Privacy Notice
This notice explains how {{LEGAL_ENTITY}}, trading as Cire (“Cire”, “we”), handles personal information across the Cire service — this marketing site, the invitation site your guests use, the organiser portal, and the vendor portal.
Two kinds of people use Cire
- Organisers (couples and their helpers) create an account with us. For your account and purchase information, we decide how it is handled, as described here.
- Guests don’t create accounts. Your couple uploads your details to manage their wedding, and we process them on the couple’s behalf and instructions. Three things are ours to decide rather than theirs, and we decide them the same way for every wedding: how long guest information survives the event, how the service is secured, and what technical telemetry it produces. If you are a guest with questions about why your details are in Cire, your couple is the first port of call — but you can always contact us directly too.
What we collect
- Organiser accounts — your name, email address and passkey credentials (public key only — no passwords), and the weddings you manage.
- Wedding content — invitation wording, images, event schedules, checklists and budgets you create.
- Guest information uploaded by organisers — guest names, household groupings, RSVP responses, dietary needs and similar details the couple chooses to record.
- Vendor listings and enquiries — if you are a wedding supplier, the contact details on your directory listing (which for a sole trader identify a person), and the enquiry threads between you and a couple. An enquiry sends the couple’s wedding name and message to the vendor they chose.
- Purchases — handled by our merchant of record, {{MERCHANT_OF_RECORD}}. We receive order confirmation (what was bought, for which wedding) but never see your card details.
- Site usage — the technical logs needed to keep the service secure. We run no third-party analytics or advertising trackers.
Why we collect it
- To provide the service — hosting invitations, collecting RSVPs, powering the planning tools.
- To process purchases and unlock paid add-ons.
- To send transactional email (sign-in codes, security notices) — never marketing without consent.
- To keep the service secure and improve it.
We do not sell personal information, and we do not use it for third-party advertising.
Who we share it with
We use a small set of service providers to run Cire:
- Cloudflare — hosting, content delivery and databases (global network).
- {{MERCHANT_OF_RECORD}} — payment processing, as merchant of record for purchases.
- Resend — transactional email delivery, including vendor claim invitations.
- The vendor you enquire with — an enquiry is sent to that supplier, who then holds it under their own responsibility.
- Upstash — infrastructure supporting security features such as rate limiting.
- Grafana Cloud — service telemetry (metrics and traces; pseudonymised identifiers only, never guest content).
- Google Fonts — our pages currently load fonts from Google’s CDN, which sees your IP address when they load. We plan to self-host these fonts.
We also disclose information where the law requires it. Our primary region is Australia; the infrastructure supporting the service’s security is pinned to Sydney, and some technical records — email delivery, service telemetry, payment processing — are handled by providers outside it. If you are in the EEA or the UK, that means your information is transferred out of that area to Australia and elsewhere; ask us and we will tell you what protections apply to that transfer.
How long we keep it
Only as long as needed for the purposes above. Guest information (guest lists, RSVPs, dietary needs) is automatically deleted one year after the wedding’s final event. That window is set by us and applies to every wedding — an organiser cannot extend it. Other wedding and account data is kept while your account is active and removed when you ask us to; specific periods for account data: {{RETENTION}}.
Security
Traffic is encrypted in transit, organiser sign-in uses passkeys rather than passwords, and session credentials are stored hashed. No system is perfectly secure, but we design for security first.
Your rights
You may have rights to access, correct, delete or port your information, and to object to certain uses — under the Australian Privacy Act, and for people in the EEA or UK, the GDPR and UK GDPR. To exercise them, contact us at [email protected]. You can also complain to a regulator — in Australia, the Office of the Australian Information Commissioner (OAIC), or your local data protection authority.
Cookies
We use only the cookies the service needs to work (such as session cookies for signed-in organisers and guests). No advertising or cross-site tracking cookies.
Contact
{{LEGAL_ENTITY}} (trading as Cire), {{POSTAL_ADDRESS}} — [email protected].