Privacy policy (UK GDPR)

Last updated: August 2026

Who is responsible

WedReply is the data controller for the account and wedding data a couple provides, and for the guest records created from it. Guests are data subjects for RSVP data and, where they opt in, for facial matching.

Facial recognition

A reference selfie is used only to find that guest in the wedding's photos. Matching runs on AWS Rekognition in eu-west-2 (London). Explicit consent is required before the selfie is uploaded, and the face vector and every reference image are deleted when the guest asks or when matching is no longer needed.

This is automated analysis of biometric data. A guest may decline it and still use every other part of the service; declining affects nothing except photo matching.

Where the data is held

Hosting, the database and the job queue run on Oracle Cloud in uk-london-1. Photographs are stored in Cloudflare R2 with the bucket in WEUR. Face matching uses AWS in eu-west-2 (London). Transactional email is sent through Resend, payments are handled by Stripe, and Google is used only if a couple chooses to sign in with it.

Your rights

You may ask for access, correction or erasure. A guest can erase their own data from the link in their invitation email — that link carries the token which proves it is their record, so no unauthenticated request can delete anyone's data. Couples can remove a guest from their guest list, which erases the same data.

Retention

RSVP and guest data are kept for the lifetime of the wedding event. Reference selfies and face vectors are deleted on request and are not kept beyond what matching requires. Photographs remain until the couple deletes them or closes the wedding.

Return home