Privacy at GuestiGram

Your moments are personal. We treat them that way.

This notice explains what information GuestiGram handles, why we need it, who can see it and the choices available to hosts, guests and event contributors around the world.

Last updated: 28 July 2026

We do not sell your dataPersonal information and event media are not sold or rented to advertisers.
Hosts control their eventsHosts choose the event settings, invited guests and visibility of contributed media.
Payments stay with PaddleGuestiGram does not receive or store complete payment-card details.
Analytics is optionalGoogle Analytics remains off unless you choose to allow it. Advertising storage stays disabled.

1. Who we are and what this notice covers

GuestiGram is a United Kingdom-based digital event service for collecting photographs, videos, voice notes and guestbook messages, and for managing invitations, RSVPs, meal choices, seating and event information. GuestiGram is a trading name of Saasybrands Ltd trading as GuestiGram, International House, 22-28 Wood Street, Doncaster, DN1 3LW, United Kingdom. In this notice, “GuestiGram”, “we”, “us” and “our” mean that business.

This notice applies to guestigram.com, GuestiGram event pages, host dashboards, payment journeys, support communications and the related services we provide. It does not govern an external gift registry, maps service or other third-party website opened from an event page.

For privacy questions, contact support@guestigram.com with “Privacy request” in the subject line. GuestiGram is the controller for host accounts, billing administration, service security, support and our own website operations.

2. The different roles of hosts, guests and GuestiGram

An event host decides what event information to publish, whom to invite, which guest details to record, which planning tools to use and whether contributed media requires approval. For this event information, the host determines the purpose and use of the data. GuestiGram stores and processes it to provide the service to the host.

If you are a guest and want to change an RSVP, meal selection, photograph or other event contribution, contacting the host is usually the quickest route. You may also contact us and we will help route a valid request where appropriate.

Hosts must use GuestiGram fairly, tell guests how their information will be used where required, avoid entering unnecessary sensitive information, and have an appropriate reason for uploading or sharing information about other people. Dietary details should be collected only where needed for catering and handled carefully by the host.

3. Information we collect

Host account and event information

  • Name, email address, authentication records and account identifiers. Passwords are handled by our authentication provider and are not available to GuestiGram in readable form.
  • Event name, type, date, venue, hosts' names, welcome design, schedule, travel information and event settings.
  • Plan, purchase, invoice, tax and payment-status information. Paddle handles complete card details as merchant of record.

Guest and planning information

  • Guest or group names, party size, invite token and optional contact details entered by the host.
  • RSVP answers, attendance, meal choices, optional dietary requirements, seating assignments, song requests and guest action status. Dietary details may reveal information about health or religious beliefs.
  • Information a host provides about a guest, even when that guest has not entered it directly.

Event content

  • Photographs, videos, voice notes, guestbook messages, captions, uploader name and album membership.
  • File information such as type, size, original filename, capture time when available, upload time and moderation status.
  • Images or recordings may incidentally reveal sensitive characteristics. We do not use face recognition, create biometric templates or use event content to train artificial-intelligence models.

Technical, payment and support information

  • IP address, browser and device type, request and error logs, referrer, language and basic activity needed to operate and protect the service.
  • Authentication cookies, event identifiers and choices stored in the browser.
  • Paddle customer, transaction and adjustment references, but not full card numbers or security codes.
  • Messages sent to support and information supplied when reporting a fault or exercising a privacy right.

4. How and why we use information

PurposeExamplesUK lawful basis
Provide the serviceCreate accounts and events, authenticate hosts, accept contributions, manage RSVPs and display approved event content.Performance of our contract with the host; processing on the host's instructions for event data.
Handle dietary requirementsRecord optional dietary information supplied for a guest and make it available to the host for catering and event planning.The host acts as controller and determines the applicable Article 6 lawful basis and, where the information is special-category data, the Article 9 condition. This will often be Article 9(2)(a) (explicit consent) where a guest enters the information directly and is separately asked to provide a clear express statement of consent. GuestiGram acts as processor and handles it only on the host's documented instructions, unless the law requires otherwise.
Take paymentCreate one-off payments, confirm a plan and keep transaction records.Contract and legal obligations relating to tax, accounting and fraud prevention.
Protect GuestiGramSecure sessions, rate-limit abuse, diagnose errors, investigate misuse and maintain reliable backups.Our legitimate interests in security, availability and preventing fraud.
Support and communicateAnswer questions, send essential account or service messages and resolve privacy requests.Contract, legitimate interests and legal obligations.
Improve the productReview service errors and aggregate operational performance without using private event media for advertising.Our legitimate interests in improving a useful and reliable service.
Optional analyticsMeasure public page views and privacy-safe signup, checkout and purchase steps after analytics has been allowed.Consent. Consent may be withdrawn at any time through Cookie settings.

Dietary requirements may reveal health information or religious beliefs and therefore may be special-category data. The host remains responsible for choosing and documenting the appropriate lawful basis and Article 9 condition, including when a guest enters the information directly into the event form. Where the host relies on explicit consent, that consent must be freely given, specific, informed, unambiguous, recorded through a clear statement, and capable of being withdrawn. Entering dietary information alone must not be treated as explicit consent without that separate clear statement.

We do not make decisions about people using solely automated processing that produce legal or similarly significant effects. We do not sell personal information or share it for cross-context behavioural advertising.

5. Event pages, links and contributed media

Event information is intended to be shared with the people chosen by the host. Anyone who receives a shared event link or QR code may be able to open the corresponding guest experience, so hosts and guests should forward links carefully. A personal invitation link may identify a particular guest group and should be treated as private.

Where media approval is enabled, an upload remains awaiting review until the host approves or declines it. Approved content may appear in guest photos, albums, the live feed or guestbook to people who can access the event. Declined media is not shown in those guest-facing views.

People shown in a photograph or recording may not be the person who uploaded it. Hosts and contributors should respect the wishes of people depicted and avoid uploading content that is unlawful, unsafe or unexpectedly intrusive. Contact the host or us if content should be reviewed or removed.

6. Who receives information

We disclose information only where it is needed to operate the service, follow the host's settings, protect people, complete a transaction, measure the public website with consent or comply with law. Recipients may include:

  • Event hosts and authorised participants, according to event links, invite tokens, approval choices and album visibility.
  • Supabase, for database, authentication and related backend services. Read Supabase's privacy policy.
  • Cloudflare, for hosting, content delivery, security and R2 media storage. Read Cloudflare's privacy policy.
  • Paddle, as merchant of record for checkout, payment processing, tax, invoicing and fraud controls. Read Paddle's privacy policy.
  • Google Analytics, only after analytics consent, for public-page usage and privacy-safe signup, checkout and purchase events. GuestiGram does not intentionally send names, email addresses, event names, private event paths or contributed media. Read Google's privacy policy.
  • Professional advisers, insurers, auditors, regulators, courts or law-enforcement bodies where reasonably necessary and lawful.
  • A buyer or successor if the GuestiGram business is reorganised or transferred, subject to suitable confidentiality and privacy protections.

Service providers are permitted to use information only for the services they provide to us and under their own legal duties. We do not rent guest lists or event media to third parties.

7. International data transfers

GuestiGram is based in the UK and serves events internationally. Our service providers, including Google when analytics is allowed, operate global infrastructure, so information may be processed in the UK and in other countries.

Where UK data-protection law restricts a transfer, we use an applicable adequacy regulation or appropriate contractual safeguards, such as the UK International Data Transfer Agreement or UK Addendum to approved standard contractual clauses, together with supplementary security measures where required. For transfers governed by the EEA GDPR, we use an adequacy decision or another approved transfer mechanism. You may ask us for more information about the safeguard relevant to your information.

8. How long we keep information

We keep information only for as long as it is needed for the purpose described, the host's selected access period, security, dispute resolution and legal obligations.

InformationNormal retention approach
Event content and planning dataKept while the event remains within its plan access period. When access expires or a host asks us to delete an event, access may be restricted and the data enters our deletion process. Residual encrypted backups are removed as backup cycles expire.
Host account dataKept while the account is active and for a reasonable period afterwards to complete closure, resolve disputes and prevent abuse.
Payment, accounting and refund-eligibility recordsKept for up to six years after the relevant transaction or activity where needed for UK tax, accounting, fraud prevention or legal claims. Refund evidence is limited to the event identifier, upload count and first and last media-upload timestamps; it does not retain the media, filename or guest identity.
Security and diagnostic logsKept for the shortest useful operational period, normally no longer than 12 months unless an incident requires longer investigation.
Support correspondenceKept while the issue is active and normally for up to 24 months afterwards so we can understand previous decisions and recurring faults.

Specific records may be retained longer where law requires it, a legal claim is active, fraud is being investigated or deletion would affect another person's rights. A request to erase an event does not require us to erase limited records that we lawfully need to comply with legal obligations, prevent fraud or establish, exercise or defend legal claims. Where possible, we delete or anonymise information that is no longer needed. Hosts should download important event media before their plan access period ends.

9. Cookies, analytics and browser storage

GuestiGram uses cookies and local browser storage that are necessary to provide requested features. These include secure host authentication, the optional “Stay signed in” choice, short-lived event hand-off information, the last event opened, guest or event preferences on a device, and the saved cookie choice itself. Necessary storage operates without analytics consent because the service cannot provide the requested security and functionality without it.

Choosing “Stay signed in” permits the hardened host-authentication cookie to remain for up to 30 days. Otherwise, host authentication is configured for the browser session. Signing out ends the server session and removes the relevant authentication state.

Google Analytics is optional and remains off until “Allow analytics” is selected. If allowed, it measures public page views and the completion of signup, checkout and purchase steps. Page query strings are removed before page measurement, advertising storage and personalisation remain denied, and private guest, event, dashboard, DJ and administration routes are excluded. We do not intentionally send names, email addresses, event names, guest details or private wedding content to Google.

You can withdraw or restore analytics consent at any time through the “Cookie settings” control. Withdrawing consent stops new analytics events and removes the Google Analytics cookies that GuestiGram can access. Paddle and our infrastructure providers may still use their own strictly necessary security and checkout technologies.

10. How we protect information

We use safeguards designed for the sensitivity of event and account information, including encrypted HTTPS connections, hardened authentication cookies, access controls, private service credentials, signed or authorised upload routes, separation between host and guest access, logging and backup procedures.

No internet service can promise absolute security. Hosts should use a unique password, keep personal invite links private and remove access from shared devices. Please report suspected unauthorised access promptly to support@guestigram.com. If a personal-data breach creates a legal duty to notify affected people or a regulator, we will do so.

11. Your privacy rights

Depending on the applicable law and our role, you may have rights to:

  • be informed about processing and obtain a copy of your personal information;
  • correct inaccurate or incomplete information;
  • ask for deletion or restriction in certain circumstances;
  • receive information you supplied in a portable format;
  • withdraw consent, where processing depends on consent; and
  • complain to a data-protection authority.
Your right to object

You may object at any time to processing based on legitimate interests, including any direct marketing. We will stop unless we can demonstrate compelling legitimate grounds or need the information for legal claims. We do not currently use personal information for direct behavioural advertising.

Email support@guestigram.com and describe the event, account and request. Do not send a password, verification code or full payment-card details. We may need to verify identity and authority before acting. Where UK GDPR applies, we normally respond within one month; complex or numerous requests may lawfully take longer.

Some rights are limited by the lawful basis, another person's rights, legal retention duties and whether GuestiGram or the host controls the relevant processing. We will explain any lawful limitation.

12. Children's information

GuestiGram is designed for event hosts and is not intended for children under 13 to use independently. Events may naturally include children in guest lists, photographs or videos. The host and the child's parent or guardian should decide whether that information is appropriate to provide and how a child participates.

We do not knowingly create host accounts for children under 13 or use children's information for advertising or profiling. If you believe a child has provided information without appropriate involvement from a parent, guardian or host, contact us so it can be reviewed promptly. Children have privacy rights over their information as well as adults.

13. Information for people outside the UK

Privacy rights differ by country and state. Where another law applies to GuestiGram's processing, we will honour the rights it provides. These may include rights to know, access, correct, delete or obtain information, to appeal a refusal, and to opt out of sale, sharing or targeted advertising.

GuestiGram does not sell personal information, share it for cross-context behavioural advertising, or discriminate against a person for exercising a privacy right. We may ask an authorised agent for proof of authority and may verify a request directly with the individual. If a local representative or additional regional notice becomes legally required for a market, we will publish those details here.

14. Changes to this notice

We will update this page when our service, providers or legal duties materially change. The updated date at the top identifies the current version. If a change significantly affects how existing information is used, we will provide a more prominent notice to affected hosts and, where appropriate, event participants before the new use begins.

15. Contact and complaints

For a question, content concern or privacy-rights request, email support@guestigram.com. Include the event link or account email where relevant, but never include your password or payment-card details.

If you are in the UK, you may complain to the Information Commissioner's Office. If you live elsewhere, you may also contact the data-protection authority where you live or work. We would appreciate the opportunity to address the concern first, but that is not a condition of contacting a regulator.