Skip to main contentMain content
Glenthea

Privacy Policy

Last updated: 24 August 2026

1. Controller Identity

The data controller responsible for processing your personal data is:

Glenthea GmbH

c/o Jurata AG

Stampfenbachstrasse 151

8006 Zürich

Switzerland

UID: CHE-293.014.901

Email: support@glenthea.com

This policy applies to glenthea.com and everything we offer there (the "Platform"). Glenthea is established in Switzerland, so the Swiss Federal Act on Data Protection (nFADP) applies to everything we do. The EU General Data Protection Regulation (GDPR) applies where Glenthea offers the Platform to people in the European Economic Area, or otherwise falls within its territorial scope. The UK GDPR applies on the equivalent basis in the United Kingdom.

This policy covers two different roles, and it matters which one you are reading about. For your own account, your payments, and the security, integrity and lawful operation of the Platform, Glenthea decides how personal data is used and is answerable for it. For a wedding's guest list, it is the couple who decide who is invited, what is asked of them and what becomes of their answers; Glenthea stores and processes that information on the couple's behalf and on their instructions, and never uses it for its own marketing. A guest who wants their details corrected or removed can ask the couple who invited them, and can also write to us: we act on the request ourselves where we are able to, and otherwise pass it to the couple.

2. Data Collected

We collect and process the following categories of personal data:

  • Account data: name, email address, profile image (couples who register an account).
  • Payment data: Stripe customer ID, plan tier. We never store raw card numbers – payment processing is handled entirely by Stripe, Inc.
  • Gift bank details: if you choose to accept wedding gifts by bank transfer, the IBAN you enter. It is encrypted at rest and only the last four digits are stored unencrypted, for display. It is shown in full to a guest only when they claim a bank-transfer gift, and to you in your own data export.
  • Wedding content: couple names, wedding date, venue, the photographs you upload, any welcome video, your story text, and other content you choose to add to your card. Photographs and video are stored with Bunny; it is listed in section 6.
  • Guest data: guest name, email address, phone number (optional), attendance response status, meal preference, and the personalised invitation link that lets a guest in without an account. Most of this is entered by the couple; the rest comes from the guest when they reply.
  • Guest responses: attendance status, meal choice, party member details, free-text message, consent timestamp.
  • What guests share on a wedding card: guestbook entries, messages to the couple or to another guest, song requests, answers to quizzes, predictions and other games, time-capsule messages, and photos uploaded to the couple's photo wall. This is stored with the wedding card and is visible to the couple; some of it is also visible to other guests of the same wedding, depending on what the couple has switched on.
  • Seating and arrivals: the table and seat a guest is assigned to, any "do not seat together" notes the couple records, and, where the couple uses check-in on the day, the time a guest arrived and the location they were checked in at.
  • Gifts: which gift a guest has chosen or contributed to, any amount and any message they leave with it, and the thank-you notes the couple writes afterwards.
  • Children's activities: where the couple switches on the children's area, a child's first name (optional), their drawings, their wishes for the couple, and the activities they have completed. It is meant to be used by a child together with the adult who brought them: a child takes part through that adult's own invitation link, and the adult using it confirms they are responsible for the child and entitled to submit what the child makes. We ask for nothing else about a child, we never invite a child to give us anything directly, and what they make is visible only to the couple.
  • Notes the couple keeps: a couple can write a private note against a guest's name. It is never shown to that guest or to any other guest, and it is erased together with the wedding card.
  • Technical data: IP address, used for rate limiting and abuse prevention and recorded on the security audit entries for sign-in, sign-out and credential changes; browser type; page-view analytics via Vercel Analytics (aggregated, and collected only after you accept analytics cookies).
  • Communications: emails sent or received via our platform, including invitation and attendance confirmation emails.

Some of what a guest chooses to enter can be sensitive. Dietary requirements and allergies can say something about a person's health or their religion, and a free-text note can say more than a category does. Because of that, the invitation reply now asks for explicit consent before it will store anything in those fields: they stay inactive until the box is ticked, ticking it is optional and nothing else depends on it, and un-ticking it deletes what was stored. The information is used only to plan catering, and is shown only to the couple and to whoever the couple gives their catering list to. Please enter no more than the couple actually needs. The same restraint applies to anything written about a child.

3. Purpose of Processing

  • Providing the wedding invitation platform and associated features.
  • Processing one-time payments and managing your plan.
  • Sending transactional emails (attendance confirmations, invitations, system alerts).
  • Sending a small number of promotional emails to registered users who have started building a wedding card but have not completed checkout, inviting them to come back and choose a plan. These are advertising rather than service messages, and we send them only to people who have switched them on in their account settings. Nobody receives them by default. They stop after roughly the first month, every one of them carries a one-click unsubscribe link, and switching them off withdraws your permission.
  • Customer support and responding to data subject requests.
  • Security monitoring, fraud prevention, and rate limiting.
  • Aggregated, anonymised analytics to improve the Platform.
  • Compliance with legal obligations.

4. Legal Basis

Where the GDPR applies, we rely on the legal bases set out below. The Swiss nFADP does not mirror those bases one for one: under it we process personal data in accordance with its processing principles and, where a justification is required, rely on consent, on an overriding private or public interest, or on a provision of law.

  • Contract performance (GDPR Art. 6(1)(b)): processing necessary to deliver the services you have contracted for, including account management, wedding card creation, guest invitation delivery, collecting and recording the responses guests give to those invitations, and payment processing.
  • Consent (GDPR Art. 6(1)(a), and Art. 9(2)(a) for special-category data): three things run on consent and on nothing else. The non-essential analytics named here – Vercel Analytics page-view measurement as well as Speed Insights and web-vitals reporting – load only after you accept analytics cookies, and you can change that choice at any time from the Cookie Policy page. The promotional emails described in section 3 are sent only to a registered user who has switched them on, and switching them off withdraws that permission. Dietary requirements and allergies entered on an invitation reply are special-category data: they are stored only where the person entering them has ticked the explicit consent box beside the field, and un-ticking it deletes what was stored. Error and performance monitoring is not part of any of that, and runs on the legitimate-interests basis described below.
  • Legitimate interests (GDPR Art. 6(1)(f)): organising the wedding a guest has been invited to, on behalf of the couple who invited them, where that guest has no contract with us themselves; keeping the Platform secure, preventing fraud and abuse, and improving it; and error and performance monitoring. Each of these is weighed against your privacy rights, and you can object to any of them at any time. We do not rely on legitimate interests for advertising.
  • Legal obligation (GDPR Art. 6(1)(c)): where required by applicable Swiss or EU law.

5. Data Retention

  • Account and wedding data: retained while your account is active. When you delete your account, or ask us to erase your data, it is hidden from the Platform immediately and removed from our live systems within 30 days. Copies remain in our encrypted backups until those backups expire, which can take up to 12 months; the next item explains what that means in practice.
  • Encrypted backups: we keep encrypted backups for one purpose, which is recovering from a failure or a disaster. The oldest backup we hold is 12 months old, so a copy of deleted data can survive there for up to that long after it has gone from our live systems. Backups are never used for anything else, they are never searched to answer a routine request, and if we ever have to restore from one, any erasure that had already been carried out is applied again.
  • Wedding cards: we do not delete your wedding card on a timer. You can delete it yourself at any time from your account, and when you do, the photos and the guest data attached to it are erased with it.
  • Guest response data: kept alongside the wedding card for as long as the card exists, and erased with it when you delete it. We do not delete it on a timer, which means it can be held for a long time: please collect only the guest details you actually need, delete the card once you no longer want it, and tell us if a guest asks to be removed, which we action individually.
  • Payment records: retained for 10 years in accordance with Swiss accounting law.
  • Server logs: retained for 30 days, then permanently deleted.

Operational logs: we keep operational logs for security and performance monitoring. They record system events such as page loads and API requests, and identifying fields are removed or replaced before a line is written wherever that is possible; a few entries keep an identifier deliberately, such as the IP address on a security event. Operational logs are retained for 90 days.

6. Third Parties and Data Transfers

We share personal data with the following categories of third-party processors:

Stripe, Inc.

Purpose: Payment processing

Location: USA

Vercel, Inc.

Purpose: Hosting, serverless functions, analytics

Location: USA / EU

Resend, Inc.

Purpose: Transactional email delivery (invitations, RSVPs, account)

Location: USA

Upstash, Inc.

Purpose: Rate-limit counters and real-time event buffers (Redis)

Location: USA / EU

Neon Inc.

Purpose: Managed PostgreSQL database (production)

Location: USA / EU

Google LLC

Purpose: Sign in with Google (optional; if you choose it, Google shares your name, email address and a Google account identifier; no other data and no ongoing account access are requested or stored); delivery of the single test email you can send yourself when previewing your own card; and the embedded Google Maps venue map on a public wedding card when the couple has added one – that embed is loaded by your browser, so Google receives your IP address and the page address

Location: USA

BunnyWay d.o.o. (Bunny.net)

Purpose: Image hosting and delivery for wedding cards, galleries and guest photos, and welcome-video hosting and transcoding. Files are stored in the EU and delivered only from servers in the European Economic Area.

Location: EU (storage) / global (delivery)

Spotify AB

Purpose: Embedded music player on a public wedding card, when the couple has added a Spotify playlist. The embed is loaded by your browser, so Spotify receives your IP address and the page address; it is not loaded on any card without a playlist.

Location: Sweden / USA

Vimeo.com, Inc.

Purpose: Embedded welcome-video player on a public wedding card, when the couple has linked a Vimeo video. The embed is loaded by your browser, so Vimeo receives your IP address and the page address.

Location: USA

Google Ireland Ltd. / Google LLC (YouTube)

Purpose: Embedded welcome-video player on a public wedding card, when the couple has linked a YouTube video. The embed is loaded by your browser, so YouTube receives your IP address and the page address.

Location: Ireland / USA

Cloudflare, Inc.

Purpose: Encrypted database backup storage and temporary delivery of GDPR data-export files (R2; export files are deleted within 24 hours of generation)

Location: EU / USA

We do not sell personal data, and we do not share it for advertising. Each processor listed above is used under its data processing terms and only for the purpose named beside it. Where personal data leaves Switzerland or the EEA, the transfer is protected by whichever of these applies to that recipient and that data: an applicable adequacy decision, the recipient's participation in the Swiss-US or EU-US Data Privacy Framework, or Standard Contractual Clauses together with any Swiss adaptations and supplementary measures required. Switzerland recognises those clauses under the nFADP. Write to us at the address in section 11 if you would like the details for a particular processor.

7. Your Rights

Under the Swiss nFADP and, where applicable, the EU GDPR, you have the following rights:

  • Right of access (Art. 25 nFADP / Art. 15 GDPR): request a copy of the personal data we hold about you.
  • Right to rectification (Art. 32 nFADP / Art. 16 GDPR): correct inaccurate or incomplete data.
  • Right to erasure (Art. 32 nFADP / Art. 17 GDPR): request deletion of your personal data, subject to legal retention obligations.
  • Right to data portability (Art. 28 nFADP / Art. 20 GDPR): receive your data in a structured, machine-readable format.
  • Right to object (Art. 30 nFADP / Art. 21 GDPR): object to processing based on legitimate interests.
  • Right to restrict processing (Art. 18 GDPR): in certain circumstances, request that we restrict processing of your data.
  • Right to lodge a complaint: with the Swiss Federal Data Protection and Information Commissioner (FDPIC) at edoeb.admin.ch, or the supervisory authority in your EU member state.

To exercise any of these rights, please submit a Data Subject Access Request or email support@glenthea.com. We generally respond within 30 days. Where the GDPR applies, that period may be extended by up to two further months where a request is complex or where we have received a number of them, and we will tell you inside the first month if that happens.

8. Cookies

We use a minimal set of cookies:

  • Session authentication cookie: essential for keeping you signed in. No consent required (strictly necessary).
  • Locale preference cookie: remembers your language preference. Essential, no consent required.
  • Vercel Analytics: page-view measurement that loads only after you accept analytics cookies. It is configured not to build a profile of you; what it receives is the address of the page, the page that referred you, and general device and browser information. It does not load at all on the pages a guest reaches through their personal invitation link, and the secret in that link is stripped from any address it does report.

See our Cookie Policy for full details.

9. Security

We implement technical and organisational measures to protect your personal data, including: encryption at rest and in transit, rate limiting, access controls, structured audit logging, and regular security reviews. Payment card data is never stored on our servers – all payment processing is handled by Stripe. To help protect your account, we derive an approximate location (country level) from your IP address on our own servers and notify you when your account is accessed from a new country.

10. Changes to This Policy

We may update this Privacy Policy. Where a change materially affects how we use your personal data, we will tell registered users by email at least 30 days before it takes effect, and where a change needs your consent we will ask for it rather than assume it. The "Last updated" date at the top of this page shows the most recent revision, and you can ask us which version applied on a particular date.

11. Contact

For privacy-related enquiries, please contact:

support@glenthea.com

This policy is published in every language the Platform supports, and each version is intended to say the same thing. If you find a discrepancy between two language versions, please tell us and we will correct it.