Legal

Privacy Policy

Last updated: June 2026

1. Who We Are

Ndoa (“we,” “our,” or “us”) operates the wedding planning platform available at ndoaplan.com (the “Platform”). We provide tools for couples, wedding planners, committees, and vendors to coordinate weddings. You can contact us at hello@ndoaplan.com.

When a user (a “Couple” or “Planner”) creates a wedding on our Platform, they act as the data controller for the personal data they enter about their guests, vendors, and wedding party. Ndoa acts as a data processor on their behalf.

2. What Data We Collect

2.1 Data You Provide Directly

  • Account information: name, email address, profile photo, and account type (Couple or Event Manager).
  • Wedding details: wedding name, bride and groom names, venue, event dates, cultural type, timeline, theme preferences, and photos.
  • Guest data: names, phone numbers, email addresses, RSVP status, dietary notes, tags, check-in status, and household assignments.
  • Vendor data: business names, contact names, phone numbers, email addresses, contract files, amounts, and notes.
  • Bridal party data: names, phone numbers, email addresses, roles, and confirmation status.
  • Event data: event names, dates, times, venues, program items, contacts, and dependencies between events.
  • Committee and contribution data: member names, pledge amounts, paid amounts, and notes.
  • Budget and financial data: budget categories, estimates, actual costs, committed amounts, payment schedules, and payment records.
  • Gift data: gift registry items, received gifts with giver names, phone numbers, and thank-you status.
  • Logistics data: transport routes, accommodation bookings, contact names and phone numbers.
  • Incident reports: descriptions, resolutions, and notes containing event-day issues.
  • Media uploads: photos, documents, contracts, receipts, and other files you upload.
  • Team invites: email addresses of people you invite to collaborate on a wedding.

2.2 Data Collected Automatically

  • Session data: NextAuth.js manages your login session via a JWT stored in a browser cookie containing your user ID and role.
  • IP addresses: we log IP addresses in our audit trail when certain actions are performed.
  • Share link views: we count how many times a share link is viewed.
  • Offline storage: data is cached locally in your browser using IndexedDB (via Dexie.js), including guest names, phone numbers, emails, vendor contacts, and other wedding data you have accessed.

2.3 Data from Third Parties

  • Google OAuth: when you sign in with Google, we receive your name, email address, and profile photo.

3. How We Use Your Data

We use the data we collect to:

  • Operate, maintain, and improve the Platform.
  • Authenticate users and manage access permissions.
  • Enable wedding coordination features including guest management, vendor management, budgeting, scheduling, and day-of-event operations.
  • Generate export files (CSV, XLSX, PDF) containing wedding data.
  • Provide offline access to wedding data via local browser storage.
  • Sync data between devices when connectivity is restored.
  • Send you service-related communications (we do not send marketing emails).
  • Maintain an audit log of changes made to wedding data.
  • Detect and prevent abuse, fraud, or unauthorized access.

4. Legal Basis for Processing

We process your personal data on the following legal bases:

  • Contractual necessity: to provide the wedding planning services you have signed up for.
  • Legitimate interests: to maintain platform security, generate audit trails, and improve our services.
  • Consent: where you have explicitly consented (e.g., uploading files, inviting collaborators).
  • Legal obligation: to comply with applicable laws and regulatory requirements.

5. Who We Share Your Data With

We share your data only with the following third-party service providers:

  • Neon (PostgreSQL): our primary database provider. Data is hosted on servers in the EU (Frankfurt, Germany).
  • Supabase: file storage for photos, documents, contracts, and receipts in private buckets accessed via time-limited signed URLs.
  • Google Cloud (OAuth): handles user authentication via Google sign-in.
  • Vercel: hosts the Platform application code (no persistent data stored beyond application logs).

We do not sell your personal data. We do not use advertising networks, analytics services, or tracking pixels.

6. International Data Transfers

Your data is stored and processed in the following locations:

  • Neon (PostgreSQL): EU (Frankfurt, Germany).
  • Supabase: US or EU (depending on configuration).
  • Vercel: US and EU edge network.
  • Your browser: data cached in IndexedDB resides on your local device.

Where data is transferred out of your country of residence, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms.

7. Data Retention and Deletion

7.1 Retention Periods

  • Account data: retained until you request deletion or your account is inactive for 24 months.
  • Wedding data (guests, vendors, events): retained until the wedding is deleted or you request removal.
  • Audit logs: retained for the lifetime of the wedding record.
  • Payment records: retained for legal and financial record-keeping purposes (minimum 7 years in Kenya).
  • Offline cache (IndexedDB): retained in your browser until cleared or synced and removed.

7.2 Deletion Methods

When you delete data through the Platform:

  • Guests, vendors, bridal team members, checklist items, budget lines, and media are soft-deleted (marked with a deletedAt timestamp and hidden from the interface).
  • Gifts, registry items, dowry items, contributions, appointments, incidents, transport routes, accommodations, contacts, and program items are hard-deleted (permanently removed).
  • Wedding members are hard-deleted when removed from a wedding.
  • Share links are hard-deleted when revoked.

We currently do not offer a self-service “delete my account” feature. To request deletion, contact us at hello@ndoaplan.com.

8. Your Rights

Depending on your jurisdiction, you may have the following rights:

  • Right to access: request a copy of the personal data we hold about you.
  • Right to rectification: request correction of inaccurate or incomplete data.
  • Right to erasure: request deletion of your personal data, subject to legal retention requirements.
  • Right to restrict processing: request that we limit how we use your data.
  • Right to data portability: request your data in a structured, machine-readable format (CSV/XLSX/PDF export is available within the Platform).
  • Right to object: object to processing based on legitimate interests.
  • Right to withdraw consent: withdraw consent at any time where processing is based on consent.

To exercise any of these rights, contact us at hello@ndoaplan.com. We will respond within 30 days.

9. Security

We implement the following security measures:

  • Passwords are hashed using scrypt with per-user random salts.
  • Session authentication uses JWTs encrypted with a server secret.
  • File storage uses private Supabase buckets with time-limited signed URLs (1-hour expiry).
  • All API traffic is served over HTTPS.
  • Security headers: X-Content-Type-Options, X-Frame-Options (DENY), Referrer-Policy.
  • Role-based access control limits what each user can view or modify within a wedding.
  • Share links expose only limited, non-sensitive fields. Financial modules cannot be shared.

No method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.

10. Children's Privacy

The Platform is not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified via the Platform or by email. Your continued use of the Platform after changes take effect constitutes acceptance of the updated policy.

12. Contact

For questions, concerns, or data subject requests: