Privacy Policy
Last updated: September 15, 2026
1. Who We Are
Vowesta is a trade name of RentalTide Inc. The Platform at vowesta.com, api.vowesta.com, wedding websites hosted by us, the Kept photo features inside Vowesta, and our connected-app (MCP) interface are operated jointly by:
- RentalTide Inc., a Canadian corporation based in Ontario, Canada, which is the primary entity responsible for your personal data and our point of contact for privacy regulators.
- RentalTide Inc., a Delaware corporation in the United States, which serves users in the United States.
Together they are "Vowesta," "we," or "us." They are joint controllers of the personal data described in this policy and have agreed between themselves how responsibilities are shared. You may exercise your rights against either of them. The standalone Kept mobile app at kept.film has its own privacy policy.
Our Privacy Officer can be reached at privacy@vowesta.com. This is the person responsible for our compliance with Canada's PIPEDA and Quebec's Law 25, and our contact for data protection matters everywhere else.
2. Our Roles: Controller and Processor
We handle personal data in two capacities:
- As a controller (or "business" under US state laws) for Account Holders' own data, for visitors to vowesta.com, for payment and transaction records we must keep by law, and for the technical data generated when anyone uses the Platform.
- As a processor (or "service provider") for the guest lists, RSVPs, addresses, meal choices, messages, and photos that a Couple collects for their wedding. The Couple decides why and how that data is used and we act on their instructions. Section 14 sets out our processing terms with Couples.
If you are a Guest and want to know how a Couple uses your information, ask them first. You can also contact us and we will help.
3. Personal Data We Collect
Account and identity data
- Email address and, if you use SMS sign-in, mobile phone number
- Passkey public keys and device identifiers, if you register a passkey (the private key never leaves your device)
- Your name, your partner's name, wedding date, venue and location, language preference
- Team members you invite (name, email, role)
Wedding and guest data (processed on behalf of the Couple)
- Guest names, email addresses, phone numbers, mailing addresses, household groupings, and notes the Couple adds
- RSVP responses, plus-ones, meal choices, dietary and accessibility needs (which can reveal health or religious information), song requests, and messages to the Couple
- Seating charts, table assignments, event schedules, and day-of timelines
- Registry items, gift funds, and who gave what
- Raffle ticket purchases and winners
Content
- Photos and images uploaded by Couples or Guests, including photos taken through Kept, and the metadata embedded in them (such as time taken and, if your device includes it, location)
- Wedding website text, design choices, themes, and custom domain
- Prompts you enter into AI features, wedding context sent with them, and the AI's responses
Payment and transaction data
- Amount, currency, date, description, and payment status of gifts, registry contributions, raffle tickets, Kept purchases, and domain fees
- Guest name, email, and optional message attached to a gift or ticket
- Payout details for Couples: bank account information, identity verification documents, and tax information where required
- Card numbers are entered directly into Stripe and never reach our servers. We receive a token, the card brand, last four digits, and Stripe's fraud signals.
Domain registration data
- If you register a domain, your name, address, email, and phone number are supplied to the registrar as ICANN requires, with WHOIS privacy protection enabled where available
Technical and usage data
- IP address, approximate location derived from it, browser and device type, operating system, language, referring page
- Pages viewed, features used, and events such as RSVP submitted or checkout started
- For visits to a wedding website: the date and time, country, region and city (derived from the IP address at the moment of the visit and not stored with it), referring site, device type, browser language, and whether the browser has visited before. The Couple sees these as aggregate counts. IP addresses are not kept.
- Error reports and diagnostic logs, which may include the URL, device details, and account identifier at the time of an error
- Cookies, local storage, and similar technologies described in our Cookie Policy
Communications and support
- Emails and messages you send us, and our records of support sessions, including when a support team member accesses your account with your permission (these accesses are logged)
Connected apps
- If you connect a third-party app through our MCP interface: the app's identity, the permissions you granted, and access tokens
Where it comes from. Most data comes directly from you. Guest data comes from the Couple or from Guests themselves when they RSVP or pay. Payment status and fraud signals come from Stripe. Address suggestions come from Mapbox when you type an address.
Sensitive data. We do not ask for it, but dietary and accessibility fields can reveal health, religious, or similar information. We use this only to pass it to the Couple and their caterer as intended. We do not collect government ID numbers except where required to verify a Couple before a payout, and we do not collect precise geolocation.
4. Why We Use Personal Data and Our Legal Bases
Where the GDPR, UK GDPR, or a similar law requires a legal basis, the basis for each purpose is shown. In Canada, our lawful authority is your consent (express or implied depending on sensitivity) or a permitted exception under PIPEDA and provincial law.
| Purpose | Examples | Legal basis |
|---|---|---|
| Provide the Platform | Accounts, wedding websites, RSVP, seating, registry, invitations, Kept, domains | Contract |
| Sign you in and secure your account | One-time codes, passkeys, session tokens, rate limiting | Contract; legitimate interests (security) |
| Process payments and payouts | Charging Guests, verifying Couples, paying out, refunds, chargebacks | Contract; legal obligation (anti-fraud, anti-money-laundering, tax) |
| Send transactional messages | Codes, receipts, RSVP notifications, domain renewal reminders, service notices | Contract; legal obligation |
| Send invitations and updates on a Couple's behalf | Save-the-dates, invitations, reminders emailed to Guests | Processing on the Couple's instructions |
| Power AI features | Planning assistant, design studio, drafting text | Contract (when you choose to use them) |
| Understand and improve the Platform | Aggregated analytics, feature usage, error monitoring | Legitimate interests; consent where required for analytics cookies |
| Prevent fraud and abuse | Detecting fake weddings, payment fraud, spam, unauthorized access | Legitimate interests; legal obligation |
| Provide support | Answering questions, investigating problems in your account | Contract; legitimate interests |
| Comply with law and enforce our Terms | Tax records, responding to lawful requests, resolving disputes | Legal obligation; legitimate interests |
| Marketing to Account Holders | Occasional product news (you can unsubscribe at any time) | Consent, or legitimate interests where the law allows for existing customers |
We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not use it to train AI models. We do not make decisions with legal or similarly significant effects about you by purely automated means. Stripe applies automated fraud screening to payments; if a payment is declined you can contact us for a human review.
5. Who We Share Personal Data With
We share personal data only as needed to run the Platform, with the following categories of recipients:
| Recipient | Purpose | Data | Location |
|---|---|---|---|
| Amazon Web Services (AWS) | Hosting, database, file storage, content delivery, email delivery (Amazon SES), domain registration (Amazon Registrar) | All Platform data, encrypted at rest and in transit | United States (primary region us-east-1); CloudFront edge locations worldwide |
| Stripe | Payment processing, fraud screening, payouts, identity verification | Payment details, name, email, amount, IP address, payout and verification data | United States, with regional entities in Canada, EU, UK, and elsewhere |
| Anthropic | AI features | Prompts, wedding context you include, responses | United States |
| Twilio | SMS delivery of one-time codes | Phone number, code, country | United States |
| Mapbox | Address autocomplete when you type an address | The address text you type, IP address | United States |
| GeoJS | Approximate location of wedding website visitors, for the Couple's visitor statistics | IP address at the moment of the visit (not retained by us) | United States and worldwide |
| Google Analytics on vowesta.com (IP anonymized, no advertising features); Google Fonts on some wedding website themes | Pseudonymous usage data, IP address, browser details | United States and worldwide | |
| Plausible Analytics | Cookieless, aggregated page analytics (where enabled) | Page URL, referrer, browser and country (IP hashed and discarded) | European Union |
| Sentry | Error monitoring (where enabled) | Error details, URL, device and browser, IP address | United States |
| Connected apps you authorize | Reading or updating your wedding through our MCP interface | Wedding data within the permissions you grant | Depends on the app |
| The Couple | If you are a Guest, everything you submit is shared with the Couple hosting the wedding and their team members | RSVP, contact details, gifts, messages, photos | Where the Couple is located |
| Our affiliates | The two RentalTide Inc. entities and companies under common control share infrastructure and staff | As needed to operate the Platform | Canada, United States |
| Professional advisers, authorities, and successors | Legal, accounting, and insurance advisers; courts, regulators, and law enforcement where required; a buyer or successor if our business is sold or reorganized | As required | Varies |
Each service provider is bound by a contract that limits how it may use personal data. We do not share personal data with advertisers or data brokers, and we do not allow third-party advertising on the Platform. Wedding websites are public to anyone who has the link or guesses the address unless the Couple sets a password, so Guests should assume information shown on a wedding website can be seen by other Guests.
6. International Transfers
We are based in Canada and the United States and our servers are located in the United States. If you use the Platform from anywhere else, your personal data is transferred to and processed in the United States, and may be accessed by our staff in Canada. Our service providers may also process data in other countries where they operate.
Where the law requires a transfer mechanism we rely on:
- EEA and Switzerland: the European Commission's Standard Contractual Clauses (with the Swiss addendum), supplemented by our providers' certifications under the EU-US Data Privacy Framework where they hold them, and transfer impact assessments.
- United Kingdom: the UK International Data Transfer Addendum to the Standard Contractual Clauses, and the UK Extension to the Data Privacy Framework where applicable.
- Canada: contractual protections with each provider as PIPEDA requires; Quebec residents are informed that their data is stored outside Quebec and a privacy impact assessment has been carried out as Law 25 requires.
- Australia, New Zealand, Brazil, Singapore, Japan, South Africa, and other countries: contractual protections and, where required, your consent given when you use the Platform.
You can ask for a copy of the relevant transfer safeguards by emailing privacy@vowesta.com. Please be aware that authorities in the United States and Canada may be able to access personal data under local law.
7. How Long We Keep Personal Data
- Active accounts: kept while the account is open so the Couple can plan, host, and look back on their wedding.
- After the wedding: we may delete or archive wedding data, including guest lists and photos, starting 24 months after the wedding date. We will email the Account Holder before doing so and they can download what they want to keep or ask us to retain it.
- Deleted accounts: when an Account Holder deletes their account, the wedding, website, guest data, photos, Kept films, passkeys, and connected-app authorizations are permanently removed from our live systems immediately. Copies in encrypted point-in-time backups expire within 35 days.
- Transaction records: kept for 7 years after the transaction to meet tax, accounting, and anti-fraud obligations in Canada and the United States, then deleted.
- Sign-in codes: expire after 5 minutes and are deleted when used or replaced.
- Server logs and error reports: kept only as long as needed for security and debugging and purged on a rolling basis; error reports in Sentry are kept for 90 days.
- Analytics: Google Analytics data is retained for no more than 14 months; Plausible data is aggregated and contains no personal data.
- Support emails and legal records: kept as long as needed to resolve the matter and for limitation periods that follow.
8. Your Rights
Depending on where you live you have some or all of the following rights. We extend the core rights of access, correction, and deletion to everyone regardless of location.
- Access: know whether we hold personal data about you and receive a copy, including the categories, sources, purposes, and recipients.
- Correction: fix inaccurate or incomplete data. Most account data can be edited directly in your dashboard.
- Deletion: ask us to erase your data. Account Holders can delete their entire account from their settings, which takes effect immediately.
- Portability: receive your data in a structured, machine-readable format, or have it sent to another provider where technically feasible.
- Restriction and objection: ask us to limit processing, or object to processing based on legitimate interests, including any direct marketing.
- Withdraw consent: at any time, without affecting processing that already happened. Withdrawing consent to essential processing may mean we cannot provide the service.
- Not to be subject to automated decisions: and to ask for human review of any automated decision that significantly affects you.
- De-indexing (Quebec): ask us to stop disseminating your information or to de-index a link to it where the law provides.
- Non-discrimination: we will not deny service, charge different prices, or provide a different level of service because you exercised a right.
- Complain: to us first, and to a supervisory authority at any time (see Section 9).
How to exercise your rights. Email privacy@vowesta.com from the address on your account, or tell us how to verify you if you are a Guest. We may need to confirm your identity before acting and will only use the information you provide for that purpose. We respond within 30 days, or sooner where local law requires (for example 45 days with a possible 45-day extension under US state laws, and one month under the GDPR). If we refuse a request we will explain why and how to appeal. Requests are free unless they are clearly excessive.
Authorized agents. Where local law allows, you may ask someone else to make a request for you. We will ask for proof of their authority and may verify your identity directly.
If you are a Guest. The Couple controls your RSVP and contact details. We will pass your request to them and help them respond, or act directly where we are the controller (for example, your payment records or a photo you took).
9. Regional Information
Canada (PIPEDA and provincial laws)
RentalTide Inc. (Canada) is accountable for personal data under PIPEDA and the substantially similar laws of Quebec, British Columbia, and Alberta. Our Privacy Officer is listed in Section 1. You may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, in Quebec, to the Commission d'accès à l'information. Quebec residents have the additional rights under Law 25 described above, and this policy is available in French on request. We use technology that identifies, locates, or profiles you only as described in the Cookie Policy, and analytics cookies are off by default for visitors whose device indicates they are in Quebec.
United States
If you live in California, Colorado, Connecticut, Delaware, Iowa, Indiana, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, or another state with a comprehensive privacy law, you have the rights to know, access, correct, delete, and port your personal data, to opt out of sale, sharing, targeted advertising, and certain profiling, and to appeal a decision on your request by replying to our response. We do not sell personal data or share it for targeted advertising, and we do not process sensitive personal data for purposes other than providing the service. We honour Global Privacy Control signals as an opt-out of analytics cookies. In the past 12 months we collected the categories of personal information listed in Section 3 for the purposes in Section 4 and disclosed them to the service providers in Section 5. California residents may request this information up to twice a year free of charge.
European Economic Area, United Kingdom, and Switzerland
RentalTide Inc. (Canada) is the controller for GDPR, UK GDPR, and Swiss FADP purposes. We do not have an establishment in the EEA or UK; you can contact us at privacy@vowesta.com. You may lodge a complaint with the supervisory authority in your country of residence or work, with the UK Information Commissioner's Office (ico.org.uk), or with the Swiss Federal Data Protection and Information Commissioner. Where we rely on legitimate interests we have balanced them against your rights; you can ask for details of that assessment.
Australia and New Zealand
We handle personal information in line with the Australian Privacy Principles and the New Zealand Privacy Act 2020. Your data is disclosed to recipients in the United States and Canada as described in Section 6. Complaints may be made to the Office of the Australian Information Commissioner (oaic.gov.au) or the New Zealand Privacy Commissioner (privacy.org.nz).
Brazil
We process personal data under the LGPD on the legal bases described in Section 4 (execution of a contract, compliance with legal obligations, legitimate interests, and consent). Our representative for LGPD purposes is our Privacy Officer at privacy@vowesta.com. You may complain to the Autoridade Nacional de Proteção de Dados.
Other countries
Wherever you are, you can exercise the rights in Section 8 and complain to your local data protection authority. If a law in your country gives you more protection than this policy, we will honour it.
10. Security
We protect personal data with technical and organizational measures appropriate to its sensitivity:
- Encryption at rest (AES-256) and in transit (TLS 1.2 or higher)
- No passwords to steal: one-time codes with attempt limits, and passkeys based on public-key cryptography
- Short-lived signed session tokens
- Private storage buckets served only through our content delivery network
- Input sanitization, Content Security Policy headers, and rate limiting
- Least-privilege access for staff, with logging of any support access to customer accounts
- Card data handled only by Stripe, a PCI DSS Level 1 provider
No system is perfectly secure. If we discover a breach that creates a real risk of significant harm, we will notify affected people and the relevant authorities as the law requires, including within 72 hours to EU and UK supervisory authorities where the GDPR applies. Please report security concerns to security@vowesta.com.
11. Children
Vowesta accounts are for adults. We do not knowingly collect personal data from children under 13 (or under 16 where that is the local threshold) without parental consent. A Guest may include the names and meal choices of children attending with them, which we process on the Couple's behalf. If you believe a child has provided us with personal data directly, contact privacy@vowesta.com and we will delete it.
12. Marketing and Communications
Most messages we send are transactional: sign-in codes, receipts, RSVP notifications, renewal reminders, and important service or legal notices. You cannot opt out of these while you have an account. After you create an account we send a short series of setup tips, and occasional product news, under the existing-relationship rules of CASL and with consent where the law requires it. Every such email includes a one-click unsubscribe link, and you can turn them off from your profile. We comply with Canada's Anti-Spam Legislation (CASL), the US CAN-SPAM Act, and the EU and UK ePrivacy rules. Invitations and reminders sent to Guests are sent on the Couple's behalf and at their request.
13. Cookies, Analytics, and Tracking Signals
Our Cookie Policy lists every cookie and local storage item we use. In summary: we use essential storage to keep you signed in and remember your language, Google Analytics with IP anonymization on vowesta.com, and no advertising cookies. We honour Global Privacy Control and Do Not Track signals by turning off analytics cookies, and analytics cookies are off by default for visitors whose device indicates they are in Europe or Quebec, until they opt in on the Cookie Policy page.
14. Data Processing Terms for Couples
This section applies between Vowesta and each Account Holder for the Guest data they collect through the Platform, and is intended to meet Article 28 of the GDPR and UK GDPR and equivalent requirements elsewhere.
- Instructions. We process Guest data only to provide the Platform as you configure it, and as required by law. Your use of the Platform's features is your documented instruction.
- Confidentiality. Our staff who can access Guest data are bound by confidentiality obligations.
- Security. We apply the measures in Section 10.
- Sub-processors. You authorize the providers listed in Section 5. We will update that list on this page at least 30 days before adding a new sub-processor that handles Guest data, and you may object by deleting your account.
- Assistance. We help you respond to Guests' requests, security incidents, and any data protection impact assessment you need to carry out.
- Breach notification. We notify you without undue delay after becoming aware of a personal data breach affecting your Guest data.
- Deletion and return. You can request an export of Guest data at any time, and all Guest data is deleted when you delete your account or the wedding.
- Audit. We provide the information reasonably needed to demonstrate compliance, and a signed copy of these terms or our standard data processing agreement on request at privacy@vowesta.com.
- Transfers. Guest data is processed in the United States under the safeguards in Section 6.
15. Changes to This Policy
We may update this policy as the Platform, our providers, or the law change. For material changes we will notify Account Holders by email or through the Platform before the change takes effect. The "Last updated" date at the top shows the current version, and previous versions are available on request.
16. Contact Us
- Privacy Officer: privacy@vowesta.com
- Security: security@vowesta.com
- RentalTide Inc. (Canada), doing business as Vowesta, Ontario, Canada
- RentalTide Inc. (Delaware), doing business as Vowesta, Delaware, United States