Legal
Privacy Policy
This page explains what data we collect, what we use it for, who we share it with, and what rights you have over your own data.
- Version:
- 3.0
- Effective from:
- 2026-09-07
- Last updated:
- 2026-09-07
1. Scope
This policy covers the Thiệp Cưới Online website and the invitations created and shared through it.
For guest data inside an invitation, the invitation's owner decides what is collected; we process that data on the owner's behalf.
2. What we collect
Account data: email, display name, phone number (if you enter one) and a one-way hash of your password. We never store passwords in readable form.
If you sign in with Google or Facebook, we receive from that provider your email address, display name and an identifier that lets us recognise you next time. We never receive your password for those services.
Invitation content: the couple's names, family details, ceremony times and places, photos, thank-you notes and gift details that you enter.
What guests submit: the name and wish they leave in the invitation's guestbook.
Technical data: IP address, browser type, time of access, and a random viewer identifier stored in a guest's cookie so we can count how many people have seen an invitation.
Payment data: amount, order code, timestamp and the transaction details the bank sends back. We never receive or store your card number.
3. What we use it for
Creating, storing and displaying your invitation to whoever opens the link.
Authenticating sign-in, keeping your session, and protecting your account from unauthorised access.
Processing payment and applying the right plan, voucher and repeat-purchase discount.
Sending transactional email: password resets and payment receipts. We do not send marketing email unless you opt in.
Counting how many people have viewed an invitation, so the unpaid link limit is applied correctly and so you know how far your invitation has travelled.
Detecting abuse, fighting spam and improving the service.
6. Public invitations and the guestbook
Anyone with an invitation link can see its content. Think twice before publishing sensitive details such as a home address or a personal bank account number.
An invitation does have one form: the guestbook, where guests leave a name and a wish. We never ask guests whether they are attending, and there is no form asking for a head count.
A submitted wish is held for review and appears on the invitation only after the owner approves it. The owner may delete any wish.
The names and wishes guests enter are the owner's data; we store them on the owner's behalf and use them for nothing else.
7. Photos you upload
Photos are re-compressed before storage, and all metadata is stripped in the process — including the GPS coordinates phones usually attach.
This is deliberate: an invitation is a public link, and a wedding photo carrying its coordinates would reveal where it was taken to anyone who opens the invitation.
Uploaded photos are served from hard-to-guess URLs but do not require sign-in. Anyone holding a photo's URL can view it.
When an invitation is deleted — whether you delete it yourself or the retention window in section 13 runs out — its image files are removed from storage, not merely hidden from the interface.
8. Security
Connections to the service are encrypted with HTTPS. Passwords are hashed one-way before storage.
Internal access to data is limited by role and used only for operating and supporting the service.
No system is perfectly secure; use a strong password and do not share your account.
9. Your rights
You may view, correct or request deletion of your personal data.
You may request a copy of your data, including your acceptance history for the legal documents, and withdraw consent you gave earlier.
To exercise these rights, write to the support channel on the Contact page; we may need to verify your identity first.
10. Children
The service is for people aged 18 and over. We do not knowingly collect children's data; if we find any, it is deleted.
11. Changes to this policy
This policy may be updated as the service or the law changes. The current version and last-updated date always appear at the top of this page.
12. Deleting your account
When you delete your account from the Account page, your account data is really deleted, the email address is released, and you may register again with it.
When we disable an account (for example, for a breach of the terms), it loses sign-in access, the related data is kept, and that email address cannot be registered again.
In both cases orders and payment transactions are not deleted — accounting law requires those records to be kept.
13. Retention periods
This section has not been finalised. We leave it open rather than state a rule that has not been confirmed — if you need an answer for your particular case, please contact support.
An unpaid invitation link stops being reachable 3 days after publication.
When the link expires we send you an in-app notification. If the invitation is still unpaid 5 days after that notification, the invitation and every photo you uploaded for it are deleted permanently — both the database record and the image files in storage.
This deletion is performed automatically, needs no action from anyone, and cannot be undone. We count the 5 days from the notification rather than from the expiry itself, so that you always get the full window after being told.
The numbers above are current operational settings. If we extend the retention window, the change applies immediately, including to invitations already waiting to be deleted.
A paid invitation is kept for as long as your account exists; no automatic deletion applies to paid invitations.
Orders and payment records are not deleted along with an invitation — see section 12.
Retention periods for the remaining data types — accounts, activity logs and backups — have not been set.
14. Contact
This section has not been finalised. We leave it open rather than state a rule that has not been confirmed — if you need an answer for your particular case, please contact support.
For any question about your personal data, please use the support channel on the Contact page.