Privacy Policy
Last updated: 23 July 2026
1. Introduction and Data Controller
This Privacy Policy explains the personal data processing activities relating to the digital invitation creation service offered at https://nousmarions.com (the "Platform").
All personal data processing activities carried out through the Platform are conducted by Zerda Yılmaz, a sole proprietor established in the Republic of Türkiye, trading as "Nous Marions", acting as data controller within the meaning of the EU General Data Protection Regulation ("GDPR") and other applicable data protection legislation.
Data Controller contact details:
Name: Zerda Yılmaz
Email: hello@nousmarions.com
Website: https://nousmarions.com
2. Categories of Personal Data We Process
2.1 Account and Identity Data
The following data is collected to create a user account and provide access to the Platform:
- First name, last name
- Bride's name, groom's name
- Email address
- Phone number
- Wedding date
- Password (stored only after processing with a one-way cryptographic hash function; never kept in plain text)
2.2 Purchase and Order Data
The following data is processed to manage the service purchase process:
- First name, last name
- Email address
- Phone number
- Wedding date
- Bride's name, groom's name
- Selected package name and its contents
- Payment amount and transaction date
- Order number
Note on payment data: Purchases are processed by our merchant of record, Polar Software, Inc., which acts as an independent data controller for the payment transaction (payment processing, invoicing, taxes, fraud prevention). Card numbers, CVV codes, and similar sensitive payment data are never seen, recorded, or processed by us; they are processed solely by Polar and its payment providers under Polar's own privacy policy.
2.3 Invitation Content Created by Users
Because users create their invitation content themselves, the data entered into the system varies according to the user's choices. This content may include:
- Names of the couple and family members
- Event date, time, and program
- Venue name and address
- Story texts and personal notes
- Frequently asked questions and their answers
- Menu, transportation, and accommodation details
- Dress code information
- Gift preferences and bank account details (at the user's discretion)
- Photographs
- Map links
The user is personally responsible for the accuracy, currency, and lawfulness of the content they enter into the system.
2.4 Guest and RSVP Data
The invitation owner may enter the following data into the system for guest tracking purposes, and guests may submit it through the RSVP form:
- Full name
- Email address (optional)
- Phone number (optional)
- Attendance status
- Message or personal note
This data is managed solely by the invitation owner, and we process it on the user's behalf as part of providing the service. Legal responsibility arising from third-party data entered into the system rests with the user. No advertising or tracking technologies are used on invitation viewing pages (see the Cookie Policy).
2.5 Contact Form Data
The following data may be processed in messages sent via the contact form:
- Full name
- Email address
- Content of the message
2.6 Technical and Session Data
The Platform may store limited technical data on the user's device for session management and security functions, including:
- Authentication token
- User role information
- Email address
- Order number
This data contains no payment information and is used solely for the technical operation of the Platform.
2.7 Usage Analytics and Session Recording Data
Page views, click and scroll behavior, mouse movements, device/browser information, and session recordings (session replay) may be processed to improve the user experience and detect errors and usability issues. Sensitive fields such as form inputs, passwords, bank details, and prices are automatically masked during recording; under no circumstances are they recorded as entered. These tools are only activated with your consent (see the Cookie Policy).
3. How We Collect Personal Data
Personal data is collected through the following channels:
- Registration and login forms: when a user account is created and sessions are opened
- Purchase process: when a service package is selected and an order is completed (via Polar checkout)
- Invitation management panel: when invitation content is created and edited by the user
- Contact form: when a message is sent by the user via the form
- Technical processes: through session management and security mechanisms as part of the operation of the Platform infrastructure
4. Purposes of Processing
The personal data collected is processed for the following purposes:
- Creating and managing the user account and performing authentication
- Delivering the purchased digital invitation service in full
- Providing access to the user panel and managing invitation content
- Supporting guest tracking and RSVP management
- Coordinating the payment process with our merchant of record (Polar)
- Responding to user support requests
- Protecting the security and integrity of the Platform
- Carrying out anonymized usage analytics and session recording (session replay) to improve the user experience and detect errors and usability issues
- Fulfilling legal obligations
- Establishing evidence in potential legal disputes
5. Legal Bases (GDPR Article 6)
Under the GDPR, your personal data is processed on the following legal bases:
- Art. 6(1)(b), performance of a contract: account, order, invitation content, and guest/RSVP data are processed to conclude and perform the service contract.
- Art. 6(1)(c), legal obligation: data whose processing is mandatory to fulfill obligations under tax and other applicable legislation.
- Art. 6(1)(f), legitimate interests: contact form data and technical data relating to platform security are processed to protect the controller's legitimate interests (providing support, securing the service).
- Art. 6(1)(a), consent: data processed via functional, analytics, and marketing cookies is based on your explicit consent, which you may withdraw at any time.
6. Retention Periods
Personal data is retained for as long as required by the purpose of processing and in accordance with applicable legislation:
- Account and order data: for as long as the account remains active, and thereafter within the framework of statutory retention obligations
- Invitation content: for the publication period of the invitation and thereafter for as long as the user account remains active
- Payment records: for the mandatory retention periods under tax legislation
- Contact form data: for the evaluation of the request and a reasonable period thereafter
- Technical and session data: until the relevant session ends
- Usage analytics and session recording data: for a maximum of one (1) month, the default retention period of the service provider (PostHog)
When the retention period ends or the user account is deleted, personal data is deleted, destroyed, or anonymized, except where legal obligations require otherwise.
7. Data Security Measures
The controller takes appropriate technical and organizational security measures to protect the personal data processed against unauthorized access, disclosure, alteration, or destruction, in line with Article 32 GDPR. These measures include:
- Storing user passwords only after one-way cryptographic processing
- Encrypting Platform communication with the HTTPS protocol
- Using authentication token mechanisms
- Restricting access to personal data to authorized persons only
- Processing payment data exclusively through the merchant of record's infrastructure, without storage by the controller
Users are also personally responsible for protecting their account security. Keeping account credentials confidential and not sharing them with third parties is essential.
8. Recipients and International Transfers
Personal data may be shared with third parties only to the extent necessary to provide the service and limited to the purposes stated below:
8.1 Infrastructure and Hosting Providers
The Platform runs on cloud-based infrastructure and database service providers (Microsoft Azure). These providers may access data necessary for the technical operation of the service and act under their own privacy policies and data processing agreements.
8.2 Merchant of Record (Polar)
Purchases are processed by Polar Software, Inc. as merchant of record. Data transferred in the payment process is processed by Polar as an independent controller under its own privacy policy. Card details and sensitive payment data are not transmitted to us.
8.3 Product Analytics and Session Recording (PostHog)
To improve the user experience and detect errors and usability issues; data is hosted in the European Union region (eu.posthog.com) and retained for a maximum of one (1) month.
8.4 Advertising Measurement (Meta Platforms, Inc.)
To measure the effectiveness of advertising campaigns, data may be processed in two ways: (i) Meta Pixel, which runs only if you give your explicit consent and only on marketing pages; no advertising/tracking data is processed on invitation viewing pages. (ii) Conversions API: when you complete a purchase and only if you have given cookie/marketing consent, your contact details (email and phone) are shared with Meta after one-way hashing (SHA-256) on our server, so that the conversion can be measured; your raw contact details are never shared. If you have not consented, no such sharing occurs. In both methods, data may be transferred to Meta's servers (including in the USA) and is protected under Standard Contractual Clauses (SCCs).
8.5 Competent Authorities
Personal data may be shared with competent public institutions and authorities where required by lawful requests and legal obligations.
Your personal data is never sold or rented to third parties for commercial purposes.
International transfers: We are established in Türkiye, and your data is processed in Türkiye and within the infrastructure of the providers listed above (EU region for PostHog; USA for Google and Meta under Standard Contractual Clauses). Where personal data is transferred to countries that do not benefit from an adequacy decision, we rely on appropriate safeguards such as Standard Contractual Clauses, or on the necessity of the transfer for the performance of the contract between you and us.
9. Your Rights (GDPR Articles 15–22)
Under the GDPR, you have the following rights regarding your personal data:
- Access: to learn whether your data is processed and to request a copy of it
- Rectification: to request correction of incomplete or inaccurate data
- Erasure ("right to be forgotten"): to request deletion of your data where the conditions of Article 17 are met
- Restriction of processing: to request that processing be restricted in the cases set out in Article 18
- Data portability: to receive the data you provided in a structured, commonly used, machine-readable format and to transmit it to another controller
- Objection: to object to processing based on legitimate interests, on grounds relating to your particular situation
- Withdrawal of consent: to withdraw consent-based processing at any time, without affecting the lawfulness of processing before withdrawal
- Automated decision-making: not to be subject to a decision based solely on automated processing that produces legal effects concerning you
- Complaint: to lodge a complaint with a supervisory (data protection) authority, in particular in the EU member state of your habitual residence
To exercise these rights, you can apply in writing to the contact address below. Requests are answered without undue delay and at the latest within one (1) month.
10. Children
The Platform is intended for adults planning their events and is not directed at children under the age of 16. We do not knowingly collect personal data from children.
11. Cookies
For detailed information about the cookies used on the Platform, their purposes, and how to manage them, please see our Cookie Policy.
12. Changes to This Policy
This Privacy Policy may be revised in line with legal regulations, changes in Platform services, or updates to data processing practices. The updated policy takes effect on the date it is published on the Platform. If changes materially affect users, they are announced via the Platform. We recommend reviewing the current policy regularly.
13. Contact
For questions under this Privacy Policy, requests regarding your rights, or any inquiries about your personal data, you can use the following contact details:
Data Controller: Zerda Yılmaz (sole proprietor), trading as "Nous Marions"
Email: hello@nousmarions.com
Website: https://nousmarions.com
Including information verifying your identity in your application will help us evaluate your request more quickly.
