← Vowlist Privacy Policy
Last updated: August 2026. This describes what the software actually does today — when the code changes, this page changes with it.
Vowlist is a small, independent product run by Shahoreer Talha. We collect as little as possible and never sell your data. Here's exactly what we collect and why, in plain language.
What we collect from you (the couple)
- Your email — for sign-in links and your receipt. That's the only personal detail we ask for. Optionally, at signup: your wedding date and how you heard about us.
- Your wedding data — budget numbers, guest names, RSVP replies, meals, dietary notes, guest notes. It exists so the product works, it belongs to you, and you can export or delete all of it any time.
- Anonymous usage events — page views and feature use tied to a random id in a first-party cookie (
vl_sid, 90 days), plus the campaign tags in the link you arrived from (utm/ref). No names, no email in these events. We use them to see which pages lead to signups and where people get stuck. - Payment confirmation — Stripe tells us "this email paid $79" and gives us a customer id so refunds work. Card numbers never reach us.
- Your partner's email, if you invite them — typed by you on Wedding details. We send that address one invite email; if they accept they get their own sign-in to the same wedding. It's the only email address other than your own we ever hold, and it's a member of the couple, never a guest.
- Email preferences — whether you want planning tips, and how you want to hear about RSVP replies (daily digest, every reply, or off). Both live on Wedding details and take effect immediately.
Advertising measurement — marketing pages only
On our marketing pages only (the home page, /start, /buy, /welcome, /from-rsvp and the free tools under /free) we load Meta's pixel and send Meta's Conversions API a matching server-side event, so we can tell whether an ad led to a visit, a signup or a purchase. What Meta receives: the page viewed, an event id, your IP address and browser info, and Meta's own cookies if you have them. We do not send Meta your email — not even hashed.
The pixel is never loaded inside the app (/app), on guest RSVP pages (/r), on the demo, on this page, on the terms, or on sign-in pages. Ad blockers and browser tracking protection stop it, and Vowlist works exactly the same without it.
Your guests
- Guests never need an account and we never email, text or contact them. You share the link.
- Guest pages carry no ads and no third-party trackers. The only measurement is an aggregate count per wedding per day (page opened / reply sent) — no cookie, no id, no IP address stored.
- Their names and replies belong to you (the couple). Any guest can ask you or us to remove their row and we'll comply.
- A household link shows that household its own names and previous answers only. The wedding-wide link shows names only, never anyone's answers.
What we never do
- Sell, rent, or share your data or your guest list with anyone, including "partners" and vendors. We have no such partners.
- Show ads or send vendor promotions.
- Store your card details — payment runs entirely on Stripe.
- Send marketing email to couples who haven't opted in. Sign-in links, receipts and the RSVP-reply / deadline / headcount / post-wedding notes are account-service email; planning tips and the free-spreadsheet series are separate, carry a one-click unsubscribe and a postal address in every message, and stop the moment you turn them off on Wedding details.
Who processes data for us
| Provider | What for | What they see |
|---|
| Cloudflare | Hosting, database, network | Everything, encrypted in transit and at rest on Cloudflare's network |
| Stripe | Payments, refunds | Your email, card (never us), billing country |
| Resend | Sign-in links, receipts, our own alerts | Your email address and the message |
| Meta | Ad measurement on marketing pages only | Page views/conversion events, IP + browser info; no email |
| Loops | The free-spreadsheet email series and planning tips — only while you're opted in | Your email address, whether you have an account, household count |
| Sentry | Error reports (only if configured) | Stack traces, no personal data |
That's the whole list. No analytics SaaS, no chat widget, no session recorders.
Deleting everything
- Self-serve, immediately: Details page → "Delete my account and all data" → type DELETE. Your account, wedding, budget, checklist, every guest row and every reply are deleted at once. No email to us required.
- After a refund: your dashboard closes, export stays open for 30 days, then the account is deleted automatically.
- Anonymous usage events are kept but detached from the deleted account (they never contained your name or email).
- You can also email hello@getvowlist.com and we'll do it for you within 2 business days.
Your rights
Wherever you live, you can export your data (Export page), correct it (edit anything in the app), delete it (above), or ask us questions at hello@getvowlist.com. We don't "sell" or "share" personal information as those words are used in US state privacy laws, so there is nothing to opt out of.
Changes
If we start collecting something new, this page changes first and account holders get an email. Cosmetic edits just move the date at the top.