Last updated: 26 July 2026
This policy covers Viahly, a wedding website service operated as a sole proprietorship in Ontario, Canada. We are the contact for any privacy question: viahlysites@gmail.com.
Canadian privacy law (PIPEDA) applies to us. Because anyone can sign up from anywhere, we have written this to the stricter standard set by the GDPR, and we apply it to everyone rather than only to people in Europe.
Two different roles
This is the part most privacy policies get wrong, and it matters here, so it comes first.
For your own information — your email, your wedding details, your planner conversations — we decide how it is handled. We are the controller, and this policy governs it.
For your guests’ information — the names, emails, and dietary notes people submit through your RSVP form — you decide what to ask and who to invite. We only store it on your behalf. We are the processor; you are the controller.
Practically: if a guest asks us to delete their RSVP, we will point them to you, because it is your guest list and not ours to change.
What we collect about you
Account
Your email address and name, held by Clerk. Our own database stores only an anonymous account identifier — we never hold your password, and we never see it.
Your wedding
Whatever you enter: couple names, event names, dates, venues and their addresses, dress codes, descriptions, schedules, and any photos you upload. Photos are stored directly in our database rather than a separate image service.
AI planner
Your conversations with the planner, and the planning data it maintains for you — total budget, currency, region, guest count, notes, budget line items, checklist items, and vendor entries. We also record token counts per message so we can apply daily usage limits.
Billing
We store your subscription status, the price you are on, your renewal date, and the identifiers Stripe uses for your customer and subscription records. We never receive your card details.Payment happens entirely on Stripe’s own checkout page; no payment code runs on our site.
Technical
Standard server logs — IP address, browser, pages requested — kept briefly for security and debugging. We also use Vercel Web Analytics to count page views in aggregate. It sets no cookies and creates no persistent or cross-site identifier, so it cannot follow you between sites or between visits. We run no advertising trackers and no third-party pixels.
What we collect about your guests
When a guest submits your RSVP form, we store the name they typed, their email if they gave one, their party size, which events they are attending, any note they left, and any dietary requirements they entered.
Dietary information deserves a specific mention because it can reveal something about a person’s religion or health. We store it, show it to you, and do nothing else with it. If you collect it, please handle it with the same care.
Why we are allowed to hold it
- To provide the service you asked for — your account, your site, your planner. Without this data there is no service.
- To take payment — required to run a paid subscription.
- Our legitimate interest in keeping the service secure, working, and free from abuse.
- Legal obligations — tax and accounting records, where they apply.
Who else touches it
We use a small number of providers to run the service. Each one only receives what it needs, and none of them may use your data for their own purposes.
| Provider | What for | Where |
|---|---|---|
| Clerk | Signing you in and managing your account | United States |
| Supabase | Database — everything you create, including photos | United States |
| Stripe | Taking payments and managing subscriptions | United States |
| Anthropic | Generating AI wedding planner replies | United States |
| Vercel | Hosting, serving the website, and aggregate page-view analytics | United States |
These providers are in the United States, so your information is stored and processed there. We rely on their contractual data-protection commitments for that transfer.
On the AI planner specifically: when you send a message, your conversation and relevant wedding details go to Anthropic to generate the reply. Anthropic does not use this to train their models. If you would rather nothing was sent to an AI provider, simply do not use the planner — the rest of Viahly works without it.
We never sell your data, and we never share it for advertising. We will disclose information if the law genuinely requires it, and we will tell you when we are permitted to.
Cookies
We set one kind of cookie: the session cookie that keeps you signed in, set by Clerk. It is strictly necessary — without it you could not stay logged in — so there is no consent banner, because there is nothing optional to consent to. No analytics cookies, no advertising cookies, no third-party trackers.
How long we keep it
- While your account exists — your wedding content, RSVPs, and planner history stay put, including after a subscription ends. Cancelling takes your site offline but does not delete anything, so resubscribing restores it exactly as it was.
- When you ask us to delete your account— we remove your content, and your guests’ RSVP data along with it.
- Billing records — kept as long as tax and accounting rules require, even after deletion.
Your rights
You can ask us to:
- Give you a copy of what we hold about you
- Correct anything wrong
- Delete your account and its contents
- Stop or restrict a particular use of your data
- Withdraw consent you previously gave
- Explain a decision we made about your data
Email viahlysites@gmail.com and we will respond within 30 days. There is no charge, and we will not make it difficult. If you are a guest rather than an account holder, contact the couple who invited you — it is their guest list.
If you are unhappy with how we have handled a request, you can complain to the Office of the Privacy Commissioner of Canada, or to your local data protection authority if you are in the UK or EU.
Security
Data is encrypted in transit. Passwords are handled entirely by Clerk and never reach us. Card details are handled entirely by Stripe and never reach us. Access to the production database is limited to the operator.
No service is perfectly secure, and we would rather say so than imply otherwise. If a breach affects you, we will tell you and the relevant regulator as quickly as we reasonably can.
Children
Viahly is not intended for children, and we do not knowingly collect their information. If you believe a child has given us data, email us and we will remove it.
Changes
If we change this policy in a way that materially affects you, we will email you before it takes effect. The revision date at the top always reflects the current version.
See also our Terms of Service and Refund Policy.