Last updated · Oct. 9, 2026
Privacy Policy
1. Controller
The controller responsible for data processing in connection with Nuptria, within the meaning of the General Data Protection Regulation (GDPR), is:
Byteweb OÜSepapaja tn 6, 15551 Tallinn, Estonia
hello@nuptria.com
2. Hosting and server log data
Nuptria is hosted on a virtual server provided by Hostinger, located within the European Union. Each time Nuptria is accessed, the server automatically records technical data required to deliver the page and keep it secure: the requesting device's IP address, the date and time of access, the page requested, the browser type and version, and the referring page. This data is processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in operating a secure and functional application, and is not combined with any other data source.
3. Cookies and local storage
Nuptria itself sets only strictly necessary cookies: a session cookie (sessionid), a security cookie for CSRF protection (csrftoken), a cookie that remembers your chosen language (django_language), and two cookies that remember your answers to our cookie banner (nu_ads_consent and nu_analytics_consent). None of these require consent (§ 25(2) TDDDG; Art. 6(1)(f) GDPR). Google Analytics, the Meta Pixel and their cookies are only loaded if you allow them in that banner — see sections 10 and 11.
Your browser's local storage is used only for purely functional purposes — for example, remembering whether the sidebar is collapsed, or that you've already dismissed the waiting-list popup. This information never leaves your browser.
4. Account data
When you create a Nuptria account, we process your name, email address, password (stored only as a hash), your wedding date, and your preferred language, in order to provide you with the service (Art. 6(1)(b) GDPR — performance of a contract). If you invite a partner to your account, this information is also visible to them.
5. Guest & RSVP data
When you, as a couple, add guests, or your guests respond via their personal RSVP link (no account is required for this), the following data is processed: names, email address, phone number, address, meal choice, allergy or dietary notes (which may constitute health-related data under Art. 9 GDPR), and free-text notes. The couple who owns the account is the controller of this guest data; Byteweb processes it on their behalf to provide the invitation and RSVP feature. Guests with questions about their own data should contact the couple who invited them, or reach out to us directly.
6. Billing (Stripe)
When you upgrade to Nuptria Premium, your email address is shared with Stripe to create a Checkout session. All payment data is handled entirely within Stripe's own hosted Checkout and Customer Portal pages — card details never reach our servers. For more information, see Stripe's Privacy Policy.
7. Email (Resend)
Account verification, password reset, invite, welcome, RSVP reminder, and waiting-list confirmation emails are sent via our email provider, Resend. Your email address and first name are shared with Resend solely for the purpose of delivering these emails. Resend also tells us whether each email was delivered, bounced or marked as spam; we keep that status together with the recipient and subject so we can look into delivery problems.
Emails you send to an address ending in @nuptria.com are also received via Resend. We store them in our own database — including the sender, recipients, subject, content and the names of any attachments — so our team can read and answer them; the attachments themselves remain with Resend. Our replies are sent via Resend and stored the same way. When a new email arrives, our team is notified in a private group chat on Telegram; this notification contains only the sender's address and the subject line, never the content of the email (see Telegram's Privacy Policy). The legal basis is our legitimate interest in answering your messages (Art. 6(1)(f) GDPR) or, where your email concerns your account, the performance of our contract with you (Art. 6(1)(b) GDPR).
8. Addresses & maps (Google Maps)
On the Events and Timeline pages, the first time you use an address field we ask via a banner whether you're okay with sending your input to the Google Maps Platform for suggestions. If you agree, your input is sent to the Places Autocomplete and Distance Matrix services (Google Ireland Limited) to provide address suggestions and travel-time estimates; this involves transferring data to Google's servers, including in the United States, with the EU-U.S. Data Privacy Framework serving as the safeguard for that transfer (Art. 44 et seq. GDPR). If you decline, or don't respond, no Google script is loaded at all, and address suggestions and travel-time estimates stay off. You can reset your choice at any time via our Cookie Policy.
9. AI assistant (Nuptria AI, OpenAI)
Premium workspaces can use Nuptria AI to turn pasted text into suggested entries and to answer questions about their own plan. When you send a message, we transmit it to OpenAI together with the context needed to answer it: the names and dates of your events, your budget category names, the recent messages of the conversation and, where a question or a guest reply requires it, the names of matching guest parties and their members, RSVP counts, open tasks, expenses and schedule items. Guests' email addresses, phone numbers, postal addresses, meal choices and allergy notes are never sent unless you paste them into a message yourself; please paste health information such as allergies only if the guest has agreed to share it with you. OpenAI processes this data on our behalf as a processor under a data processing agreement and does not use it to train its models. Nothing is added to your plan until a member of your workspace saves a suggestion. The legal basis is the performance of our contract with you (Art. 6(1)(b) GDPR). Conversations are visible to both members of the workspace, can be deleted at any time and are deleted automatically after 90 days.
10. Advertising measurement (Meta Pixel and Conversions API)
We advertise Nuptria on Facebook and Instagram. To measure whether these ads work and to show them to people likely to be interested, we use the Meta Pixel and the Meta Conversions API, provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland — but only if you allow advertising in our cookie banner. The legal basis is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). If you decline, or don't respond, no Meta script is loaded and nothing is sent to Meta.
With your consent, your browser loads a script from Meta that sets the cookies _fbp and, if you arrived through a Meta ad, _fbc. It sends Meta the pages you visit, your IP address, browser and device information, and these events: page views, starting a checkout, completing sign-up, and buying Premium or AI credits (including the amount). On our public pages (homepage, pricing, sign-up and legal pages), it also reads the page's title, description and published details such as our prices, so Meta can understand what Nuptria offers; inside the signed-in app it doesn't. If you're signed in, it also sends a hashed (SHA-256) version of your email address and a pseudonymous ID, so Meta can match the events to a Meta account. Our server additionally sends the sign-up and purchase events directly to Meta (Conversions API) with the same details, including your hashed email address, so they're counted even if a browser extension blocks the script. It does this only if you consented in that browser, and both routes share an event ID so Meta counts each event only once. For a purchase, these details are stored with the Stripe checkout session so our server can report the purchase once Stripe confirms the payment; our server keeps them only until the event has been sent, for at most 30 days. We never send Meta the contents of your wedding planning, such as guests, budget or seating.
We and Meta are joint controllers for collecting this data and transmitting it to Meta (Art. 26 GDPR); our arrangement is Meta's Controller Addendum. Meta alone is responsible for what happens afterwards, including combining the data with your Meta account and using it for its own purposes, as described in Meta's Privacy Policy. Meta may transfer data to Meta Platforms, Inc. in the United States, relying on the EU-U.S. Data Privacy Framework. You can withdraw your consent at any time, with effect for the future, via "Change my choice" in our Cookie Policy; this deletes the Meta cookies from your browser and stops any further transfer.
11. Usage analytics (Google Analytics)
To understand how people find Nuptria and which pages and features couples use, we use Google Analytics 4, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland — but only if you allow analytics in our cookie banner. The legal basis is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). If you decline, or don't respond, no Google Analytics script is loaded and nothing is sent to Google.
With your consent, your browser loads a script from Google that sets the cookies _ga and _ga_<ID>. It sends Google the pages you visit, the website that referred you, your IP address, browser and device information, and events such as page views, scrolling, clicks on links to other websites and starting a checkout. Page addresses are shortened before they're sent: IDs and codes in the address are replaced by placeholders, and everything after the "?" is removed except campaign tags such as utm_source. If you're signed in, it also sends a pseudonymous ID derived from your account, so that visits from your phone and your laptop count as one person; this ID doesn't reveal your name or email address. Our server additionally sends the sign-up and purchase events (including the amount) to Google via the Measurement Protocol, linked to the same browser ID, so they're counted even if a browser extension blocks the script. It does this only if you consented in that browser. For a purchase, these IDs are stored with the Stripe checkout session so our server can report the purchase once Stripe confirms the payment; our server keeps them only until the event has been sent, for at most 30 days. Google Analytics doesn't log or store IP addresses. We've switched off Google signals and ad personalisation, so the data isn't used for advertising, and Google keeps it for 14 months. We never send Google the contents of your wedding planning, such as guests, budget or seating.
Google processes this data on our behalf as a processor (Art. 28 GDPR) under its data processing terms. Google may transfer data to Google LLC in the United States, relying on the EU-U.S. Data Privacy Framework. You can withdraw your consent at any time, with effect for the future, via "Change my choice" in our Cookie Policy; this deletes the Google Analytics cookies from your browser and stops any further collection.
12. Waiting list
If you join our pre-launch waiting list from the homepage, we store your email address to notify you once Nuptria is available. This processing is based on your consent, given by submitting the form (Art. 6(1)(a) GDPR).
13. Data retention
Account and guest data is kept for as long as the account exists, and is deleted upon request or account deletion. Waiting-list email addresses are kept until launch or until you request their deletion. Your answer to the cookie banner is stored for 12 months, after which we ask again; Meta's cookies _fbp and _fbc expire after 3 months, and Google Analytics' cookies _ga and _ga_<ID> after 2 years. Emails in our mailbox are kept for as long as we need them to handle the correspondence and to meet statutory retention obligations for business correspondence, and are then deleted.
14. Your rights
Under the GDPR, you have the right to request access to, correction of, or deletion of your personal data, to restrict or object to its processing, and to data portability. You also have the right to lodge a complaint with a data protection supervisory authority. To exercise any of these rights, contact us at the address above.
15. International data transfers
Nuptria's hosting stays entirely within the EU. Using Resend, Stripe, Google Maps, Nuptria AI (OpenAI) and, if you consent, Google Analytics and the Meta Pixel may involve transfers of data to the United States, each relying on recognized safeguards, such as the EU-U.S. Data Privacy Framework or the EU Standard Contractual Clauses. The Telegram notifications about new emails (sender address and subject) are processed on Telegram's servers, which may be located outside the EU.
16. Children
Nuptria is intended for adults planning their wedding and is not directed at, or intended for use by, children.
17. Changes to this policy
We may update this privacy policy from time to time. The current version is always available at this address, with the "last updated" date shown at the top of this page.