Privacy Policy
Last updated: August 2026
1. Introduction
PlanHitch Ltd ("PlanHitch", "we", "us", or "our") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and share your personal information when you use our wedding planning platform and related services (the "Service").
PlanHitch Ltd is a company registered in Scotland, company number SC869251, with its registered office at Office 1325, 3 Fitzroy Place, 1/1, Sauchiehall Street, Glasgow Central, United Kingdom, G3 7RH. We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Who is responsible for what
Data protection law distinguishes between the party that decides why and how personal data is used (the "controller") and the party that handles it on that party's instructions (the "processor"). Two different kinds of data pass through the Service, and they are not in the same position:
- Your account, billing and technical data: we are the controller. We decide what we collect to run your account, take payment, keep the Service secure, and fix faults.
- The wedding data you enter, including your guest list: you are the controller and we are your processor. You decide who goes on your guest list, what you record about them, and what you use it for. We hold and process that information on your instructions, so that you can. Where a wedding planner runs the account, the planner is the controller for the guest data they enter on a couple's behalf.
Because you are the controller of your guest data, two obligations sit with you rather than with us. You must have a lawful basis under data protection law for holding and sharing the information you enter about your guests, and you must make sure your guests know their details are being held in a wedding planning tool and who to approach about them. We do not tell you which lawful basis to rely on — that depends on your circumstances — but you do need one. If a guest asks you to remove them, you can delete them from your guest list at any time, and you can contact us if you would like help.
The terms on which we process guest data for you are set out in the Data Processing Terms in our Terms of Service, which you accept when you create an account. They cover what we may do with that data, the security we apply to it, the other companies we use, and what happens to it when you leave.
By using PlanHitch, you acknowledge that you have read and understood this Privacy Policy. If you have any questions, please contact us at contact@planhitch.com.
2. What We Collect
We collect the following categories of personal data:
Account Information
- Name (forename and surname), email address, and password (stored securely using one-way hashing)
- Account type (couple or wedding planner)
- Subscription plan and billing history
- Support correspondence, including the messages and tickets you send us and our replies
Wedding Data
- Wedding details including partner names, wedding date, venue information, and budget
- Guest lists including names, email addresses, phone numbers, dietary requirements, and RSVP responses
- Invitation designs, table plans, vendor contacts, and timeline events
- Photographs, videos, and other media uploaded to the Service
Voice Recordings and Planning Transcripts
- The written transcript of what you dictate or type to the planning assistant, which we do keep. The audio itself never reaches us — your browser turns speech into text before anything is sent, as section 5 explains. The transcript is the record of what you told the assistant, and everything the assistant adds to your plan is derived from it.
- Whatever you happen to say while recording. In practice this includes guests' names, family relationships, dietary needs and allergies, accessibility needs, and your reasons for seating people together or apart.
Health and Accessibility Information
- Food allergies and how severe they are, other dietary requirements, and accessibility needs recorded against a named guest.
- This reaches us in one of two ways: a guest enters it on an RSVP form themselves, or you tell the planning assistant about it and it is recorded against that guest. Section 6 explains how we treat this category of information.
Technical Data
- IP address, browser type and version, operating system
- Device information and screen resolution
- Pages visited, time spent on pages, and navigation paths
- Referring website addresses
- Diagnostic data when something goes wrong, which includes the error itself and a recording of the on-screen actions leading up to it. This is handled by monitoring software we run on our own servers; section 7 explains how.
Payment Data
Payment card details are collected and processed directly by our payment processor, Stripe. PlanHitch does not store your full card number, expiry date, or CVV. We receive only a truncated card reference and transaction confirmations from Stripe. Please refer to Stripe's Privacy Policy for details on how they handle your payment data.
3. How We Use Your Data
We use your personal data for the following purposes:
- Providing the Service: To create and manage your account, process your wedding planning data, send invitations, manage RSVPs, and deliver all features of the platform.
- Processing payments: To manage your subscription, process payments through Stripe, and send invoices and receipts.
- Communication: To send transactional emails (account verification, password resets, invitation deliveries, RSVP confirmations), service notifications, and important updates about the Service.
- AI and voice features: To turn your recordings into text, to read your planning transcripts and pull structured details out of them, to analyse supplier contracts and budgets you upload, and to suggest a colour palette from your style quiz answers. Section 5 sets out exactly what is sent, and to whom.
- Improving the Service: To analyse usage patterns, diagnose technical issues, and develop new features. We use anonymised and aggregated data for analytics wherever possible.
- Security: To detect and prevent fraud, abuse, and unauthorised access to the Service.
- Legal compliance: To comply with applicable laws, regulations, and legal processes.
4. Legal Basis for Processing
Under the UK GDPR, we process your personal data on the following legal bases:
- Performance of a contract (Article 6(1)(b)): Processing necessary to provide you with the Service under our Terms of Service, including account management, wedding data processing, and subscription billing.
- Legitimate interests (Article 6(1)(f)): Processing necessary for our legitimate interests, such as improving the Service, ensuring security, and sending service-related communications, provided these interests are not overridden by your rights and freedoms.
- Consent (Article 6(1)(a)): Where we rely on your consent, such as for marketing communications and non-essential cookies. You may withdraw your consent at any time.
- Legal obligation (Article 6(1)(c)): Processing necessary to comply with legal obligations, such as tax and accounting requirements.
Health information, such as a guest's allergies, needs a condition under Article 9 as well as one of the bases above. Section 6 deals with that separately.
5. AI, Voice and Automated Processing
Several features of the Service work by sending your data to an AI model. This section sets out which features do that, what leaves our systems, and who receives it.
Text sent to Anthropic
We use Claude, an AI model provided by Anthropic, to power four features. In each case the text described below is sent to Anthropic's API, processed, and returned to us as structured data. No audio is ever sent to Anthropic.
- Planning assistant:The full transcript of your planning session is sent so that structured details can be pulled out of it. Because the transcript is whatever you said, this will often include guests' names, their relationship to you, their allergies and dietary needs, their accessibility needs, and any reason you gave for keeping two people apart.
- Contract analysis: The text of a supplier or venue contract you upload is extracted from the PDF and sent for analysis. This includes anything written in that contract, such as supplier names, addresses, prices, and payment dates. Long contracts are truncated to roughly the first 12,000 words before being sent.
- Budget intelligence: Your budget line items are sent — the name and category of each item, its estimated and actual cost, the supplier name where you have given one, and the region of your wedding.
- Style quiz: Your five style-quiz answers are sent so that a colour palette can be generated. These answers do not identify anyone.
We use Anthropic's API under its published commercial terms. Those terms provide that what we send through the API is not used to train Anthropic's models, and that Anthropic keeps it only for a limited period before deleting it. We have no separate arrangement with Anthropic that changes this.
Voice recordings and speech-to-text
When you dictate to the planning assistant, speech recognition is performed by your own web browser, using its built-in dictation engine. Your audio is never sent to PlanHitch: we receive only the text, and only once you have read it over and pressed send.
Depending on your browser and device, the browser's engine may recognise speech on the device itself or by using the browser vendor's own speech service (for example, Google's for Chrome or Apple's for Safari). That processing happens between your browser and its vendor under the vendor's privacy policy — it is the same mechanism as the dictation built into your keyboard or operating system, and PlanHitch is not a party to it. If you prefer not to use it, typing works identically.
The transcript itself, once you send it, is kept — see section 8.
Automated decision-making
Nothing the AI produces is applied to your wedding on its own. Details pulled out of a transcript are held as suggestions until you confirm them, and you can reject any of them, correct who they refer to, or undo them after they have been applied. Contract analyses, budget ratings, and colour palettes are presented to you as output to read; they do not change anything by themselves. We do not make decisions about you that produce legal or similarly significant effects by automated means alone.
6. Health and Other Special Category Data
Information about a person's allergies, and information about their accessibility needs, is data concerning health. Under the UK GDPR this is "special category" data and needs more protection than ordinary personal data. We want to be plain about the fact that the Service collects it.
It reaches us in two ways. A guest may enter their own allergies and dietary requirements when they complete an RSVP form. Alternatively, you may mention them to the planning assistant, in which case they are recorded against that guest once you confirm them.
The second route matters, because the person the information is about is usually not you. When you tell us about a guest's nut allergy, you are giving us health data about a third party who has no account with us and may not know we hold it.
The condition we rely on
Special category data needs a condition under Article 9 of the UK GDPR on top of an ordinary legal basis. The condition relied on here is explicit consent, under Article 9(2)(a). How that consent is obtained depends on which of the two routes the information arrived by.
- Where a guest fills in the RSVP form themselves: the guest gives that consent directly. The form explains that the information is used to plan the wedding menu, and the dietary and allergy fields are optional — a guest who would rather not say can leave them blank and still send their reply. Filling them in is the guest's own choice.
- Where the couple or planner enters it: whether typed in or dictated to the planning assistant, the couple is responsible for having obtained the guest's explicit consent before recording it, and for being able to show they have it. We act on the couple's instructions here and are not in a position to ask the guest ourselves. If you record a guest's allergy, you are confirming that the guest is content for it to be held for that purpose.
A guest can withdraw that consent at any time, either by asking the couple to remove the information or by contacting us directly. Because the information is recorded against a guest by the couple, it is usually the couple who must tell their guests that it is being held — the same transparency duty described in section 1.
We use this information only to show it back to you and your collaborators for catering and accessibility planning. We do not use it to profile anyone, we do not share it with anyone outside the providers listed in section 7, and we do not use it for any purpose beyond the one it was given for.
If you are a guest and you would like to know what we hold about you, or would like it removed, contact us at contact@planhitch.com and we will deal with your request directly.
7. Data Sharing and Sub-processors
We do not sell your personal data. We use the following companies to run the Service. Each receives only the data it needs for the purpose described, and each processes that data on our behalf:
- Hetzner: Hosting. The Service, its database, and the self-hosted systems described after this list run on servers provided by Hetzner in Europe. Hetzner supplies the infrastructure and does not access your data in the ordinary course.
- Cloudflare:File storage. The files you upload — photographs, videos, uploaded contracts, supplier listing images, and data exports — are held in Cloudflare's R2 object storage. We use storage with a European Union jurisdiction restriction, which guarantees the files themselves are stored in EU datacentres. Cloudflare is nonetheless a United States company, and section 11 explains how that transfer is covered.
- Stripe: Payment processing. Stripe receives the personal and payment data necessary to take your subscription payments. Stripe is certified as a PCI Level 1 Service Provider.
- Anthropic: AI text processing for the planning assistant, contract analysis, budget intelligence, and the style quiz. Section 5 sets out what is sent for each.
- Resend: Email delivery. Resend receives recipient email addresses and the content of the transactional and campaign emails we send, including account verification, password resets, invitations, and RSVP confirmations.
- Spotify: Music search and playlist import. When you search for a track or import a playlist, your search terms and the playlist address you supply are sent to Spotify. We connect to Spotify as an application rather than as you, so no Spotify account of yours is linked and Spotify does not learn who you are from us.
- Law enforcement and legal authorities: We may disclose your data if required by law, court order, or governmental regulation, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
Some things that are commonly outsourced, we instead run ourselves on the Hetzner servers described above, so no third party is involved: rate limiting; background and scheduled jobs such as reminders, anniversary emails, and data exports; and error monitoring. (Dictation is different again — it runs in your own browser and never reaches our servers at all; section 5 explains.) When something goes wrong, our own monitoring system receives a report describing the failure, which can include the page you were on and the data your browser was sending at the time, and for a sample of sessions a replay of on-screen activity. We filter these reports before they are sent, removing email addresses, telephone numbers, card-length number sequences, passwords, and tokens, and we exclude our sign-in and registration pages entirely; filtering of this kind reduces the risk but cannot be guaranteed to catch everything.
Each of these providers publishes standard data processing terms for its customers, and those terms are incorporated into our contract with the provider when we sign up for the service. That is the basis on which Stripe, Anthropic, Resend, Cloudflare, Spotify and Hetzner process data for us. We rely on each provider's published terms rather than on separately negotiated agreements. Section 11 explains how transfers outside the UK are covered.
If we add a new provider that handles personal data, or replace one of those above, we will update this list and this policy before the change takes effect.
On analytics, to be clear: we do not currently use any third-party web analytics service. There is no Google Analytics, and no equivalent product, running on the Service. Usage information described in section 2 is collected by us, and the error monitoring described above is the only third-party measurement in place. Should we introduce an analytics provider we will name it here and update this policy first.
Wedding websites:the fonts used on a couple's public wedding website are served by us rather than fetched from Google Fonts, so a guest visiting that website does not make a request to a third-party font service.
8. Data Retention
We retain your personal data for as long as necessary to fulfil the purposes for which it was collected, including:
- Active accounts: Your data is retained for the duration of your account. Wedding data is retained for as long as your account is active.
- Planning transcripts: Transcripts of your planning sessions are kept for the life of the wedding they belong to. They are not deleted when the details in them are applied to your plan, because they are the record the plan was built from. Deleting the wedding or your account deletes them.
- Voice recordings: Not held at all — dictation audio never reaches our servers (section 5).
- After account deletion: When you delete your account from your settings, your account and the weddings you solely own are removed from our live database immediately, as part of the same operation. Where a wedding has another owner, that wedding remains and only your access to it is removed. Financial records are retained where the law requires it, for example for at least 6 years for tax purposes.
- Data exports: Export files you request are deleted 30 days after they are produced.
- Demo accounts: Demo data is deleted 48 hours after it is created.
- Anonymised data: Anonymised or aggregated data that cannot be used to identify you may be retained indefinitely for analytical and statistical purposes.
- Backups: We keep routine backups of our database so that we can recover from a failure. Copies of your data may therefore persist in those backups for up to 30 days after you delete it, after which they are overwritten and gone. We do not restore deleted accounts from backup except where we are recovering the whole service from an incident.
- Uploaded files: Deleting your account also deletes the files belonging to it — photographs, videos, uploaded contracts, and any data exports you had produced. These are removed from our file storage as part of the same operation that removes your account, not left behind. Files belonging to a wedding that has another owner stay with that wedding.
9. Your Rights
Under the UK GDPR, you have the following rights in relation to your personal data:
- Right of access: You have the right to request a copy of the personal data we hold about you. You can request a data export through your account settings.
- Right to rectification: You have the right to request correction of inaccurate or incomplete personal data. You can update most of your information directly through your account.
- Right to erasure ("right to be forgotten"): You have the right to request deletion of your personal data, subject to certain legal exceptions. You can delete your account through your settings, or contact us to request erasure.
- Right to data portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format (such as JSON or CSV) and to transmit that data to another controller.
- Right to restrict processing: You have the right to request that we restrict the processing of your personal data in certain circumstances.
- Right to object: You have the right to object to the processing of your personal data where we rely on legitimate interests as our legal basis.
- Rights related to automated decision-making: You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects or similarly significant effects on you.
To exercise any of these rights, please contact us at contact@planhitch.com. We will respond to your request within one month, as required by law. In complex cases, we may extend this period by up to two additional months, and we will notify you if this is necessary.
10. Cookies
We use cookies and similar technologies to provide, secure, and improve the Service. For detailed information about the cookies we use, their purposes, and how to manage them, please see our Cookie Policy.
11. International Data Transfers
The Service is hosted in the European Union. Some of the providers listed in section 7 are based outside the United Kingdom, so your data does leave the UK. Two different safeguards apply, depending on where the provider is:
- Hetzner, which provides our hosting, is in the European Union. The UK government has determined that the EU provides an adequate level of data protection, so no additional safeguard is needed for the data held on our servers.
- Stripe, Anthropic, Resend and Cloudflare are headquartered in the United States. Transfers to them are covered by the UK International Data Transfer Addendum to the European Commission's standard contractual clauses, or by the UK International Data Transfer Agreement (IDTA), together with each provider's own published transfer terms. These are the mechanisms UK data protection law provides for sending personal data to a country without an adequacy decision. This applies to Cloudflare even though the files it stores for us are kept in EU datacentres: the storage location does not change the fact that a United States company processes them.
- Spotify receives only your search terms and any playlist address you supply. As section 7 explains, we connect to Spotify as an application rather than as you, so it does not receive information that identifies you.
In each case the safeguard is intended to give your personal data essentially the same protection abroad that it has under UK law. You can ask us for more detail about the arrangements covering any particular provider by writing to contact@planhitch.com.
12. Children's Privacy
The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child under 18 without appropriate parental consent, we will take steps to delete that data as soon as possible. If you believe a child has provided us with personal data, please contact us at contact@planhitch.com.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the Service. When we make material changes, we will:
- Update the "Last updated" date at the top of this page.
- Notify you by email and/or by posting a prominent notice within the Service at least 30 days before the changes take effect.
- Where required by law, seek your consent to any material changes in how we process your personal data.
14. Contact and Data Protection
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:
- Company: PlanHitch Ltd, registered in Scotland
- Company number: SC869251
- Registered office: Office 1325, 3 Fitzroy Place, 1/1, Sauchiehall Street, Glasgow Central, United Kingdom, G3 7RH
- Data Protection Contact: contact@planhitch.com
- Website: planhitch.com
- ICO registration: PlanHitch Ltd is registered with the Information Commissioner's Office, the UK's data protection regulator.
If you are not satisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Telephone: 0303 123 1113