1Who is responsible
The controller for the data described here is Nimble Panda Ltd, registered in England and Wales, company number 17122751, registered office 30 Grange Road, Barnton, Northwich, England, CW8 4PE, which runs Perfect My Wedding. No data protection officer is appointed, because none of the three tests in Article 37 of the UK GDPR applies to us: we are not a public authority, monitoring people is not our core activity, and we process no special category data at scale. Write to us at the address above or at hello@perfectmywedding.com.
You can complain to us, and you do not have to come to us first. The Information Commissioner’s Office takes complaints directly at ico.org.uk, and Complaints sets out what we will do with one and how long we will take, which for a data complaint is the statutory month rather than our usual twenty working days.
2What we hold, and why we are allowed to
| What | Why | Lawful basis |
|---|---|---|
| Your email address | Signing in, and telling you a supplier replied | Contract |
| Your wedding: date, venue, guest count, budget | So a supplier can quote a real figure rather than asking four questions | Contract |
| Messages and quotes between you and a supplier, including a PDF a supplier attaches to a quote | The conversation is the booking, and the record if it is disputed | Contract |
| Payment and payout records | Holding the money, and six years of accounts | Legal obligation |
| Reviews you write | Shown publicly on the supplier's listing | Contract |
| Flagged messages | Every message is checked automatically against a fixed list of patterns: bank details, phone numbers, email addresses and wording about paying outside the site. A match flags the message for a person here to review. Nothing is blocked or edited. Paying outside the site removes your protection | Legitimate interests |
| Notices about a supplier's listing, and the supplier's answer | Section 9 of the supplier agreement: telling a business before we pause its listing, and keeping what it said back | Contract |
| Staff access records | So there is a record when a person here opens a private thread | Legitimate interests |
| A complaint you send us, and our answer | Answering it, and reading the pattern across complaints so the same thing is not answered twice | Legal obligation |
| A record of which version of the terms, the supplier agreement and the conduct policy you agreed to, and when | So we can show what you were shown. A rule nobody was shown cannot be enforced, and this is the proof | Contract |
| A wedding business asking to join: business and contact name, email, phone if given, trade, area, website and anything written in the form | So we can reply, and decide who to invite while we open one region at a time | Legitimate interests |
| Widget counts on suppliers' websites | How often a supplier's widget is seen and clicked, and on which website. No cookies, and nothing that identifies you | Legitimate interests |
| Analytics, if you allow it | Google Analytics and Microsoft Clarity, to see which parts of a page work | Consent |
| Marketing email, if you ask for it | Telling you about the platform | Consent |
We do not buy personal data, we do not scrape it, and we do not build profiles of you for advertising.
3Who else sees it
The supplier you brief. They see your wedding details and your messages. They do not see your budget for the whole wedding, your other conversations, or which other suppliers you are talking to.
Whoever you are marrying, if you add them to your wedding. They see everything you see.
Our processors. Supabase hosts the database in London and Cloudflare serves the site and pools the database connection. Google Analytics and Microsoft Clarity receive analytics data, but only from visitors who allowed it. Stripe processes payments and holds suppliers’ bank and identity details, which never reach us. Resend sends every email the site sends.
Each of those is a processor under a written agreement, and in every case it is that provider’s own standard data processing addendum, which forms part of the terms of the account we hold with them rather than something separately negotiated. We have not asked any of them for a bespoke one and do not need to. Stripe is the exception to the word processor: for a supplier’s identity and bank details it is a controller in its own right, under its own notice, because the law obliges it to verify them and it does not do that on our instructions.
Nobody else receives anything. We use no advertising network, no data broker, no customer data platform, no session-replay tool beyond the one named above, and no AI service that would be sent your messages.
Staff here, only when a message in your conversation has been flagged or a dispute has been raised on the booking. A conversation with neither stays closed to staff, and every conversation says so at the top. Every time a member of staff opens one it leaves a record, which is the only reason that sentence is worth anything. Staff can also post a note into a conversation, to one side or both, and it is marked as coming from us.
4Where it lives
The database is in London, on Supabase’s eu-west-2 region, and the site is served from Cloudflare’s network with the code placed in Manchester. Your messages, your wedding and your bookings are held in the UK.
Three of the processors are United States companies and their support and infrastructure reach across borders, so a transfer outside the UK happens with each of them. Google (Analytics) and Microsoft (Clarity) are both covered by the UK extension to the EU–US Data Privacy Framework, which is an adequacy decision, and neither receives anything at all from a visitor who did not allow analytics. Stripe and Resend transfer under the UK International Data Transfer Addendum to the European Commission’s standard contractual clauses, which is part of their standard terms.
There is no transfer we have arranged ourselves, to anybody, on any other basis.
5How long we keep it
| Enquiries that never became a booking | 18 months |
| Bookings, payments and payouts | 6 years after the wedding, for HMRC |
| Message bodies in notifications we sent | 12 months |
| Notification records | 24 months |
| Launch list signups | 24 months |
| Requests to join from wedding businesses | 24 months after the last update |
| Staff access records | 6 years |
| Complaints and our answers | 6 years |
| Notices about a listing, and the answer | 6 years, because a repeat breach is only provable from the first one |
| Which version of which document you agreed to | As long as the account, then 6 years |
| Your account, once you ask us to erase it | Severed immediately, see section 7 |
| Analytics, if you allowed it | Google 14 months, Clarity 30 days |
These are enforced by a scheduled job rather than by anyone remembering, which is the only version of a retention policy that means anything.
6Your rights
You can ask for a copy of everything we hold about you, ask us to correct it, ask us to erase it, object to us using it, or withdraw a consent you gave. We have one month to answer and it is free.
All of it is on your account page. The export downloads immediately; erasure is logged with its deadline so the clock is visible to both of us.
7What erasure actually does
Honestly: it cannot delete everything, and a platform that promises otherwise while holding financial records is lying to you.
A booking is a financial record and we are required to keep six years of those. So erasure severs you from the record rather than destroying it. Your profile keeps its identifier so the accounts still balance, and stops carrying your email, your name or anything else that identifies you. Reviews you wrote stay on the supplier’s listing, because other couples relied on them, but they stop carrying your name.
Your messages are the other party’s record as much as yours, so on a booking still inside the six years the words survive and the authorship does not. After six years the whole booking goes.
8Security
Every table has row level security, denying by default, so the public API key that ships in the browser cannot read a private message even if someone pulls it out of the page. Photographs are stripped of their EXIF data on upload, because a wedding photograph routinely carries the GPS coordinates of somebody’s house. A PDF a supplier attaches to a quote is kept in private storage: the couple and the supplier on that booking can open it, and staff only where they can read the conversation, which is recorded.
Sign-in is a link rather than a password, so there is no password here to leak.
9Children
This service is for adults. We do not knowingly hold data about anyone under 18, and will delete it if we find it.