Privacy Policy
Last updated: 2 August 2026
Introduction
This policy explains how Amore in Vespa collects, uses and protects personal data when you plan your wedding with us. It covers both your own account data and the guest data you manage on the platform.
Who Is Responsible
Amore in Vespa is the data controller for your account data. You can reach us at any time using the details below.
Amore in Vespa
The Netherlands
privacy@amoreinvespa.com
What We Collect
We collect three kinds of information: what you give us, what we record automatically, and what you upload about your guests.
Information you give us
- Your name and email address when you create an account.
- Wedding details such as the date, the venue and the names of the couple.
- Photos, text and design choices for your wedding website.
- Payment records when you upgrade to a paid plan.
Guest information
When you add guests we store the details you provide — names, contact details, dietary requirements, plus-ones and RSVP responses. You decide what to collect; we process it on your behalf.
Information we collect automatically
- Log data such as IP address, browser and device type.
- Usage data such as which features you open and when.
- Cookies and similar technologies needed to keep you signed in.
Legal Basis for Processing
Under the GDPR we rely on the following grounds:
- Performance of a contract — to provide the service you signed up for.
- Legitimate interests — to secure, maintain and improve the platform.
- Consent — for optional cookies and marketing emails, which you can withdraw at any time.
- Legal obligation — to keep records required by tax and accounting law.
How We Use Data
We use personal data to run the platform and improve it:
- To create and maintain your account.
- To publish your wedding website and deliver invitations and RSVPs.
- To provide AI-assisted planning and seating suggestions.
- To process payments and send transactional emails.
- To keep the service secure and prevent abuse.
- To understand which features are used so we can improve them.
Guest Data and Your Responsibilities
For guest data you are the controller and we are your processor. You decide what to collect, and you are responsible for having a lawful basis to share it with us — usually the legitimate interest of organising your wedding. We process guest data only on your instructions, keep it confidential, and delete it when you close your account.
Who We Share Data With
We do not sell personal data. We share it only with the service providers who help us run the platform:
- Supabase — database, authentication and file storage.
- Netlify — website hosting and content delivery.
- Stripe — payment processing.
- Resend — transactional, invitation and RSVP emails.
- Twilio — SMS invitations, where you choose to send them.
- OpenAI, Anthropic and Perplexity — AI planning and seating assistance, where you use those features.
Each provider acts under a data processing agreement and may use the data only to deliver their service to us.
International Transfers
We host our infrastructure in the European Union wherever possible. Where a provider processes data outside the EEA, the transfer is covered by the European Commission's Standard Contractual Clauses or by an adequacy decision.
How Long We Keep Data
We keep personal data only as long as we need it:
- Account data — for as long as your account is open, and up to 30 days after you delete it.
- Wedding and guest data — until you delete it or close your account.
- Payment records — seven years, as required by Dutch tax law.
- Log data — up to 12 months.
Your Rights
Under the GDPR you have the right to:
- Access the personal data we hold about you.
- Correct data that is inaccurate or incomplete.
- Delete your data — the right to be forgotten.
- Restrict or object to certain kinds of processing.
- Receive your data in a portable, machine-readable format.
- Withdraw consent at any time, without affecting processing that already happened.
- Lodge a complaint with a data protection authority.
To exercise any of these rights, email privacy@amoreinvespa.com. You can also complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or to the authority in your own country.
Cookies
We use cookies that are strictly necessary to keep you signed in and remember your language, plus optional analytics cookies that run only if you accept them. You can change your choice at any time on the cookie preferences page.
How We Protect Data
Data is encrypted in transit and at rest. Access is restricted by row-level security so one account cannot reach another's data, and administrative access is limited to the people who need it. We review our security practices regularly, though no online service can ever be completely secure.
Changes to This Policy
We update this policy when our practices or the law change. The date at the top shows the current version, and we will tell you about material changes by email or in the app.
Contact Us
Questions about privacy or about your data? Email privacy@amoreinvespa.com and we will respond within 30 days.