Last updated: June 2026
Trust & Privacy
This page is maintained by <strong>Inversiones El Cisne</strong> to answer common security and privacy questions about WeddingOps Pro. It describes the controls we have enabled and the practices we follow today. It is not an independent certification or audit report.
1. What we collect and why
We collect the minimum data needed to run your studio: account information (name, email, studio name), wedding operational data (couples, guests, vendors, tasks, payments, timeline) that you enter, and essential usage telemetry for security and support. We do not sell personal data or use it for advertising.
2. How long we keep data
We retain operational data while your account is active. After cancellation, we keep data for a reasonable grace period to allow exports, then delete or anonymize it. Backups are retained for disaster recovery and are also purged on the same schedule.
3. Role-based access controls
WeddingOps Pro uses Row Level Security (RLS) policies at the database level. Every table that holds operational data has RLS enabled. Access is decided by your role and your relationship to a wedding, not by application logic alone.
4. Who can see what
Access is scoped by role:
- Planner / Owner: full access to their organization's weddings, leads, budgets, vendors, guests, and communications.
- Assistant: operational access to tasks, timeline, guests, vendors, and communications within the organization. Does not see margins or private financial notes unless explicitly granted.
- Couple: read-only access to their own wedding portal — tasks, documents, payments due, guest RSVP summary, and timeline. Cannot see margins, commissions, vendor costs, private planner notes, or other couples' data.
- Vendor: sees only the wedding and service details assigned to them. No access to guest lists, budgets, or other vendors.
- Guest: interacts only with the public RSVP website for the specific wedding they are invited to. No access to operational data.
5. How RLS protects guests and couples
Guest personal data — such as email, phone, allergies, accessibility needs, and RSVP preferences — is protected by database-level RLS policies. A couple can see a guest's name and RSVP status, but not their contact details or health notes. Planners and assistants in the same organization can see full guest records for operational purposes. No user can access guest data from weddings outside their organization.