privacy notice
How Promessera handles your information
Last updated 24 August 2026. Version 2.0, replacing the waitlist privacy notice previously published here.
1. Who we are
Promessera is a wedding planning service operated by Promessera Limited, a company registered in England and Wales, company number 17369508, registered office 128 City Road, London, EC1V 2NX, United Kingdom.
Promessera Limited is the data controller for the information described in this notice. That means we decide what information we collect and what we do with it, and we are responsible to you for how it is handled.
You can reach us about anything in this notice at enquiries@promessera.com, or by post at the address above.
We are registered with the Information Commissioner's Office (the UK's data protection regulator) under registration number ZC229674.
2. What this notice covers
This notice covers promessera.com, the Promessera planner (the part of the product you sign in to), and the emails we send you. It applies whether you are on the waitlist, using Promessera for free, or subscribed.
It also explains, in section 13, how we handle information about wedding venues and suppliers that appears in our catalogue. If you are a venue or a supplier, that section is written for you.
We have tried to write this the way we write everything else: plainly, and without hiding anything in the middle of a long sentence. If something here is unclear, ask us and we will explain it.
3. What we collect
When you visit the site. Your IP address, browser and device type, the pages you looked at, and how you arrived (for example, from an advert). Some of this comes from cookies and similar technologies, which are covered in section 8.
When you join the waitlist or create an account. Your email address, and your name if you give it. Accounts are passwordless, so we send a six-digit code to your email address to sign you in. We store the code briefly and the number of attempts made against it.
When you use the planner. Everything you type to the planner and everything it replies is stored, so the conversation carries on where you left it and the planner remembers what you have told it. We also hold your brief (dates, location, guest numbers, budget, style, what matters to you, what you are trying to avoid) and your plan (venue and supplier shortlists, your budget and its line items, your timeline and tasks, and your guest list).
Your guest list. Guest names, and anything else you choose to record about them, which may include contact details, dietary requirements, accessibility needs, who is travelling with whom, and children's names and ages. This is information about other people, so section 6 covers it separately.
When you subscribe. We use Stripe to take payments. Your card details go straight to Stripe and never reach our systems. We hold a Stripe customer reference, your subscription status and its history, the amounts and dates of payments, and the billing country you gave.
When you contact us. Your email address, what you wrote, and our reply.
4. Where the information comes from
Most of it comes from you directly, either because you typed it in or because you told the planner. Some comes automatically from your device when you use the site, as described in section 8. A small amount comes from our providers: Stripe tells us whether a payment succeeded, and Meta tells us in aggregate whether an advert led to a signup.
5. Why we use it, and our legal basis
Under UK data protection law we need a lawful basis for every use of your information. Ours are set out below.
| What we do | Lawful basis |
|---|---|
| Create and run your account, and sign you in | Performance of our contract with you |
| Run the planner: hold your conversation, brief and plan, and generate replies | Performance of our contract with you |
| Send service emails (sign-in codes, confirmations, changes to the service) | Performance of our contract with you |
| Take payment and manage your subscription | Performance of our contract with you |
| Keep accounting and tax records of payments | Legal obligation |
| Keep the service secure, prevent fraud and abuse, and enforce our usage limits | Our legitimate interests in running a secure service |
| Understand how Promessera is used, fix what is broken, and make it better | Our legitimate interests in improving our service |
| Keep your brief and conversation if you use the free planner and do not subscribe | Consent, given when you gave us your email address |
| Send you marketing emails about Promessera | Consent, which you can withdraw at any time |
| Set analytics and advertising cookies, and measure advertising | Consent, which you give or refuse when you first arrive and can change at any time (see section 8) |
| Handle your enquiries and complaints | Our legitimate interests in responding to people who contact us |
| Deal with legal claims and regulatory requests | Our legitimate interests, or legal obligation |
Where we rely on legitimate interests, we have weighed our interest against your rights and concluded that our use is not intrusive and is what you would reasonably expect. You can ask us for the reasoning behind any of these, and you can object (see section 16).
Where we rely on consent, you can withdraw it at any time and we will stop. Withdrawing consent does not affect anything we did before you withdrew it.
6. Information about other people
When you build a guest list, you are giving us information about people who have not signed up to Promessera and who may not know we exist. We take that seriously.
What we do with it. We use guest information only to run your plan: to count heads, to seat people, to track dietary requirements, to build your timeline. Nothing else.
What we will never do with it. We will never market Promessera to your guests. We will never sell or share your guest list. We will never contact your guests for our own purposes. Your guests came to your wedding, not to us, and treating your guest list as a sales list would be a betrayal of the whole point of this product. This is a commitment, not a policy we intend to relax later.
Your part. By entering someone's details, you are confirming you are entitled to share them with us for this purpose. If a guest asks you about it, you can point them at this notice, and they can contact us directly at enquiries@promessera.com to ask what we hold or to have it removed.
Our part. If a guest contacts us directly, we will deal with their request, and we will tell you if doing so changes your plan.
7. Sensitive information
Some things you may naturally record while planning a wedding count as special category data under UK law, and get extra protection. In practice that means health information (a dietary requirement, an allergy, an accessibility need, a pregnancy) and information that reveals religious belief (the kind of ceremony you want, a faith venue, a religious dietary rule).
We do not ask you for any of this. But it comes up in wedding planning, and if you tell the planner, we will hold it and use it to help you plan.
Where we hold this kind of information, we rely on your explicit consent, given when you choose to enter it. You do not have to. If you would rather not record it here, you can leave it out and handle it another way, and the rest of the product still works.
You can withdraw that consent at any time by removing the information or by asking us to (enquiries@promessera.com).
We do not use sensitive information for advertising, for analytics, or for anything other than helping you plan your wedding.
8. Cookies and similar technologies
Cookies are small files stored on your device.
Essential cookies. These keep you signed in and let Stripe prevent payment fraud on the checkout page. Promessera does not work without them, so we do not ask permission for them. Your sign-in lasts about eight hours, after which you sign in again.
Analytics and advertising. We use Meta, Microsoft Clarity and Pinterest on our public marketing pages, to measure whether our advertising works and to see where the site confuses people. None of them loads until you say yes. If you do, Meta, Microsoft and Pinterest each receive your IP address, your browser type, and the pages you viewed, and each uses that information under its own privacy policy as well as ours.
They run only on those pages, and nothing loads once you sign in. No advertising or session-recording technology follows you into the planner, and nothing you say to the planner is ever seen by an advertising provider.
You can stop them by blocking third-party cookies in your browser, by using your browser's tracking protection, or by emailing enquiries@promessera.com and asking us to exclude you, which we will do.
Saying no is as easy as saying yes. The first time you visit a marketing page we ask, with two buttons of equal weight and nothing chosen for you. If you say no, nothing is loaded and nothing is set, and we do not ask again. If you say yes, we remember that for a year so you are not asked on every visit. The only thing we store either way is your answer, which we keep because it is the only way to honour a refusal.
Changing your mind. Use the Cookies link in the footer of our homepage to be asked again, or clear this site's cookies in your browser, which forgets your answer and stops anything that was running.
Advertising measurement. When you sign up after clicking one of our adverts, we tell Meta that a signup happened. We send a scrambled (hashed) version of your email address, your IP address, and your browser type, so Meta can match it to the advert you clicked. If you go on to subscribe, we also tell Meta that a subscription was taken, and the amount. For that we send the scrambled version of your email address and the Meta identifiers already stored in your browser, and nothing else — no IP address and no browser type. We do not send your name, your brief, or anything about your wedding. You can control this through your Meta account settings.
Only if you said yes. Both of those depend on the Meta identifiers that exist in your browser only because you accepted advertising cookies on one of our marketing pages. If you declined, or you never saw one of those pages, there are no identifiers and we tell Meta nothing — not about a signup and not about a subscription. The planner itself carries no trackers at all, so nothing you do inside it is measured this way.
Working with Meta on this, and who is responsible for what. For the collection of that information and its transmission to Meta, Meta and Promessera are joint controllers. Which Meta company that is depends on where you live. If you live in the United Kingdom, it is Meta Platforms, Inc. in the United States, under Article 26 of the UK GDPR. If you live in the European Union, it is Meta Platforms Ireland Limited in Dublin, under Article 26 of the EU GDPR. Meta's own terms are what decide this, and they give the UK arrangement precedence for anyone living in the UK. What Meta does with the information afterwards is Meta's own responsibility and not part of what we do jointly.
We have an agreement with Meta setting out which of us answers for what. There is one for each of those two arrangements and they say the same thing on this point. In summary: we are responsible for telling you about this, which is what this section does; and Meta is responsible for handling your requests to see, correct, delete, restrict, move or object to the information Meta holds after we have sent it. You can make those requests to Meta directly.
Meta explains how it uses the information, what it relies on in law to do so, and how to exercise those rights, in its own privacy policy at facebook.com/about/privacy. If you would rather come to us, email enquiries@promessera.com and we will pass it to Meta within seven days.
9. How the planner uses AI
The Promessera planner is built on a large language model. Today that model is supplied by Anthropic. We do not build or train our own, and we may change supplier: if we do, we will update this notice before the change takes effect, as section 18 says. Being straight about what that means:
What is sent. When you talk to the planner, your message, the conversation so far, and the relevant parts of your brief and plan are sent to Anthropic to generate the reply. That includes your first names and your guests' names, because the planner cannot seat people or talk to you naturally without them.
What is not sent. Your email address, your payment details, and your account identifier. Anthropic never receives anything that lets it connect a conversation to an account or to you as a customer.
Training. Anthropic does not use what we send it to train its models. That is not a promise we are relaying, it is a term of the contract we are on: Anthropic's commercial terms say it "may not train models on Customer Content from Services", and what you type to the planner is our Customer Content. Anthropic holds it briefly to generate the reply and deletes it, normally within 30 days. The one exception is that if its automated safety systems flag a conversation as breaking its usage rules, Anthropic can keep that conversation for longer while it looks into it. That is the only purpose of its own it can put your words to.
Web searching. The planner can search the web to research venues and suppliers. When it does, the search terms it uses (things like a place name, a style, a guest number) are sent through Anthropic to a search provider. Your identity is not.
Decisions. The planner suggests, ranks and explains. It does not make any decision about you that produces a legal effect or anything similarly significant, so the rules on solely automated decision-making do not apply. It can still be wrong, and everything it produces is for you to accept, change or ignore.
Payment. Suppliers and venues cannot pay to appear, to rank higher, or to be recommended. Nothing you see in the planner has been bought.
10. Aggregate insights
We may produce aggregated statistics from how Promessera is used, for example how many couples in a region are looking for a particular kind of venue in a particular month, and we may in future offer such statistics to venues and suppliers as a product.
Three hard limits apply to that, and they are not negotiable:
- It never contains personal data. Not your name, not your email, not your plan, not your guest list, not anything that could be traced back to you or your wedding.
- It is only ever reported for groups large enough that no individual couple can be identified within them.
- It is never used to advertise to you, to rank suppliers, or to pass your details to anyone as a lead.
11. Who we share your information with
We do not sell your information. We share it only with the providers we need to run Promessera. Most of them act purely on our instructions, under a contract that requires them to protect your information and use it for nothing else. Three do not, and it is fairer to say so: Stripe also acts in its own right when it prevents payment fraud and meets its own regulatory duties; Microsoft Clarity acts in its own right for the analytics it runs; and Meta and Pinterest are joint controllers with us for advertising measurement, as section 8 explains.
| Provider | What it does | Where |
|---|---|---|
| Anthropic | The AI model behind the planner | United States |
| Stripe | Payments and subscriptions | United States, Ireland |
| Resend | Sends our emails | United States |
| Neon, a Databricks company | Hosts our database, through Replit | United States |
| Replit | Hosts the application | United States |
| Mapbox | Turns venue addresses into map locations (venue data, not yours) | United States |
| Microsoft Clarity | Marketing-page analytics | United States |
| Meta, Pinterest | Advertising measurement | United States, Ireland |
We will also disclose information if the law requires it, if we need to establish or defend a legal claim, or if we are ever bought or merged, in which case the buyer would be bound by this notice and we would tell you first.
12. Where your information is held
Our application and our database are hosted in the United States, and several of our other providers are based there too. Your information is therefore transferred outside the UK. We are only allowed to do that if it keeps essentially the protection it has here.
Here is what covers each one.
| Provider | What covers the transfer |
|---|---|
| Anthropic | The UK Addendum to the European Commission's standard contractual clauses (ICO template version B.1.0) |
| Replit (our host), and Neon under it (our database) | The UK Addendum to the standard contractual clauses. Our database is provided through Replit, so Neon is Replit's sub-processor and Replit's safeguard is what covers it |
| Resend | The UK Addendum to the standard contractual clauses, and certification under the UK Extension to the EU-US Data Privacy Framework |
| Mapbox | The UK International Data Transfer Addendum (version B1.0), and certification under the UK Extension to the EU-US Data Privacy Framework |
| Microsoft Clarity | Microsoft's certification under the UK Extension to the EU-US Data Privacy Framework |
| Meta (advertising measurement) | Meta's UK Data Transfer Addendum, which is the safeguard Meta's own terms apply to the transfer to Meta Platforms, Inc. |
Stripe and Pinterest each contract with us through their Irish companies, and transfers to Ireland need no separate safeguard because the UK recognises the European Economic Area as offering equivalent protection.
We check each of these before we rely on it, and we check them again when a provider changes its terms. If you want to know more about any one of them, ask us and we will tell you.
13. Venues and suppliers in our catalogue
This section is for wedding venues and suppliers whose business details appear in Promessera. If you are a sole trader or run the business in your own name, your business details are also your personal data, so you are entitled to this explanation.
What we hold. Business name, address, location, website, publicly listed contact details, the services you offer, price bands where published, and our own written assessment of the kind of wedding your business suits.
Where we got it. From your own website and from public sources. We did not buy a list.
Our lawful basis. Legitimate interests: couples need an accurate, honest picture of what is available, and a wedding directory cannot exist without describing the businesses in it. We have weighed that against your interests and consider it proportionate, because we hold business information rather than private information, and we describe you fairly.
Imagery. Where we display your photographs, we do so with attribution and a link back to you. We do not claim them as ours.
How we describe you. We write an honest read of who your business suits and who it does not. It is never a fault list, and no one can pay to change it.
Your rights. You can ask us to correct anything inaccurate, to remove an image, or to remove your business from the catalogue altogether. Email enquiries@promessera.com and we will act on it. We do not make you argue for it.
14. How long we keep things
| What | How long |
|---|---|
| Waitlist email address | Until you ask us to delete it. The waitlist closed in August 2026 and we no longer add to it |
| Your account and your wedding plan | For as long as your account is open. You can delete it yourself, whenever you like |
| A free brief where you never subscribed | The same: it stays until you delete it or ask us to |
| Sign-in codes | A code works for 10 minutes. The record of it is cleared when the next sign-in code is issued, and the only thing it is kept for in the meantime is counting repeat requests to one address over an hour, so that nobody can use your address to send you codes you did not ask for. On a quiet day that clear-out can be a few hours rather than two |
| Payment and accounting records | 6 years from the end of the financial year they relate to, as UK tax law requires |
| Emails you send us | 24 months |
| Analytics and advertising cookie data | Under the provider's own retention policy |
When a retention period ends, we delete the information or anonymise it so it can no longer be linked to you.
We do not run a clock on your wedding plan. Planning takes a year or more and people come back to what they built, so we do not quietly delete it after a period of quiet. Instead, deleting it is something you do, and we have made it real rather than a request you have to chase: there is a delete control in your account settings, it removes your plan, your conversation, your budget, your timeline and your guest list together, and it happens immediately rather than being queued for someone to action. Your guests never signed up to us, so nothing about them survives it either.
15. Security
Access to your information inside Promessera is restricted to those who need it. Data is encrypted in transit and at rest by our hosting and database providers. Sign-in is passwordless and codes are single-use, expire after ten minutes, and lock out after five failed attempts. We never hold your card details.
No system is perfectly secure. If a breach ever affects your rights and freedoms, we will tell the ICO within 72 hours and we will tell you directly where the law requires it.
16. Your rights
Under UK data protection law you have the right to:
- Be told what we hold about you and what we do with it, which is what this notice is for.
- Get a copy of your information.
- Have it corrected if it is wrong or incomplete.
- Have it deleted, in the circumstances the law allows.
- Restrict how we use it while a dispute about it is resolved.
- Object to us using it on the basis of legitimate interests, and to object to direct marketing at any time, with no reason needed and no exceptions.
- Take it with you in a portable format, where we hold it on the basis of consent or contract.
- Withdraw consent at any time, where consent is what we relied on.
To use any of these, email enquiries@promessera.com. We will respond within one month. There is no charge. We may ask you to confirm who you are before we act, to make sure we are not handing your wedding plan to someone else.
One honest limit on deletion. When we delete you, we delete what we hold. Emails we have already sent you — a sign-in code, a payment receipt — leave a record with the provider that sent them, as part of our own sending history rather than anything about you we still use. Those records are not searchable by us as a profile of you, they are not shared, and they age out under that provider's own schedule rather than ours. We would rather say this than let "deleted" imply something cleaner than it is.
If you are unhappy with how we have handled your information, please tell us first and we will try to put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk, or on 0303 123 1113.
17. Children
Promessera is for people planning their own wedding and is not intended for anyone under 18. We do not knowingly create accounts for children.
A guest list may contain children's names and ages, because weddings have children at them. We treat that information the same way as the rest of your guest list: used only to run your plan, never marketed to, never shared. If you are a parent or guardian and want a child's details removed from a plan we hold, email us and we will remove them.
18. Changes to this notice
We will update this notice when what we do changes. The date at the top tells you when it last changed. If a change materially affects how we use your information, we will tell you by email before it takes effect rather than quietly republishing the page.
19. Contact
Promessera Limited128 City Road, London, EC1V 2NX, United Kingdom
Company number 17369508
enquiries@promessera.com