Skip to content
Vows
How it worksPricing
Get started
How it worksPricing

Privacy policy

What we hold about you, why, who else sees it, how long we keep it, and what you can ask us to do with it.

In effect from September 16, 2026. Operated by Migambi Global, LLC.

The short version

We hold your email address so you can sign in, whatever you tell us about your wedding so a site can be built from it, the files you upload, and the replies your guests send you. We charge through Stripe and never see your card. We send what you type to an AI provider so it can write your site. We do not sell anything about you, we do not advertise to your guests, and nothing you or they write is used to train a model. We do advertise Vows itself, and a tag on vows.day tells Pinterest whether an advertisement led to anybody, where the law lets it run without asking first.

The rest of this page is the detail, and it is written to be checkable rather than to be reassuring. Questions to legal@vows.day.

Two different roles, and which one we are in

This matters because it decides who you ask for what.

For you, the couple, and for anybody visiting vows.day, we are the controller. We decide what is collected and why, and this policy is the whole answer.

For the replies your guests send, the couple is the controller and we are their processor. We only hold and handle those replies to provide the service, on the couple’s instructions. The terms of that are in the data processing addendum. A guest who wants their reply changed or removed should ask the couple first, and can ask us if they cannot reach them: section 3 is written for them.

We are Migambi Global, LLC, a Delaware limited liability company, at 131 Continental Dr, Suite 305, Newark, DE 19713, United States. We have not appointed a data protection officer, because we are not required to. Write to legal@vows.day for anything covered here.

If you replied to somebody’s wedding

This section is for guests rather than for customers. Everything else on this page is about the couple who built the site; this is about you, and it is the whole of what you need.

A couple built their wedding site with Vows. When you fill in their form, your answers go to them. We store the reply on their behalf and email it to them, and that is all we do with it. We do not sell it, we do not advertise to you, and we will never send you marketing or add you to a list. The only message anybody gets because of your reply is the one that goes to the couple.

What is actually stored

  • What you typed: your name, whether you are coming, how many of you, and whatever else the form asked. That often includes an email address, and may include a meal choice, something you cannot eat, a song, or a note.
  • The time it arrived.
  • A scrambled, one-way form of your network address, used to stop the form being attacked and to notice if the same reply arrives twice. Your actual network address is not stored: it is hashed the moment it arrives and thrown away.

Nothing else. No cookies are set on the couple’s site, nothing tracks you across the internet, and no analytics runs on their page at all. One thing is stored in your browser’s session memory so that reloading shows a thank you rather than an empty form, and it is gone when you close the tab. If the couple chose to embed a video or a live map, that loads from YouTube, Vimeo, Twitch, Google or OpenStreetMap and those companies will see your network address: that is their choice rather than ours, and a site without one contacts nobody.

You do not have to write much

Only your name and whether you are coming are ever required. Everything else on the form is optional. Wedding forms sometimes ask about food, which for some people means saying something about their health or their religion. You do not have to. If you would rather tell the couple something privately, tell them privately.

Changing or withdrawing your reply

The easiest way is to fill the form in again. A second reply with the same email address replaces the first rather than adding to it, so if you said yes in March and cannot come after all, just say so again.

Otherwise, ask the couple. They can correct or delete any reply themselves, and they can delete all of them at once. If you cannot reach them, or they will not act, write to legal@vows.day with the address of the wedding site and the name you replied under. We will pass it on and tell you we have, and where the law requires us to act ourselves, we will. What we will not do is quietly delete somebody’s guest list entry without telling them, because that reply is theirs rather than ours.

Depending on where you live you may have the right to see what is held, have it corrected or erased, object to it, or complain to your data protection authority. Those rights are against the couple in the first instance, and we will help them meet them. Your reply is kept for as long as they keep it: everything goes when they delete their site or their account, and we apply no period of our own.

What we hold

If you only visit vows.day

  • The analytics events described in the cookie notice: which pages were opened, roughly where in the world from, and what kind of device. Only where analytics runs at all, which is not everywhere.
  • What the Pinterest tag reports, described in the same notice: which pages were opened, whether an account was made, and whether a payment was started or made. Pinterest holds that under its own policy rather than ours, and the tag runs under the same rules as the analytics above.
  • The ordinary server records our hosting provider keeps: network address, time, page and browser. We do not build these into profiles.

If you open an account

  • Your email address, and your name and profile picture if you sign in with Google.
  • Sign-in records: a keyed hash of the six digit code while it is live, and counters against a hash of your network address so codes cannot be brute forced. We do not store the code and we do not store your network address.
  • What you tell us about your wedding: your first message, the whole conversation, and the brief built from it, which holds names, the date and times, the venue and town, the dress code, a reply-by date and anything else you say.
  • Your site, every version of it, and everything in it.
  • What you upload: photographs, video and documents, and the text extracted from a document so the model can read it.
  • Payment records: what was bought, when, for which site, and the Stripe identifiers for it. Stripe holds the card and the billing address; we do not.
  • Your settings, including your address, your domain and whether the site is published.

What your guests send you

Their name, whether they are coming, how many of them, and their answers to whatever the form asks, which usually includes an email address and may include a meal choice, something they cannot eat, a song and a note. Plus a hash of the network address the reply came from, kept so abuse can be counted and a duplicate can be recognised.

A guest’s network address is never stored.

It is hashed the moment it arrives and only the hash is kept. There is nothing we could do with the address itself, so we do not have it.

What we deliberately do not hold

  • Card numbers, or anything that could be used to charge a card.
  • Passwords, because there are none.
  • Location beyond a country, and never a precise one. Location data in the photographs you upload is stripped before anything is stored.
  • Special category data. We do not ask for health, religion, ethnicity or anything like it. A guest may write something like that into a dietary note or a message, and if they do it is stored as part of their reply and nothing else is done with it.

Why, and on what legal basis

The bases named here are the ones in the UK and EU GDPR. If you are somewhere those do not apply, the first two columns still describe what happens.

WhatWhyBasis
Your email address To sign you in and to write to you about your site. Performance of the contract.
The brief, the conversation, the site To build, host and change the thing you bought. Performance of the contract.
Files you upload To put them on your site. Performance of the contract.
Payment records To take the payment, invoice it and account for the tax. Contract, and legal obligation for the records we must keep.
Sending your words to a model provider It is how the site gets written. Performance of the contract.
Rate limits and abuse counters To keep the service working and stop it being attacked. Our legitimate interest in a service that stays up.
Analytics To learn which pages work. Consent where consent is required, and not run at all where it has not been given.
Security and error logs To find out what broke and to investigate abuse. Legitimate interest, and legal obligation where one applies.
Guest replies To deliver them to the couple. We hold these as the couple’s processor. The basis is theirs, not ours.

We do not use your information for automated decisions that have a legal or similarly significant effect on you.

What is sent to the AI, and what never is

Writing a site means sending text to a model provider. Being precise about which text is the only useful thing this section can do.

Sent:

  • what you type in the conversation, and a rolling summary of the older part of it;
  • the brief built from what you said;
  • the markup and stylesheet of your own site, so a change can be made to it;
  • the text extracted from a document you upload;
  • a photograph, only when you ask for something that requires looking at one. Photographs are not routinely described.

Never sent:

  • your guests’ replies, or any part of them. Nothing in the model path reads them;
  • your email address, your payment details or your account identifiers;
  • anything belonging to another couple.

Our provider is named in section 7. Under our agreement with them, what we send is not used to train their models, and it is held only long enough to answer the request and to meet their own abuse-monitoring obligations.

Who else sees it

We share personal data with the companies that run parts of the service for us, and with nobody else for their own purposes. Each is bound by a written contract, may only act on our instructions, and is listed with what it handles and where:

WhoFor whatWhere
Google LLC Hosting, database, file storage, sign-in and product analytics United States
Anthropic, PBC The model that plans, writes and edits a site United States
Stripe, Inc. Payments, invoicing and tax calculation United States
Resend Transactional email United States
Cloudflare, Inc. Serving published wedding sites A global edge network, with stored objects in the United States

What each one actually receives

Company Google LLC , as Google Cloud and Firebase
What it doesHosting, database, file storage, sign-in and product analytics
What it receivesEverything the product holds: accounts, site content, uploaded photographs, documents and video, guest replies, and the analytics events described in the cookie notice.
WhereUnited States
Their terms https://cloud.google.com/terms/data-processing-addendum
Company Anthropic, PBC , as The Claude API
What it doesThe model that plans, writes and edits a site
What it receivesWhat a couple types, the brief built up from it, the markup and stylesheet of their own site, and text extracted from documents they upload. A photograph only when a couple asks for something that needs one looked at. Never guest replies.
WhereUnited States
Their terms https://www.anthropic.com/legal/commercial-terms
Company Stripe, Inc. , as Stripe Checkout and Stripe Tax
What it doesPayments, invoicing and tax calculation
What it receivesName, email address, billing address and payment details. Card numbers are typed into Stripe’s own form and never reach us.
WhereUnited States
Their terms https://stripe.com/legal/dpa
Company Resend , as Plus Five Five, Inc.
What it doesTransactional email
What it receivesSign-in codes, reply notifications and account confirmations. A reply notification quotes the guest’s answers and uses their address as the reply-to, so a guest’s data passes through it.
WhereUnited States
Their terms https://resend.com/legal/dpa
Company Cloudflare, Inc. , as Workers, KV, R2 and DNS
What it doesServing published wedding sites
What it receivesThe published pages themselves, and the network address of anybody who opens one, in the ordinary course of serving and protecting it.
WhereA global edge network, with stored objects in the United States
Their terms https://www.cloudflare.com/cloudflare-customer-dpa/

Who we do not use, and why it looks as though we might

Each of these appears in the product in some form and receives nothing about anybody. They are listed so the claim can be checked rather than taken on trust.

OpenStreetMap FoundationMap tiles are fetched by us while a site is being built and stored in the site as one flat picture. Nobody visiting a wedding site contacts OpenStreetMap, and nothing personal is sent when we fetch a tile.
Google FontsEvery typeface is subset and served from our own storage. No page in the product, and no couple’s site, asks Google for a font.

A published wedding site with none of the options below switched on makes no third-party request at all. Every font, every photograph, every stylesheet and the map are served from the site’s own address.

What a couple can switch on

These are the couple’s decision rather than ours. Turning one on puts that company in front of everybody who opens the site, and the studio says so once when it is asked for. That company’s own privacy policy then applies to what it sees.

YouTube, Vimeo or TwitchA video embedded in the page.
Google Maps or OpenStreetMapA live, pannable map in place of the drawn one.

How a change to this list is announced

Before a new subprocessor starts handling personal data, we update this page and email every account holder at least 30 days beforehand. If you object on reasonable data protection grounds, write to legal@vows.day within those 30 days. We will try to find a way round it, and if we cannot, you may end the agreement for the affected part of the service and we will refund the unused portion of what you paid. That is section 6 of the data processing addendum.

Everybody else

We will also disclose information where we have to or plainly should:

  • to comply with a law, a court order or a valid legal request. We will tell you unless we are forbidden from doing so;
  • to enforce our terms, or to investigate fraud, abuse or a security problem;
  • to protect somebody from serious harm;
  • to a buyer, if the business or its assets are sold. Your data stays under a policy at least as protective, and we will tell you before anything moves.

We do not sell personal data. One thing on this page goes to a company for its own purposes rather than ours, and it is not a subprocessor: the Pinterest tag on vows.day, in the cookie notice, which tells Pinterest what an advertisement of ours led to. Pinterest decides for itself what it does with that, under its own policy. It does not run where consent would be required and has not been given, it does not run for a browser sending Global Privacy Control or Do Not Track, and it never runs on a couple’s published site.

Where it goes

We are a US company and our suppliers are US companies, so if you are outside the United States your information is transferred there and to wherever else those suppliers operate.

For transfers out of the UK, the EEA or Switzerland, we rely on the European Commission’s Standard Contractual Clauses, with the UK International Data Transfer Addendum where the UK version is needed, together with the technical measures described below. Our suppliers’ own transfer terms are linked in section 7, and several of them are also certified under the EU-US Data Privacy Framework.

Ask us at legal@vows.day for a copy of the safeguards that apply to a particular transfer.

How long we keep it

WhatHow long
Your accountUntil you delete it. Deleting it removes the account, every site on it, every uploaded file and every guest reply, and cannot be undone.
A site and everything in itFor as long as the account holds it. A site you delete goes at once, with its files and its published bytes.
Past versions of a siteThe most recent fifty, plus the first one and whichever is published. Older ones are pruned as new ones are recorded.
Guest repliesUntil you delete them or delete the site. There is a one-press delete for all of them in the studio.
Files uploaded and never sentRemoved after seven days. An upload reserved and never completed is removed after an hour.
Sign-in codesTen minutes, and deleted the moment one is spent. The code itself is never stored, only a keyed hash of it under a salt written for that one code.
Abuse countersTwo days for the studio, replies and edits. One hour for sign-in. Held against a hash of a network address rather than the address.
Payment recordsHeld by Stripe under their own retention, and by us as the record of what a site was bought with. Financial records are kept for as long as tax and accounting law requires them, which we treat as seven years.
An address a published site used to answer onKept as a redirect for as long as the site exists, up to three at a time, so a printed invitation goes on working. An address never made public is released at once. A deleted site’s addresses are held for thirty days before anybody else may take them.
What the models cost usKept indefinitely, by day and by site. It carries no name, no address and no account identifier, and it is the only record of what the product costs to run.

Deletion is immediate in the live service. Our infrastructure providers keep their own short-lived copies for disaster recovery, so something you deleted can persist in one of those for a short time afterwards. It is never restored to the live service and it ages out on their cycle rather than ours.

What survives deleting your account

These four things do, and the email you receive when it is done says so too:

  • A counter against a hash of a network address. That is a household on one connection rather than a person, and it is the control that stops sign-in abuse.
  • What the models cost, which carries nothing that identifies anybody.
  • Payment event identifiers and timestamps for webhooks already processed, on a fortnight’s expiry.
  • Your Stripe customer record, and the charges and invoices against it, because those are financial records with their own legal retention.

One thing worth knowing about timing: after your account is swept, a published address can go on answering for up to a minute while the change reaches every edge location. Everything behind it is already gone.

Your rights

Wherever you live, you can ask us to do all of the following, and we will do it. Some of them are rights you hold under a particular law, and where they are, that law decides the detail.

  • See it. Get a copy of what we hold about you.
  • Correct it. Have something inaccurate put right.
  • Delete it. There is a button for this in the studio and it does the whole job. You can also just ask.
  • Take it elsewhere. Get what you gave us in a machine readable form.
  • Object, or ask us to stop. Including to anything we do on the basis of a legitimate interest.
  • Restrict. Ask us to hold something without using it while a disagreement is sorted out.
  • Withdraw consent. Where we asked for it, you can take it back at any time, and that does not undo what was done before.
  • Not be treated worse for asking. Exercising any of these changes nothing about the service you get or the price you pay.

Write to legal@vows.day. We answer within 30 days, and tell you if a request will honestly take longer. We may need to check you are who you say you are, which usually means writing from the address on the account.

You are free to use an authorised agent. We will still need to satisfy ourselves that you asked them to act.

If you are in the UK, the EEA or Switzerland

The rights above are your GDPR rights, and you can complain to your national data protection authority. In the UK that is the Information Commissioner’s Office. We would rather you came to us first, but nothing requires you to.

If you are in California or another US state with a privacy law

In the last twelve months we have collected the categories of personal information described in section 4: identifiers, customer records, commercial information about what you bought, internet activity, approximate location at country level, and the audio, visual or similar information in the files you upload. It comes from you, from your device and from Stripe. The purposes are in section 5 and the recipients in section 7.

We do not sell personal information. We share it for cross-context behavioural advertising in exactly one way: the Pinterest tag described in the cookie notice, which tells Pinterest which pages of vows.day were opened, whether an account was made and whether a payment was started or made, so that our own advertising can be measured. It runs only on vows.day, never on a couple’s published site, and it is told nothing you type. We do not knowingly share anything about anybody under 16: the service is for adults, and the tag does not run for a browser that asks not to be tracked. We do not use or disclose sensitive personal information for anything beyond providing the service, so there is nothing to limit.

You can exercise the rights to know, delete, correct and opt out through the same address, and we do not discriminate against anybody who does. To opt out of sharing, turn on the Global Privacy Control signal in your browser: we honour it without asking anything further, and a browser sending it is not measured at all, by Google or by Pinterest. Writing to the address above does the same.

How it is protected

Everything is encrypted in transit and at rest by our infrastructure providers. Beyond that, the measures that actually matter here are specific to this product:

  • No client can read the database. The rules deny every read and write from a browser. Data is only ever returned by a function that has checked who is asking.
  • Ownership is checked on the record, not inferred from the URL, and “not yours” and “does not exist” give the same answer, so the API cannot be used to find out which sites are real.
  • Uploads are never trusted. The bytes are sniffed against what was claimed, executable and script-bearing formats are refused outright, location data is stripped on the way in, and originals are never served.
  • Nothing a guest types into is generated. The reply form is ours, injected at build time, so no template and no model can write a field that posts somewhere else.
  • Published sites carry a strict content security policy, which is what stops a script reaching the network from a couple’s page.
  • Codes, not passwords, so there is no password database to lose. Sign-in codes are stored as a keyed hash and deleted the moment they are used.
  • The upload bucket has public access prevention enforced, so a mistake cannot make somebody’s photographs public.

No system is perfectly secure. If we discover a breach affecting your personal data, we will notify the relevant supervisory authority within 72 hours where the law requires it, and tell you without undue delay where the risk to you is high. If you have found a problem, please write to legal@vows.day. We will not pursue anybody who reports something in good faith and gives us a reasonable chance to fix it.

Children

Vows is for adults. You must be 18 to open an account and we do not knowingly collect anything from a child. A child may well appear in a wedding photograph or on a guest list, and if they do it is your responsibility as the couple to have their parent or guardian’s agreement before publishing it.

If you believe a child’s information has reached us in some other way, tell us at legal@vows.day and we will remove it.

Changes to this policy

We will update this page when what we do changes. The date at the top always says which version you are reading. If a change is material, we will email every account holder at least 30 days before it takes effect, and adding a new subprocessor is announced in section 7 before it starts.

Old versions are available on request.

Getting hold of us

Privacy: legal@vows.day
Security: legal@vows.day
Anything else: hello@vows.day

By post: Migambi Global, LLC, 131 Continental Dr, Suite 305, Newark, DE 19713, United States.

Vows

© 2026 Vows

Product

  • How it works
  • What it does
  • Designs
  • Pricing

Vows

  • Sign in
  • Contact

Compare

  • Vows vs Zola
  • Vows vs The Knot
  • Vows vs Joy
  • Vows vs Minted
  • Vows vs Riley & Grey
  • Vows vs Bliss & Bone
  • Vows vs Squarespace
  • Vows vs Wix
  • Vows vs Appy Couple

Legal

  • Terms
  • Privacy
  • DPA
  • Cookies
  • Refunds