Privacy Policy
Last updated: 2 March 2026
1. Introduction
The Wedding Notebook ("we", "us", or "our") operates theweddingnotebook.com (the "Platform"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our Platform, in accordance with the Malaysian Personal Data Protection Act 2010 (PDPA) and other applicable laws.
By accessing or using the Platform, you consent to the practices described in this Privacy Policy. If you do not agree, please do not use the Platform.
2. Data We Collect
2.1 Account Information
When you create an account, we collect:
- Name and email address
- Phone number (optional)
- Profile photo (optional)
- Account type (couple or vendor) and role (e.g. bride, groom, partner)
- Password (stored in hashed form — we never have access to your plain-text password)
2.2 Wedding Planning Details (Couples)
To personalise your experience, we may collect:
- Wedding date and preferred dates/months
- Estimated budget range (in MYR)
- Estimated guest count
- Venue and style preferences
- Planning stage (e.g. newly engaged, already planning)
2.3 Business Information (Vendors)
If you register as a vendor, we collect:
- Business name and contact details
- Vendor category (venue, photographer, etc.)
- Service areas, pricing, packages, and portfolio content
- Venue address, coordinates, and Google Maps information
2.4 Photos & Moodboards
When you upload photos or import images (including from Pinterest), we store the image files and associated metadata such as dimensions and source information. We may automatically analyse photos to detect objects, scenes, and colours to power our recommendation and discovery features.
2.5 Messages & Communications
We store messages exchanged between couples and vendors through our chat system, including message content, timestamps, and read status. This allows us to provide a reliable messaging experience and resolve disputes.
2.6 Appointment Data
When you request or manage appointments with vendors, we store the requested date, time, status, and related details.
2.7 Automatically Collected Data
When you use the Platform, we may automatically collect technical information such as your IP address, browser type, device information, and pages visited. This helps us maintain security and improve the Platform.
3. How We Use Your Data
We use your personal data to:
- Create and manage your account
- Connect couples with wedding vendors and facilitate enquiries
- Provide personalised venue and vendor recommendations based on your preferences
- Enable moodboard creation, photo organisation, and visual inspiration features
- Facilitate messaging and appointment scheduling between couples and vendors
- Send transactional emails (e.g. welcome emails, appointment confirmations, enquiry notifications)
- Improve, maintain, and secure the Platform
- Comply with legal obligations
4. Automated Image Analysis
We use automated image analysis technology to detect objects, scenes, and colour palettes in uploaded photos. This processing powers features such as smart photo recommendations, visual search, and moodboard suggestions. No human reviews your photos as part of this automated process.
5. Third-Party Services
We share data with trusted third-party service providers who assist us in operating the Platform. These providers are contractually obligated to protect your data and may only use it for the purposes we specify:
- Supabase — authentication, database hosting, and real-time messaging infrastructure
- Cloudflare — content delivery, image storage, and security protection
- Amazon Web Services (AWS) — automated image analysis for photo recommendations
- Google — Maps integration for venue locations, and social login (if you choose to sign in with Google)
- Pinterest — board import functionality (only when you explicitly connect your Pinterest account)
- Resend — transactional email delivery
- Sentry — error monitoring to help us fix bugs and improve reliability
We may also display advertisements through Google AdSense, which may use cookies or similar technologies to serve relevant ads. Please see Google's privacy policy for details on how they handle data.
6. Cookies & Local Storage
We use essential cookies and browser local storage to keep you signed in and remember your preferences. Third-party services we integrate with (such as Google Maps and Google AdSense) may set their own cookies. You can manage cookie preferences through your browser settings, though disabling essential cookies may affect Platform functionality.
7. Data Storage & International Transfers
Your data may be stored and processed on servers located outside Malaysia, including in the United States and other countries where our service providers operate. We ensure that any such transfers are carried out with appropriate safeguards to protect your personal data.
8. Data Retention
We retain your personal data for as long as your account is active or as needed to provide you with our services. When you delete your account, we will delete or anonymise your personal data within a reasonable timeframe, except where we are required to retain it by law. Related data such as moodboards, uploaded photos, and chat messages are automatically removed when your account is deleted.
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include:
- Encryption of data in transit (HTTPS/TLS)
- Secure password hashing
- Role-based access controls
- Regular security monitoring
While we strive to protect your personal data, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.
10. Your Rights
Under the Malaysian PDPA and applicable laws, you have the right to:
- Access — request a copy of the personal data we hold about you
- Correction — request correction of inaccurate or incomplete data
- Withdrawal of consent — withdraw your consent for us to process your data (this may limit your ability to use certain features)
- Deletion — request deletion of your account and associated data
To exercise any of these rights, please contact us using the details below.
11. Children's Privacy
The Platform is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised "Last updated" date. We encourage you to review this page periodically.
13. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us through our website.