Legal
Privacy Policy
This Privacy Policy explains how Wedding Seat collects, uses, discloses, and protects personal information when you use our website and services.
Overview
Wedding Seat is a global wedding planning platform. This Privacy Policy describes how we handle personal information across the website, dashboard, and all product features, including the guest list, seating chart, budget, wedding websites, RSVP tools, and vendor/venue experiences.
- We do not sell personal information.
- We collect data to operate the Service, secure accounts, deliver features, and improve reliability.
- You control what you publish publicly (for example, on a wedding website).
Company details
Wedding Seat is owned and operated by Sigvanta LLC, a limited liability company registered in the State of Wyoming, United States. Sigvanta LLC is the data controller for personal information processed through the Service, except where we act as a processor (see “Controller / Processor roles”).
- Legal name: Sigvanta LLC
- Registered address: 30 N Gould St Ste R, Sheridan, Wyoming 82801, USA
- Mailing address: 30 N Gould St Ste R, Sheridan, Wyoming 82801, USA
- Contact: via our contact page
- Data protection contact: via our contact page
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we may appoint an authorized representative where required. Any representative details will be listed here once applicable.
Scope
This Policy applies to personal information processed in connection with:
- Our public website and marketing pages
- User accounts and authentication
- Private wedding projects (dashboard)
- Wedding website builder and public wedding sites
- RSVP collection and communications
- Budget planning and checklists
- Vendor / venue directories and white-label experiences
- Customer support
- Payments and subscriptions
This Policy does not cover third-party services you may access through the Service. Their privacy practices are governed by their own policies.
Controller / Processor roles
In most cases, we act as a data controller for personal information processed through the Service. In certain white-label or business configurations (for example, when a venue, vendor, or planner uses the Service to manage their own customer interactions), we may act as a data processor on behalf of that business. Where applicable, data processing terms (such as a Data Processing Addendum) will apply.
If you use the Service to store or process third-party personal information (such as guest details), you represent that you have a lawful basis to provide that information to us for processing in connection with the Service.
Guest data: when you (a couple or account holder) add guests, RSVPs, or other personal details about third parties to your project, you are the controller of that information and Sigvanta LLC (Wedding Seat) acts as your processor, processing it on your behalf to provide the Service.
Personal data we collect
1) Account and profile data
- Name, email address, profile preferences
- Authentication data (hashed passwords, OAuth identifiers)
- Account settings and feature configuration
2) Wedding project data (private workspace)
- Guest list details (names, groups, RSVP status, notes)
- Seating chart data (tables, assignments, relationships)
- Planning data (tasks, checklist items, schedule details)
- Budget entries (estimates, categories, vendor-related notes)
- Uploaded content (images, text content, templates)
3) Public wedding website data (if you publish)
- Content you choose to publish publicly (names, event details, images, stories)
- RSVP form submissions (guest responses and messages)
Publishing is optional. You control the content that appears on a public wedding website. Public pages may be indexed by search engines and copied or cached by third parties beyond our control.
4) Communications and support
- Support requests, messages, and attachments
- Transactional emails (verification, password reset, service notices)
- RSVP / invitation communications (if you enable them)
5) Payment and subscription data
Payments are processed by Stripe (or another payment processor you select). We do not store full card details. We may receive billing status, subscription identifiers, and limited metadata necessary to provide the paid Service and comply with tax/legal obligations.
6) Device, usage, and log data
- IP address, device identifiers, browser type, operating system
- Approximate location derived from IP (for security and localization)
- Usage events and diagnostics (pages/features used, timestamps, errors)
Sources of data
- Directly from you when you create an account, set up a project, publish a website, or contact support.
- From your guests when they submit RSVPs or interact with a wedding website you publish.
- Automatically from your device and browser when you use the Service.
- From vendors/venues if you use white-label features that include their profiles or inquiry flows.
- From payment processors (subscription and billing status).
How we use data
We use personal information to:
- Provide, operate, and maintain the Service
- Create and manage accounts, authentication, and access control
- Store and process wedding project content (guest list, seating, budget, planning)
- Publish wedding websites and process RSVP submissions (if enabled)
- Send transactional communications (verification, resets, important notices)
- Enable invitation/RSVP communications you initiate (if enabled)
- Provide customer support and respond to requests
- Detect, prevent, and investigate fraud, abuse, and security incidents
- Analyze performance, debug issues, and improve product reliability
- Comply with legal obligations and enforce our agreements
We do not use wedding project content to advertise third-party products to your guests. If we introduce marketing features in the future, we will provide appropriate choices and controls.
Legal bases (GDPR / UK GDPR)
Where the GDPR or UK GDPR applies, we process personal data based on one or more of the following legal bases:
- Contract: to provide the Service you request (account creation, project tools, subscriptions).
- Legitimate interests: to secure, improve, and operate the Service (fraud prevention, analytics, support, reliability).
- Consent: where required for non-essential cookies and certain analytics/marketing activities.
- Legal obligation: to comply with applicable laws (tax, accounting, lawful requests).
Where we rely on legitimate interests, we consider your privacy rights and implement safeguards, including data minimization and access controls.
Feature-by-feature processing
The table below summarizes how key features typically process personal data.
- Guest List: Stores guest names and optional contact details you provide; used to manage invitations and planning.
- Seating Chart: Processes guest list data to help you build seating arrangements and assignments.
- Budget: Stores planning estimates and vendor notes; does not require bank account data or card numbers.
- Website Builder: If enabled, publishes content you choose; may include public RSVP forms and guest messages.
- RSVP: Collects RSVP submissions from guests and stores responses in your project; optional email communications may be sent at your direction.
- Vendors/Venues: May display vendor profiles and handle inquiries; data flows may vary in white-label configurations.
- Accounts & Security: Processes login logs, device data, and security signals to protect accounts and the Service.
- Payments: Stripe processes payments; we store subscription status and limited metadata.
- Analytics: Used to measure performance and improve features; consent may apply depending on region and configuration.
Public content warning: If you publish a wedding website, information on that website may be accessible to anyone with the link, and may be indexed by search engines. You control what is published.
Subprocessors
We use trusted subprocessors to deliver core functionality. Subprocessors are contractually required to protect personal data and process it only for the purposes we specify.
- Payments: Stripe (subscription billing & payment processing).
- Transactional & authentication email: Postmark.
- Hosting & object storage: Hetzner (Helsinki, EU — primary data residency in the European Union).
- Maps & venue search: Google (Places / Maps).
We may update subprocessors as the Service evolves. If you need a current list, contact us via the Contact page.
International transfers
Sigvanta LLC is a U.S. company, but our primary hosting and object storage run on Hetzner infrastructure in Helsinki, in the European Union (EU data residency). We may also process limited data in the U.S. and other countries where our service providers operate. Where required under the GDPR/UK GDPR, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms.
Retention schedule
We retain personal data only as long as necessary for the purposes described in this Policy.
- Account data: retained while your account is active; some logs may be retained for security for a limited period.
- Project data: retained until you delete it or close your account (subject to backups).
- Public wedding website content: retained while published; removed when you unpublish or delete it (subject to caching/backups).
- Support communications: retained for a reasonable period to resolve requests and maintain support history.
- Billing records: retained as required by law (tax/accounting obligations may require multi-year retention).
- Backups: deleted on a rolling schedule consistent with disaster recovery policies (typically within 30 days).
When you request deletion, we remove or anonymize data where feasible. Some information may be retained where required by law or for legitimate security and fraud prevention purposes.
Security
We implement reasonable administrative, technical, and organizational measures designed to protect personal information, including:
- Encrypted transmission (HTTPS)
- Access controls and least-privilege policies
- Audit logging for sensitive operations
- Monitoring and incident response procedures
- Secure development and change management practices
No security system is perfect. Please use strong passwords and keep account credentials confidential.
Your rights
Depending on your location, you may have rights to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Request deletion (subject to legal and security exceptions)
- Request portability of certain data
- Object to or restrict certain processing
- Withdraw consent where processing is based on consent
To exercise your rights, contact us. We may need to verify your identity before fulfilling requests.
U.S. state privacy rights
Several U.S. states provide privacy rights (such as access, deletion, and correction) similar to California. Where applicable, we will honor verified requests as required by law.
California privacy notice (CPRA)
California residents may have the right to request:
- Categories of personal information collected
- Categories of sources
- Business or commercial purposes for collection
- Deletion and correction (subject to exceptions)
- Information about disclosures to service providers
We do not sell personal information.
Children
The Service is not intended for children under 16 (or the relevant age in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided personal data, contact us so we can take appropriate action.
Automated processing
We may use automated systems to detect spam, prevent fraud, protect accounts, and monitor performance. We do not conduct automated decision-making that produces legal or similarly significant effects solely by automated means.
Changes to this Policy
We may update this Privacy Policy from time to time. The “Last updated” date reflects the most recent revision. If changes are material, we will provide notice as required by law.
Contact
Questions about this policy? Contact us and we’ll help.