Privacy Policy
Last updated 17 July 2026
This policy explains what personal data Aetherial Studio collects, why, who we share it with, how long we keep it, and the choices and rights you have.
Who we are
Aetherial Studio(“we”, “us”) designs and hosts custom-crafted digital invitations. For questions about this policy or your data, contact us at contact@aetherial-studio.com.
Two roles: hosts and guests
We handle two kinds of personal data differently:
- Host account data — for the couples/hosts who sign up, we are the data controller.
- Guest data — the names, contact details and RSVP answers a host adds about their guests belong to the host. For that data the host is the controller and we act as their processor, handling it only to run their invitation on their instructions.
What we collect
- Account details — your name, email address and an authentication credential (managed by our auth provider; we never see your raw password).
- Event details — the event title, date, venue and your design brief (fonts, colours, notes, requested add-ons).
- Guest details you provide — guest and group names, optional email and phone, RSVP status, meal and dietary answers, comments, plus-one names and seating assignments.
- Uploaded media — inspiration images you share and any media provided for your design.
- Messages — the conversation between you and our studio.
- Technical data — essential cookies and standard server logs needed to operate and secure the service (see our Cookie Policy).
- Invoice records — the invoice number, amount and whether it has been paid. We do not collect or store any card, wallet or bank details (see Payments below).
Payments
All payments are processed entirely by PayPal. Whatever method you pay with — any card, a digital wallet (such as Apple Pay), or your PayPal balance — is entered on PayPal's own checkout, never on ours. We never see, handle or store your card numbers, wallet tokens or bank details. The only payment data we hold is the invoice record listed above (its number, amount and paid status). PayPal's own privacy terms apply to what you enter with them.
Why we use it (legal bases)
- To provide the service and perform our contract with you — creating your invitation, collecting RSVPs, seating, check-in.
- Our legitimate interests — securing the service, preventing abuse, and communicating about your engagement.
- Consent — for optional things like featuring a testimonial, which you can withdraw at any time.
Who we share it with
We do not sell personal data. We share it only with the service providers (sub-processors) that run the platform, under contract and only as needed:
- Supabase — database, authentication and hosting of stored data.
- Vercel — application hosting and delivery.
- Cloudflare R2 — storage of uploaded images.
- Resend — sending transactional email (invitations, RSVP notifications, reminders).
- PayPal — payment processing (their own privacy terms apply).
How and where we store it
Your account, event and guest data is held in a managed PostgreSQL database at Supabase; uploaded images are held as separate files in Cloudflare R2 object storage. Data is encrypted in transit (HTTPS/TLS) and encrypted at rest by those providers. Access is restricted by row-level security so each host can reach only their own events, and guest invitation pages resolve through unguessable single-use links rather than exposing the database. Payment card and bank details are never stored on our systems at all — see Payments above.
How long we keep it
- Guest data is kept to run your event. You can export it as CSV or permanently delete your event and all of its guest data at any time from your dashboard.
- Uploaded media is deleted about 30 days after the event, unless you opt into prolonged (keepsake) storage, in which case it is kept for the agreed period and then deleted.
- Account data is kept while your account is active. Delete your events and contact us to close your account.
- Invoice records — the invoice number, amount and paid/unpaid status (never card or bank details) are kept as long as needed for our accounting and tax obligations.
- Technical and usage data — server logs and privacy -friendly, cookieless usage analytics are kept only as long as needed to operate and secure the service, then deleted or aggregated.
International transfers
Our providers may process data outside your country. Where required, we rely on appropriate safeguards (such as standard contractual clauses) offered by those providers.
Your rights
Subject to your local law, you may request access to, correction of, or deletion of your personal data; object to or restrict certain processing; and receive a portable copy. Much of this is self-service in your dashboard (export and delete). For anything else, or if you are a guest wanting your data changed or removed, contact the host who invited you, or reach us at contact@aetherial-studio.comand we'll help or route it to the responsible host.
Security
Access to stored data is restricted by row-level security so hosts only reach their own events, and guest pages resolve through single-use links rather than exposing the database. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your data.
Children
The service is intended for adults arranging events. It is not directed at children, and we do not knowingly collect data from them.
Changes
We may update this policy; we'll change the date above and, for material changes, notify you. Continued use after an update means you accept the revised policy.
Contact
Questions or requests: contact@aetherial-studio.com.