Privacy
The Wedding Library holds some of the most personal information anyone will ever type into a website: who they are marrying, who they are inviting, what those people can and cannot eat, and what the day cost. This page says exactly what we hold, why, who else sees it, and how to make it go away.
Last updated 11 September 2026
Who we are
The Wedding Library is operated by Godji Tech, a company based in South Africa. It is a wedding planning service, a directory of wedding businesses, and a shared photo album — reachable as a website at weddings.godjitech.com and as an app for iPhone and Android. This policy covers both; they are the same service reading the same database.
Couples, guests and wedding businesses use it from wherever they are. Two laws are named throughout this page because they are the two we are directly answerable to: POPIA, South Africa’s Protection of Personal Information Act, because that is where we operate from, and the GDPR, because we hold information about people in Europe. They stand equally here. If you are somewhere else, the rights described below are written to be the ones you have too — most privacy laws now grant something close to the same list, and we do not run a shorter version of this service for people whose regulator is further away.
For anything on this page, write to privacy@godjitech.com.
Three kinds of people, and who is responsible for each
This matters more here than in most services, because most of the personal information on this platform is not typed in by the person it describes.
- Account holders — couples planning a wedding, and the businesses they hire. You signed up, and we are the responsible party for what you give us.
- Guests — the people on a couple’s list. You did not sign up and probably never visited this site. The couple entered your details, the couple decides what happens to them, and we hold them on the couple’s behalf. In the language of POPIA the couple is the responsible party and we are the operator; the GDPR calls the same two roles controller and processor. If you want to be removed from a list, the fastest route is to ask the couple — but you can write to us and we will act.
- Visitors — anyone reading a public wedding page or browsing vendors without an account.
What we collect
If you have an account
Your name, email address and password, and a phone number if you add one. Passwords are hashed by our authentication provider and are never visible to us. If you are a couple: your partners’ names, your wedding date, venue and address, your story and schedule, your budget, and — if you set up a registry — your bank account name, number and branch or routing code. If you are a business: your trading name, category, description, contact details, prices, portfolio images, and anything you submit when asking to be verified.
About your guests
Names, and where the couple has them, email addresses and phone numbers. RSVP status and headcount. Table assignments. Song requests. And dietary notes — which we treat carefully, because an allergy or a religious requirement is special personal information under POPIA section 26, and a special category of personal data under GDPR Article 9. Most privacy laws single out health and religion the same way. Be aware that the catering export exists precisely so a couple can hand this list to a caterer; that is a real disclosure to a third party, and it is the couple’s to make.
Photographs and video
The photos uploaded to a wedding album, together with who uploaded each one and when. Wedding album photos are stored in a private bucket: they are not on a public URL, and every view is a short-lived signed link issued only to someone who has proved they belong to that wedding or is holding the couple’s invitation.
Photos added through the mobile app are re-encoded before they are uploaded, which strips the embedded metadata — including the GPS coordinates a phone camera writes into every picture. Photos added through a browser’s file picker are not, so a photo uploaded that way may still carry the location it was taken. Vendor portfolio images are public by design, since the point of them is to be seen.
Messages and enquiries
When a couple contacts a business, we keep the enquiry and the conversation that follows, including the name, email and phone number given with it.
We record the address, subject line and outcome of every email we send — invitations, reminders, quote notifications, daily digests. We do not keep the body.
Visits to public wedding pages
We count views and shares on published weddings. The counter uses a key made by hashing the visitor’s IP address, browser and today’s date together — so it can tell two refreshes apart on the same day and cannot connect anything across two days, by construction. The IP address itself is never stored.
What we do not collect
This list is as much a part of the policy as the one above, and each line is a decision rather than an omission.
- No card or payment details, ever. There is no payment processor connected to this service. Registry contributions and vendor payments are recorded here after the money has moved somewhere else; we never see the transaction.
- No analytics, advertising or tracking software. There is no Google Analytics, no Meta pixel, no Mixpanel, no Sentry, no attribution SDK, nothing from an ad network. The app contains no advertising identifier and will never show you Apple’s tracking prompt, because there is nothing to ask you about.
- No identity documents. Business verification asks for a registration number and a link; we do not collect or store copies of IDs or passports.
- No device identifiers or push tokens are collected today. If that changes, this page changes first.
- No selling of anything, to anyone. Your data is not a product and we do not share it for anyone else’s marketing.
Who else sees it
We use a small number of companies to actually run the service. They process data on our instructions and for nothing else.
- Supabase — the database, file storage and sign-in behind everything here.
- Netlify — hosts the website, so it handles every request to it.
- Our email provider — delivers the mail we send on your behalf.
- Expo — builds and updates the mobile app. It receives information about the app version on a device, and no personal data from inside it.
- Apple and Google — distribute the app through their stores.
- Google Fonts — the website loads its typeface from Google’s servers, which means your browser contacts Google and Google sees your IP address when you load a page.
We will also hand over information if the law requires it — a court order, a lawful request from an authority — and we will tell you unless we are forbidden from doing so.
Where it is stored, and where it crosses a border
Our database and files sit on infrastructure operated by Supabase, and the website runs on Netlify. Both are international providers running in data centres in several countries, and we are based in South Africa. Whatever country you are in, your information will cross a border at some point — for most of the people using this service, it already has.
Those transfers are made under the contractual protections the law requires of them: POPIA section 72 where information leaves South Africa, and the European Commission’s standard contractual clauses where it leaves the EEA or the UK. In both cases the obligation is the same in substance — the provider on the other end is bound to a standard of protection comparable to the one you started with, and to using the data only on our instructions.
If you would like to know which providers hold what, and where, write to privacy@godjitech.com and we will tell you.
What is visible to other people
Some of this service is public on purpose. The parts worth knowing:
- A wedding page shared by link is readable by anyone holding that link, whether or not they were invited. The link is unguessable, but it is not a password — it gets forwarded on WhatsApp.
- That includes your registry bank details. If you add bank details so guests can send a gift, anyone with your wedding link can see the account number and branch or routing code. Add them only if you are comfortable with that, and remove them after the wedding.
- A wedding listed in the public library appears in our feed and can be found by search engines.
- A published vendor listing — including the business phone number and email — is public, as a directory listing has to be.
How long we keep it
- An account and everything in it: until you delete it.
- A deleted wedding goes to a bin for 30 days, so an accident can be undone, and is then destroyed along with its photographs.
- An archived guest stays until the couple purges them, which takes effect immediately.
- Messages between a couple and a business cannot be deleted. A conversation belongs to both sides, and removing half of it would leave the other party with a record they cannot make sense of. If you delete your account, your name is removed from those messages but the text remains.
- Email records and business verification requests are kept as an audit trail.
Deleting your account
You can delete your account yourself, at any time, and you do not need to ask us. In the app: More → Your account → Delete my account. It is immediate and it cannot be undone.
Deleting your account removes your profile, your wedding and its website, your guest list, your budget, your registry and every photo in your album — or, for a business, your listing, packages, portfolio, enquiries and bookings. If someone else is an owner of your wedding, the wedding stays with them and only your account is removed. The one exception is messages, for the reason above.
Your rights
Under POPIA and under the GDPR alike — and, in substance, under most other privacy laws, including the UK GDPR, Brazil’s LGPD, Australia’s Privacy Act, Nigeria’s NDPA, Kenya’s Data Protection Act and the California privacy laws — you may ask what we hold about you, ask for a copy in a portable form, have mistakes corrected, have your information deleted, object to how we are using it, and withdraw consent you have given. We do not ask which country you are in before answering any of that. Write to privacy@godjitech.com and we will answer within 30 days.
If you are a guest and want off a list: ask the couple, who can remove you in a tap, or write to us and we will contact them and act. You do not need an account to ask.
If you are not satisfied with how we have handled something, you can complain to a regulator, and you do not need our permission to do it. In South Africa that is the Information Regulator, at inforegulator.org.za. In the EEA it is the data protection authority of the country you live in; in the UK it is the Information Commissioner’s Office. Elsewhere it is whichever authority supervises privacy where you are. If you cannot work out which one that is, write to us and we will tell you who it is rather than send you looking.
Keeping it safe
Every table in our database is protected by row-level security, which means the rules about who may read what live in the database itself rather than in a screen that might forget to check. Wedding photographs are in a private store behind short-lived signed links. Connections are encrypted. On a phone, your sign-in is held in the device keychain. None of this makes a breach impossible, and if one happens that puts you at risk we will tell you and the regulators we answer to — the Information Regulator in South Africa, and the relevant supervisory authority for anyone affected in Europe or the UK — within the deadlines each of them sets.
Children
This service is for adults planning and supplying weddings. We do not knowingly collect information from anyone under 18 who is holding an account. Children do appear on guest lists and in wedding photographs; that information is entered and controlled by the couple, and we act on their instructions.
Changes
When this policy changes we will update the date at the top, and for anything significant we will tell account holders by email before it takes effect.