Privacy Policy
Short version: You register with an email and password. Your wedding planning data is yours. We don't sell it, share it, or use it for advertising. We use only functional cookies — no tracking, no analytics platforms.
Overview
This Privacy Policy explains how Amar Micro Inc. ("we," "us," or "our") collects and uses information in connection with wed.money at https://wed.money.
What We Collect
Information You Provide
| Data | When | Purpose |
|---|---|---|
| Name | Registration | Account identity |
| Email address | Registration, invitations | Account access, verification, support |
| Password (hashed) | Registration | Authentication — stored as bcrypt hash, never in plain text |
| Phone (optional) | Registration | Optional contact preference |
| Payment information | Purchase | Payment details are processed by third-party payment processors. We do not intentionally store full credit card numbers on our servers. |
| Support messages | When you contact us | Resolving your request |
Collected Automatically
| Data | Purpose |
|---|---|
| IP address at registration | Fraud prevention, security |
| IP address at last login | Security audit, account recovery support |
| Session cookie | Keeping you logged in (functional only) |
We do not use analytics platforms, advertising networks, or any third-party tracking scripts.
Your Planning Data
All wedding planning data you enter — vendors, budgets, payments, events, attachments, and celebration member details — is stored on our servers and is treated as confidential. We access it only to operate the Service (e.g. backups, performance monitoring) and never for marketing or analytics purposes.
Locked or expired accounts may be disabled and processed using the same retention and backup constraints described in this policy.
How We Use Your Information
- Provide, operate, and improve the Service;
- Verify your email address and authenticate your account;
- Process your purchase and deliver your license;
- Send you transactional emails (verification, purchase confirmation, support responses);
- Notify you of important service changes or security issues (you may not opt out of these);
- Prevent fraud and protect the security of the Service;
- Comply with legal obligations.
We do not sell your personal information, use it for advertising, or share it with data brokers.
Legal Basis for Processing (GDPR)
If you are located in the European Union or European Economic Area, we process your personal data under the following legal bases as defined by the General Data Protection Regulation (GDPR):
| Processing Activity | Legal Basis |
|---|---|
| Creating and managing your account | Contract performance — necessary to provide the Service you signed up for (Art. 6(1)(b)) |
| Email verification | Contract performance — required to activate your account (Art. 6(1)(b)) |
| Processing your purchase | Contract performance — necessary to fulfill your purchase (Art. 6(1)(b)) |
| Storing your planning data | Contract performance — the core purpose of the Service (Art. 6(1)(b)) |
| Sending transactional emails | Contract performance and legitimate interest — service-critical communications (Art. 6(1)(b) and (f)) |
| Security logging (IP addresses) | Legitimate interest — fraud prevention and account security (Art. 6(1)(f)) |
| Retaining purchase records | Legal obligation — tax and accounting compliance (Art. 6(1)(c)) |
We do not rely on consent as a legal basis for processing, except where you explicitly opt in to optional communications.
Sharing & Disclosure
Service Providers
We use limited third-party processors bound by confidentiality obligations:
- Payment processor — to process purchases (payment details are processed by third-party payment processors, and we do not intentionally store full credit card numbers on our servers);
- Transactional email service — to send verification and support emails;
- Hosting provider — for server infrastructure.
Celebration Members
When you invite a user to your celebration, their display name and email are visible to other celebration members with appropriate access. You consent to this visibility by choosing to invite them.
Legal Requirements
We may disclose information when required by law, subpoena, or court order, or in good faith to protect our rights, your safety, or others' safety.
Business Transfers
If Amar Micro Inc. is acquired or merges, user information may transfer. Where appropriate or legally required, we will provide notice to affected users.
Staff Access & Impersonation
Authorized Amar Micro Inc. staff may access account and planning data in the following limited circumstances:
| Type of Access | Purpose | Who |
|---|---|---|
| Administrative support access | Technical support, abuse investigation, system maintenance | Authorized support and engineering staff |
| Read access to planning data | Reproducing and diagnosing reported bugs; verifying data integrity | Authorized support and engineering staff |
| Account impersonation support access | Logging in as your account to reproduce a technical issue exactly as you experience it | Authorized support staff only |
What Staff Cannot Access
Payment details are processed by third-party payment processors. We do not intentionally store full credit card numbers on our servers.
Impersonation
We may use administrative support tools to access or view account information only when reasonably necessary to provide support, troubleshoot problems, investigate abuse, maintain security, or comply with legal obligations. Where practical, we will seek your authorization before using account impersonation for support. Administrative access should be recorded in an administrative audit log.
Impersonation is performed through a privileged administrative mechanism designed to avoid requiring or exposing your password to staff.
Audit Logging
Administrative access events should be recorded in an administrative audit log, including who accessed the account and when. You may request a summary of staff access to your account through our contact form (or email privacy@wed.money if you can't access the form).
Confidentiality
All staff with access to user data are bound by confidentiality obligations. Data accessed during support sessions is used solely to resolve the issue and is not retained, shared, or referenced beyond that purpose.
Cookies
We use only functional cookies — strictly necessary to keep you logged in. We do not use tracking, analytics, or advertising cookies. See our Cookie Policy for full details.
Security
We implement appropriate technical measures including HTTPS for all traffic, bcrypt password hashing, and access controls on server infrastructure. No system is 100% secure — if you discover a vulnerability, please see our Security Policy.
Data Retention
| Data | Retention |
|---|---|
| Active account data | For the life of the account |
| Purchase records | 7 years (tax and legal compliance) — anonymized at deletion; see below |
| Support correspondence | 3 years from last interaction |
| Locked / expired accounts | Deleted at day 44 from registration |
| Server access logs (IP) | 90 days |
| Session cookies | Usually deleted when the browser closes; persistent functional cookies may remain for configured periods (for example language, active celebration, event filter, and remember-me email preference) |
Account Deletion & Financial Records
When you delete your account, we disable access as soon as reasonably possible and use reasonable efforts to delete personal data from live production systems, typically within 30 days, except records we are required or permitted to retain for legal, tax, security, fraud-prevention, dispute-resolution, or backup purposes. Deleted data may remain in encrypted backups until those backups expire under our backup retention schedule. Timelines are subject to operational and technical constraints.
Financial transaction records (date, amount, product, transaction reference) are retained for up to 7 years as required by US tax law and equivalent legal obligations. At the point of account deletion, these records are anonymized — your name and email are replaced with an internal reference ID. We retain the transaction, not the person. Timelines for anonymization may vary based on operational or legal requirements.
Backups
We maintain encrypted backups of our systems solely for disaster recovery purposes. Backups are retained under our backup retention schedule (currently configured internal schedule).
Deleted personal data may remain in encrypted backups until those backups expire under that schedule. Backup data is used for recovery operations, and deleted accounts are intended to be re-deleted after restoration where technically feasible. Timelines for backup expiration and re-deletion are subject to operational and technical constraints.
EU / EEA Residents — GDPR Rights
If you are located in the European Union or European Economic Area, the General Data Protection Regulation grants you the following rights regarding your personal data:
| Right | What It Means |
|---|---|
| Access (Art. 15) | Request a copy of the personal data we hold about you |
| Rectification (Art. 16) | Request correction of inaccurate or incomplete data |
| Erasure (Art. 17) | Request deletion of your personal data from live systems. We disable access as soon as reasonably possible and use reasonable efforts to delete personal data from live production systems, typically within 30 days, subject to legal and operational retention exceptions. Financial transaction records may be anonymized rather than deleted (legal obligation carve-out, Art. 17(3)(b)). Deleted data may remain in encrypted backups until those backups expire under our backup retention schedule. |
| Portability (Art. 20) | Receive your personal data and planning data in a structured, machine-readable format (JSON or CSV) for transfer to another service |
| Restriction (Art. 18) | Request that we restrict processing of your data in certain circumstances |
| Object (Art. 21) | Object to processing based on legitimate interest; we will cease unless we demonstrate compelling grounds |
How to Exercise Your Rights
Submit a request through our contact form (or email privacy@wed.money if you can't access the form) with the subject line "GDPR Request." We respond to privacy rights requests within the timeframe required by applicable law. We may ask you to verify your identity before fulfilling the request.
Data Portability
You can export supported planning data where available from your account settings. Availability and format may depend on current product functionality and operational constraints.
Supervisory Authority
You have the right to lodge a complaint with your local data protection authority (DPA) if you believe we have not handled your data in accordance with GDPR. A list of EU/EEA supervisory authorities is available at edpb.europa.eu.
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware. Where the breach is likely to result in a high risk to you personally, we will notify you directly without undue delay.
Sub-Processors
Where required, we use service providers under appropriate contractual terms, which may include data processing terms or similar protections. Providers handling personal data are expected to process data only for the services they perform on our behalf.
California Residents — CCPA Rights
If you are a California resident, you have the right to: know what personal information we have collected and how it is used; request deletion of your personal information (subject to legal exceptions); and opt out of the sale of personal information. We do not sell personal information.
To exercise your rights, use our contact form (or email privacy@wed.money if you can't access the form). We respond to privacy rights requests within the timeframe required by applicable law. We may ask you to verify your identity before fulfilling the request. You will not be discriminated against for exercising CCPA rights.
Children's Privacy
wed.money is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have done so inadvertently, contact us immediately through our contact form (or email privacy@wed.money if you can't access the form) and we will delete it.
Changes to This Policy
We may update the effective date and, where appropriate or legally required, notify registered users by email when we make material changes. Continued use after the effective date constitutes acceptance. Timelines for notice and effect may vary based on operational or legal requirements.
Contact
Amar Micro Inc. — Privacy
P.O. Box 352086 Los Angeles CA 90035
USA
Use our contact form, or email privacy@wed.money if you can't access the form.
We respond to privacy rights requests within the timeframe required by applicable law. We may ask you to verify your identity before fulfilling the request.