Your information

Privacy Policy

Effective: 11 August 2026

This Privacy Policy explains how Co-ordinAIte collects, uses and handles personal information when couples, guests and wedding professionals use our websites, applications and related services.

1. Information we collect

Information you provide

We collect information you submit when creating or using an account, contacting us, or using service features. This may include names, email addresses, contact numbers, sign-in details, business information and communications.

Wedding and guest data

Couples may provide wedding details, planning tasks, budgets and expenses, guest names and contact details, RSVP responses, meal or attendance information, seating arrangements, invitations, registry information, website content, photos and vendor communications. Couples are responsible for having an appropriate basis to provide their guests’ information.

Vendor data

Wedding professionals may provide business and contact details, location, service category, listing images, availability or blocked dates, messages, subscription and invoice information, and scheduling data.

Account and sign-in information

Depending on the sign-in option used, we may receive identifiers and basic account information from an identity provider, such as an email address and verification status. Passwords used for direct accounts are stored as password hashes, not in readable form.

Technical and security data

Our hosting and security providers may process IP addresses, browser and device information, request times, diagnostic logs, cookie or session identifiers, and security events needed to operate, secure and troubleshoot the service.

2. How we use information

  • Provide, maintain and personalise requested planning and vendor features.
  • Authenticate users and protect accounts.
  • Enable guest, RSVP, seating, invitation, website, registry, vendor and communication features.
  • Process subscriptions and payments through payment providers.
  • Respond to support requests and service communications.
  • Monitor reliability, prevent abuse, enforce our Terms and meet legal obligations.
  • Improve the service using operational information, subject to applicable law.

3. How information is shared

We may share information with service providers that help us host, secure, communicate, process payments, store content or provide a feature requested by the user. We may also share information when required by law, to protect rights and safety, in connection with a business transaction, or with the user's direction or consent. Couples and vendors may see information that the other party deliberately shares through discovery, enquiries and messages.

We do not state that personal information is never transferred internationally; hosting and service providers may process information in other countries, subject to applicable safeguards.

4. Google Calendar and Google User Data

Google Calendar connection is optional and available to wedding vendors. A vendor must explicitly authorise Co-ordinAIte through Google OAuth and then select an editable calendar.

Data accessed and purpose

Co-ordinAIte requests access to read the vendor's Google Calendar list so the vendor can choose an editable calendar. For the selected calendar, Co-ordinAIte reads event identifiers, titles, start and end times, all-day status, descriptions, locations and status so events can be displayed in the vendor portal. At the vendor's request, Co-ordinAIte can create, update and delete events in that selected calendar. This supports two-way scheduling and vendor availability functionality.

Data stored

Co-ordinAIte stores an encrypted Google OAuth refresh token, the selected Google calendar identifier and name, connection time, and last synchronisation time in its database. The inspected implementation fetches calendar events from Google when required and does not persist copies of Google event contents in the Calendar connection store. Temporary processing and ordinary server logs may still occur through the application or hosting environment.

Retention and deletion

The Calendar connection record is retained while the integration remains connected. When a vendor uses the portal's disconnect action, Co-ordinAIte attempts to revoke the Google token and deletes the stored Calendar connection record, including the encrypted refresh token and selected calendar metadata. Existing events remain in the vendor's Google Calendar. The broader backup-retention period and the timing for deletion from backups have not yet been formally confirmed.

Control and revocation

Vendors may disconnect Google Calendar in the Co-ordinAIte vendor portal or revoke access through their Google Account permissions. They may request deletion or assistance by emailing support@co-ordinaite.com.

Google user data is not sold, is not used for advertising, and is used only to provide the user-requested Calendar selection, event synchronisation, availability and scheduling functionality.

Co-ordinAIte's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including applicable Limited Use requirements.

5. Cookies and local storage

The applications use cookies or similar storage that are necessary for sign-in, security and session operation. This public website does not include analytics or advertising trackers.

6. Data retention

We retain information for as long as needed to provide the service, maintain legitimate business and security records, resolve disputes, and meet legal obligations. Different categories may require different retention. Formal retention schedules for account data, backups, security logs and payment records must be confirmed before this policy is treated as final.

7. Security

We use reasonable technical and organisational measures intended to protect information. The inspected Calendar implementation encrypts stored Google refresh tokens using ASP.NET Core Data Protection and uses HTTPS endpoints in production configuration. No online service can guarantee absolute security.

8. Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing of personal information, request portability, withdraw consent, or complain to a data-protection authority. To exercise a right, contact us. We may need to verify your identity and may retain information where legally required.

9. Account and data deletion

To request account or personal-data deletion, email support@co-ordinaite.com from the address associated with your account and describe the account or data concerned. The operational identity-verification process, response timeframe, deletion timeframe and backup treatment must be confirmed internally. Disconnect Google Calendar separately in the vendor portal or through your Google Account to revoke access promptly.

10. Third-party services

Our services may link to or integrate with providers such as Google, hosting, email, payment, mapping and domain services. Their own privacy terms govern information they process independently. Co-ordinAIte is not responsible for unrelated third-party websites.

11. Children

Co-ordinAIte is not directed to children and is intended for adults able to enter a binding agreement. Contact us if you believe a child has provided personal information without appropriate authority.

12. Changes to this policy

We may update this policy as the service or legal requirements change. We will publish the revised policy here and update its effective date. Material changes may also be communicated through the service where appropriate.

13. Contact

Questions, privacy requests and deletion requests can be sent to support@co-ordinaite.com.