Skip to main content

Website policy

Privacy Policy

This policy explains the information handled when you browse the directory, contact us, request a business listing review, or join the newsletter.

Last updated

1. Who this policy covers

Weddings Greece is the directory available at weddingsgreece.com and is operated from Australia. In this policy, “Weddings Greece”, “we”, “us”, and “our” refer to the operator of that directory. You can contact us at hello@weddingsgreece.com.

This policy covers the public website, directory listings, contact and listing-request forms, newsletter, analytics, and related support and security operations. A venue, wedding professional, social network, map provider, or other third party you contact has its own privacy practices.

2. Information we collect

Information you provide

  • Contact enquiries: your name, email address, optional phone number, subject, message, and any listing or page you ask about.
  • Business listing and claim requests: business and contact names, email address, optional phone number, category, location, website, Instagram handle, message, and the existing listing reference where relevant.
  • Newsletter: email address and, if you choose to provide them, your name, wedding month, and wedding year. We also keep subscription, unsubscribe, and suppression information needed to honour your choice.
  • Privacy requests and corrections: the information in your request and any additional details reasonably needed to verify and action it.

Technical, security, and form metadata

When the site or a public form is used, our hosting and security systems may process the requested URL, timestamp, IP address, browser and device information, user-agent string, referrer, form source, rate-limit counters, and bot-detection signals. Contact and newsletter submissions currently store the submitting IP address with the record. Listing requests store the page URL, referrer, and user agent where available.

Directory interaction analytics

  • Vercel Web Analytics: aggregated page views and selected conversion events, including URL or route, timestamp, referrer, approximate location, operating system, browser, and device type. Vercel states that Web Analytics does not use cookies or associate the data with an IP address.
  • Listing analytics: views and interactions involving a venue or vendor profile, including the listing identifier, page or action, source location, referrer, browser user agent, viewport size, and a temporary in-memory session identifier. The identifier is not saved to cookies, local storage, or session storage.

Error and performance diagnostics

We use Sentry to identify errors and performance problems. Diagnostic events may include an error message and stack trace, route, browser or device information, and technical request context. Default PII collection is disabled. Error replays, when sampled, mask page text and form inputs and do not capture form request bodies. We still recommend that you do not include unnecessary sensitive information in a form.

Information from public and third-party sources

Directory profiles may contain business information supplied by a business or gathered from its public website, public social profile, public review platform, or another publicly available source. Source-labelled ratings and reviews remain information from the named platform. Contact us if a published profile requires correction.

3. Why we use information

  • respond to enquiries, corrections, privacy requests, and listing-review requests;
  • operate, secure, troubleshoot, and improve the site and its public forms;
  • send requested receipts, service messages, and newsletter emails;
  • measure directory use and produce listing-level and site-level reporting;
  • detect spam, automation, abuse, and other security threats;
  • maintain records, resolve disputes, and meet legal obligations; and
  • publish and maintain directory information from submitted or public sources.

No sale of personal information: We do not sell personal information or use it for cross-site behavioural advertising.

Where the GDPR applies, the legal basis depends on the activity:

  • Consent: newsletter subscriptions and any other activity for which we specifically ask for consent. You may withdraw consent without affecting earlier processing.
  • Steps at your request or performance of a contract: where processing is needed to provide a service you requested or to administer an agreed service.
  • Legitimate interests: operating and improving an independent directory, responding to ordinary enquiries, measuring useful interactions, maintaining accurate listings, preventing abuse, and diagnosing errors, balanced against the rights of the people affected.
  • Legal obligations and legal claims: where records or disclosures are required by law or reasonably needed to establish, exercise, or defend a legal claim.

5. Who receives information

We disclose information only where reasonably needed for the purposes above, including to the following service providers:

  • Vercel: hosting, Web Analytics, firewall, and BotID protection;
  • Supabase: database and directory-data infrastructure;
  • Resend: transactional and newsletter email delivery;
  • Sentry: error and performance monitoring;
  • Upstash: IP-based rate limiting for public forms; and
  • Cloudinary: image delivery.

We may also disclose information to professional advisers, authorities, courts, or another party where required by law, needed to protect rights or safety, or connected with a genuine sale, restructure, or transfer of the service. We do not give a listed business your contact-form message unless the form clearly says it will be sent to that business.

6. Overseas processing

Weddings Greece is operated from Australia and uses service providers with infrastructure and personnel in more than one country. Information may therefore be processed outside your country, including in Australia, the European Economic Area, the United States, and other locations used by the providers above.

Where required, we rely on provider contracts, approved transfer mechanisms, and other appropriate safeguards. Provider locations and sub-processors can change, so consult the provider’s current privacy information if you need country-specific detail.

7. How long we keep information

We keep information only for as long as reasonably needed for the purpose for which it was collected, taking account of the record’s status, security and operational needs, dispute and legal-claim periods, and applicable record-keeping obligations.

  • Contact and listing-review records are kept while the request is active and afterwards where reasonably needed for follow-up, audit, security, or dispute handling.
  • Newsletter records are kept while you are subscribed. After an unsubscribe request, we may retain a minimal suppression record so that we do not send further newsletter email.
  • Rate-limit, hosting, analytics, and error records follow the relevant operational configuration and provider retention settings and are reviewed as those settings change.

When information is no longer required, we delete it, de-identify it, or retain only the minimum record required by law or to honour a suppression request.

8. Security

We use reasonable technical and organisational measures designed to protect information. Current measures include HTTPS, access controls, server-side validation, honeypots, rate limiting, bot detection, restricted database writes, and diagnostic-data minimisation. No internet service can guarantee absolute security.

9. Your choices and rights

Access, correction, deletion, and objections

You may ask what personal information we hold about you, request access or correction, ask us to delete information that is no longer needed, object to or restrict certain uses, or unsubscribe from marketing. Some requests are subject to identity checks, legal exceptions, and records we must retain.

Where the GDPR applies, you may also have rights to erasure, restriction, data portability, objection, and withdrawal of consent, and the right to complain to the supervisory authority where you live or work. We will respond within the period required by the law that applies to your request.

Privacy complaints

Email us with the subject “Privacy request” or “Privacy complaint”. We will acknowledge the request, may ask for information needed to verify your identity or understand the issue, investigate it, and explain the outcome and any action taken.

If an Australian privacy complaint is not resolved, you may contact the Office of the Australian Information Commissioner (opens in a new tab). If the GDPR applies, you may contact your local data-protection supervisory authority.

The site is intended for adults researching weddings or operating wedding-related businesses. We do not knowingly ask children to submit personal information. Contact us if you believe a child has submitted information.

Links, social profiles, and optional embedded content are controlled by third parties. Review their privacy information before sharing information with them. Our Cookies & Similar Technologies Policy explains when third-party map content is loaded.

We may update this policy when site practices, providers, or legal requirements change. The date at the top shows the latest published version. For a material change, we may also provide a prominent site notice or direct notice where appropriate.

Contact us about privacy

Email hello@weddingsgreece.com with the subject “Privacy request”. Please do not send identity documents unless we ask for them through an appropriate channel.