Privacy Policy
WeddingBoard Privacy Policy
Development revision: September 30, 2026
Publication review pending. This revision describes the expanded product being developed. It is not evidence that an integration is activated or approved by a provider. The final provider list, processing locations, contracts, retention schedule and legal notices must be verified together before this revision is published to production.
This notice describes information handled by WeddingBoard at weddingboard.us. It covers professional and couple workspaces, invited collaborators, clients, guests and gallery visitors. A business using the service also decides which client or guest information it collects and shares; contact that business about its planning records as well as contacting us about the platform.
1. Information the product handles
Account information includes identity and contact details, workspace memberships, roles and subscription status. Planning records can include client and vendor contacts, wedding details, tasks, schedules, guest households, meal or accessibility requests, forms, contracts, notes and financial records. Adult organizers may enter information about children attending an event; the account service is intended for adults.
Uploaded content can include documents, photographs, videos, voice notes, receipts and design files. Gallery processing creates previews, watermarks or downloadable renditions when those options are configured. Originals, processing metadata, checksums and recovery records support integrity checks and authorized delivery.
Connected services may supply the selected calendar events, mailbox messages, attachments, file metadata or accounting records described in the relevant connection screen. Operations also produce access, approval, delivery, error and audit records. Payment providers handle card or bank details through their supported payment flows; the application stores the identifiers and financial records needed to reconcile the result.
2. Purpose and workspace access
Information is used to provide the planning, communication, commerce and collaboration features you request, maintain reliable history, reconcile approved transactions, and diagnose abuse or failures. Private business records belong to their workspace. Sharing a wedding does not automatically share another business's inbox, prices, contracts or payment history.
Invitations and share links expose only the sections allowed by that particular route and permission. A public wedding website, a guest RSVP link, a private gallery and a signed contract link have different audiences. Review the recipient preview before sharing. Anyone receiving a capability link may be able to use it until it expires or is revoked; some routes require additional authentication, a password or email verification.
Public anonymous tools keep drafts in the current browser until you deliberately export or import them. Signing up does not publish those drafts. See public tool privacy for the import boundary.
3. Google and Microsoft calendar connections
Calendar connections are optional and separate from mailbox connections. They read the selected calendars for the enabled calendar display and booking availability features, and synchronize appointments explicitly linked to the application. For linked appointments, the app stores event identifiers, synchronized details and conflict history. It does not automatically adopt every unrelated personal event as a workspace appointment.
Google Calendar uses event access and calendar-list access for calendar selection. Meeting links may use Google Meet, Microsoft Teams or Zoom when the selected service and account support them. Read the current Google Calendar, Microsoft Calendar and Zoom instructions before connecting.
Disconnecting stops new local work and removes usable stored credentials for that connection. Work already accepted by the provider cannot necessarily be recalled. Provider-side grant revocation and cleanup are separate where the connection screen says so.
4. Private Gmail and Outlook inboxes
The workspace owner can authorize a primary Gmail or Outlook mailbox, choose labels or folders and an earliest message date, and enable synchronization and sending separately. Provider permissions cover the mailbox; the selected folders and date are additional application boundaries. Gmail uses read-only mailbox access plus sending. Outlook uses mail read/write permission to create the specific outgoing drafts you approve, with separate send permission. These scopes are described by Google and Microsoft.
Selected messages are copied into the private business inbox as plain text with sender, recipient, subject, timestamps and attachment metadata. Only full-access business operators can read these copies. Linking a thread to an existing lead is a separate reviewed action. Supported attachments are copied into private storage when you request it. Reading copied mail does not load remote email images or tracking pixels.
Sending requires a deliberate sender selection and review of the recipient, message and files. Connecting an inbox does not replace studio automation or authorize automatic mailbox replies. Provider acceptance, recipient delivery and recipient reading are different states. Disconnecting or narrowing the selection stops new copying but does not erase previously copied private history or messages already sent. Google grant revocation is attempted with visible recovery when it fails; Microsoft grants also need removal at the provider.
Conversations containing connected Gmail or Outlook messages are held from assistant source retrieval while provider-policy and data-sharing review is pending, including after disconnect. The source picker names the provider where available. See connected inbox boundaries.
Google API information is restricted to the connected features disclosed here. It must not be sold, used for advertising targeting, or repurposed for generalized model training. Applicable access, consent, transfer and human-review restrictions come from the Google API Services User Data Policy, including Limited Use. Required provider verification and any security assessment remain launch gates; this page does not certify their completion.
5. Requested AI assistance
Supported AI features send their displayed context to the configured model provider to prepare drafts or answers. In the workspace assistant, you select the records and source text or image, then approve the displayed usage price for that request. Ordinary studio conversation sources include recent message text; connected-mailbox conversations are held as described above. Do not paste private mailbox content into another source field to bypass that hold.
The app saves request inputs, selected source snapshots, results and proposal history for review. Saving an AI result is separate from applying a task, expense or other operational change. Each proposed action requires explicit approval; email delivery requires its own recipient and content review. A stage change can start an automation already published for that stage. See assistant review.
Provider retention, training settings and contractual terms must be verified for the actual production account before activation. Anthropic publishes its commercial data-use policy; this notice does not promise account-specific contractual terms that have not been established.
6. Messages, gallery consent and browser storage
Operational wedding updates and optional gallery marketing have separate consent records. Joining a guest list or recovering gallery favorites does not itself subscribe someone to gallery marketing. Marketing recipients need a recorded opt-in and verified email; unsubscribe and suppression states prevent later queued marketing sends. A send already accepted by a provider cannot be recalled by a later unsubscribe.
Approved gallery campaigns can record delivery status, replies, link visits and qualifying purchases to support campaign reporting and stop rules. A link visit is not proof that a human read an email; automated scanners may visit links. Click-assisted purchase attribution requires a qualifying verified viewer and the same gallery. It is not an email-open metric.
Browser storage supports authentication, share-page access, gallery viewer sessions and locally saved tool drafts. Gallery campaign links also set a first-party attribution cookie for up to 30 days. It can associate a subsequent qualifying gallery checkout with that link. This is additional to essential session storage; regional consent requirements and the visitor controls must be reviewed before campaign tracking is activated. See gallery campaign controls.
7. External processing and sharing
The product integrates with the following services for the stated purposes. Availability depends on configuration and the connection you choose. This development inventory is not a claim that every provider currently receives your data or that all data stays in a particular country. Production processors, regions, contracts and any additional integrations must be recorded before activation.
| Service | Purpose |
|---|---|
| Vercel, Neon, Clerk | Application hosting, database and account authentication. |
| Private S3-compatible storage and configured CDN | Original files, derived previews, private documents and authorized delivery. Legacy Blob files require a verified migration before private-storage claims apply to them. |
| Resend, Twilio, Expo | Approved studio email, SMS and device notifications; these routes have separate configuration and consent requirements. |
| Google, Microsoft, Zoom | Optional calendar, mailbox and meeting connections described below; each requires an owner connection and the applicable permissions. |
| Anthropic | Requested AI processing of the supported sources you select, subject to the source restrictions below. |
| Stripe, QuickBooks | Enabled payment processing and optional reviewed accounting synchronization. Financial records include provider identifiers and payment status. |
| Google Drive, Dropbox, WHCC | Optional selected-file imports and approved print fulfillment, including the order files and delivery address needed to fulfill an order. |
| Trigger.dev, Ably, configured monitoring | Background jobs, live updates and operational diagnostics when activated. Diagnostic access and redaction require launch verification. |
Recipients also receive the content you deliberately send, share, publish or order. Print fulfillment needs the approved production files and shipping details. Authorized API credentials and webhooks expose only their permitted scope, but the destination you connect has its own handling practices. Legal or security requests for access require a documented review; they are not general permission for staff to browse private content.
8. Retention, deletion and recovery
Archiving a project, disconnecting an integration, revoking a share link and deleting data have different effects. Disconnecting a mailbox retains its copied history. Revoking a link prevents later access through that link; it does not retrieve files someone already downloaded.
Signed records, payment receipts, dispute evidence and order history can have retention or integrity restrictions. Gallery deletion can be held by active orders and can have a recovery window before physical cleanup. A successful deletion request is not a promise that every derivative, backup or provider copy disappeared immediately. See file deletion and recovery.
The production retention schedule, backup expiry, provider deletion behavior and account-deletion procedure are pending verification. No fixed backup-purge deadline is promised in this development revision. Request an export or deletion assessment through the support address below; the response should identify records that can be removed and any specific retained records and reasons.
9. Security, choices and contact
The implementation uses workspace and membership checks, scoped share links, encrypted integration credentials and short-lived authorized file URLs. These controls need deployment verification alongside TLS, storage policies, access logging, backups and operational access. This is not a claim of a security certification, universal malware scanning or end-to-end encrypted email.
You can manage supported record edits, sharing permissions, connection settings and marketing preferences in the app. The available legal rights and response requirements depend on the person and jurisdiction; the final notice and request process require review before publication. For an access, correction, export, deletion or privacy request, contact team@weddingboard.us. If the record belongs to an organizing business, identify that business so the request can be directed without exposing someone else's records.
Material changes to the purposes of connected data require updated disclosures and any required renewed consent before the new use begins. The development date above identifies this draft; the production effective date will be set after review.