Privacy Policy
Last updated: 13 September 2026
1. Who we are
vow.day is a wedding supplier marketplace operating in and targeting the Republic of Ireland. This policy explains what personal data we collect when you use vow.day, why we collect it, who we share it with, and the rights you have over it under the General Data Protection Regulation (GDPR) and, where applicable, the UK GDPR and Data Protection Act 2018.
vow.day is a trading name of AMP SYNC LTD, a company registered in Northern Ireland, United Kingdom, Company No. NI739404. Our registered office is at 10 Baltreagh Road, Lisnaskea, County Fermanagh.
Because we offer services to, and monitor the behaviour of, individuals in the EU (the Republic of Ireland), Article 27 GDPR requires us to appoint a formal EU representative — a contact point established in the EU. We have appointed Data Protection Representative Limited (trading as DataRep) as our EU representative for this purpose.
EU representative: Data Protection Representative Limited (trading as DataRep), 77 Camden Street Lower, Dublin, D02 XE80, Ireland. To exercise your GDPR rights or raise a question about our processing of your personal data, you can contact DataRep on our behalf at datarequest@datarep.com(please quote "vow.day / ampsync.uk" in the subject line) or via their web form at www.datarep.com/data-request.
We intend to trade in Northern Ireland in future, in addition to the Republic of Ireland. Where we do, UK GDPR applies to that activity in parallel with EU GDPR for our Republic of Ireland activity — the two are separate legal regimes. AMP SYNC LTD is already established in the UK, so no separate UK representative is required.
2. What data we collect
We collect different data depending on whether you use vow.day as a couple or a supplier. In both cases, we only collect what's needed to run bookings, payments, and communication on the platform.
2.1 Data we collect from couples
- Account & identity — email address, password (encrypted), phone number, account creation and last-active dates.
- Wedding & profile details— your first name, your partner's first name, wedding date, budget, guest count, preferred supplier styles, county, home address (including Eircode), and ceremony/reception venue details (name, address, county, time). Free-text notes you add yourself.
- Bookings & payments — booking status, package chosen, price, deposit/balance status and dates, messages sent when requesting a booking, quote requests and responses, cancellation/amendment history, signed contracts (including your e-signature), and payment records (amounts, dates, status — we never store card numbers; Stripe holds those and we keep only their reference IDs).
- Communication — messages exchanged with suppliers (text, photos, videos, voice notes), read receipts, reviews you write, helpful votes on other reviews, AI wedding-assistant chat history, and support tickets.
- Planning tools — favourited suppliers and your notes on them, saved budget-planner combinations, budget tracker entries, day-of timeline entries, personal to-dos, and uploaded documents.
- Activity & preferences— which supplier profiles you've viewed (to power your own recent-activity view), notification preferences and history.
2.2 Data we collect from suppliers
- Account & identity — email address, password (encrypted), phone number, account creation and last-active dates.
- Business profile — business name, contact first name, bio, category, coverage counties, business address and contact email (kept private), pricing and packages, years of experience, weddings completed, response-time stats, profile and portfolio media, verification status (identity and insurance, including the uploaded insurance document itself), Instant Book and scheduling settings, contract templates, and location data derived from your county for map search.
- Bookings & payments — the same booking records as couples, from your side, plus your Stripe Connect account ID and onboarding status (used to receive payouts — we never see your bank details, Stripe holds those), monthly earnings statements, and featured-listing subscription status.
- Communication — messages exchanged with couples, saved message templates, reviews received and your replies.
- Calendar & availability — blocked/available dates, and Google Calendar connection tokens if you choose to connect your calendar.
- Profile view analytics — every visit to your profile records a view count, referral source, and device type, whether or not the visitor is logged in. If the visitor happens to be logged in as a couple at that moment, the view is also linked to their account; logged-out visits are recorded with no visitor identity attached. See Section 2.3 for how this is derived.
- Activity & preferences — notification preferences and history, support tickets.
2.3 Where files are stored, and how profile views are recorded
Uploaded files — profile photos, portfolio media, insurance documents, contract files, chat attachments, wedding documents, and review photos — are stored in Supabase file storage, separately from the database records that describe them.
Profile view analyticsare recorded server-side, not by any script running in your browser. When a supplier profile page loads, the server logs a view: an atomic counter on the supplier's profile is incremented, and a row is added recording the referral source and device type. If the visitor is signed in as a couple at that moment, the view is linked to their account; if not, it's recorded with no visitor identity attached. We don't set a cookie, store an IP address, or use any fingerprinting technique to identify or track anonymous visitors.
3. Our legal basis for using your data
Under GDPR, we can only process personal data where we have a valid legal basis. We rely on the following:
- Contract — processing needed to create your account, manage bookings, process payments, generate contracts, and support planning tools (account, profile, and booking information).
- Legitimate interests— understanding platform usage, profile view analytics, preventing fraud and abuse, and improving the Service, where these interests aren't outweighed by your rights. You can object to this at any time — see Section 9.
- Consent — Google Calendar sync (suppliers actively choose to connect their calendar and can disconnect at any time), and non-essential analytics cookies (see Section 10).
- Legal obligation — retaining payment and booking records to meet our accounting and tax obligations (see Section 8), and verifying supplier identity/insurance documentation.
4. How we use your data
- Create and manage your account.
- Connect couples with suppliers and process booking requests, contracts, and payments.
- Support planning tools — budget tracking, day-of timelines, saved packages.
- Power the AI wedding assistant when you choose to use it.
- Send booking, payment, and account-related notifications by email.
- Keep supplier calendars accurate through Google Calendar sync, where connected.
- Verify supplier identity and insurance documentation.
- Understand how the Service is used, including profile view analytics, so we can maintain and improve it.
- Detect and prevent fraud, abuse, and breaches of our Terms of Service.
5. Who we share data with
We don't sell your data. We share the minimum data necessary with the following service providers, each of whom processes it on our behalf under a data processing agreement:
- Stripe — payment processing for deposits, balance payments, supplier payouts, and featured-listing subscriptions. (US-based; see Section 7.)
- Resend — sending transactional emails. (US-based.)
- Google — Google Calendar sync, only for suppliers who choose to connect their calendar. (US-based.)
- Supabase — our database, authentication, and file storage provider, hosted in the EU region.
- Vercel — hosts the vow.day application itself. (US-based.)
- Anthropic — powers the AI wedding assistant. When you use it, the wedding details on your profile — names, date, county, venue, budget and style preferences — are sent to Anthropic to generate a reply. (US-based; see Section 7.)
- Sentry — error monitoring and performance tracking for the platform, so we can detect and fix technical issues. Configured to use Sentry's EU data region. (Data hosted in the EU.)
6. AI Features & Google Workspace Data
vow.day uses AI features (including an AI wedding planning assistant) to help couples plan their wedding. Data obtained through Google Workspace APIs, including Google Calendar, is used solely to display supplier availability and create booking confirmations within the vow.day platform.
The use of raw or derived data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. Specifically, vow.day does not use, transfer, or sell Google Workspace API data — including raw, aggregated, or derived data — to train, retrain, or improve any AI or machine learning models, whether foundational or generalized.
7. International data transfers
Some of our service providers — Stripe, Resend, Google, Vercel, and Anthropic — are based in the United States or otherwise transfer data outside the European Economic Area (EEA) and the UK. Where this happens, we rely on approved safeguards: the European Commission's Standard Contractual Clauses (SCCs) for EEA transfers, the UK's International Data Transfer Agreement (IDTA) or UK Addendum for transfers from the UK, or a valid adequacy decision. You can ask us for more detail on the safeguards used for a specific provider by emailing us — see Section 12.
8. Data retention
We keep your account and booking data for as long as your account is active. When you close your account or ask us to delete your data, we remove it, subject to the following retention periods we're required to observe:
- Payment and booking financial records — kept for 6 years from the end of the relevant tax year, in line with Irish Revenue and UK accounting record-keeping requirements.
- Dispute-related records (messages, contracts, reviews tied to a disputed booking) — kept for as long as reasonably necessary to resolve the dispute and any follow-on claim.
Outside of these specific obligations, we don't keep personal data longer than is needed for the purpose it was collected for.
9. Your rights under GDPR
As a data subject under GDPR, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — ask us to delete your personal data, subject to any legal obligations we have to retain it (see Section 8).
- Restriction — ask us to limit how we use your data in certain circumstances, for example while a disputed accuracy issue is resolved.
- Portability — request your data in a structured, machine-readable format.
- Object — object to certain kinds of processing, such as processing based on legitimate interests or direct marketing.
This applies whether you're a registered couple or supplier. To exercise any of these rights, email us at hello@vow.day. You also have the right to lodge a complaint with the Irish Data Protection Commission (DPC), or with the UK Information Commissioner's Office (ICO) given AMP SYNC LTD's Northern Ireland registration.
10. Data security
We take reasonable technical and organisational measures to protect your personal data, including encryption in transit, access controls, and regular review of our systems. Verification documents (identity and insurance uploads) are treated as higher-sensitivity and access to them is restricted accordingly. No method of transmission or storage is completely secure, but we work to protect your data to industry standards.
11. Cookies
We use essential cookies to keep you signed in and to remember your preferences. These don't require your consent, as they're necessary for the Service to function.
We don't currently use any analytics, advertising, or tracking cookies, and no third-party tracking scripts (such as Google Analytics or Meta Pixel) run on vow.day. The profile view analytics described in Section 2.3 are generated server-side from each page request, not from a cookie or script in your browser. If this changes in future, we'll update this section and show a consent banner before any non-essential cookie is set.
12. Contact
Questions about this Privacy Policy, or about your data? Email hello@vow.day. See also our Terms of Service.