legal
Privacy notice
Who processes the data, which data and for how long. And specifically for guests: what happens to the reply and the photos you submit on a couple's site.
Version of 28 August 2026
Controller
The controller of personal data processed on ewelin.app and in the portal at app.ewelin.app is a sole proprietor established in Slovenia who provides the Ewelin service (the Provider). The Provider is reachable at info@ewelin.app.
For guest data a couple collects through their wedding site, the couple is the controller and the Provider is the processor. The section Guests below applies to that data.
Which data and what for
The Provider processes only the data the service needs:
- Account: the email address and name you enter at sign-up, and the times of your logins — to give you access to the portal and to notify you about your account.
- Site content: the names, wedding date, texts, photos and contacts you enter in the editor — to display your wedding site.
- Purchase: the chosen plan, amount, time of payment and the identifier of the payment session at Stripe — to activate the site, confirm the payment and keep tax records. The Provider never receives card details.
- Email: the purchase confirmation and notices about your account or site. We send no marketing emails.
- Technical data: IP address and browser details in server logs, and a hashed IP when an RSVP is submitted or a photo uploaded — for security and to limit the number of submissions from one device.
- Visits to the ewelin.app website and to the sign-in-free theme preview (app.ewelin.app/preizkusi): aggregated, anonymous visit data via Vercel Analytics (page, country, device type) — without cookies and without a profile of any individual. Visits to couples' wedding sites are not measured.
Legal bases
We process the account, site content and purchase because it is necessary to perform the contract (Article 6(1)(b) GDPR). We keep payment records to comply with tax and accounting obligations (Article 6(1)(c)). We process technical data and aggregated visits on the basis of our legitimate interest in the security and operation of the service (Article 6(1)(f)). Guests' dietary requirements, a special category of data, are processed only with the guest's explicit consent (Article 9(2)(a)).
Retention periods
The periods are those the system actually enforces:
- Account and site content: for as long as the account is active. After the plan expires the site is no longer public and its data is kept for at most 6 months so it can be published again; then it is permanently deleted.
- Deleted site or account: 30 days after deletion, then permanently; immediately on express request. During those 30 days a mistake can be undone.
- Payment records: for as long as tax and accounting law requires; they survive the deletion of the site.
- Hashed IP at form submission: counted for 10 minutes for the submission limit; the record is cleared at the next submission on the same site.
- Hosting server logs: short-term, per the hosting provider's settings.
Data processing agreement, processors and transfers to third countries
For guest data the Provider is the couple's processor: it processes the data only to run the site and on the couple's instructions. The content of this data processing agreement (Article 28 GDPR) is in the Terms of Use, section Guest data.
The Provider does not build the service from the ground up; parts of the processing are carried out by providers bound by contract who process data only on the Provider's instructions:
- Payments: Stripe.
- Sign-in and accounts: Clerk.
- Email: Resend.
- Error monitoring: Sentry — technical data about the error (path, error type, stack trace). Personal data is stripped before sending; request bodies are not sent.
- Hosting, database and photo storage: Vercel, Neon and Cloudflare R2.
- Data is stored on servers in the European Union. Where a provider carries out part of the processing in the USA (e.g. payments, sign-in), the transfer is based on the EU–US Data Privacy Framework (DPF) or the European Commission's standard contractual clauses.
Cookies
Ewelin's public pages and the couples' wedding sites use only cookies without which the service does not work or which store your choice. There is therefore no cookie banner — nothing that would require consent is stored in your browser.
Guests
If you came to a couple's wedding site as a guest, this is what applies to you. The couple who invited you is the controller of your data; Ewelin stores it on their behalf as a processor and uses it for nothing else.
When you RSVP you submit your name, email address, whether you are attending, the number of people and, optionally, a message. If the couple enables it, you can also enter dietary requirements; these are a special category of personal data, so you submit them only with the explicit consent you confirm next to the form, and the couple may use them only to organise the wedding.
You can upload photos to the gallery and, optionally, your name. A photo becomes publicly visible on the couple's site only once the couple approves it. By uploading you confirm that you have the right to share the photo.
Your data is kept for as long as the couple's site exists (see Retention periods) and is deleted together with it. You exercise your rights — access, rectification, erasure, withdrawal of consent — with the couple; the Provider at info@ewelin.app can also help, by forwarding the request to the couple or carrying it out on their instructions.
Your rights
You may ask the Provider for access to your data, its rectification, erasure or restriction of processing, for a copy of the data in a structured format, and you may object to processing based on legitimate interest. You may withdraw consent at any time without affecting the lawfulness of processing before the withdrawal.
Send your request to info@ewelin.app. We reply within one month at the latest.
Supervisory authority
If you believe the Provider processes your data unlawfully, you may lodge a complaint with the Information Commissioner of the Republic of Slovenia (Informacijski pooblaščenec), Dunajska cesta 22, 1000 Ljubljana, gp.ip@ip-rs.si, www.ip-rs.si.
Changes to this notice
We update the notice when the service changes — for instance with a new processor or a new cookie. Each version is dated; we notify couples of material changes by email.