Married on Tape
DEEN
Book now

Privacy policy

English translation. This policy mirrors the German Datenschutzerklärung, version 28 August 2026. The German text is the authoritative legal version.

1. Controller and contact

Rita Bouça de Almeida, sole trader, trading as Married on Tape
Tarnowitzer Str. 3, 81929 Munich, Germany
Phone: +49 1525 5953014
Email: [email protected]

2. Website delivery and security

Cloudflare processes technically required connection, device, browser, referrer, security and error data to deliver and protect the website. The legal basis is Article 6(1)(f) GDPR. Booking, customer and document data are stored using Cloudflare Workers, D1, Durable Objects, Queues and private R2 storage. Personal customer fields and PDF documents are encrypted with AES-256-GCM before storage. Keys are kept separately, and administrative access is protected by Cloudflare Access and multi-factor authentication.

3. Enquiry, availability and booking

We process contact and couple names, email, optional phone number, wedding date and country, logistics period, selected package, camera and extras, billing and delivery addresses, price, status, internal reference and the versions of legal documents accepted. The legal basis is Article 6(1)(b) GDPR and, for statutory records, Article 6(1)(c) GDPR. Required information is necessary to process availability, contract, payment, invoice and shipping. Availability and price are calculated automatically, but no solely automated decision with legal or similarly significant effect under Article 22 GDPR is made.

When you enter your name and email address in the compact booking configurator and check availability, we store them together with the selected configuration as an encrypted booking draft. This allows us to check the requested availability, recognise open processes in our access-protected booking dashboard and restore the process through a secure continuation link for seven days. The booking dashboard shows authorised users the name, email address, exact wedding date, selected period and progress status of this draft. We also use the status to analyse where started bookings were not continued. This analysis is based on Article 6(1)(f) GDPR and our legitimate interest in improving the booking process. If you separately opt in, we send one reminder if the process is not completed. That reminder is based on Article 6(1)(a) GDPR. You can withdraw the consent at any time by replying to the email or contacting us, with effect for the future.

4. Payment through Stripe

Online payment is completed on Stripe-hosted Checkout. Stripe processes the payment and contact information entered there and security and fraud signals. We provide amount, booking, reservation and reference identifiers. Card and wallet credentials are not stored by us. Depending on the method selected, Stripe and PayPal may process the payment. The legal bases are Article 6(1)(b) and, for fraud prevention, Article 6(1)(f) GDPR. Further information: Stripe privacy policy and PayPal privacy statement.

5. Invoices and communication

After successful payment we create and store a final invoice. Encrypted copies are retained in private application storage and archived separately in Google Drive. We use Google Workspace for business communication and Resend for transactional messages such as payment links, booking confirmations, shipping notices and invoices. These providers process the name, email address, subject, necessary booking data and, where required, the invoice. The legal bases are Article 6(1)(b), Article 6(1)(c) and, for delivery evidence and IT security, Article 6(1)(f) GDPR.

Cancellation requests sent to [email protected] are stored as an encrypted, manually reviewed case with a bounded text preview. Attachments and the complete raw email are not copied into the booking system. No AI assessment, automatic cancellation or automatic refund occurs.

6. DHL shipping

When a shipping label is prepared, the required recipient, address, contact, parcel and internal reference data is sent to Deutsche Post DHL for postage, transport, delivery, return and tracking. The legal basis is Article 6(1)(b) GDPR. Further information: DHL privacy information.

7. Protection against automated access

Cloudflare Turnstile processes technical browser and device signals to identify automated or abusive booking attempts. The legal basis is Article 6(1)(f) GDPR. Further information: Cloudflare privacy policy.

8. First-party analytics and form progress

We process coarse location, language, device type, traffic source, selected offer and non-content form-progress signals to improve the website and booking funnel. The analytics data store does not contain the customer's name, email address, referral-code content or exact wedding date. The protected booking dashboard displays those anonymous journeys alongside the separately stored booking drafts created by submitted availability checks. Only a submitted availability check is shown with personal details as described in section 3; earlier anonymous journeys are not subsequently identified. Daily counters and a random in-memory form-run identifier are stored in EU-scoped Cloudflare D1 without cookies or browser storage. The legal basis is Article 6(1)(f) GDPR. Data older than 30 days is removed during the next analytics activity.

9. Instagram links

Images are hosted locally. Data is sent to Meta only after the user actively follows an Instagram link.

10. Retention

  • Incomplete booking drafts from an availability check are retained for twelve months and then deleted. The secure continuation link remains valid for seven days only. A completed draft is linked to the booking.
  • Unfinished or cancelled enquiries without an invoice are generally anonymised after 30 days.
  • Booking, payment, shipping and communication data is retained for performance of the contract and applicable limitation and evidence periods.
  • Invoices and required tax evidence are generally retained for eight years.
  • Public booking-status links expire no later than 90 days after the agreed return date.
  • The application does not write addresses, email content, payment credentials or document content to technical logs.

11. Recipients and international transfers

Cloudflare, Stripe, PayPal, Google and Resend may process data outside the EEA. Where no adequacy decision applies, transfers rely in particular on EU Standard Contractual Clauses and supplementary safeguards.

12. Your rights

Subject to the statutory conditions, you have rights of access, rectification, erasure, restriction and portability. You may object to processing based on Article 6(1)(f) GDPR for reasons relating to your particular situation. Contact [email protected]. You may also lodge a complaint with a data-protection authority; the competent authority is generally the Bavarian State Office for Data Protection Supervision.

13. External links

External websites are responsible for their own privacy practices.

14. Changes

The current version of this policy is published on this page.

Version: 28 August 2026

© 2026 Married on Tape · Owner Rita Bouça de Almeida

Back to website · Terms · Booking conditions · Legal notice