Privacy Policy
Last updated: August 26, 2026
This Privacy Policy explains what information The Veil collects, why we collect it, who we share it with, and the choices you have. It applies to The Veil mobile app, our website at theveilwedding.com, and related services (together, the “Service”).
We have tried to write this in plain language rather than boilerplate. If anything here is unclear, please email us — we would rather explain it than have you guess.
Who we are
The Service is operated by Wilt Interactive LLC, 113 Chestnut St, Mifflinburg, PA 17844, United States. For the purposes of the UK and EU General Data Protection Regulation, Wilt Interactive LLC is the data controller for personal information processed through the Service, except as described in “Information about your guests” below.
Information we collect
We collect the following categories of information.
Information you give us directly
- Account information — your name, email address, and password credentials. Passwords are handled by our authentication provider and are never visible to us in plain text.
- Profile information — display name, username, profile and banner photos, and any bio you choose to add.
- Wedding planning content — couple names, wedding date and location, budgets, vendor notes, checklists, DIY projects, floor plans and seating charts, itineraries, vows, your couple story, attire guidelines, and music selections.
- Guest list information — the names, phone numbers, party sizes, group assignments, RSVP status, dietary notes, and seating assignments of people you invite. See “Information about your guests” below.
- Registry and shipping information — registry items and, if you provide one, a shipping address for gifts.
- Messages and posts — direct messages, group wedding chat, social posts, comments, and hashtags you create in the app.
- Support and feedback — anything you send us through the in-app feedback form, including an optional screenshot.
Information you allow us to access from your device
Each of these requires your permission, is requested only when you use the related feature, and can be revoked at any time in your device settings.
- Contacts — used only to let you select people to invite to your wedding. We access contacts at the moment you use the invite feature; we do not upload or store your full address book.
- Photos and camera — to add images to your wedding vision, DIY projects, social posts, profile, and feedback screenshots, and to scan invite QR codes.
- Location — where the feature is available, to show nearby venues and vendors and to power map views. We do not track your location in the background.
Information collected automatically
- Identifiers — your account ID, and a push notification token for the device if you enable notifications.
- Purchase information — your subscription status and purchase history, and records of registry contributions.
- Product usage — first-party analytics events describing which features you use (for example, creating a wedding or sending an invite), the platform you are on, and your subscription tier. We do not use third-party advertising or cross-app tracking SDKs.
- Website analytics — our website uses Vercel Analytics and Speed Insights, which collect aggregate, privacy-focused usage measurements.
We do not collect health or fitness data, biometric data, browsing history from outside the app, credit information, or advertising identifiers for tracking.
How we use your information
We use the information above to:
- Create and secure your account, and authenticate you.
- Provide the planning features you use, and sync your data across your devices.
- Let you collaborate with a partner, secondary host, or co-planners, and share the appropriate wedding information with the people you invite.
- Deliver invitations, RSVPs, and guest passports.
- Process subscriptions and registry contributions, and provide receipts.
- Send notifications you have enabled, and transactional messages about your account.
- Respond to your support requests and feedback.
- Detect, investigate, and prevent fraud, abuse, and violations of our Terms, including reviewing reported content.
- Understand which features are used so we can improve the product.
- Comply with legal obligations.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
AI features
Some features — including the AI checklist, music curation, DIY suggestions, and content moderation — send the relevant content you have entered to a third-party AI provider (currently OpenAI) so it can generate a response. All such requests are routed through our own servers; the provider receives only the content needed to fulfil the request, and does not receive your account credentials.
We do not use your personal information to train third-party AI models, and our provider agreement does not permit your content to be used for that purpose. If you would prefer not to use AI features, you can simply not use them — the rest of the Service works without them.
Connecting Spotify
Connecting Spotify is optional, and the music curator works without it. If you do connect it, Spotify asks you to approve exactly two permissions, and we use both:
- Seeing your top artists and tracks. We read your most-played artists and tracks, and the genre tags Spotify has attached to those artists, so the curator can suggest music that sounds like yours rather than generic wedding music.
- Creating a private playlist. Used only when you choose to export a finished playlist back to your Spotify account. We cannot read your existing playlists or modify anything we did not create.
Your Spotify sign-in stays on your device. The access token Spotify issues is never sent to our servers. Your device contacts Spotify directly, and only the resulting list of artist names, genre tags and track titles is sent onward — alongside your questionnaire answers — to generate a suggestion.
We do not store your listening data. It is held in memory for as long as the music screen is open, used to make each request, and never written to our database. Closing the screen discards it. You can disconnect at any time from your Spotify account settings, under Apps, which immediately revokes our access.
Service providers we use
These providers process personal information on our behalf, under contract, and only for the purposes we specify:
- Supabase — database, authentication, file storage, and backend functions.
- Stripe — payment processing for registry cash funds and web subscriptions.
- RevenueCat — subscription management for in-app purchases.
- Apple and Google — app distribution and in-app purchase billing.
- OpenAI — AI-generated features and content moderation, as described above.
- Google Maps Platform / Places — venue and vendor search and map features.
- SerpAPI and the Amazon Associates Program — registry product search and links.
- Resend — transactional and moderation email.
- Expo — push notification delivery.
- Notion — internal triage of feedback you submit through the app.
- Vercel — website hosting and privacy-focused analytics.
- Apple (iTunes Search) — looking up song titles, artwork and previews. Anonymous: it receives a search term and nothing that identifies you.
As an Amazon Associate, we may earn commission from qualifying purchases made through registry links. This does not change the price you pay.
Payments, subscriptions, and cash funds
We never see or store your full card number. Card details are entered directly into Stripe, Apple, or Google and are handled by them under their own privacy policies. We receive only confirmation of the transaction and limited details such as the last four digits, card brand, and amount.
If you receive registry cash funds, Stripe Connect will collect identity and payout information from you directly in order to meet financial regulations. That information is provided to Stripe, not to us.
Information about your guests
When you add someone to your guest list, you provide us with their personal information — typically their name, and sometimes a phone number and dietary notes. You are responsible for making sure you have the right to share that information with us, and for telling the people on your list that you are using The Veil to plan your event.
For that guest data, you act as the data controller and we act as your processor. We use guest information only to operate your event: sending invitations, tracking RSVPs, managing seating, and providing guest passports. We do not use it to market to your guests.
Guests who claim a passport create their own account, at which point the information in that account is governed by this policy directly. A guest can remove their own passport at any time.
Businesses and wedding vendors
Some of the businesses on The Veil have never signed up for it. When a couple searches for a vendor we do not yet have a profile for, we create an unclaimed listing so their enquiry has somewhere to go. That listing is built from information the business already publishes: its name, address, phone number, categories and photos, drawn from Google Places, together with an email address only where the business publishes one on its own website.
We do not guess at contact details.We look for an address the business has chosen to publish — a mailto:link or a visible address on its homepage or contact page — in the same way a person would by clicking “Contact”. If there isn’t one, we do not construct an address from a pattern, and no email is sent.
Where we do find one, we email the business once to tell it that a couple asked for it by name, with that couple’s wedding date, guest count band and budget band. We keep a record of which addresses we have contacted so that we do not contact them repeatedly, and a suppression list of addresses that have asked us to stop.
Every one of those emails carries a one-click unsubscribe link and our postal address. Using it removes the address permanently, without any account, sign-in, or reply — and the removal is by address, so one “stop” covers every listing that address serves. You can also write to privacy@theveilwedding.com and we will remove it by hand.
We never sell, rent, or resell a business’s details, and we never sell a couple’s enquiry as a lead — not to that business’s competitors, not to anyone. A vendor hears from us because one couple asked for them, and that enquiry goes to them alone.
A business that claims its listing becomes an account holder, and from that point the rest of this policy applies to it directly: the storefront and portfolio it publishes, its availability, the enquiries and messages in its inbox, invoices and payment schedules it issues, documents it sends for signature, and its Stripe Connect payout account. A business can ask us to remove an unclaimed listing entirely by writing to the address above.
Electronic signatures
When a vendor sends you a document to sign, and you sign it, we record what is needed for that signature to mean something later: your typed legal name, the signature you draw, the date and time from our servers, your confirmation that you agreed to sign electronically, and the network (IP) address and browser or device the signature was sent from. We also store a cryptographic fingerprint of the exact file you signed.
We collect the network address and device because they are what makes a signature attributable to a person if the agreement is ever disputed. This is standard practice for electronic signing, and it is the reason an electronic signature holds up. We tell you this before you sign, not afterwards.
This information is shared with the vendor who sent you the document, and with nobody else. It is never used for advertising, never used to build a profile of you, and never sold. The vendor sees a plain summary by default; the exact address and device are shown only if they explicitly open the full audit trail.
We keep a signature record for as long as the agreement it belongs to could reasonably be relied on or disputed, and for at least the period required for contract claims where you live. You can ask us about a specific record at any time using the contact details below. Deleting your account does not automatically delete a signed agreement, because the other party has their own legitimate interest in the record of what was agreed.
Legal bases for processing (EEA/UK)
If you are in the European Economic Area or the United Kingdom, we process your personal data on these bases:
- Performance of a contract — to provide the Service you signed up for, including collaboration, invitations, and subscriptions.
- Legitimate interests — to secure the Service, prevent fraud and abuse, moderate reported content, and improve our features. We balance these against your rights.
- Consent — for device permissions such as contacts, photos, location, and push notifications, and for optional features. You may withdraw consent at any time.
- Legal obligation — where we must retain or disclose information to comply with the law.
How long we keep information
We keep your information for as long as your account is active. When you delete your account, we delete your account data as described below. Some records are kept longer where we are required to — for example, transaction records needed for tax, accounting, and anti-fraud obligations, and records related to a legal claim.
Backups are retained on a rolling basis by our infrastructure provider and are overwritten in the normal course.
Your rights and choices
Depending on where you live, you may have the right to:
- Access the personal information we hold about you, and request a copy.
- Correct information that is inaccurate or incomplete.
- Delete your personal information.
- Object to or restrict certain processing.
- Withdraw consent you previously gave, without affecting processing already carried out.
- Port your data to another service.
- Not be discriminated against for exercising any of these rights.
You can exercise most of these directly in the app: your profile and wedding data are editable at any time, you can export your data from Settings, and you can delete your account permanently. For anything else, email privacy@theveilwedding.com and we will respond within the time required by applicable law.
If you are in the EEA or UK and believe we have not resolved your concern, you have the right to complain to your local data protection authority.
Deleting your account
You can permanently delete your account from Settings in the app. Deleting your account removes your profile, your wedding builds and planning data, your guest list, your saved preferences, and your notification tokens.
Some information may remain: messages you sent to other users may persist in their conversations, content you posted publicly may have been seen or saved by others, and transaction records are retained where we are legally required to keep them. If you host a wedding, deleting your account removes the passports of guests connected to that wedding.
Security
We protect your information with encryption in transit, row-level access controls in our database so that users can only reach their own data and data explicitly shared with them, private storage buckets with time-limited signed links for images, and server-side authorization checks on sensitive operations.
No service can promise perfect security. If we become aware of a breach affecting your personal information, we will notify you and the relevant authorities as required by law.
Children's privacy
The Service is not intended for children under 13, and we do not knowingly collect personal information from them. If you are in the EEA or UK and under the age of digital consent in your country (between 13 and 16 depending on where you live), you may only use the Service with the consent of a parent or guardian.
If you believe a child has provided us with personal information, please contact privacy@theveilwedding.com and we will delete it promptly.
International data transfers
We are based in the United States and our infrastructure is hosted there. If you access the Service from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those in your country. Where required, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses for these transfers.
Changes to this policy
We may update this policy as the Service evolves. When we make material changes, we will update the “last updated” date above and give you notice in the app or by email before the change takes effect. Continuing to use the Service after that means you accept the updated policy.
Contact us
For privacy questions or to exercise your rights: privacy@theveilwedding.com
For general help: support@theveilwedding.com
Wilt Interactive LLC, 113 Chestnut St, Mifflinburg, PA 17844, United States