Privacy Policy.
What we collect, why we collect it, and who can see it. In plain language.
Who we are
Shuubh operates shuubh.io, a wedding coordination service for couples in the United States and Canada. This policy covers the Shuubh website, the wedding workspace, the wedding websites couples publish with it (including on their own custom domains), the RSVP and contact-collector pages guests use, and the emails and WhatsApp messages we send for couples.
What we collect
From couples
- Your email address and a password, which we store only as a bcrypt hash.
- Your wedding's name, dates, plan, RSVP settings, and, if you tell us, your planning stage and the events and traditions you plan to have.
- Guest lists: names, households, postal addresses, sides of the family, email addresses, phone numbers, notes, dietary needs and tags. If you import a CSV file, the file is deleted once the import finishes.
- Invitation and save-the-date designs, website content, registry links, and the photos and files you upload.
- Messages you write to send to guests.
- Order records for anything you buy.
From your team
When you invite a family member, helper or planner, we keep the invited email address, the role and side you give them, and whatever they enter or change in the workspace.
From guests
- The details a couple enters about you.
- What you submit yourself through a contact-collector link: name, email, phone, postal address, dietary needs, household members and whether you opt in to WhatsApp messages.
- Your RSVP replies for each event, plus-one and children counts, and your answers to the couple's own questions, with timestamps.
- Delivery status for messages sent to you: for email, sent, delivered, bounced or delayed, as reported by our email provider; for WhatsApp, the status reports Meta returns, which can include read status. We do not track email opens or clicks.
- The text of a WhatsApp reply to us, such as STOP or START.
From visitors
- A signed session cookie that keeps you signed in, and, if you choose to stay signed in, a remember-me cookie.
- A request identifier and standard request records kept for security and debugging.
- Your IP address, held briefly in server memory to apply rate limits. It is not written to our database for that purpose.
- Your theme preference, stored in your browser.
The pages we serve contain no advertising or analytics trackers, and no third-party scripts or fonts. Our hosting provider may keep network-level records of its own.
How we use it
To run the wedding: show the couple who is coming to which event, show each guest only the events they are invited to, and send the invitations, reminders and RSVP confirmations the couple asks us to send. To bill the couple if they buy Premium or a print-ready file. To keep the service secure and working. To answer you when you write to us.
We do not sell, rent or share your data with anyone for marketing. Ever.
Guests and the couple
The couple decides what guest details to collect and whom to invite. Shuubh handles those details on the couple's instructions, to run their wedding. If you are a guest and want your details corrected or removed, ask the couple first, since they decide what they hold about you. You can also write to us and we will help.
Who can see it
The couple who created the wedding, and the family members, helpers and planners they invite, within the scope they are given: parents see their own side, family helpers see the groups assigned to them. A parent on one side cannot see the other side's guests. A guest can see only their own household's replies and their own invited events. Every wedding is isolated from every other at the database layer.
Service providers
We use a small number of providers to run Shuubh:
- Fly.io for hosting and the database, in the United States.
- Tigris for photo, file and export storage.
- Resend for email.
- Stripe for payments. Card details go to Stripe directly and never touch our servers.
- The Meta WhatsApp Business Platform, where WhatsApp messaging is enabled.
Each provider processes data only to provide its service to us. We share data with no one else, except where the law requires it.
Cookies and local storage
- _shuubh_key is the session cookie that keeps you signed in. It is signed and set to SameSite Lax.
- _shuubh_web_user_remember_me is set only if you choose to stay signed in. It lasts up to 90 days, is signed, uses SameSite Lax, and is marked Secure so it is sent only over HTTPS.
- Your browser's local storage holds your theme preference, and session storage remembers if you dismissed the phone-app prompt.
The installable web app keeps a cache of the app shell only. That cache holds no personal data, and everything else is fetched from the network. No cookie we set is used for advertising.
Guest access links
Each guest link or code is tied to one household in one wedding. We store the access token only as a hash, so reading our database does not reveal a working link. Replies are no longer accepted once the couple pauses RSVP or the reply-by date has passed. Issuing a new individual code for a guest retires the previous one. Anyone who holds a link can reply for that household, so guests should share it carefully.
Messaging and unsubscribe
Every email we send on a couple's behalf carries an unsubscribe link. Using it records an opt-out for that wedding and that channel, and we stop later sends to you from that wedding.
WhatsApp messages are sent only where you have opted in, using message templates approved by Meta. Replying STOP stops WhatsApp messages from every wedding on Shuubh to that number, and replying START turns them back on.
Account emails, such as sign-in links and email-change confirmations, are transactional and needed for the service to work.
How long we keep it
Wedding data stays until the couple deletes it or asks us to delete it. A few things expire on their own:
- Sign-in sessions last up to 90 days and expired ones are cleared daily.
- Sign-in links last 15 minutes.
- Download links for purchased print files last one hour.
- Contact-collector links last about two years.
- CSV files you import are deleted once the import finishes.
Photos and exports you delete are removed from storage.
Deletion and export
Couples can edit or delete guests, households, photos and website blocks in the workspace at any time, and can download their guest list as a CSV file. To delete a whole wedding or account, write to us through the contact page and we will delete it. That is a request handled by a person, not a button. Guests can ask the couple, or write to us.
Security
- Every wedding's data is separated by database row-level security, and the application connects with a restricted database role that cannot bypass it.
- Guest access tokens are stored as hashes. Passwords are stored as bcrypt hashes.
- Traffic to Shuubh is required to use HTTPS.
- Cookies are signed.
- Webhooks from Resend, Meta and Stripe are signature-checked before we act on them.
- The guest-facing finder, RSVP and contact-collector pages are rate limited.
More detail is on our privacy and security page. No system is perfect; if you think you have found a problem, tell us through the contact page.
Your choices and rights
You can ask us for access to your data, a correction, deletion, an export, or to stop messages, in the ways described above. We honour these requests wherever you live. Write to us through the contact page. If you are a guest, we may point you to the couple, since they decide what they hold about you. If you are a couple, you can edit or delete anything in your workspace yourself.
Children
Shuubh accounts are for adults, aged 18 or over. Couples may list children as guests; that information is the couple's to manage. We do not knowingly collect information directly from children.
Where data is processed
Shuubh stores and processes data in the United States. Our providers may process data in other places under their own policies. If you use Shuubh from Canada or anywhere else, you understand that your data will be handled in the United States.
Changes
If this policy changes in a way that matters, we will say so on this page and, for couples with an account, by email.
Contact
Contact us with any question about your data.