done rather than leaving you to wonder.

Complaints

Write to the address above first. If we do not resolve it, you may complain to the Data Protection Board of India, or to your local supervisory authority if you are in the EU or UK.

Security

  • Passwords are stored hashed, never in readable form. We cannot see yours.
  • Traffic is encrypted in transit; data is encrypted at rest by our database provider.
  • Access inside a wedding is scoped per section, so a member you invite for the guest list cannot open the budget.
  • The code is open source, so the security model is inspectable rather than asserted.

No service is immune. If a breach affects your data we will notify you and the relevant authority as the law requires, and tell you what actually happened.

Children

The service is not directed at children and accounts are for adults. Guest records may include children in a household headcount; that is a number of people, entered by you, and we ask for nothing further about them.

Changes

If we change this policy materially we will update the date at the top and, where the change affects how your data is used, tell account holders by email rather than relying on you to re-read the page.