Privacy Policy
Last updated: July 27, 2026
This policy explains how Shared Beginning Inc. ("Shared Beginning", "we", "us"), located at Edmonton, Alberta, Canada, handles personal information across the Shared Beginning wedding-site builder, planning tools, messaging tools, and Trusted Partner directory (the "Service"). We are a Canadian service, hosted in Canada, and we write for a worldwide audience: this policy is designed to meet PIPEDA (Canada), the GDPR and UK GDPR (EU/EEA and UK), and the CCPA/CPRA (California). It should be read together with our Terms of Service and Cookie Policy.
1. The two roles we play
- Controller. For couples' accounts, vendor (Trusted Partner) applications and listings, payments, and our own website analytics and security logs, Shared Beginning decides how and why data is processed — we are the controller.
- Processor / service provider. For the personal information that couples enter about their guests (and that guests submit through RSVP forms and photo uploads), the couple decides how it is used and we process it on their behalf. If you are a wedding guest, the couple who invited you is your first point of contact for privacy questions — and we will always help them respond, or help you directly if they cannot.
2. What we collect
From couples (account holders)
- Account data: your name, email address, and a hashed password (we never store passwords in plain text); optional two-factor authentication secrets and passkeys.
- Wedding content: your wedding site text and photos, events, checklists, budgets, vendor notes, seating plans, travel details, documents, and message drafts.
- Purchase data: the plans and add-ons you buy, order history, and custom-domain registration details. Payments are handled by Stripe — we never see or store your card number.
About guests (entered by couples or submitted by guests)
- Guest names, email addresses, phone numbers, mailing addresses, party/household groupings, and tags.
- RSVP responses, answers to the couple's custom RSVP questions, dietary requirements, and song requests.
- Photos and videos guests upload through the wedding's share link, with basic file metadata.
- SMS consent state: delivery records and STOP/START opt-out records, which we must keep to honour opt-outs.
From vendors (Trusted Partners)
- Application details: business and contact information, service categories, cities served, pricing ranges, inclusivity and accessibility information, and the agreements you accept.
- Listing content (logo, photos, descriptions) and inquiries sent to you by couples.
- Membership payment status (again via Stripe — no card numbers).
Automatically
- Security and technical logs: IP addresses, login and failed-login records, and rate-limit counters — used to protect accounts and prevent abuse.
- Cookieless analytics: we use Fathom Analytics, which collects aggregate, anonymised page statistics without cookies and without tracking individuals. See the Cookie Policy.
- Essential cookies for sessions, security (CSRF), "remember me", and bot protection — listed in the Cookie Policy.
3. How we use it, and our legal bases (GDPR)
- Providing the Service — hosting your wedding site, collecting RSVPs, sending the emails and SMS you compose, processing purchases. Legal basis: performance of a contract; for guest data, the couple's instructions.
- Security and abuse prevention — login monitoring, rate limiting, bot protection, enforcing SMS sending caps. Legal basis: legitimate interests (keeping the Service and its users safe).
- Service communications — receipts, hosting-expiry warnings, security notices. Legal basis: performance of a contract / legitimate interests.
- Product analytics — aggregate, cookieless usage statistics. Legal basis: legitimate interests; no individual profiles are built.
- Legal compliance — tax records, responding to lawful requests, honouring SMS opt-outs. Legal basis: legal obligation.
We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use your data or your guests' data to train AI models or for marketing to guests.
4. Subprocessors and third parties
We share personal information only with the providers below, only as needed to run the Service:
- Amazon Web Services (AWS) — application hosting, database, and file storage in the Canada West (Calgary, ca-west-1) region; also domain registration/DNS (Route 53) and email delivery (SES). Region: Canada (email delivery infrastructure may route globally).
- Stripe — payment processing. Stripe receives your payment details directly; region: global (US/EU infrastructure). Stripe is an independent controller of the payment data it collects.
- Twilio — SMS delivery for guest messages and opt-out (STOP) handling. Region: primarily United States.
- Microsoft 365 — our business mailboxes; if you email us, your message is stored there. Region: global.
- Bugsnag (SmartBear) — error monitoring, which may incidentally capture technical request context when something breaks. Region: United States.
- Fathom Analytics — cookieless, privacy-first website analytics (aggregate data only). Region: Canada/EU infrastructure.
- Cloudflare Turnstile — bot protection on sign-in and sign-up. Region: global edge network.
- Domain registrars (AWS Route 53; Namecheap) — when you buy a custom domain, your registrant contact details are provided to the registrar as required by ICANN rules (with WHOIS privacy applied where available). Region: United States/global.
5. Where data lives, and international transfers
Our servers and databases are in the AWS Calgary region, so the primary copy of your data stays in Canada. Canada holds an EU adequacy decision for PIPEDA-covered commercial organisations, which supports EU-to-Canada transfers. Some providers above process data outside Canada (for example Twilio and Stripe in the US); where GDPR/UK GDPR applies to those transfers, they are covered by appropriate safeguards such as Standard Contractual Clauses or the providers' own approved transfer mechanisms.
6. Retention
- Account and wedding data is kept while your account is active. When a plan's 12-month hosting term ends, the public site is archived but your data is retained so you can extend hosting or export it.
- Deletion. Ask us to delete your account and we will delete or anonymise your data within 30 days, except what we must keep (tax and purchase records, and SMS opt-out records, which must persist so opt-outs stay honoured).
- Guest photos follow the wedding's hosting/album term and the couple's own deletions.
- Security logs (IPs, login records) are kept for a limited period appropriate to security monitoring, then deleted or anonymised.
- Backups roll off on a fixed schedule; deleted data disappears from backups as they expire.
7. Your rights
Depending on where you live, you have some or all of these rights, and we honour them for everyone regardless of location:
- Access and portability — get a copy of your personal information in a usable format.
- Rectification — correct inaccurate information (most of it you can edit directly in the app).
- Erasure — ask us to delete your data, subject to the retention exceptions above.
- Objection and restriction — object to processing based on legitimate interests.
- Withdraw consent — where processing is based on consent (for example SMS: reply STOP to any message to opt out instantly).
- CCPA (California) — rights to know, delete, correct, and to opt out of "sale" or "sharing". We do not sell or share personal information as the CCPA defines those terms, and we do not use sensitive personal information beyond what the Service requires. We will never discriminate against you for exercising your rights.
To exercise any right, email privacy@sharedbeginning.com. We will verify your identity and respond within the timeline your local law requires (30 days under PIPEDA, one month under GDPR, 45 days under CCPA). Guests: because the couple controls the guest list, we may refer your request to them or process it on their instructions — but we will never leave you without an answer.
8. Children
The Service is for adults (18+). We do not knowingly collect personal information directly from children. Couples may include minors on a guest list (for example, a family RSVP); that information is the couple's responsibility as controller and is used only for their wedding.
9. Security
- All traffic is encrypted in transit (TLS); data is stored on encrypted infrastructure.
- Passwords are hashed; two-factor authentication and passkeys are available on every account.
- Uploaded files and photos are served through expiring signed URLs, not public links.
- Access to production systems is restricted, logged, and limited to what operating the Service requires.
- Rate limiting, bot protection, and sending caps protect guests from abuse of the messaging tools.
No system is perfectly secure. If a breach affects your personal information, we will notify you and the relevant regulators as applicable law requires.
10. Complaints
We would like the chance to fix any concern first: privacy@sharedbeginning.com. You can also complain to the Office of the Privacy Commissioner of Canada (OPC), and — if you are in the EU/EEA or UK — to your local data protection authority or the UK ICO. California residents may contact the California Privacy Protection Agency.
11. Changes to this policy
We will update this policy as the Service and the law evolve, and will give notice of material changes (email or in-app) before they take effect. This policy is governed by the laws of Alberta, Canada, without limiting the protections your local law gives you.
12. Contact
Privacy requests and questions:
Shared Beginning Inc.
Edmonton, Alberta, Canada
privacy@sharedbeginning.com