Privacy Policy
Last updated 2026. This describes how Medding, operated by Ghazali Trust ("Medding", "we", "us"), actually handles data today — it reflects what the product genuinely does, not a generic template.
Who is responsible for your data
Medding is the data controller for account and billing information. For guest, invitation, and RSVP data added to a wedding workspace, the workspace owner (the couple or planner running that wedding) is the data controller, and Medding acts as the data processor on their behalf — the same relationship as any address book or event-planning tool a couple might otherwise use.
What we store
Account details (name, email, hashed password or session), your wedding and event details, your guest and invitation records (including any phone number or town you add to tell guests apart), RSVP responses, wedding-site content, task/budget/vendor records, support tickets, and uploaded files. Uploaded files are stored on our own infrastructure, not a third-party media host.
Why we process it
We process account and wedding data to provide the service you've signed up for (performance of a contract), to keep the service secure and prevent abuse (legitimate interest), and to meet legal obligations such as retaining payment records (legal obligation). Where a workspace owner adds guest contact details, they do so under their own legitimate interest in organizing their wedding, and we process that data only as their processor, strictly to operate the service.
Guest data is never advertising inventory
Guest lists, contact details, and RSVP responses are never sold, shared with advertisers, or used to build marketing profiles. There is no third-party analytics or tracking script on Medding.
Who can see what
A wedding's data is visible only to members of that wedding's workspace, scoped to their role. Guests never receive accounts. They reach their own invitation either by opening a private, revocable link, or by entering their full name on the wedding's website; a name lookup is rate-limited, returns only that guest's own invitation, never reveals whether any other name exists, and asks for one extra detail (such as a town) when two guests share a name. A guest invited only to one event cannot see details of an event they weren't invited to, at any layer, including the API.
Who we share data with
We use a small number of specific processors, and don't sell or rent your data to anyone else: Stripe for payment processing (Medding never sees or stores your full card details); an SMTP relay for transactional email (invitations, confirmations, reminders, support replies) — not a third-party marketing platform; and our hosting provider, which stores the database and uploaded files. We disclose data to other parties only where required by law, such as in response to a valid legal request.
International transfers
Our infrastructure and email relay operate primarily within the UK/EU. If any processor we use is based outside the UK or EEA, we rely on that processor's own adequacy or standard-contractual-clause safeguards for the transfer.
How long we keep data
We keep your data for as long as your account and workspace remain active. If a wedding workspace is deleted, its data and uploaded files are removed as described below. Financial records (purchases, invoices) are kept for the period required by tax and accounting law even after a workspace is deleted, since these are legal obligations that survive deletion of the underlying workspace.
Data export and deletion
From Workspace settings, a workspace owner or partner can download a complete export of a wedding's data (guests, RSVPs, events, tasks, budget, vendors, and website content) as a JSON file at any time. The workspace owner can permanently delete the whole workspace, and anyone can delete their own Medding account, both self-service — no email required. Account deletion is blocked only if you're a workspace's sole owner, so the workspace isn't left ownerless; delete or transfer the workspace first in that case. For anything these tools don't cover, email hello@medding.org and we'll act on it directly.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, and to object to or restrict certain processing. The export and deletion tools above cover most of these directly and immediately; for anything else, or if you're not satisfied with our response, email hello@medding.org — UK/EU residents also have the right to complain to their local data protection authority (the ICO, in the UK).
Security
Passwords are hashed, never stored in plain text. Sessions use secure, same-site cookies. Access to a wedding's data always passes through server-side authorization tied to workspace membership — never a client-side check alone. Guest invitation links use random, hashed, revocable tokens, not guessable IDs. Uploaded files are validated and stored outside any publicly browsable directory.
Cookies
We use one session cookie to keep you signed in. We don't use third-party advertising or tracking cookies.
Children's data
Medding accounts require the account holder to be at least 18 (see our Terms of Service). A guest record may describe a child (for example, a family member added to an invitation when responding), but that record is basic attendance information supplied by the adult who holds the invitation, not an account or profile belonging to the child.
Changes
If how we handle data changes in a way that matters to you, we'll update this page and, where practical, tell you directly.
Questions? Email hello@medding.org.