Privacy
What Vow holds, who else touches it, and how to get it back or get rid of it.
Effective 2026-08-21
Who is responsible
The company behind Vow — registered under KvK 98559508 — decides how your account data is handled, and is the one to write to about it: vow@gavant.eu.
Your guest list is different. You decide who goes on it and what you record about them; we only hold it for you and do nothing else with it. If a guest asks you to remove them, you can do that yourself in the guests screen.
What Vow holds
- Your account: the email address you sign in with, and a password kept by our authentication provider in a form we cannot read.
- Your wedding: the date, the two names, tasks, timeline, budget, suppliers, contracts and documents you upload, and everything else you type into the planning screens.
- Your guests: the names, the side, whether they are a child, the replies you record or they give, and the dietary needs, song requests and notes attached to them. A guest can add their own email address on the RSVP form; it is optional there.
- Your helpers: the email address you invited them at, and which areas of the wedding you granted them.
- Your payments: which package or add-on, the amount, the Mollie payment reference, and the moment you ticked the withdrawal-waiver box. No card or bank details — Vow never receives them.
- A log of email we sent: the type, the address, the subject and whether it went out, so that nothing sends twice and a failure is visible.
- Consent-based first-party analytics: a random session id, page path, referring site, device-size bucket and campaign tags. It contains no account id or email and excludes public wedding pages.
- Minimized operational events: that a data export or wedding deletion happened. A deletion event keeps no wedding names or planning content.
On the Signature package, images you put on your wedding website are stored as files, with 250 MB included. The other packages store no guest-facing media at all.
Who else touches it
Four companies do work Vow depends on, and each sees only what its job needs.
- Supabase — the database, the sign-in system and the file storage. Your wedding lives here, in the European Union.
- Netlify — hosting. It serves the site and runs the small server functions behind payments and email, from a network of servers around the world.
- Mollie — payments, in the Netherlands. Your card details are entered on their page and stay with them; we receive a payment reference and an amount.
- Resend — transactional email. An address and the text of the message pass through them so that the message can be delivered. Resend is a United States company, which we mention because it means email addresses leave the EU on their way out.
Nobody else receives your data. It is not sold, not rented, not used to advertise anything and not handed to another couple, a supplier or a marketplace.
The email Vow sends
The email Vow composes itself comes in five kinds:
- A receipt when a payment is confirmed, to the person who paid.
- A helper invitation, to the address you typed into the invite form.
- A confirmation to a guest who filled in the RSVP form and gave an address, summarising what they answered.
- Reminders to the two of you: a vendor payment past its due date, and the RSVP deadline coming up.
- One abandoned-checkout reminder with a time-limited discount, sent only to the owner of an unpaid workspace between one and thirty days old.
Our sign-in provider also emails you when you ask it to: the link that confirms a new account, and a password-reset link. Both go only to your own sign-in address.
A guest’s address is used for the confirmation that guest asked for, and for nothing else. There is no newsletter or third-party advertising. Planning and abandoned-checkout reminders can be turned off in Settings; receipts and messages you explicitly request still send. Vow does not send invitations to your guest list on your behalf — you share your links yourself.
Not every one of these is switched on yet. Where sending is unavailable the product says so and offers you a link to copy instead.
Your wedding website is public
A wedding website you publish is readable by anyone who has the address, and a search engine may find it. The RSVP form behind it asks for an invitation code, so replies and the guest list stay closed, but the pages around it do not.
Write the public pages with that in mind: a home address on the travel page is a home address on the open web. You can unpublish the site at any time.
Photographs after the day
Vow does not host the photographs your guests take. The photo-sharing screen helps you set up a folder on a service you already have — Dropbox or Google Drive — and then get the address to your guests. Whatever lands in that folder lives with that provider, under their terms and their privacy policy, not ours.
Analytics and what is not happening
- First-party page analytics runs only after you accept it. The Cookies page shows the fields, retention window and live on/off control.
- No third-party tracking pixels or advertising code. The site does not follow you around the web.
- Nothing you write is sent to a language model. There is no AI in this product.
- No profiling and no automated decisions about you.
The site stores a few things in your own browser to work at all: your signed-in session, which wedding you last had open, whether the opening animation has already played, and — while the site is still behind its pre-launch code — a signed cookie remembering that you entered it. None of them are used to track you.
How long it is kept
Your wedding stays for as long as you keep it. Deleting it in Settings first removes and verifies uploaded files, then removes the planning database rows. The product reports completion only after both stages succeed. Provider backups age out under the applicable backup schedule rather than being edited in place.
Payment records outlive the wedding: Dutch tax law requires us to keep the administration behind a sale, so the record of what was bought and when stays for as long as that law says.
What you can ask for
You can ask to see what we hold about you, to correct it, to have it deleted, or to get a copy you can take elsewhere. From the Complete package you can export the whole wedding yourself, at any time, without asking.
Write to vow@gavant.eu. If you are not happy with how we answer, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens.
Changes
When this page changes, the date at the top changes with it. A change that affects what happens to data already held will be said plainly here rather than folded quietly into a sentence.
