Privacy Policy
Last updated: 6 July 2026
This Privacy Policy explains how VowToDo (“VowToDo”, “we”, “us”, or “our”) collects, uses, discloses, and protects personal data when you use the VowToDo mobile app and related websites (together, the “Service”). VowToDo is operated by an individual based in Singapore, and we handle personal data in accordance with Singapore’s Personal Data Protection Act 2012 (“PDPA”).
By using the Service, you agree to the practices described in this Policy. If you do not agree, please do not use the Service.
1. Information we collect
Information you provide
- Account information — your email address, a password (stored only in encrypted/hashed form by our authentication provider), and any display name you set.
- Event and planning content — the wedding or event spaces you create, including names, dates, venues, tasks, budgets, checklists, and announcements or broadcasts you post.
- Guest information you enter — details you add about your guests, such as their names, guest grouping (e.g. which side), RSVP status, and their responses to questions you create (for example, meal choice or seating).
- Support communications — information you share when you contact us for help.
Information collected automatically
- Push notification tokens — if you enable notifications, we store a device token (via Expo) so we can deliver reminders and updates you have opted into.
- Device and log data — basic technical information such as device type, app version, and diagnostic or error logs used to operate and improve the Service.
- Subscription status — if you purchase a subscription or lifetime access, we receive your entitlement status from the Apple App Store or Google Play so we can unlock paid features. We do not receive or store your full payment card details.
Information from guests (RSVP)
When you share an RSVP link, the guests it covers can open a web page to view and submit their RSVP status and answers to the questions you created. We process those responses on your behalf so they appear on your dashboard.
2. How we use information
- To provide, maintain, and sync the Service across your devices.
- To send notifications and reminders you have enabled.
- To operate the guest RSVP feature and display responses to the event owner.
- To respond to your requests and provide customer support.
- To secure the Service, prevent abuse, and diagnose technical issues.
- To comply with legal obligations.
Under the PDPA, we collect, use, and disclose personal data only for purposes that a reasonable person would consider appropriate in the circumstances, and for which you have given (or are deemed to have given) consent.
3. Responsibility for guest data
Where you add information about other people (your guests) to the Service, you are responsible for ensuring you have the appropriate basis or consent to provide that information, and for using it only for planning your event. You act as the party that determines how that guest data is used; we process it on your behalf.
4. How we share information
We share personal data only as needed to run the Service, including with the service providers (data intermediaries) below, who process data on our behalf under appropriate obligations:
- Supabase — database, authentication, and backend hosting.
- Cloudflare — hosting and content delivery for our websites.
- Expo — delivery of push notifications you have enabled.
- Apple App Store / Google Play — if you purchase a subscription, your payment is processed by the relevant app store; we do not receive or store your full payment card details.
We may also disclose information if required by law, to protect our rights or the safety of others, or in connection with a business transfer.
5. RSVP links and privacy
RSVP links contain unguessable tokens rather than a login. Anyone who has a given link can view and submit responses for the guests that link covers, so please share links only with the intended guests. Event owners control privacy by choosing how they group guests into links.
6. Data retention
We retain personal data for as long as your account is active or as needed to provide the Service. You can delete your account from within the app, which removes your associated content. We may retain limited information where required for legal, security, or record-keeping purposes.
7. Your rights
Subject to the PDPA and applicable law, you may request to access, correct, or delete your personal data, or withdraw consent to our processing. To make a request, contact us at the email below. We may need to verify your identity before acting on a request.
8. International transfers
Our providers may store and process data on servers located outside Singapore. Where personal data is transferred abroad, we take reasonable steps to ensure it receives a standard of protection comparable to that under the PDPA.
9. Security
We use measures such as encryption in transit and access controls to protect personal data. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Children
The Service is intended for adults and is not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, please contact us and we will take appropriate steps to remove it.
11. Changes to this Policy
We may update this Policy from time to time. When we do, we will revise the “Last updated” date above. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
12. Contact us
If you have questions or requests regarding this Policy or your personal data, contact us at: zachlaudev@gmail.com.