Privacy Policy
How Fizz Wedding protects and handles your personal information
Effective Date: October 4, 2025 | Last Updated: August 12, 2026
Our Commitment to Privacy
At Fizz, we understand the deeply personal nature of your wedding day and the memories you create with the people you love. We are committed to protecting your privacy and handling your personal information with the utmost care and respect, recognizing that you are entrusting us with some of your most precious moments.
Privacy Summary: We collect only the information necessary to provide our wedding page services, we never sell your data, and you have full control over your information and your wedding page.
Information We Collect
Personal Information
When you create an account, we collect: Name (first and last name), Email address (for account access and important notifications), Password (securely encrypted), Profile photo (optional). Legal Basis: Contract performance and legitimate interests (account security)
Event Information
This includes all content you choose to share on your wedding page: Details about your wedding and your story as a couple, Photos and videos (stored securely with BunnyCDN), Guest book posts, messages, and well-wishes, Wedding details and family information, Custom wedding page URLs and settings, RSVP replies including attendance, meal choices, dietary requirements, song requests, and the names and details of any additional guests brought along, Table plans and seating arrangements. A note on dietary requirements: this field is optional and free text, and what you write in it may reveal an allergy, a medical condition or a religious practice. Where it does, that information is special category data under UK data protection law, and we process it only because you have chosen to give it to us so that the couple and their caterer can feed you safely. You never have to fill it in, and you can speak to the couple directly instead. Legal Basis: Consent and legitimate interests (wedding page service provision); explicit consent for any health or religious information you choose to enter in dietary requirements
Important: Fizz Wedding Ltd is the data controller for guest information. We decide how long it is kept, how it is protected and when it is deleted, so any question or request about guest data comes to us rather than to the couple. If you are a couple: please do tell your guests that you are using Fizz Wedding, and that anything they post will be handled as described in this policy. It is good manners and it means nobody is surprised. But the legal responsibility for guest data sits with us, not with you. For guests: when you join a wedding page, your name and email address are visible to the couple so they can manage who has access. Your guest book posts and uploaded media are visible on the wedding page. If you reply to an invitation, the couple can also see and download your reply: whether you are coming, your meal choices, anything you write in dietary requirements, a song request if you make one, and the names of anyone you are bringing with you. That is what an RSVP is for, and it is how the couple plan the day. Separately, the couple can export a copy of their own account data; that export contains anonymous guest totals only, and no guest's personal details. You can exercise any of the rights set out in this policy directly with us, without going through the couple.
Technical Information
To ensure security and improve our services, we collect: IP addresses (for security and approximate location), Browser type and version, Device information (mobile/desktop, and for the app the device model and operating system version), Page and screen visits and feature usage, Session data and authentication tokens. Legal Basis: Legitimate interests (service improvement and security). Usage analytics in the mobile app are collected on the basis of consent instead, as described under The Fizz Wedding App.
How We Use Information
We use your information for: Wedding Page Services (Creating, maintaining, and securing your wedding page and content), Security & Safety (Protecting your account, preventing fraud, maintaining service integrity, and checking guest book text against a fixed list of terms so the couple can review anything that matches before it appears), Service Improvement (Enhancing our services and developing new features to better serve you).
We use your information to:
- To create and manage your wedding page
- To communicate with you
- To enhance user experience
- Creating and managing wedding pages
- Communication
- Enhanced user experience
- Wedding Page Services
- Security & Safety
- Service Improvement
- Send important account and service-related communications
- Deliver subscription confirmations and billing information
- Notify you about wedding page activity (when enabled)
- Send system updates and security alerts
- Provide marketing communications (with your consent)
- Analyze email engagement to improve our communications
- Website analytics and user behavior analysis
- Conversion tracking and subscription optimization
- User experience improvement through usage data
- Providing optional writing assistance when you choose to use it
- Checking guest book text against a fixed list of terms so the couple can review anything that matches before it appears
Legal Basis for Processing
Under UK data protection law (UK GDPR), we must have a lawful basis for processing your personal information. We rely on different legal bases depending on how we use your data:
Consent
When guests submit posts, photos, or messages to wedding pages, they provide explicit consent for us to process and display their contributions. This consent is freely given and can be withdrawn at any time.
Applies to: Guest submissions, posts, photos, and messages on wedding pages
Contract
We process subscriber personal information as necessary to fulfil our contractual obligations to provide wedding page services, manage subscriptions, and deliver the features you have paid for.
Applies to: Service delivery, subscription management, account administration
Legitimate Interest
We have a legitimate interest in preventing fraud, improving our services, and ensuring platform security. We carefully balance these interests against your privacy rights.
Applies to: Fraud prevention, service improvement, security measures, analytics
Consent
Analytics in the app are collected only if you agree when asked, and never before. You can withdraw your agreement at any time in the app's Settings, and collection stops from that point.
Applies to: Usage analytics in the mobile app
Information Sharing
We share your information with third-party services to provide and improve our services. Additionally, guest information (name and email address) is shared with the wedding page owner who invited you, to enable them to manage access to their wedding page. Guest book posts and uploaded media are visible to all guests of the wedding page.
Third-Party Service Providers:
BunnyCDN
Purpose: Media Storage
Data Shared: Photos and videos
Privacy Policy: https://bunny.net/privacy
Supabase
Purpose: Database and Authentication
Data Shared: User data
Privacy Policy: https://supabase.com/privacy
Google OAuth
Purpose: Authentication
Data Shared: Authentication data
Privacy Policy: https://policies.google.com/privacy
Brevo (Email Service)
Purpose: Transactional and marketing email delivery
Data Shared: Email addresses, names, email preferences, delivery tracking data
Privacy Policy: https://www.brevo.com/legal/privacypolicy/
Google Analytics 4
Purpose: Website analytics and user behavior tracking
Data Shared: Website usage data, page views, user interactions, session information
Privacy Policy: https://policies.google.com/privacy
Google Tag Manager
Purpose: Tag and analytics management
Data Shared: Website events, user interactions, conversion tracking data
Privacy Policy: https://policies.google.com/privacy
CookieYes
Purpose: Cookie consent management and compliance
Data Shared: Cookie consent preferences, user choices, compliance records
Privacy Policy: https://www.cookieyes.com/privacy-policy/
Vercel
Purpose: Website hosting, analytics, and performance monitoring
Data Shared: IP addresses, page views, web vitals performance metrics, request metadata, user agent information
Privacy Policy: https://vercel.com/legal/privacy-policy
Sentry
Purpose: Error monitoring and session replay for debugging
Data Shared: Error and crash data, browser and device information, console logs, and a replay of the session but only where an error occurred. We do not record ordinary sessions.
Privacy Policy: https://sentry.io/privacy/
Vercel AI Gateway
Purpose: Routing writing-assistance requests to an AI provider
Data Shared: The text you enter when you use a writing-assistance feature, and the draft returned to you. Not retained after the request completes.
Privacy Policy: https://vercel.com/legal/privacy-policy
Anthropic
Purpose: AI writing assistance (sub-processor of Vercel AI Gateway)
Data Shared: The same text, for the sole purpose of returning a suggested draft. Not used to train AI models.
Privacy Policy: https://www.anthropic.com/legal/privacy
Google Analytics for Firebase
Purpose: Optional usage analytics in the mobile app, collected only with your consent
Data Shared: An on-device analytics identifier, screen views and feature usage. Only if you accept analytics in the app. No advertising identifiers.
Privacy Policy: https://policies.google.com/privacy
Cloudflare Turnstile
Purpose: Checking that a person, rather than an automated script, is using the guest invitation page and the contact form
Data Shared: IP address, browser and device characteristics, and interaction signals from the page where the check runs. Not used to build a profile of you or to track you between sites.
Privacy Policy: https://www.cloudflare.com/privacypolicy/
Writing Assistance and Artificial Intelligence
Some parts of the site offer to help you write, your story, a speech, a message to the couple. These features are optional and only ever run when you choose to use them. They are there to help you make a start, not to write anything for you. One thing that is often assumed to be artificial intelligence is not. We check the text of guest book posts and comments against a fixed list of terms, so that the couple can look at anything matching before it appears on their wedding page. That check is a straightforward comparison against a list, carried out on our own servers. Nothing is sent anywhere for it, no other company is involved, and it builds no profile of you. It has no legal or similarly significant effect, and the decision that follows is made by a person: the couple hosting the wedding, who choose whether to publish the post or delete it.
When you use one of these features, the text you have entered is sent to Vercel's AI Gateway, which passes it to an artificial intelligence provider (currently Anthropic) and returns a suggested draft. Vercel acts as our data processor and Anthropic as its sub-processor. Both operate in the United States, and the transfer is covered by the safeguards described under International Data Transfers. When you are posting a single photograph to the guest book, you can also choose to let the assistant look at it, so that the suggestions can refer to what is actually in the picture. This is switched off unless you tick the box, and it is only offered on a post with exactly one photo. If you do tick it, a reduced-size copy of that photograph is sent with your text, through the same gateway to the same provider, and everything described in this section applies to it. The copy is not kept once your request has finished and is not used to train AI models. Photographs are never sent for any other feature, and never without you choosing it each time. The seating planner works the same way when you ask it for help: the guest names and table arrangement you have entered are sent, and a suggestion comes back.
- •Nothing is sent unless you choose to use one of these features.
- •A photograph is only ever sent if you tick the box to include it, on a post with a single photo. Your photographs are never sent otherwise, and never by default.
- •What comes back is a draft. You decide whether to keep it, change it, or discard it — nothing is ever published or applied on your behalf.
- •Artificial intelligence is never used to make a decision about you, your account, your subscription, or your access to the service.
- •The gateway does not keep your text once your request has finished, and we do not permit your content to be used to train AI models.
- •You can use every part of the service without ever using a writing-assistance feature.
We also use artificial intelligence internally to help us answer support enquiries and find records more quickly. It can read and summarise information; it cannot change your account, your subscription, or your event pages. Anything that needs acting on is done by a person.
The Fizz Wedding App
Fizz Wedding has a companion app for phones and tablets, which couples and their guests can use to share photos, videos and voice toasts on the day. The app is optional. Everything it does can also be done from the website in a phone browser, so you never need to install anything to take part in someone's wedding. This section covers what the app does that the website does not. Everything else in this policy applies to the app in exactly the same way.
Permissions the app asks for
- •Camera: So you can take a photo, record a video, or record a voice toast from inside the app and share it to the couple's guest book. The camera is only opened when you tap to use it.
- •Microphone: So you can record a voice toast, and so that video you record has sound.
- •Photo library: So you can choose a photo or video you have already taken and share it to the guest book. On recent versions of Android and iOS you can grant access to selected items only, rather than to your whole library.
- •Saving to your photos: So the app can keep a clean copy of anything you capture on your own device, meaning you keep the original even if the couple later removes the post.
Each permission is requested at the moment you first use the feature that needs it, never at sign-in, and you can refuse any of them. Refusing stops that one feature working and leaves the rest of the app unaffected. You can change your mind at any time in your device's own settings under the Fizz Wedding app. We do not receive your photos, videos or recordings unless you choose to share them to a guest book.
Analytics in the app
The app can collect anonymous usage analytics through Google Analytics for Firebase, which tells us things like which screens people open and whether a feature is working. Doing that requires storing an identifier on your device. We ask you first. The first time you open the app you are asked whether you are happy for us to collect usage analytics, and the answer is no until you say otherwise. If you decline, no identifier is stored and no analytics are sent. If you accept, you can change your mind at any time in the app under Settings, and collection stops from that point. None of this is used for advertising. Advertising identifiers are switched off in the app, we do not build advertising profiles, and we do not share analytics data with advertisers. Our legal basis for this processing is your consent, which you can withdraw at any time.
Crash and error reporting
Separately from analytics, the app reports crashes and errors to Sentry so that we can find and fix faults. This runs whether or not you accept analytics, because without it we cannot tell that the app has broken for you. A crash report contains technical information about the fault and the device: the type of device, the operating system version, the app version, and what the app was doing at the time. Before anything leaves your device we remove personal information and strip the security tokens from media links. Two sets of rules apply here, and we rely on a different one for each. For the information stored on or read from your device, we rely on the exemption for preventing or detecting technical faults, which the Privacy and Electronic Communications Regulations allow without consent. For our use of the information once we have it, our lawful basis under UK GDPR is our legitimate interest in keeping the app working, weighed against the limited and technical nature of what is collected. We do not use crash reports to build a profile of you or to track you between apps.
Reporting, blocking and screening
The app lets you report a post or comment you think is inappropriate, and lets you block the person who wrote it. Both are available from the same menu on the item itself. When you report something, we record what you reported, the reason you chose, and that the report came from you. Reports go to the couple whose wedding it is and to our support team, so that either can act. When you block someone, their posts, comments and reactions stop appearing for you anywhere in that wedding. Blocking is private from other guests: the person you block is not told, sees no change, and can carry on taking part for everyone else. It only changes what you see. You can review who you have blocked, and unblock them, in the app under Settings. Our support team can see how many people have blocked someone at the same wedding, but not who did the blocking. This is so we can tell the difference between one falling-out and someone causing a problem for many guests. Neither the couple nor other guests see this. Posts and comments written in the app are also checked against a fixed list of terms, exactly as they are on the website. Anything that matches is held back from the wedding page and shown only to the couple, who choose whether to publish it or delete it. A held post is stored in the same way as any other and is deleted with the wedding page. Reports and blocks are kept for as long as the wedding page exists and are deleted with it.
App stores
The app is distributed through the Google Play Store and the Apple App Store. When you download it, the store collects its own information about that download under its own privacy policy, which we do not receive. We do not receive your payment details from the store either. If you need help with the app, please contact us rather than the store, since the store cannot see your Fizz Wedding account and we cannot see what the store holds about you.
Data Security
We take protecting your memories and personal information seriously. Here's how we keep your wedding page content safe:
Data Retention
We only keep your information as long as needed for the wedding page services we provide or as required by law. Wedding page content is preserved while your page remains active. If your subscription ends, your wedding page and its content are kept for at least 30 days so that resubscribing restores them, after which they are permanently deleted. If you cancel during a free trial, your account and content are kept for at least 5 days before permanent deletion. The specific periods we apply are set out below.
Retention Periods:
- Wedding page content, photos, and guest posts: Preserved while the wedding page remains active. If a subscription ends, kept for at least 30 days so that resubscribing restores them, then permanently deleted
- RSVP replies, meal choices, dietary requirements, song requests and additional-guest details: Kept alongside the wedding page and deleted with it
- Account details and profile information: Retained while your account is active, deleted within 30 days of account closure
- Payment and subscription data: Managed by Stripe according to their retention policies (typically 7 years for financial compliance)
- Guest posts and comments: Preserved as part of the wedding page while it remains active. Individual posts and comments can only be deleted by their authors within 24 hours of creation, after which they become part of the wedding page record
- Where a couple removes a guest from their wedding page: we keep a record of that guest's email address, and the IP address they signed up from, for as long as the wedding page exists, so that the removal can be enforced. It is deleted with the wedding page
- Email preferences and marketing consent: Retained until you unsubscribe or close your account, with unsubscribe requests honored permanently
- Records required for legal compliance: Retained for 6 years as required by applicable business record retention laws (including UK Companies Act requirements)
- Reports and blocks made in the app: kept while the wedding page remains active and deleted with it, within 30 days of permanent wedding page deletion
Your Rights
You have rights regarding your personal information.
Access Your Information
View all personal information we hold about you. How: Go to Account Settings → Download My Data
Correct Your Information
Update or correct any inaccurate personal information. How: Go to Account Settings → Edit Profile
Delete Your Information
Remove your account and the data associated with it. If you have a paid subscription, cancel it first from the customer portal, or ask us and we will cancel it as part of the deletion. Deletion is not instant: your account is taken down straight away, and for two weeks afterwards you can contact us to change your mind. After that it cannot be recovered. How: Go to Account Settings → Delete Account
Withdraw Consent
Withdraw your consent for data processing at any time. Important: Withdrawing consent will make your wedding page completely unavailable to all guests (including yourself) until consent is re-granted. How: Go to Account Settings → Privacy & Consent
Data Portability
Export your data in a structured, machine-readable format. How: Go to Account Settings → Download My Data
Restrict Processing
Ask us to pause what we do with your information rather than delete it, for example while you are disputing its accuracy or objecting to our use of it. We will keep it but stop using it, except to establish or defend a legal claim. How: email privacy@fizz.wedding and tell us what you want restricted and why.
Object to Processing
Object to certain types of data processing, including marketing communications. How: Go to Account Settings → Privacy & Consent, or use unsubscribe links in emails
Email Communication Rights
You can unsubscribe from marketing emails at any time using the unsubscribe link in our emails. However, we will continue to send essential transactional emails (e.g., subscription confirmations, security alerts, wedding page activity notifications) that are necessary for the operation of your account and wedding page. These cannot be disabled as they are integral to the service.
Age Requirements
Special protections apply to children's personal information.
Our services are for adults. Subscribers must be 18 or older to enter into a payment agreement, and guests must confirm they are 18 or older before they can join a wedding page. We do not knowingly collect personal information from anyone under 18 in their own right, and will delete such data if we discover it. There is one situation where information about a child reaches us, and we want to be clear about it. When an adult guest replies to an invitation, they may name the people they are bringing with them, including their children, and may add dietary requirements for them. That information comes from the accompanying adult rather than from the child, it exists so that the couple can seat and feed everyone, and it is deleted along with the wedding page. Children do not have accounts, cannot sign in, and cannot post. If you believe a child has provided us with personal information directly, please contact us immediately.
International Data Transfers
Your personal information may be transferred to and processed in countries outside the UK and European Economic Area (EEA), including the United States. When we transfer your data internationally, we ensure appropriate safeguards are in place to protect your information. We use third-party services that may process data in different locations: • Stripe (payment processing) - EU/Ireland and US • Supabase (database hosting) - UK region • BunnyCDN (media storage and delivery) - UK (London) with US replication • Google Analytics (website analytics) - US • Google Analytics for Firebase (optional app analytics) - US • Vercel (website hosting and AI Gateway) - US • Anthropic (AI writing assistance, as a sub-processor of Vercel AI Gateway) - US All our service providers have Data Processing Agreements (DPAs) in place and are required to maintain appropriate security measures and comply with applicable data protection laws. For transfers to the United States, we rely on: • The UK Extension to the EU-US Data Privacy Framework (UK-US Data Bridge) for certified organisations • The UK International Data Transfer Agreement (IDTA) or UK Addendum to EU Standard Contractual Clauses where applicable • Adequacy decisions for countries with adequate data protection Where possible, we prioritise UK and EU-based data storage to minimise international transfers.
All data processing decisions, transfers, and operations are controlled from the United Kingdom and governed by UK law. While we may use service providers located internationally, we remain the data controller and ensure all transfers comply with UK data protection standards. You have the right to see the safeguards we rely on for these transfers. Email privacy@fizz.wedding and we will send you a copy of the relevant transfer agreement, with any commercially confidential terms removed.
Governing Law & Supervisory Authority
Governing Law
This Privacy Policy and all data processing activities are governed by the laws of England and Wales. Any disputes arising from this policy or our data practices will be subject to the exclusive jurisdiction of the courts of England and Wales.
Supervisory Authority
Fizz Wedding Ltd is registered with and regulated by the UK Information Commissioner's Office (ICO) for data protection purposes. The ICO is the UK's independent authority set up to uphold information rights and data privacy for individuals.
Complaining to us
If you think we have handled your personal information badly, please tell us first. You have a legal right to complain to us directly, and we would rather hear it from you than read it second-hand. Email privacy@fizz.wedding with what happened and what you would like us to do about it. There is no form to fill in and no particular wording you need to use. We will acknowledge your complaint within 30 days of receiving it. We will then look into it, ask you anything we need to, and tell you what we have found and what we intend to do. If it is going to take a while, we will keep you posted rather than leave you wondering. You do not have to complain to us before going to the ICO, and you can go to them at any point, including while we are still looking into it. Details are below.
Your Right to Complain
You have the right to lodge a complaint with the ICO if you believe your personal data has been processed unlawfully or if you are dissatisfied with how we have handled your data protection rights. You can contact the ICO or submit a concern through their online portal.
Visit ICO Concerns Portal →Policy Updates
We may update this Privacy Policy from time to time to reflect changes in our data practices, legal requirements, or business operations. When we make material changes that affect how we collect, use, or share your personal information: 1. Notification: We will notify all active users via email at least 30 days before the changes take effect. 2. Grace Period: You will have 30 days from the notification date to review and accept the updated Privacy Policy. 3. Acceptance Required: During the grace period, you can continue using all features normally. After the grace period expires, if you have not accepted the updated Privacy Policy, administrative features (editing wedding page content, managing permissions, account settings) will be temporarily suspended. 4. Wedding Pages Stay Live: Your wedding page will remain accessible to your guests and fully functional during any suspension period. Only administrative access is affected. 5. Easy Acceptance: You can accept the updated Privacy Policy at any time by logging into your account and following the prompts. Minor updates (such as fixing typos, updating contact information, or clarifying existing language without changing its meaning) will be made without notification or requiring re-acceptance. You can always find the current version of this Privacy Policy on our website with the "Last Updated" date clearly displayed.
Contact Us
Fizz Wedding Ltd is the data controller responsible for your personal information. Company Number: 17194605 (England & Wales) For any questions or concerns about this policy, please contact us using the details below.
Data Protection Contact
Email: privacy@fizz.wedding