Policy Center
Privacy Policy
This privacy policy explains data handling across the couple journey, partner operations, agency management, and platform governance surfaces.
Effective: 2026-05-28·Last updated: 2026-05-28·Version: v1.0
Owner: Mangalyam Engineering + Operations·Status: active
Scope: All data collection, storage, sharing, and retention paths across product and operations.
Policy key: privacy·Audience: all·Next review: 2026-06-28
1) Data categories
Mangalyam processes account data, wedding planning records, guest and vendor metadata, uploaded media, and payment workflow references needed to run the platform.
Where payout and compliance flows apply, KYC and banking metadata may be processed with elevated security controls.
2) Why data is used
Data is used to deliver requested features, operate role-based workflows, secure platform activity, and maintain auditability for financial and governance actions.
We also use limited analytics to improve activation, reliability, and workflow clarity across personas.
3) Sharing and visibility boundaries
Data is segmented by tenant and role. Couples, vendors, agencies, and admins only see data necessary for their permitted tasks.
Payment and KYC data may be shared with regulated payment providers and controlled support workflows only when required for transaction or compliance processing.
Service providers we use to run the platform: Supabase (database and authentication), Vercel (hosting), Cloudflare R2 (photo and file storage), Razorpay (payments and payouts), Resend and WATI (email and WhatsApp notifications), Sentry (error monitoring and diagnostic session replay), and PostHog (product usage analytics). PostHog receives page and feature-usage events; PostHog session recording is switched off and form input values are masked, so it never receives your guest lists, budgets, payment details, or KYC documents.
Sentry captures a small, sampled share of sessions as diagnostic replays to reproduce errors. These replays are privacy-masked at capture, in your browser, before anything is sent: all on-screen text is masked, every form input value is masked, and all media is blocked. A replay therefore records interaction and layout shape only — never the actual content you type or view (passwords, card numbers, guest lists, budgets, or KYC documents).
4) Storage, retention, and security
Mangalyam uses cloud storage, role controls, and audit logging for sensitive transitions. Access to high-risk operations is limited to authorized roles.
Retention periods differ by data class. Financial and audit records may be retained longer to satisfy regulatory, fraud-prevention, and reconciliation requirements.
5) User rights and support
You can request profile corrections, consent updates where applicable, and data handling clarifications through support.
Certain deletion or export requests may be staged where legal, audit, or financial integrity obligations require temporary retention.
6) Cross-border data transfers (DPDP Act §16)
Some of the service providers above process data on infrastructure located outside India, in the United States. Specifically: PostHog (product analytics), Sentry (error monitoring and diagnostic replay), and Resend (transactional email) receive the limited data described above on US-region infrastructure. Supabase (database and authentication) and Cloudflare R2 (media storage), which hold your core account and wedding data, are configured to store that data in-region.
Under Section 16 of India’s Digital Personal Data Protection Act, 2023, these transfers are made on the basis of your consent, captured at sign-up and manageable from Settings → Privacy & data, together with contractual data-protection terms (standard contractual clauses / data processing addenda) with each sub-processor that require them to protect your data to the standard this policy describes.
You can withdraw consent for non-essential processing (such as product analytics) at any time from Settings → Privacy & data. Essential providers required to operate the service and meet legal obligations — authentication, payments, storage, and email delivery — will continue to process the minimum data needed to run your account.
7) Your rights under India’s DPDP Act
If you have an account, you can exercise your data-subject rights directly from Settings → Privacy & data: grant or withdraw consent for non-essential purposes, download a copy of your personal data (right to access and portability), and delete your account (right to erasure).
Erasure anonymizes your personal data. Records we are legally required to keep — payment, invoice, and compliance/KYC records — are retained in anonymized or immutable form as the law requires, and are not hard-deleted.
To raise a grievance or reach our Grievance Redressal Officer, see the Grievance Redressal page or write to grievance@mangalyam.io.
Need a policy clarification? Email hello@mangalyam.io with your account email, booking reference, and policy question.