wding legal
wding Privacy Policy
Last updated on 12 June 2026
This Privacy Policy explains how O2OSTAYS PTY LTD ABN 60 673 215 346 (O2OSTAYS, we, us or our) collects, holds, uses and discloses personal information when you access or use wding, including the website located at https://wding.app, the wding mobile application, and any associated mobile application, website, page, social media platform, planning tool, RSVP tool, booking tool, payment tool, messaging tool or other online service made available by us from time to time (Platform).
The Platform is operated by O2OSTAYS PTY LTD ABN 60 673 215 346 under the wding brand. In this Privacy Policy, O2OSTAYS, we, us or our means O2OSTAYS PTY LTD ABN 60 673 215 346, and references to wding mean the Platform, brand, website, mobile application and related services operated by O2OSTAYS.
This Privacy Policy applies when you access or use the Platform as a customer, including where you browse, enquire about, plan, RSVP to, book or pay for wedding, venue, travel, accommodation, event, hospitality, activity or related goods or services. This Privacy Policy also applies where you access or use the Platform as a couple, wedding host, wedding guest, attendee, traveller, invitee or other person involved in planning or attending a wedding.
We are bound by the Privacy Act 1988 (Cth), including the Australian Privacy Principles (APPs), to the extent that they apply to us. This Privacy Policy describes how we manage personal information in accordance with those requirements.
We may change this Privacy Policy at any time by updating this page of the Platform. If we make material changes, we will take reasonable steps to notify you through the Platform or by another reasonable method.
1. Definitions
In this Privacy Policy:
Customer means a person who accesses or uses the Platform to browse, enquire about, plan, RSVP to, book, pay for or receive goods or services from a Supplier, and includes couples, wedding guests and other persons involved in planning or attending a wedding.
Personal information has the meaning given in the Privacy Act and generally means information or an opinion about an identified individual, or an individual who is reasonably identifiable.
Platform means the website, mobile application and any associated applications, websites, pages, social media platforms, planning tools, RSVP tools, booking tools, payment tools, messaging tools and other online services made available by O2OSTAYS from time to time.
Sensitive information has the meaning given in the Privacy Act and may include health information, dietary or accessibility information, biometric information, government identifiers and information about racial or ethnic origin, religious beliefs or other protected characteristics.
Supplier means a third party vendor, supplier, venue, accommodation provider, travel provider, activity provider or other service provider who advertises, offers, quotes for, books, supplies or provides goods or services through or in connection with the Platform.
Third Party Provider means a third party payment processor, booking provider, travel provider, accommodation provider, flight provider, activity provider, messaging provider, analytics provider, application programming interface, embedded checkout tool or other third party system used to operate the Platform or facilitate payments, bookings, inventory, availability, confirmations, communications or support.
2. What personal information we collect
The kinds of personal information we collect depend on how you use the Platform. We may collect:
1. Account and identity information, including your name, display name, username, email address, phone number, authentication provider, sign-in method, account identifiers, profile photo, account settings, preferences and password reset or verification status.
2. Profile information, including your bio, profession, city, country, profile links, profile visibility settings, activity status settings, search appearance settings, language, currency and date format preferences.
3. Wedding, event and guest information, including wedding title, handle, dates, location, venue details, cover images, event items, itinerary details, guest lists, host and guest roles, attendance status, invite details, RSVP status, RSVP notes, questionnaire questions, questionnaire answers and related wedding planning information.
4. Contact information you provide about other people, including guest names, email addresses and phone numbers. If you use native contact import, the Platform may request access to selected device contact information so that you can choose guests to add. Contact import is used to help you select guests; invitations are not sent merely because contact access is granted.
5. Posted Material, including discussion posts, comments, likes, poll questions, poll options, poll votes, event item shares, media, links, reviews, feedback and other information or content you provide through the Platform.
6. Messaging and support information, including conversations, conversation members, messages, attachments, read status, support requests, support ticket links, support agent replies and communications with us or with other users.
7. Booking and travel information, including trip details, booking references, stay details, flight details, dates, destinations, selected accommodation, selected flights, selected seats or services, cancellation information, booking status, booking social proof settings, provider references, confirmation codes, price and currency details, and booking operation history.
8. Traveller and checkout information, including lead guest details, passenger or traveller names, passenger type, title, gender, date of birth, email address, phone number, nationality where required, room occupancy details, emergency contact details, billing address and other information required to process or manage a booking.
9. Payment information, including payment attempt identifiers, payment session references, payment processor references, provider transaction references, amount, currency, payment status and limited payment metadata. We do not intend to store full payment card numbers on the Platform. Card and wallet payment details are handled by payment processors or provider payment SDKs.
10. Media and upload information, including images you upload for profile photos, wedding covers, event covers, discussion posts, chat images and related crop, file, storage, ownership and lifecycle metadata.
11. Location and search information, including typed search queries, selected place details, formatted addresses, venue or accommodation location details, coordinates for selected places, map display information, airport or destination search information and recent discovery searches. We do not currently request live GPS location permission as part of the Platform flows reviewed for this draft.
12. Device, notification and technical information, including device push tokens, device identifiers made available by the app runtime, platform, app version, notification preferences, notification delivery status, IP address, browser or device information, log data, session data, crash or diagnostic data and app update/runtime information.
13. Analytics, attribution and usage information, including screen views, route usage, feature usage, app lifecycle events, sign-in events, wedding membership counts, event and booking interaction events, notification events, campaign or deferred deep link information and other usage information collected through analytics or attribution tools.
14. Communications information, including emails we send or receive, message delivery information, unsubscribe or notification preference information, support correspondence, booking communications and operational notices.
15. Information we are required or authorised to collect by law, including information required to verify identity, prevent fraud, administer payments, comply with court orders, comply with tax or accounting obligations, respond to disputes or satisfy supplier or travel-provider requirements.
3. Sensitive information
Some Platform features may involve sensitive information. For example, a host may ask RSVP questions about dietary requirements, allergies, accessibility needs or other matters relevant to attendance. Travel, accommodation, flight, visa or supplier workflows may also require information such as date of birth, gender, nationality, passport or travel document details, emergency contact details or health-related travel information.
We only collect sensitive information where you provide it, where another person provides it on your behalf with authority, where it is reasonably necessary for a Platform function or booking, or where we are otherwise permitted or required by law to collect it. If you provide sensitive information about another person, you must have authority to do so.
4. How we collect personal information
We may collect personal information:
1. directly from you when you create an account, sign in, edit your profile, plan a wedding, invite guests, RSVP, answer questions, upload media, send messages, make bookings, make payments, contact support or otherwise use the Platform;
2. from a couple, host, wedding organiser, guest, traveller or other authorised person who provides information about you, including as part of a guest list, invite, RSVP, booking, room occupancy, traveller profile or event plan;
3. from your device or browser when you use the Platform, including through cookies, local storage, SDKs, analytics tools, attribution tools, push notification APIs and app runtime services;
4. from device contacts, but only where contact import is available, you grant permission and you choose to import or select contacts;
5. from Suppliers and Third Party Providers, including travel, accommodation, flight, activity, visa, payment, messaging, analytics, email, storage, maps and booking providers;
6. from authentication providers, including Google, Apple and Supabase authentication services, where you choose to use those sign-in methods;
7. from publicly available sources or linked third party services where you direct us to use that information, such as place, map, listing or image sources; and
8. from our own records, support systems, logs, analytics systems and administrative processes.
5. Why we collect, hold, use and disclose personal information
We collect, hold, use and disclose personal information for the purposes for which it was collected and for related purposes that you would reasonably expect, including to:
1. provide, operate, maintain, secure and improve the Platform;
2. create, authenticate, administer and support user accounts;
3. enable couples, hosts, guests, travellers and other Customers to create, manage and attend weddings and related events;
4. enable guest management, invitations, public links, app handoffs, RSVPs, questionnaire responses, itinerary planning, discussion posts, polls, comments, likes, media sharing and event item sharing;
5. enable messaging between users and support conversations with O2OSTAYS;
6. enable search, discovery, listing display, map display, place selection, travel planning and recommendations;
7. facilitate bookings, booking confirmations, booking changes, booking cancellations, refunds, support requests, booking social proof and supplier communications;
8. facilitate payment attempts, payment authorisations, payment confirmations, payment processing, payment reconciliation, chargeback handling, fraud prevention and financial administration;
9. send transactional, operational, support, invitation, RSVP, booking, payment, account, security, notification and digest communications;
10. register and deliver push notifications where you have granted permission and where notifications are enabled for the relevant category;
11. provide customer support, investigate issues, sync support conversations and respond to enquiries, complaints and disputes;
12. personalise and improve the Platform, including by remembering preferences, improving search results, measuring feature use and understanding product performance;
13. conduct analytics, attribution, monitoring, debugging, fraud detection, security review and operational reporting;
14. comply with applicable laws, court orders, regulatory requirements, accounting obligations, tax obligations, law enforcement requests and dispute resolution processes; and
15. enforce our terms, protect our rights, protect the rights of Customers, Suppliers and Third Party Providers, and prevent misuse of the Platform.
6. Disclosure to other users
The Platform is collaborative. Depending on the feature used and your settings, your personal information may be disclosed to other users, including couples, hosts, guests, travellers, invitees, support agents and conversation members.
For example:
1. profile information may be visible to confirmed guests, event hosts or other authorised users according to Platform settings;
2. RSVP status, RSVP answers and guest information may be visible to hosts and, where applicable, other authorised users;
3. discussion posts, comments, likes, polls, poll votes and uploaded media may be visible to members of the relevant wedding or conversation;
4. messages and attachments may be visible to participants in the relevant conversation;
5. itinerary items, shared event items and guest attendance information may be visible to members of the relevant wedding or trip; and
6. limited booking social proof may be shown to authorised users, for example that people are staying nearby or travelling on a similar route, subject to the relevant privacy and access rules.
You should not provide personal information on the Platform unless you are comfortable with it being used and disclosed in accordance with this Privacy Policy and the relevant Platform settings.
7. Disclosure to Suppliers and Third Party Providers
We may disclose personal information to Suppliers and Third Party Providers where reasonably necessary to operate the Platform or facilitate a requested service. This may include disclosure to:
1. accommodation, hotel, venue, flight, travel, activity, transport, visa, hospitality and other booking providers;
2. payment processors, card processors, payment SDK providers, fraud prevention providers and payment reconciliation services;
3. cloud hosting, database, authentication, storage, content delivery, app runtime and infrastructure providers;
4. email, push notification, SMS, messaging, support and customer communication providers;
5. analytics, attribution, app performance, debugging, monitoring and product measurement providers;
6. map, place search, geocoding, location search, listing, media, image and discovery providers;
7. professional advisers, insurers, accountants, auditors, lawyers and consultants;
8. related bodies corporate, contractors, agents, service providers and business partners who assist us to operate the Platform; and
9. regulators, courts, tribunals, law enforcement agencies, government agencies or other persons where required or authorised by law.
Third Party Providers used by the Platform may include Supabase, Stripe, LiteAPI and LiteAPI payment services, Google Maps and Google Places, Google Sign-In, Apple Sign-In, PostHog, AppsFlyer, Expo and Expo push notification services, Resend, Bunny Storage and Bunny CDN, and other travel, accommodation, flight, activity, visa, analytics, support, infrastructure and communication providers used from time to time.
Where a booking or payment is processed by a Third Party Provider, that Third Party Provider may also collect and process personal information under its own terms and privacy policy. You should review those terms and privacy policies before proceeding with the relevant booking or payment.
8. Payments
Where you make or attempt to make a payment through the Platform, we may create payment attempts, payment sessions, booking operations and payment metadata to manage checkout and booking status. Payment details may be handled by payment processors or provider payment SDKs, including Stripe or LiteAPI payment services.
We may receive and store limited payment information such as payment attempt identifiers, payment session identifiers, provider transaction references, amount, currency, status, booking references and reconciliation metadata. We do not intend to store full payment card numbers or card security codes on the Platform.
9. Bookings, travel and Suppliers
Where you make a booking or use a booking-related feature, we may disclose personal information to the relevant Supplier or Third Party Provider so that the booking can be searched, priced, validated, paid for, confirmed, changed, cancelled, supported or reconciled.
For accommodation bookings, this may include lead guest details, room occupancy details, dates, property information, booking context, payment confirmation information, provider booking references and contact details.
For flight bookings, this may include passenger names, passenger type, title, gender, date of birth, email, phone number, selected flights, selected seats, selected ancillaries, service selections, pricing details, payment session information and provider booking references.
For activities, experiences, transport, visa or other services, the personal information required will depend on the relevant Supplier or Third Party Provider and the nature of the service.
10. Analytics, cookies, attribution and tracking technologies
We use cookies, local storage, SDKs and similar technologies to operate the Platform, keep you signed in, remember preferences, measure product usage, understand how Customers use the Platform, attribute installs or deep links, monitor performance and improve our services.
The Platform uses Supabase authentication storage for account sessions. It also uses analytics and attribution services such as PostHog and AppsFlyer where configured. Analytics events may include screen names, route information, feature usage, app platform, account state, wedding membership counts, booking and notification event metadata and similar usage information.
Analytics events and profiles may be associated with your account and may include personal information such as your email address, display name, username, profile details, location details and identifiers for weddings, events, trips and conversations you interact with, so that we can understand and support individual Customer usage. We take steps in the Platform to exclude credential material from analytics data, including property keys that appear to contain passwords, tokens, secrets, OTPs, authorisation data, handoff tokens, access tokens, refresh tokens, redirect URLs, raw URLs and invite URLs.
We may use analytics information in aggregated, de-identified or pseudonymised form for reporting, product development, service improvement, operational monitoring and business planning.
You may be able to control some cookies or tracking technologies through your browser, device, operating system or app settings. If you block or disable necessary technologies, some Platform features may not work properly.
11. Direct marketing
We may use your contact details to send you direct marketing communications where permitted by law, including about the Platform, related services, offers, product updates, events or Suppliers. You may opt out of direct marketing communications by using the unsubscribe function in the communication or by contacting us.
Even if you opt out of direct marketing, we may still send transactional or operational communications, including account, security, invitation, RSVP, booking, payment, notification, support and legal notices.
12. Overseas disclosure
The Platform is operated using cloud, infrastructure, analytics, payment, email, map, app runtime, storage, support, booking and travel providers that may be located outside Australia or may store or process information outside Australia.
We may disclose personal information to overseas recipients, including in the United States, the European Union, the United Kingdom, Singapore, Indonesia and other countries where our Suppliers, Third Party Providers, infrastructure providers, payment providers, travel providers, support providers or booking providers are located or process data. For destination weddings or international travel services, personal information may also be disclosed to Suppliers or Third Party Providers in the destination country.
Where we disclose personal information overseas, we will take reasonable steps in the circumstances to handle the disclosure in accordance with the Privacy Act and the APPs, unless an exception applies.
13. Security
We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. These steps may include authentication controls, role-based access controls, row-level security, access tokens, server-side permission checks, rate limits, storage scoping, provider access controls, encryption in transit, logging, monitoring and administrative safeguards.
No method of transmission or storage is completely secure. To the maximum extent permitted by law, we do not guarantee that information transmitted to or from the Platform will be completely secure or confidential.
You are responsible for keeping your account details secure and for promptly notifying us if you suspect unauthorised access to your account.
14. Retention
We retain personal information for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Platform, manage accounts, administer weddings and events, maintain booking and payment records, resolve disputes, comply with legal obligations, prevent fraud, enforce our terms and maintain business records.
Retention periods may differ depending on the type of information. For example:
1. account, profile, wedding, guest, RSVP, messaging and media information may be retained while your account or the relevant wedding, event, trip, booking or conversation remains active;
2. booking, payment, tax, accounting, support and dispute information may be retained for longer periods where required for operational, legal, accounting, audit, chargeback, supplier or dispute purposes;
3. push tokens and notification preferences may be retained while they remain active or until disabled, archived or no longer required;
4. analytics and diagnostic information may be retained in identifiable, pseudonymised, aggregated or de-identified form according to our operational and analytics requirements; and
5. uploaded media may be retained while attached to an account, wedding, event, discussion post, chat or other Platform record, and may be retained for a reasonable period after replacement, deletion or archival for backup, audit or integrity purposes.
When we no longer need personal information for any purpose permitted by law, we will take reasonable steps to destroy it or de-identify it.
15. Access and correction
You may request access to personal information we hold about you. You may also request correction of personal information we hold about you if you consider it to be inaccurate, out of date, incomplete, irrelevant or misleading.
Some information can be accessed or corrected directly through your account, profile, booking, guest, RSVP, notification or privacy settings. For other requests, please contact us using the details below.
We may need to verify your identity before responding to a request. We will respond within a reasonable period. We may refuse access or correction where permitted by law, including where giving access would have an unreasonable impact on the privacy of other individuals, where the request is frivolous or vexatious, where the information relates to existing or anticipated legal proceedings, or where another legal basis for refusal applies. If we refuse a request, we will provide written reasons where required by law and tell you how you may complain.
16. Deletion, account closure and withdrawal of consent
You may request deletion of your account or personal information by contacting us. We will take reasonable steps to action deletion requests where required or appropriate, subject to legal, operational, booking, payment, fraud prevention, dispute, accounting, backup and archival requirements.
Some information may not be capable of immediate deletion, including information required to complete or administer bookings, payments, chargebacks, refunds, disputes, supplier obligations, legal obligations or safety obligations. Some collaborative information, such as messages, posts, RSVP records, guest records, booking records or event history, may need to be retained or shown in limited form to preserve the integrity of a wedding, booking, support conversation, transaction or record.
Where we rely on consent to collect, use or disclose personal information, you may withdraw that consent by contacting us or by changing the relevant Platform setting, where available. Withdrawal of consent may affect your ability to use some Platform features.
17. Notification and communication choices
You may be able to manage notification preferences in the Platform, including preferences for in-app, push, email and digest notifications by category. You can also control push notification permission through your device settings.
If you disable notifications, you may still receive communications that are necessary for account security, booking administration, payment administration, legal notices, dispute handling or operation of the Platform.
18. Children and minors
The Platform is intended for persons who are at least 18 years old. If you are under 18 years old, you must not use the Platform unless your parent or guardian has consented to your use of the Platform and accepts responsibility for your use of the Platform.
If a parent or guardian becomes aware that a child has provided personal information to us without appropriate consent, they should contact us. We will take reasonable steps to address the matter in accordance with applicable law.
Where a host, parent, guardian or authorised adult provides information about a minor for wedding, guest, RSVP, travel, accommodation or booking purposes, that person must have authority to provide the information and must ensure that the information is accurate, complete and not misleading.
19. Third party links and services
The Platform may contain links to third party websites, applications, platforms or services that are not owned or controlled by O2OSTAYS. We are not responsible for the privacy practices, security, content or availability of those third party websites, applications, platforms or services.
Where you interact directly with a Supplier or Third Party Provider, including through an embedded checkout, payment SDK, booking flow, map, support tool, external listing, email link or app store link, that third party may collect and handle your personal information under its own terms and privacy policy.
20. Anonymity and pseudonymity
You may be able to browse some public parts of the Platform without creating an account. However, many Platform features require personal information so that we can authenticate you, manage invitations, administer RSVPs, process bookings, process payments, support messages, provide notifications and maintain security.
If you do not provide requested personal information, we may be unable to provide some or all Platform features to you.
21. Privacy complaints
If you have a question, concern or complaint about how we handle personal information, please contact us using the details below.
We will consider your complaint and respond within a reasonable period. We may ask you for further information to verify your identity or understand the complaint. If you are not satisfied with our response, you may be able to complain to the Office of the Australian Information Commissioner (OAIC).
22. Contact details
For privacy enquiries, access requests, correction requests, deletion requests or complaints, please contact:
O2OSTAYS PTY LTD ABN 60 673 215 346. Privacy Officer. Email: support@email.wding.app. Website: https://wding.app.