Privacy
Last updated 16 September 2026
Short version: we collect what an invitation needs to work, we never sell it, and guest pages carry no advertising and no tracking. Our own shop pages use two advertising tags, Meta’s and Pinterest’s, described below, with one working off switch for both.
What we collect from couples
- Your names, wedding date and the details you write on your invitation.
- Your email address. It is how you sign in and how we reach you.
- What you bought and when. Card details never touch our servers. Stripe handles payment.
What we collect from guests
- The name they type, whether they are coming, meal choice and any allergies.
- A song, a message, an email or phone number, only if they choose to add them.
- How many times an invitation was opened. No names, no tracking across sites.
Guests do not create an account and are never asked for a password. What they submit is shown to the couple who invited them, and to nobody else.
The allergy box exists for one reason: so the kitchen knows what to cook. Only the couple sees what a guest writes there, we never read it or use it for anything, and it is deleted with the rest of the replies.
Photographs your guests upload
If your invitation has the guest photo album, your guests can add pictures from their phones by opening your album link or the code on the table. They do not make an account and we do not ask them who they are.
Those pictures nearly always have other people in them, so this is worth saying carefully. We keep them for you, we show them in your album and nowhere else, and we do nothing else with them at all: not advertising, not our own site, not training anything. You can hide any picture from your dashboard, at any time, without telling anyone why.
Your guests cannot see the album. They add their pictures and that is all they see. The album itself opens only for you, signed in, on your own dashboard. Nobody else has a way in, and a picture has no address anyone can keep: the ones your dashboard uses expire on their own within the hour. Hide a picture and it leaves the album; ask us and we delete the file itself.
Pictures are kept like everything else here: through the wedding and twelve months after, and sooner if you ask.
We do not sell your information
We have never sold anybody’s information, and we do not intend to. Not the couple’s, not their guests’. Not to data brokers, not to anyone who wants a list of people getting married. We earn our money by selling invitations, which is a simpler way to run a business.
One honest asterisk. The Meta pixel and the Pinterest tag described below tell Meta and Pinterest which of our shop pages you opened, and some privacy laws call that “sharing”. It never happens on a couple’s invitation or album, it does not run for visitors from California at all, and the off switch below works. That is the whole list.
Categories, plainly
The privacy laws ask us to describe what we hold in their own words, so here it is in both languages at once:
- Identifiers. Your name and email address, and the names your guests type into the reply form.
- Commercial information. What you bought, when, and the receipt for it.
- Internet activity. That a page was opened, roughly from where in the world, and on what kind of device. No name is attached to it.
- The content you write yourselves. Your wedding details, your photographs, and the replies and messages your guests leave.
All of it comes straight from you and your guests. We collect nothing from anywhere else, we buy nothing, and we hold no social security numbers, no card numbers, no precise location and nothing biometric. We use it to make your invitation work and for nothing besides. We keep it through the wedding and twelve months after, then it goes.
Cookies
We set no advertising or analytics cookies ourselves. Your browser stores a sign-in token so your dashboard remembers you, and a small note of when you last visited so we can show you what is new. On our shop pages the Meta pixel and the Pinterest tag set their own cookies; turn them off below and those cookies stop appearing.
How we count visits
We count page views through Vercel Analytics, which sets no cookies and builds no profile of you. It records that a page was opened, roughly from where in the world, and on what kind of device. It cannot follow you to another site, and we cannot tell one visitor from another.
Two tags for our ads, and the off switch
To learn which of our ads and pins actually bring couples here, our shop pages carry the Meta pixel and the Pinterest tag: the homepage, the design gallery, checkout and the help pages. Each reports that a shop page was opened, which design you looked at, and, if you buy, the fact of the purchase. Meta also receives a scrambled (hashed) version of your email so it can tell our ad worked. Neither ever sees what you write on your invitation, and neither ever sees your guests at all.
They never run where your guests are. A couple’s invitation, the reply form and the photo album are built without them, by a rule in the code, not by a setting someone could forget.
They do not run for visitors from California. If our host tells us a visit comes from California, neither tag ever starts, and the purchase reports described above are skipped too.
Do Not Sell or Share My Personal Information: press the button below, once, on any device. It costs nothing, nothing about the service changes, and it holds until you turn it back on.
Do Not Track and Global Privacy Control
If your browser sends the Global Privacy Control signal, we treat it as your “no”: both tags stay off without you pressing anything. The older “Do Not Track” signal has nothing further to switch off: beyond those two tags, we do not follow anyone across other websites, and we let no other company track you through our pages.
Error reports
When a page breaks, including a guest’s invitation, the browser sends a short error report to Sentry, the service we use to find and fix bugs. So do a small share of ordinary visits, so we can see whether pages load and how fast. A report holds the page address, the kind of device and browser, roughly where in the world the visit came from, and a technical description of what went wrong. It carries no name, no email and nothing a guest typed, it sets no cookie, and we use it only to fix the site.
Who else sees it
The companies that make the site run: Supabase (the database), Vercel (the hosting, and the cookieless counting of page views), Stripe (payments), Brevo (it delivers the emails we send you: sign-in links, receipts and the note when a guest replies) and Sentry (the error reports above). They process it on our instructions and cannot use it for anything else. And Meta and Pinterest, only in the narrow case above: shop pages only, never guests, never California, with the off switch that actually works.
How long we keep it
Through your wedding and twelve months after, then we delete it. Ask us sooner and we will delete it sooner. Write to hello@thedigitalenvelope.com.
Drafts you start before buying
If you try an invitation with your names before paying, we keep the draft (your names, email, wedding date if you gave one, everything you wrote, and the photographs you added) for fourteen days after the last time you change it, and never longer than sixty days in total. Then we delete the content and the photographs. Your email, names and date stay until you unsubscribe, so we can send you the notes you asked for and so a new draft starts with your names filled in. Draft photographs live in private storage that only your draft link can read; nothing reaches a guest until you buy. Every note we send about a draft has an unsubscribe link at the bottom, and one tap stops them. Buying turns the draft into your invitation and it is kept as described above.
Partners who ask for a code
If you ask for a partner code on our partners page, we keep what you wrote in the form (your name, what you do, email, phone, where couples find you, the code you asked for, and roughly how many couples you work with) so we can set the code up and write back. Your email and phone are seen only by us and are never shown to couples or to other partners. If we do not go ahead together, ask and we delete the request.
Your rights
You can ask for a copy of everything we hold about you, ask us to correct it, or ask us to erase it. One email is enough; we answer within a few days.
If you live in a state with a privacy law
California, Colorado, Connecticut, Virginia, Texas, Utah and more of them every year give you rights over your own information. We do not check which state you are writing from before honoring them. It is easier, and fairer, to give everybody the same rights.
You can ask for a copy of what we hold about you, ask us to correct anything that is wrong, and ask us to delete it. One email to hello@thedigitalenvelope.com is enough. Send it from the address you signed up with so we know it is you. It costs nothing, and nobody gets a worse service, a higher price or a slower answer for having asked. The law gives us forty five days to reply; we usually take two.
Children
Our service is for adults planning a wedding. We do not knowingly collect anything from children, beyond a first name a parent may add to an RSVP.
Changes to this policy
When something here changes, we change the date at the top of the page. If it is a change worth knowing about, we email everybody with a live invitation as well. We do not rewrite this page quietly.
Who holds all of this
The Digital Envelope is run by AIDP Corp. We are the ones who decide what is collected here and what it is for, which the privacy laws call being the controller. Everything on this page is a promise made by that company, and this is where to write about any of it.
AIDP Corp
Chicago, IL 60618
United States
hello@thedigitalenvelope.com