Privacy policy
Last updated: June 2026.
This policy explains what data Wedbridge processes when you create a wedding site or reply to an invitation, why, for how long, and what your rights are. Wedbridge applies the GDPR as the baseline for all of its users, wherever they live.
Data controller
The data controller is ALTIKVA, a French EURL with share capital of 1,000 €, registered with the Nanterre trade and companies register under number 930 987 342, with its registered office at 15 rue Gambetta, 92150 Suresnes, France. ALTIKVA publishes the Wedbridge service. For any question about your data or to exercise your rights, email rgpd@wedbridge.com.
Wedbridge has appointed a data protection contact, reachable at the same address.
Data we process
For a registered couple: email address, first and last name, password (hashed), site content (text, couple photos, ceremony details), payment data (Stripe identifiers, amounts, dates) and technical logs (timestamp, IP address, device type).
For a guest: first and last name, reply status, email and phone if provided, preferences (dietary needs, plus-one), table seating, and the photos and messages you choose to share in the guestbook.
- Allergies and dietary needs are treated as health data: the field is always optional, access is restricted, and the data is deleted 90 days after the wedding.
- We use no advertising cookies, no tracking pixels and no third-party analytics.
Purposes
We process this data for the following purposes:
- Let the couple build and publish their wedding site.
- Let guests reply and interact with the site.
- Collect payments (plans, options and add-ons).
- Preserve the wedding memories for the duration of the chosen plan.
- Communicate with the couple (service emails, reminders, end of retention).
- Measure product usage to improve it, in aggregate and anonymously.
- Detect and prevent fraudulent use.
- Meet our accounting and tax obligations.
Legal bases
Each processing activity relies on a legal basis under the GDPR:
- Performance of the contract, for building the site, payments and account management.
- Legitimate interest, for security, fraud prevention and aggregate audience measurement.
- The guest’s consent, given when they post a photo or a message in the guestbook.
- Compliance with a legal obligation, for the accounting retention of payment records.
Guest data
When a couple uses Wedbridge to collect their guests’ replies, seating plan, photos and messages, the couple and Wedbridge are joint controllers of that data (article 26 of the GDPR).
The couple decides who to invite and informs their guests; Wedbridge provides the tool and guarantees the retention periods and the exercise of rights. When replying, each guest is told how their data is used and that they can request its deletion.
Recipients and processors
We never sell your data. We rely on a small set of processors, bound by a contract that complies with article 28 of the GDPR:
- Google Cloud Platform, for hosting and storage, in the European Union.
- Stripe, for payments (couple identifiers and amounts only, never the photos or guest data).
- A transactional email provider (couple email address and name).
- Cloud Domains, for custom domain names.
Retention periods
We keep data only for as long as needed for the purposes above:
- Couple account and profile: until the account is deleted.
- Billing data: 10 years for accounting obligations, then anonymised.
- High-definition photos: depending on the plan, from 90 days (Free) to several years (Essentiel and legacy plans).
- Guest replies and names: until the site is archived.
- Food allergies: 90 days after the wedding.
- Technical logs containing the IP address: 30 days.
Your rights
Under the GDPR, you have the rights below over your personal data. To exercise them, email us at rgpd@wedbridge.com; we reply within thirty days. You can also lodge a complaint with the CNIL or the data protection authority of your country.
- Access: get a copy of your data. The couple has a self-service export from their dashboard.
- Rectification: correct inaccurate data.
- Erasure: request deletion of your data. The couple can delete their site from the dashboard, with a 30-day grace period.
- Restriction: limit certain processing.
- Portability: get your data back in a reusable format.
- Objection: object to processing based on legitimate interest.
Cookies
Wedbridge only uses cookies that are strictly necessary to run the service. No advertising cookies, no third-party trackers, no external analytics. No consent banner is therefore required.
- wb_session: couple authentication.
- wb_priv_access: private-site access after opening the personal link.
- wb_csrf: protection against request forgery.
- wb_locale: remembers your language.
Security
We put in place appropriate technical and organisational measures:
- Encryption of data at rest (AES-256) and in transit (TLS 1.3).
- Passwords hashed with bcrypt; access tokens never stored in clear text.
- Strict data isolation between couples.
- Restricted admin access, with stronger authentication and audit logging.
- Regular backups and rate limiting on sensitive endpoints.
Hosting and transfers
Your data is hosted in the European Union (Google Cloud, europe-west regions). Some processors such as Stripe may process data in the United States; those transfers are covered by the European Commission’s standard contractual clauses.
Users in francophone Africa get the same level of protection: Wedbridge applies the GDPR as the baseline for everyone, with no downgrade.
Contact and complaints
For any question about this policy or to exercise your rights, email rgpd@wedbridge.com. You can also use our contact page.
If you believe your rights are not respected, you can lodge a complaint with the CNIL in France, or the competent authority in your country, such as the CDP in Senegal or the ARTCI in Côte d’Ivoire.
Updates
We may update this policy to reflect changes to the product or the regulation. The last updated date is shown at the top of this page. For any significant change, we notify active accounts by email.