Short version: We use personal information to provide accounts, payments, invitations, and RSVPs. We do not sell personal information or use guest details for advertising. An active invitation is public to anyone with its link, and RSVP details are shared with the couple who invited the guest.
1. Who We Are
Kadly is operated by Irfan Rafiq trading as Kadly, ABN: 99 818 138 075, New South Wales, Australia. Contact us about privacy at privacy@kadly.co.
2. Information We Collect
From card owners
- Account information — email address and identifiers supplied by Supabase Auth or Google Sign-In.
- Invitation content — names, wedding date, venue, messages, photos, story events, music/map links, and any gift or payment details you choose to display. This content becomes public while your invitation is active.
- Payment records — Stripe processes the full payment details. Kadly receives or stores transaction/session identifiers, status, amount, currency, and related fulfilment events. Kadly does not store full card numbers.
- Acquisition source — a short referral or campaign code when a valid `?ref=` link led to the draft. This is best-effort attribution and is not used for automated decisions.
From guests
- Name, attendance response, and guest count.
- Optional email address, phone number, message, and dietary or allergy information.
- A keyed pseudonymous code derived from the request IP address for short-window RSVP abuse prevention. The Kadly application does not store the raw IP in the RSVP record, although hosting providers may process IP addresses in infrastructure logs.
Technical and device storage
- Basic request and error information generated by our hosting and service providers.
- A country code supplied by hosting infrastructure to select the regional display price.
- Strictly necessary authentication cookies.
- Browser local storage for an unfinished draft, a stable draft-claim key, first-touch referral code, and the cookie-notice preference.
Kadly does not currently run an advertising or behavioural analytics tracker.
3. How We Use Information
| Information | Why we use it |
|---|
| Account information | Sign-in, account support, and service notices |
| Invitation content | Create, edit, host, and display the invitation |
| Payment records | Process payment, publish the correct card, handle refunds, and keep accounting records |
| RSVP information | Give the inviting couple their guest responses and CSV export |
| Pseudonymous IP code | Limit repeated RSVP submissions from one connection |
| Referral code | Understand which partner or campaign led to a claimed draft or payment |
| Technical information | Security, reliability, pricing localization, and troubleshooting |
Depending on the law that applies, processing may be necessary to perform our contract with a card owner, based on a guest's submission or consent, required by law, or supported by our legitimate interests in operating and securing Kadly.
4. Public Content and Sharing
- An active invitation is available to anyone who has or discovers its public URL. Do not publish information you do not want invitation visitors to see.
- Invitation owners may embed YouTube or other externally hosted media. Loading or playing that media connects the visitor to the external provider, which may process network/device information or use cookies under its own policy. Kadly uses YouTube's privacy-enhanced embed domain and requires a click before loading a visible wedding video.
- Guest RSVP details are visible to the owner of the invitation and are processed by the service providers needed to operate Kadly.
- We do not sell personal information or share guest contact details with third parties for their advertising.
- We may disclose information where required by law, to protect users or the service, or as part of a business transfer with appropriate notice and safeguards.
5. Service Providers and Overseas Processing
We currently use:
These providers and their subprocessors may process information outside your country in the infrastructure regions and locations described in their policies. Provider roles can vary by service; for example, Stripe may act as a processor or an independent controller for particular payment activities.
6. Guest Information
The inviting couple decides why they collect and use their guest list. Where privacy law uses the terms, the couple may be the controller of RSVP information and Kadly may process it on the couple's behalf. The couple is responsible for using guest information lawfully.
- Guests see a collection notice before submitting the RSVP form.
- Kadly does not contact guests for marketing.
- A guest can request access, correction, or deletion by emailing privacy@kadly.co with the invitation URL and enough information to identify the RSVP safely.
7. Retention and Deletion
- A paid invitation stays public until you take it down or ask us to — there is no automatic expiry.
- Expiry removes access to the Kadly invitation page but does not automatically disable uploaded images at their direct Cloudinary URLs. Contact privacy@kadly.co to have those images removed.
- Card, account, RSVP, referral, and pseudonymous abuse-prevention data are currently retained until they are no longer needed or the owner/guest submits a valid deletion request. Kadly does not currently promise automatic deletion after a fixed number of days.
- Deleting a database card does not currently remove its Cloudinary-hosted images automatically. Image-deletion requests are handled manually through privacy@kadly.co.
- After a verified account or card deletion request, Kadly will remove the associated database records and separately remove uploaded images, subject to legally required retention and temporary provider backup copies.
- Payment and fulfilment records may be kept as needed for accounting, disputes, fraud prevention, and legal obligations.
- Residual copies may remain temporarily in provider backups or logs according to each provider's retention and recovery schedule.
8. Access, Correction, Deletion, and Complaints
- Card owners can edit invitation content in Kadly and export RSVP responses as CSV.
- To request a copy of other information, correct account information, delete a card/account/image, or object to processing, email privacy@kadly.co.
- Tell us what happened, the invitation/account involved, and the outcome you want. We may verify identity before disclosing or deleting information.
- We will handle requests and complaints within the timeframe required by applicable law. If you are dissatisfied, you may contact the OAIC in Australia or the relevant privacy authority where you live.
9. Security
- Kadly uses HTTPS for data in transit.
- Sign-in uses passwordless email links or Google OAuth; Kadly does not store a user-created password.
- Supabase Row-Level Security and restricted browser column privileges separate owner content from trusted payment/publication state.
- Service-role credentials remain server-side, and Stripe handles full payment-card data.
No online service can guarantee absolute security. Report a suspected issue to privacy@kadly.co.
10. Cookies and Local Storage
Kadly uses necessary authentication cookies and the local-storage values described in Section 2. The first-touch referral code provides directional acquisition attribution. Kadly itself does not set advertising cookies or third-party marketing pixels, but owner-embedded external media may use provider cookies when it is loaded or played. Disabling cookies prevents sign-in; clearing local storage removes the unfinished draft and attribution values on that device.
11. Children
Kadly accounts are intended for people aged 18 and over. Wedding guests, including minors, may appear in invitation content or RSVP as part of a household. Contact privacy@kadly.co if information about a child should be reviewed or removed.
12. Changes
We may update this policy when the product or our information handling changes. We will post the updated date here and provide additional notice where required.
13. Contact
Privacy enquiries and complaints: privacy@kadly.co
Operator: Irfan Rafiq trading as Kadly, New South Wales, Australia
Australian regulator: OAIC — oaic.gov.au
Change log: 3 August 2026 — Aligned collection, attribution, public sharing, processors, retention, deletion, export, and security descriptions with the implemented service. 16 April 2026 — Initial policy published.