Privacy Policy
Last updated: 26 September 2026
1. Introduction
This Privacy Policy explains how Maṅgalya ("we", "us", "our") collects, uses, stores, and shares personal data when you use the Maṅgalya website, Android app, and related services (the "Services"). The Services help you build and share digital invitations and related pages (for example weddings, engagements, housewarmings, birthdays, and other celebrations), including optional RSVP and guest-book features, host-managed guest lists, printable or downloadable cards, guest photo walls, Partner Studio for professionals, and online payments for publishing or card exports. The Android app is a native shell that opens the same Maṅgalya experience at mangalya.app.
Please read this Policy together with our Terms & Conditions. We aim to comply with applicable law where it applies to our processing, including India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), the EU General Data Protection Regulation ("GDPR") and ePrivacy rules, the UK GDPR / PECR, Brazil's LGPD, and applicable US state privacy laws (including California's CCPA as amended by the CPRA). This Policy is a plain-language summary and is not legal advice.
2. Data we collect
Depending on how you use the Services, we may process:
- Account and contact data: For example, if you sign in with Google or contact support: name, email address, and identifiers from your authentication provider.
- Invitation and event content: Names, dates, venue or address text, photos or images you upload, messages, and other fields you enter into your invitation ("Invite").
- RSVP and guest-related data: Responses or details guests submit through RSVP or guest-book flows associated with your Invite (for example attendance, meal choices, or messages you configure the form to collect). Hosts are responsible for collecting guest data lawfully and only for legitimate event purposes.
- Host guest lists: Names and optional email, phone, relation, and party size that you type in or import (for example from a CSV) to plan who is invited. Guests do not create this list themselves. You decide what to store; we process it only to provide the guest-list tools on your Invite dashboard.
- Card designs and exports: Names, event details, photos, and other content you place on a card; preview files; and downloadable exports you generate or pay to unlock. If you share an approval or review link, anyone with that link may see the current design until the link expires or is revoked.
- Guest photo uploads: If you enable a live photo wall, guests who sign in may upload photos. We store those images and limited account metadata needed to operate the wall.
- Partner Studio data: If you use Partner Studio, we process studio profile and branding details, team member associations, billing summaries, analytics related to your studio's Invites, showcase and signature assets, and lead or client records you enter (for example names, phone numbers, notes, and follow-up status).
- Payment-related data: When you pay to publish, our payment partner (currently Razorpay) processes payments. We receive payment status and limited transaction metadata needed for billing and support, not your full card number.
- Technical and usage data: IP address, browser and device type, general location derived from IP, pages viewed, invite view and interaction events (including traffic source such as a QR code), and similar logs used to operate, secure, and improve the Services.
- Public Invite pages: A released Invite is a public web page for anyone with the link. Unless you enable guest password protection (where that feature is available), search engines may crawl and index the page, including names, dates, venues, and photos you publish. Password-protected Invites are marked so they are not indexed.
3. How we use your data
We use personal data to:
- Provide, host, and improve the editor, live Invites, RSVP, guest lists, photo wall, card studio, and Partner Studio tools
- Generate card previews and exports, and honour paid download entitlements you purchase
- Operate Partner Studio, studio branding, and team access for professionals
- Authenticate hosts, prevent abuse, and keep accounts secure
- Process payments and confirm publishing or card-export entitlements
- Send service messages (e.g. support, receipts, important notices)
- Meet legal obligations and enforce our Terms
- Analyse product usage (including aggregated or de-identified metrics) to improve the product. Platform administrators are excluded from Mixpanel product analytics. Mixpanel honours browser Do Not Track.
We do not sell your personal information to third parties. Marketing communications, if any, will be sent in line with applicable law and your preferences.
4. Who we share with
We use trusted service providers ("processors") who help us run the Services, for example:
- Google Firebase: authentication (for example Sign in with Google) and related identity services
- MongoDB Atlas (via Prisma): storage of Invites, RSVP responses, host guest lists, card designs and export records, account records, studio profiles, leads, and related application data
- Mixpanel: product analytics (for example page views, invite views, and feature usage). Mixpanel may store identifiers in cookies or local storage, including across subdomains used for public Invites. We honour browser Do Not Track for Mixpanel. Signed-in platform administrators are not sent to Mixpanel.
- Razorpay: payment processing
- Vercel: website hosting, edge delivery, and Speed Insights (performance metrics on public pages; we skip sending Speed Insights from account, dashboard, editor, admin, and studio paths)
- Sentry: error monitoring so we can fix crashes. We disable default PII capture; reports may still include technical details such as URLs, device type, and stack traces needed to diagnose faults
- Cloudflare R2: object storage for uploaded photos and media (for example guest photo walls, host photo libraries, Partner Studio assets, card artwork, and card export files)
- Google Maps: venue maps and directions when a host adds a map. Loading an embed may allow Google to process technical data from the viewer's device under Google's terms.
- YouTube and Vimeo: if a host embeds a video, those providers may set cookies and collect technical data when a guest loads or plays the embed.
We require processors to protect personal data appropriately. We may also disclose information if required by law, to protect rights and safety, or with your clear consent.
5. Storage and cross-border transfers
Your data may be stored or processed on servers located in India and/or other countries where our providers operate. Where the DPDP Act applies, we will take steps consistent with the law for any transfer of personal data outside India (such as relying on approved mechanisms or directions issued by the authorities).
6. Retention
We keep personal data only as long as needed to provide the Services, comply with law, resolve disputes, and enforce our agreements. If you delete an account or ask us to remove certain data, we will do so where required and practicable, subject to legal retention needs (for example limited billing records).
7. Security
We use appropriate technical and organisational measures (such as access controls, encryption in transit where standard for web services, and secure hosting practices) to protect personal data. No online service is completely risk-free; please use strong passwords and protect your sign-in methods.
8. Your rights and grievances
India (DPDP Act): where it applies, you may have rights such as access, correction, erasure or updating as permitted, withdrawal of consent where processing was consent-based (without affecting prior lawful processing), nomination, and grievance redressal as the law provides.
EU/EEA and UK (GDPR / UK GDPR): where applicable, rights include access, rectification, erasure, restriction, portability, objection (including to direct marketing), and withdrawal of consent at any time. EU visitors can complain to their local supervisory authority; UK visitors to the ICO.
Brazil (LGPD): where applicable, rights include confirmation of processing, access, correction, anonymisation or deletion, portability, and information about sharing. Complaints may go to the ANPD.
US states (including California): where applicable, rights include knowing what we collect, deletion, correction, and opting out of any "sale" or "share" of personal information. Use Reject all or Cookie settings, or enable Global Privacy Control (GPC) — we honour GPC automatically as a Do Not Sell/Share request. We do not sell personal information for money.
To exercise rights or raise concerns, contact us at mangalya.app@gmail.com. We will respond within timelines required by applicable law where they apply. If you are not satisfied with how we handle a complaint, you may escalate to the Data Protection Board of India or other authority as prescribed under the DPDP Act when those mechanisms are available.
Account deletion (website and Android app): If you created a Maṅgalya account (for example by signing in with Google), open mangalya.app/delete-account while signed in and use Delete my account, or email mangalya.app@gmail.com from the same address used for your account with the subject line "Delete my Maṅgalya account". We will deactivate your account (soft delete) and stop further sign-in, and delete or anonymise associated personal data within a reasonable time, except where we must retain information for legal, security, fraud-prevention, or accounting reasons (for example payment records). Content you published on Invites may remain visible to guests until those Invites expire or are removed as part of the request. Host guest lists and card designs stored in your account are included in that deletion or anonymisation; files already downloaded to someone's device are outside our control.
9. Cookies and similar technologies
We use strictly necessary cookies (sign-in, security, guest-unlock, template previews) without asking. Analytics (Mixpanel, Vercel Speed Insights), functional embeds (Google Maps, YouTube/Vimeo), and any future advertising load only after you consent via our banner — Reject all works the same as Accept all. Manage or withdraw anytime via Cookie settings in the footer. Full categories, vendors, durations, and the US Do Not Sell / GPC mechanism are in our Cookie Policy. Mixpanel also honours browser Do Not Track.
10. Children
The Services are intended for adults organising events. We do not knowingly collect personal data from children under 18 for direct-to-child services, and we do not sell or share personal information of anyone under 16 (US state threshold) — analytics and advertising stay off for GPC signals and for any known under-16 user. If you believe a child has provided us personal data, contact us and we will take appropriate steps.
11. Changes
We may update this Privacy Policy from time to time. We will post the new version on this page and change the "Last updated" date shown at the top. For material changes, we will provide notice where the law requires or where we reasonably can (for example by email or an on-site banner).
12. Contact
For privacy questions or requests, write to mangalya.app@gmail.com.