Skip to main content

Privacy Policy

Last updated: 25 September 2026

This explains, in plain English, what personal data Plan My Nikah collects when you use the site, why, and your rights under UK data-protection law (UK GDPR). Plan My Nikah, operated by PLAN MY GROUP LTD, is the data controller for the information described here.

Plan My Nikah is operated by PLAN MY GROUP LTD, a company registered in England and Wales under company number 17275878, with its registered office at 71 to 75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.

What we collect

  • Account details: your name, email and account type (couple or vendor) when you sign up. If you sign in with Apple or Google, the provider shares an account identifier and may share your name or email according to the choices you make there. Apple can provide a private relay email when you use Hide My Email.
  • Enquiries: when you contact a vendor we collect your name, email, message, and any wedding date, guest count or package you provide.
  • Matched-quote requests: if you post your requirements to get matched quotes, we collect the wedding details you provide — location, date(s), events, guest numbers, budget and your description — together with any preferences you choose to state, such as halal catering, a no-alcohol venue, segregated seating, prayer space or female staff. Because these preferences can indicate your religious beliefs, they are special category data and we only process them with your explicit consent, which you can withdraw at any time by deleting the request or your account.
  • Supplier-finding help requests: when you ask our team to find a vendor, we collect your search context, private message and the contact details needed to reply. An optional checkbox lets you permit a separate, contact-free summary to be shown to matching vendors. We store the consent wording version and time with the request; the permission expires after 30 days, and legacy, unchecked, resolved or archived requests cannot be broadcast.
  • Vendor listings: if you list a business, the business details you submit (name, description, photos, pricing, contact details).
  • Vendor verification evidence: if you apply for identity or insurance checks, we collect the private documents, expiry dates and notes you choose to submit, together with the reviewer’s decision. These documents are not published and are available only to you and authorised reviewers.
  • How you found us: for new accounts, we record the answer selected when we ask how you heard about PlanMyNikah, plus optional "Other" text of up to 200 characters. If you sign up through a dedicated event or stall link, the server records that event or stall attribution instead.
  • Optional browser alerts: if an account holder turns on browser alerts, we store that browser's unique push endpoint, public encryption key and authentication secret, when and which version of the opt-in was accepted, and its server-side enabled or revoked status. We mark it revoked when the account holder turns alerts off, it expires, the push service reports that it has gone, or it is replaced after a key change. We send an RFC 8291 encrypted routing label with no couple, request, category, city, date, quote or message content; the browser decrypts it and displays fixed text for that alert type. We keep no more than the 10 most recent disabled endpoints per account whose delivery work has safely completed, delete any remaining disabled endpoints after 90 days, and delete completed or failed delivery records after 30 days.
  • Saved items: the vendors you add to your shortlist.
  • Planning profile and wedding website: any couple profile photo, wedding website details, cover photo and gallery images you choose to add.
  • Anti-spam signal: to stop abuse of the enquiry form we store a one-way, salted hash of your IP address (never the IP address itself) for up to 24 hours, then it is deleted automatically.
  • Operational session and diagnostics data: a random per-tab session identifier, the current page, a coarse device/browser description, approximate city/region/country derived by our hosting provider, and sanitised technical errors. This lets us operate the service and investigate failures without collecting GPS, keystrokes, private form values or message contents. A masked IP is shown by default. The complete IP is kept separately for up to 30 days and can only be revealed one session at a time by an MFA-verified senior administrator who gives a written reason; every reveal is audited. We hold the complete IP for this limited period under our legitimate interest in investigating security incidents, abuse and fraud; it is never used for marketing, profiling or advertising.
  • Mobile app updates: in versions with background updates enabled, Expo receives your IP address, operating system, a persistent random installation identifier, and technical identifiers for the app version and update. If the app fails to start, its update software can also send technical startup-error details. This helps deliver compatible fixes, measure update adoption and recover failed updates. It runs automatically, separately from optional product analytics; our app does not deliberately attach account details, wedding plans or messages to update requests.
  • Optional product analytics: if you enable analytics, we retain meaningful page and feature events (for example a search, vendor-profile view, shortlist or completed enquiry) against the per-tab identifier and, when signed in, your account. We never record mouse movement, keystrokes, enquiry text or private form values. Detailed events are deleted within 90 days; non-identifying daily totals may be kept for up to two years. Existing registrations, applications, listings, subscriptions and enquiries may also be counted from the authoritative records needed to provide those services, rather than from invented events.

Wedding website and photo visibility

Wedding website cover and gallery photos uploaded from 20 September 2026 are stored privately. Guests see them only through your wedding website while it is published and they are allowed to open it, for example with your passcode.

Couple profile photos, and wedding website photos uploaded before 20 September 2026, are stored at long, randomly generated media links. We prevent anonymous browsing or listing of those files, but anyone who has the exact media link can view the image, even after you hide or unpublish your website. The media link does not expire automatically. In the website editor these older photos are marked Public link, and you can replace each one with a private copy and then remove the old public copy.

A wedding website passcode, the Website hidden setting and unpublishing control access to the wedding website page and its private photos. They cannot withdraw a copy or a direct image link that somebody already obtained while the image was shared. Avoid uploading an image you would not want an invited guest to save or share.

Replaced or removed profile photos are deleted from file storage. Wedding website photos you remove in the editor are not deleted automatically, so the currently published invitation is not broken by an unfinished draft. Guests stop seeing a private photo once your published website no longer includes it; an older public photo stays reachable at its direct link until you remove the old public copy. Unpublishing retains the site and its images for later republishing. Account deletion removes the account's stored files through our deletion workflow.

Why we use it (and our legal basis)

  • To run the marketplace and connect couples with vendors, to perform our service to you.
  • To maintain mobile app reliability and security through compatible updates and startup diagnostics, based on our legitimate interests in operating a reliable service.
  • To deliver your enquiry to the vendor you chose, so they can reply, to perform our service.
  • To match your quote request with a small number of suitable vendors (we cap how many vendors see each request), to perform our service. Where your request includes faith-related preferences, we rely on your explicit consent to use them for matching, and matching never makes automated decisions about you — you always choose which vendors to talk to, and any moderation decision about a request is reviewed by a person.
  • To answer supplier-finding help requests. Only when you explicitly opt in may a staff member write a separate, minimized summary for matching vendors; the original message and your contact details remain private.
  • To send optional operational browser alerts that an account holder explicitly enables for matched quote requests, direct enquiries and replies, or Hilal planning updates. We rely on consent, which can be withdrawn at any time in notification settings.
  • To measure which channels, events and stalls introduce new users and improve our marketing using internal acquisition analytics, based on our legitimate interests in understanding and growing the service.
  • If you use Hilal (our wedding planning assistant on /ai-planner or the Ask Hilal chat), to answer your questions and offer confirmable planning suggestions. That uses a commercial AI provider (DeepSeek). Conversation content you send, plus limited server-grounded context about your account and tools, may be processed so Hilal can reply. Hilal drafts and suggests only — it does not send enquiries, publish listings, book vendors or change your records until you confirm. Our legal basis is performing the service you asked for.
  • If a vendor chooses our AI quote-drafting tool for a matched quote request or direct enquiry, to help that vendor prepare an editable quote. The AI provider receives only a restricted structured summary of the request or enquiry and that vendor's pricing — never your raw description or message, location, name, contact details or account/request/enquiry identifiers. The vendor reviews the draft and nothing is sent automatically.
  • Vendors on an eligible plan may keep a private reusable template library for their own replies, follow-ups, quote sections and client communications. Templates are isolated to that vendor account and use inert placeholders whose current values are resolved only when the vendor explicitly inserts a template. If the vendor asks Hilal to draft or generalise reusable wording, names and contact details are removed before provider use; the vendor must review and save the result, and nothing is sent or published automatically.
  • To prevent spam and abuse of the enquiry form, our legitimate interest in keeping the service usable.
  • To keep the service reliable, understand failures and provide support using short-lived live-session state and sanitised diagnostics, relying on our legitimate interests in security and service operation.
  • To understand product use and improve journeys when you have enabled optional analytics.

Who we share it with

When you send an enquiry, its details are shared with the vendor you contacted so they can respond to you. When you post a quote request, its details (including any preferences you stated) are shared with the small number of matched vendors so they can quote — but never your name or contact details: vendors only see who you are if you choose to reply to them. We also rely on trusted service providers who process data on our behalf:

A supplier-finding help request is private to our team by default. If you tick its optional vendor-sharing checkbox, matching vendors may receive only a new, contact-free summary written by our staff — never your original help message, search text, name, email address or phone number. That permission expires after 30 days and is no longer usable once the help request is resolved or archived.

If you choose Compare with Hilal after receiving at least three quotes, we use the structured quote fields already shown to you to create neutral guidance. Our AI provider receives only opaque comparison fact labels, not vendor names, prices, terms, request text or contact details. PlanMyNikah inserts the exact figures from the stored quotes after the provider selects relevant labels.

  • Supabase: database, authentication and file storage (EU region).
  • Vercel: website hosting and serverless functions.
  • Resend: transactional email delivery (enquiry confirmations, vendor notifications).
  • Your browser push service (Google, Mozilla or Apple): receives the endpoint and an RFC 8291 encrypted routing label only after an account holder opts in. It can deliver the alert but cannot read the label, and the encrypted payload contains no couple, request, category, city, date, quote or message content.
  • Expo (650 Industries, Inc.): delivers compatible mobile app updates and processes update and startup diagnostics for versions with this feature enabled. Expo is based in the United States and uses infrastructure providers there and in other countries. Expo states that it participates in the EU–US Data Privacy Framework, including its UK Extension. See the Expo privacy policy.
  • Sentry: error monitoring to help us fix technical problems (EU region). We redact report content and omit account details; reports still contain technical app, device and update diagnostics.
  • Cloudflare: bot and spam protection (Turnstile) on our forms.
  • DeepSeek: commercial AI processing for Hilal chat and optional planning or vendor quote-drafting features. For Hilal conversations, this can include the messages you type and limited server-grounded context. Quote-draft and compare features use minimized inputs as described above. DeepSeek processes data outside the UK; we are completing the contractual and transfer safeguards for that processing. Email privacy@planmynikah.co.uk if you want more detail about those safeguards.
  • Google Analytics & Meta Pixel: optional marketing analytics, loaded only with your cookie consent (see Cookies & storage).
  • Google: only if you choose to sign in with Google.

We do not sell your personal data. Optional advertising analytics (Google Analytics and Meta Pixel) load only if you accept them in our cookie banner.

International transfers

Some of the service providers we use are based outside the United Kingdom, or use sub-processors outside the UK, so some of your personal data may be processed outside the UK. Several of our providers are headquartered in the United States, although some are configured to store data in the EU, for example our database, authentication and file storage (Supabase) and our error monitoring (Sentry) use EU regions.

Where personal data is transferred outside the UK to a country that does not have ‘adequacy’ status, we make sure the transfer is protected by an appropriate safeguard. Depending on the provider, this may be:

  • an applicable UK adequacy regulation, where the destination country or a certified recipient is covered by it;
  • the UK International Data Transfer Agreement (IDTA);
  • the UK Addendum to the EU Standard Contractual Clauses; or
  • another lawful safeguard permitted under UK data protection law.

Not every provider relies on the same mechanism. If you would like more information about the safeguards that apply to a particular transfer, email privacy@planmynikah.co.uk.

How long we keep it

  • The anti-spam IP hash is deleted automatically within 24 hours.
  • Expo retains update-service data for as long as reasonably necessary for its stated purposes; it does not publish a fixed retention period for these update request logs. Deleting your PlanMyNikah account does not automatically identify or erase a separate Expo installation record. Contact us about applicable access or deletion requests.
  • Live page/action state without analytics consent is cleared and deleted after approximately 15 minutes of inactivity.
  • Mission Control raw IP context is deleted within 30 days; detailed consented sessions, events and sanitised errors are deleted within 90 days.
  • Non-identifying daily Mission Control totals are kept for up to two years. Older first-party event types outside Mission Control retain their existing maximum of 180 days.
  • Enquiries are kept so the vendor can service your request and for their records.
  • Quote requests expire automatically within 90 days (or by your event date if sooner) and stop being shown to vendors. We delete an ordinary expired request and its related quote data 30 days later. If a quote was accepted or linked to a booking, we instead remove the raw request brief after 30 days and retain only the linked quote, enquiry and conversation records needed by the couple and vendor to service that transaction. Unfinished drafts are deleted after 30 days. You can delete a request at any time from My matched quotes.
  • Account and listing data is kept while your account is active, and deleted on request.
  • Private vendor identity and insurance evidence is kept with the vendor account and removed with account deletion. Approval status and re-review dates may change sooner when evidence or a policy expires.
  • Private vendor reusable templates are kept with the vendor account, including read-only preservation after an ineligible plan change, and are removed with account deletion.
  • Data-export download links expire after 24 hours. The private export files they point to are deleted automatically after the link has expired.
  • Administrative and security audit logs are kept for 12 months, then deleted automatically. We keep a relevant log for longer only while a documented legal hold or security investigation requires it.
  • When we act on a deletion request, your account, files and personal data are removed or anonymised straight away; copies in our encrypted database backups expire within the provider’s backup window (currently 7 days).

Young people

Wedding-planning accounts are available from age 13. If you are under 18, ask a parent or guardian to review this notice and the Terms of Service with you before creating an account. Vendor accounts and vendor bookings are for adults aged 18 and over.

The information uses and privacy rights described in this notice also apply to young people. If you have a question about your information, or believe a child under 13 has created an account, contact privacy@planmynikah.co.uk.

Your rights

Under UK GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict or object to its use, or provide it in a portable form. To exercise any of these, email privacy@planmynikah.co.uk. You also have the right to complain to the UK Information Commissioner’s Office (ICO).

How we handle your requests

When you make a request about your data, we will respond without undue delay and in any event within one month of receiving it. If your request is complex, or you have made a number of requests, we may extend this by up to two further months. If we need to extend the time, we will tell you within one month of your request and explain why.

We may ask you to verify your identity before we act on a request, where it is reasonable to do so to protect your information. Where we need that verification, or need to ask you to clarify your request, the one-month period may not start (or may pause) until we have the information we reasonably need.

You can exercise your rights, including deletion and a copy of your data, by emailing privacy@planmynikah.co.uk, or, if you have an account, from the app’s Account → Your data section. If you no longer have the app, follow our public account-deletion instructions.

Cookies & storage

We use essential storage to keep you signed in, remember your shortlist and run the site. A random per-tab visit identifier also supports short-lived live service state. It is cleared when the tab closes and does not become a cross-session anonymous ID. Historical product events are retained only when you enable analytics.

With your consent, we load optional analytics cookies from Google Analytics and Meta Pixel to measure how people find and use PlanMyNikah and to improve our marketing. These tools receive only aggregated event data (for example which category was searched or that an enquiry was sent), never your name, email, phone number, message text or address. You can accept or reject optional cookies in the banner on your first visit; your choice is remembered in local storage.

For a full list of the cookies and similar technologies we use, including their provider, purpose, duration and which ones need your consent, see our Cookie Policy.

Changes to this policy

We may update this policy from time to time. When we do, we will update the date at the top of this page. Continued use of the site after a change constitutes acceptance of the updated policy.

Contact

Questions about your privacy? Email privacy@planmynikah.co.uk.