Wedding Draft Open the planner

Privacy

Last updated 29 September 2026

This explains what Wedding Draft (weddingdraft.com) keeps about you and the people on your guest list, why, and how to get it deleted. The planner works without an account: until you sign in, your layouts and guest list stay in your own browser and are never sent to us.

Who we are: MakeHelm Ltd, a company registered in England and Wales (company number 17433308), registered office 66 Paul Street, London EC2A 4NA. Privacy questions: [email protected]. We are the controller for the account and planning data described here.

What we keep

Your account

  • Your email address, your name if you give one, your preferences (units, currency) and a salted hash of your password (never the password itself).
  • If you sign in with Google: your Google account id and the email Google confirms. We don't get your contacts or anything else.
  • Sign-in security records: failed attempts, when an account was locked, when you last signed in.

Your plans

  • Your layouts: the room, furniture, scenes, wedding details (your names, the date, the venue) and any floor-plan image you trace over. Layouts, their names and your wedding details are encrypted in our database; floor-plan images are stored privately with Cloudflare R2.
  • Earlier versions of each layout (so you can go back), kept for a limited time — see how long.
  • If you invite someone to plan with you: their email address and the role you gave them.

Your guests' details

Your guest list is information about other people: their names, households, whether they're coming and — if you add them — meal choices and dietary or allergy notes. Allergy and dietary notes can reveal health conditions or religious belief, which data-protection law treats as special category data. We handle it accordingly:

  • We use it only to show your plan back to you and the people you invite, and to build what you ask for (prints, the find-your-seat page, the caterer's list).
  • It is encrypted in our database (each layout, every saved version and the find-your-seat page's list are encrypted at rest with keys held outside the database), and only travels over encrypted connections.
  • Our staff don't look at it. Support can only open a layout as an explicit, logged action when you ask us to help with it.
  • It is never used for analytics, advertising or training anything. Our measurement records kinds and counts ("added 8 tables", "imported 110 guests"), never names.
  • Only add what you need: meal and allergy notes are optional.

Why we're allowed to: we hold your account and plans to provide the planner you signed up for (our contract with you). Your guests' details are there because you put them there to plan your own wedding; we hold them for you on the basis of our legitimate interest in providing that service, and for nothing else. Allergy and dietary notes are only held if you add them, and only with your guests' agreement: please add them only when a guest has told you so you can pass it to your venue or caterer.

The find-your-seat page

If you publish one, anyone with its link or QR code can see guests' first names, surnames and table numbers, plus what the page needs to show the room: your names, the wedding date and venue, and the floor plan with its furniture. Nothing else about guests (no meals, no notes, no RSVPs). It isn't listed in search engines, and you can switch it off or change its link at any time.

Payments

The Wedding Pass is sold by Stripe as merchant of record (Stripe Managed Payments): Stripe takes the payment, handles tax and sends your receipt, under Stripe's privacy policy. We never see your card details. We keep a record of the sale: which wedding it covers, the amount, currency and date. With the checkout we send Stripe our own ids for your account and wedding, the price you were offered and, if you accepted measurement cookies, your random visitor id (so a sale can be counted in the test that showed you the price) — never your plans or guest list.

Measurement and cookies

  • Before you choose, or if you reject: we count page views and actions without cookies. Your IP address is shortened (masked) before it's stored, and visits are grouped by an anonymous code worked out from the shortened address and your browser type. That code changes every day, so it can't link one day's visits to the next, and nothing is stored on your device.
  • If you accept: a random visitor id (a cookie and your browser's storage) lets us compare versions of pages. Change your mind any time on the cookie settings page.
  • If you're signed in: which version of a test you see is remembered on your account so it stays the same on every device. We do this on the basis of our legitimate interest in improving the product; you can object by emailing us.

How long we keep it

  • Layouts and guest lists: until you delete them, and automatically 12 months after your wedding date (the whole wedding: layouts, versions, images, find-your-seat page, invites). We only do this once the plan hasn't been changed for 12 months, and we email the owner at least 30 days before.
  • Saved versions: the 20 most recent plus one a day for 30 days.
  • Analytics: 90 days in detail, then only daily totals.
  • Your account: until you delete it (your weddings are still deleted on the schedule above).
  • Sale records: kept for six years for tax and accounting, even after you delete everything else, without your name, email or wedding.
  • Backups roll over within 30 days.

Who else handles it

Only the services we need to run the planner, each under a data processing agreement:

  • Hosting and database: a DigitalOcean server in London, UK, managed through Hatchbox.
  • Cloudflare: network, security and file storage (R2) for floor-plan images and thumbnails.
  • MailPace: sending account emails (sign-in links, confirmations, invites).
  • Stripe: payments, as merchant of record (above).
  • Google: only if you choose "Continue with Google".

Our servers and database are in the UK. Cloudflare, Stripe, Google, DigitalOcean and Hatchbox are US companies and may handle data outside the UK. Those transfers are protected by the UK–US data bridge where the company is certified, and otherwise by the UK International Data Transfer Agreement or Addendum in their data processing agreements.

Your rights

  • Delete your wedding: account menu → Delete my wedding. Its layouts, guest lists, versions, images, find-your-seat page and invites are erased at once (backups roll over as above).
  • Delete your account: account menu → Delete my account. Everything above plus your account; your past visits lose any link to you.
  • Get a copy: every layout can be exported as a file from the layout menu. For everything else we hold, email us.
  • You can also ask us to correct or restrict what we hold, or object to how we use it. You can complain to the UK Information Commissioner's Office (ico.org.uk).

If someone on your guest list asks us about their data, we'll tell them it's held on behalf of the couple who planned the wedding and help you answer them.

Children

The planner is for adults planning a wedding. Guest lists may include children's names (e.g. to seat them with their family); treat them with the same care.

Changes

If we change this policy in a way that matters, we'll say so in the planner and, if you have an account, by email.

© 2026 Wedding Draft Privacy Terms Refunds Cookie settings

Wedding Draft is run by MakeHelm Ltd, registered in England and Wales (company no. 17433308), 66 Paul Street, London EC2A 4NA.