This Privacy Policy explains how We Wil Marry (“Service”) collects, uses, and protects personal data.
We Wil Marry is operated by REDHEAD STUDIOS LTDA, a legal entity registered in Brazil under CNPJ 48.257.504/0001-18 (“Redhead Studios”, “we”, “our”). For Brazilian users, Redhead Studios is the controller under the LGPD (Lei nº 13.709/2018).
This page describes how the product works. It is not legal advice.
By creating an account, acknowledging the Terms and this Policy at sign-up when Clerk shows that checkbox, or continuing through onboarding and creating a site, you agree to this Policy.
Guests are not shown a Terms or Privacy checkbox. We process guest data as described in this Policy (contract and legitimate interests) when they RSVP, report a gift, or sign hearts.
Contact for privacy and data-subject requests: caina@welmarry.com.
1. Whose data we process
1.1 Couples (site owners)
When you create an account and a wedding site, we process:
- Account data from Clerk: name, e-mail, authentication identifiers, and sign-in metadata.
- Onboarding and site content you enter: partner names, wedding date and time, timezone, place (including Google Places results when you search), story, section copy, RSVP settings, gift lists, and similar wedding information.
- Photos and videos you upload.
- Bank or PIX details you save so guests can transfer gifts (encrypted at rest; shown to a guest only after they identify themselves).
- Billing data related to Stripe Checkout: what you bought, amounts, dates, refund status. We do not store full card numbers.
- Site-time entitlement (trial, paid months, Vitalício, grace).
- In-app notifications and e-mail preferences.
- Owner analytics: page and section view counts, not identified visitors.
Pre-account drafts exist only so you can finish creating a site. We do not use drafts as marketing leads.
1.2 Editors
If a couple invites you as an editor, we process your name and e-mail for the invite, your Clerk account if you accept, and the same site operational data you can access (including guest and gift records). A site has at most 10 editors.
1.3 Guests
Guests are not required to create a We Wil Marry account. To RSVP, report a gift, or sign hearts, a guest must give name, e-mail, and phone (all required). We also process, depending on what they do:
- RSVP answers (household members and the events they will attend).
- Hearts they send, and an optional signed name.
- Gift reports: which item, optional message, and a receipt file.
- Locale used in the browser, so we can show and e-mail them in that language.
Household members listed by a lead guest or by the couple may be name-only (no e-mail or phone). That often includes children. Section 10 describes how we handle that.
Guest e-mail and phone are encrypted at rest. Lookup uses an HMAC of the canonical value, not the plaintext. Names are stored so the couple can see who replied. Receipt files sit in private object storage, not on the public wedding page.
The public wedding page shows couple-authored content. It does not publish guest e-mail, phone, receipts, private gift messages, or signed heart names. Signed names appear to the couple (owner hearts breakdown) and on that guest’s own “signed as” caption. The only guest name on the public page is a gift-list first-name chip (with time) when someone reports a gift.
2. Why we use the data (purposes)
- Operate accounts, authentication, and editor invites.
- Host and publish the wedding page the couple asks us to publish.
- Let guests RSVP, send hearts, and report gifts; show the couple those records.
- Show payment instructions to an identified guest; store unverified receipts for the couple.
- Sell, refund, and explain site time through Stripe.
- Send transactional e-mail (security, RSVP/gift/hearts notices, payment-critical mail) and, for owners, founder onboarding / lifecycle messages with unsubscribe.
- Send product communications to guests after they give contact details, with immediate opt-out (section 9).
- Count visits to the published page and its sections so the couple can see “how many views”, not who visited.
- Keep the Service secure, prevent abuse, and comply with law (including chargebacks and deletion requests).
- Improve reliability (technical logs such as IP or user-agent may appear in infrastructure logs for a short time; we do not use them to build marketing profiles).
We do not sell personal data. We do not use guest contacts to advertise unrelated products.
3. Legal bases (LGPD)
Depending on the processing, we rely on:
- Contract — providing the account, the wedding site, site time, RSVP, gifts, and hearts the user asked for (LGPD art. 7º, V).
- Legitimate interests — keeping the Service secure, counting anonymous-style page views, storing unverified gift evidence for the couple, and operating editor access (art. 7º, IX), balanced against your rights.
- Consent — where we ask for it, including acknowledgement of Terms and Privacy at sign-up when that checkbox is shown, and optional marketing-style owner onboarding enrollment disclosed in those documents (art. 7º, I). You can withdraw consent without affecting processing that has another basis.
- Legal obligation — tax, consumer, and dispute records we must keep (art. 7º, II).
Guests provide data to participate in a couple’s wedding page. The couple must only collect what they need and must not use exported lists for unrelated marketing.
4. Processors and other operators
We use these providers to run We Wil Marry. They process data on our instructions, or as independent controllers for their own payment/auth services where the law treats them that way:
- Clerk — authentication and account profiles
- Upstash Redis — application data and realtime updates
- Vercel — hosting, and Blob storage for images and private gift receipts
- Mux — video upload, transcoding, and playback
- Stripe — site-time payments and refunds (not gifts)
- Resend — transactional and lifecycle e-mail, unsubscribe
- Google Places — wedding-location search when the couple looks up a place
We only list processors we actually use. Gift money does not pass through Stripe or through us.
5. Retention
We keep guest identities, messages, gift reports, receipts, RSVP records, media, and related site data for:
- the site’s active lifetime; and
- one year of deactivated grace after expiry;
then we permanently delete that site’s data in cleanup.
We may delete sooner if you ask, if the couple deletes the site or account, or if the law requires it. Account deletion schedules irreversible deletion of every owned site, including remaining Vitalício time, guest data, billing records, and media.
We may keep a minimal record needed for disputes, chargebacks, or legal obligation after deletion, for as long as that obligation lasts.
Onboarding drafts that are never claimed expire automatically (seven days) and are not used as leads.
6. Cookies and similar technologies
We use:
- Clerk session cookies — to keep owners and editors signed in.
- locale — remembers the interface language.
- Theme preference — remembers light/dark/system in the browser (next-themes).
- wwm_guest_device — an opaque device id for guests (HttpOnly, SameSite=Lax, typically up to 400 days). It is not your name or e-mail.
- wwm_guest_remembered — signed list of guest identities this device has used on wedding sites, so we can ask “still you?” without showing full contacts to the wrong browser.
We mint wwm_guest_device when a guest sends hearts (including unsigned taps) or uses an identity flow (RSVP, gifts, or signing hearts). Unsigned heart taps store a device-bound contributor counter without name, e-mail, or phone. wwm_guest_remembered is written only after an identity is committed. Clerk sign-in does not clear guest cookies.
Published-page view counts do not use those guest cookies. A view ping sends only the slug (or section); it does not store a visitor id, IP, or user-agent in the analytics counters.
You can block cookies in your browser. The wedding page still opens, but sign-in, language memory, unsigned heart counting, and returning-guest recognition may break.
7. International transfers
Redhead Studios is established in Brazil. Several processors host data in the United States (and possibly other countries), including Clerk, Upstash, Vercel, Mux, Stripe, Resend, and Google. When we transfer personal data outside Brazil, we do so to provide the Service, with appropriate contractual and technical safeguards, and you understand that US law may differ from the LGPD.
8. Your rights (LGPD)
If you are in Brazil — and, equivalently, for users elsewhere — you may ask us to:
- Access the personal data we hold about you.
- Correct incomplete or outdated data.
- Delete data that is unnecessary, excessive, or processed unlawfully.
- Port your data to another service when applicable, in a structured format we can reasonably export.
- Oppose processing that relies on legitimate interests, or withdraw consent where consent is the basis.
- Ask for information about the public and private entities with which we share data (the processor list above is the starting point).
How to exercise these rights:
- Owners and editors can edit site content, payment settings, and some account details in the product, and can delete the account in Clerk.
- Guests may ask the couple to correct or remove them from RSVP or gift records, or e-mail us.
- Everyone may e-mail caina@welmarry.com. We may need to verify that the request is yours. We will respond within the LGPD time limits.
Unsubscribing from onboarding or guest product e-mail does not by itself delete your account or guest identity. Section 9 describes e-mail in full.
You may also contact the Autoridade Nacional de Proteção de Dados (ANPD).
9. E-mail communications
Owners. After the first site is created we enroll the account in our onboarding / lifecycle Topic (Resend). That enrollment is disclosed by the Terms and this Policy (and by the Clerk acknowledgement when it is shown). There is no separate Topic checkbox. Every lifecycle message includes an unsubscribe link and List-Unsubscribe headers. Opting out stops that Topic; it does not stop transactional mail (security, RSVP/gift/hearts notices, payment-critical mail). There is no Settings resubscribe control yet (T13). Use the unsubscribe link on a message, or e-mail caina@welmarry.com, to change lifecycle mail.
Guests. After you give name, e-mail, and phone, you may receive product messages about that wedding (for example RSVP or gift confirmation). You are enrolled for those communications when you submit the identity form; there is no extra pre-send checkbox. Every message offers immediate opt-out. Transactional confirmations of an action you just took may still be sent as needed to complete that action.
Sender addresses you may see include We Wil Marry notifications and caina@welmarry.com for founder onboarding. Replies to the founder inbox are monitored; we may not send an individual reply.
10. Children
We Wil Marry is a wedding product for couples, not a service directed at children.
Guests may include minors whom the couple or a lead guest lists in a household (often name only). We do not require a child to create an account. We do not use a minor’s data to market to them.
The couple (and the adult who lists the household) must have a lawful reason to include those names. If you are a parent or guardian and want a minor’s name or other data removed, e-mail caina@welmarry.com or ask the couple to remove them from the guest list.
We do not knowingly allow someone under the age of legal capacity to create a paying owner account. If we learn that has happened, we will delete that account.
11. Security
We use technical and organizational measures appropriate to the data we hold, including:
- Encryption at rest for guest e-mail and phone, with a separate HMAC for lookup so we do not search plaintext.
- Encryption of couple payment-instruction fields.
- Private Blob storage for gift receipts (not a public URL).
- Access checks so only the site’s owner and editors see full guest contacts and receipts.
- Signed, short-lived links when an owner opens a receipt.
No system is perfectly secure. Use of the Service is at your own risk. Never send passwords or card numbers to caina@welmarry.com.
12. Changes to this Policy
We may update this Policy. The effective date at the top is the version we store when you accept. Continued use after a change, or a later acknowledgement, means you accept the new version.
13. Contact
Privacy and LGPD requests: caina@welmarry.com.