Skip to content

Privacy policy

This explains which data we process when you order in the shop, and which data comes up in the wedding apps.

Last updated: October 1, 2026

1. Controller

The controller for data processing in the shop is hansenexus GmbH, Eidelstedter Weg 2, 20255 Hamburg, Germany, represented by its managing director Lennard Finsterbusch. Email: service@hansenexus.de, phone: +49 40 57307846. EasyWedding is a product brand of hansenexus GmbH.

We have not appointed a data protection officer because we are not required to. Please send data protection requests to the email address above.

2. Overview

We process data of two groups: customers of the shop (the couple) and guests who use a wedding app. We are the controller for the data in the shop. The couple are the controller for the content of their wedding app; we process it on their behalf (section 7).

In the shop we measure reach without cookies and without profiling (section 3). There is no analytics in the wedding apps. We use no advertising or tracking services anywhere, and we do not sell data.

3. Hosting, server logs and audience measurement

The shop and the wedding apps run on servers we operate ourselves, in data centres of Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany) in Germany. Hetzner processes the data on our behalf (Art. 28 GDPR).

When you open a page, the server processes technically necessary information: IP address, time, the address requested and browser details. This serves to deliver the pages and to fend off abuse; the legal basis is our legitimate interest in secure operation (Art. 6 (1) (f) GDPR). We delete the logs after 15 days at the latest.

Audience measurement: to see which pages of the shop are used and how many visits lead to an order, we use the open-source software Plausible Analytics on the same servers we operate in Germany. Plausible sets no cookies and stores nothing in your browser. It records the page opened without parameters, the referring website, browser, operating system, device type and country, plus individual steps of the order (planner opened, order started, package chosen, payment started, payment completed) with the package chosen. IP address and browser details are only combined with a random value that changes daily into an identifier that can no longer be linked after 24 hours; the IP address itself is not stored. The result is aggregate statistics only, never a profile of a person. An order's code is removed from the address before it is sent. If you come via the link in a wedding app, we only see that the visit came from a wedding app, not from which one. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in improving our offer). The couples' wedding apps, including those on their own domain, are excluded: nothing is measured there.

4. Orders and customer account

For an order we process:

  • the customer's email address,
  • the details of the wedding (the couple's names, date, venue, chosen colour palette, the app's address),
  • for the Premium package, the delivery address for the printed QR table cards (name, address, country),
  • package, price, time of order and payment, payment status and the time of the consents given in the order process,
  • if you fill in the “Plan” questionnaire: your answers and, if you give it, your email address.

The purpose is to perform the contract (Art. 6 (1) (b) GDPR) and to meet statutory retention duties (Art. 6 (1) (c) GDPR). We keep order data relevant for accounting for ten years (section 147 German Fiscal Code, section 257 German Commercial Code) and delete the rest together with the app (section 9).

5. Payment through Mollie

Payment is handled by Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, the Netherlands. You are taken to Mollie's payment page and enter your payment details there. We do not receive them, only whether and how payment was made. We pass Mollie the amount, a description of the order with the couple's first names, and an order reference.

Mollie processes the payment data as an independent controller; Mollie's privacy statement applies (mollie.com). The legal basis for passing on the data is Art. 6 (1) (b) GDPR. Refunds (for example under the money-back guarantee) are also made through Mollie.

6. Sign-in and emails

The customer account has no password. To sign in you enter your email address and receive a six-digit code by email, valid for ten minutes. Of the code and the session we store only check values (hashes), never the code itself.

We send emails (sign-in codes, notices about your order) through our own mail server in Germany. We do not send advertising emails. The legal basis is Art. 6 (1) (b) GDPR.

7. The wedding app and guests' photos

Every couple gets their own wedding app. Guests open it with a guest code; there are no accounts. The app holds:

  • the name guests give with their first contribution,
  • entries in the potluck buffet, including notes on diet and allergies if guests give them,
  • uploaded photos and their captions; photos may contain metadata stored by the phone (for example the time or place taken) and are kept in their original form,
  • hearts and comments under photos (Komplett package and above),
  • the information the couple enter, such as the schedule, venue and info cards.

The couple are responsible for this content; we provide the technology and process the data on their behalf under Art. 28 GDPR (section 12 of the terms). Only people with the guest code of that wedding can see the content; the apps are blocked for search engines, and each wedding's data is kept separate from every other wedding's.

Guests can delete their own photos, comments and entries again on the same device; the couple can delete all content in their app. If you appear in a photo and want it removed, contact the couple or us. Please only upload photos the people shown are happy with.

How long content is kept: the app runs until 3 months after the wedding day and is then archived. The couple can then download the handoff for 3 months, a ZIP file with every photo in its original quality, the app's data and an offline archive. After that we delete all of the app's content within 30 days. After a refund under the money-back guarantee the same applies from the day of the refund.

8. Cookies and local storage

We use only technically necessary cookies and storage entries; no consent is needed for these (section 25 (2) no. 2 German Telecommunications Digital Services Data Protection Act, TDDDG):

  • hz_customer: keeps you signed in to your account for 14 days. An httpOnly cookie that JavaScript cannot read.
  • hz_pay_… and hz_tip: link a payment in progress to your order so you return to the right page after paying. They last two hours.
  • NEXT_LOCALE and hz_locale: remember the language you chose in the shop or in the wedding app.
  • In the wedding app, the browser stores locally the session after the code is entered, a device ID to limit failed attempts, and keys that let guests edit or delete their own contributions later.

There are no advertising, analytics or tracking cookies; audience measurement (section 3) works without cookies.

9. Retention

Wedding app data: as described in section 7. Customer account and order: until the app is deleted; anything we must keep under tax or commercial law is deleted when the statutory period ends. Server logs: 15 days at most. Orders that were never completed are deleted after seven days.

10. Recipients

  • Hetzner Online GmbH (Germany): operation of the servers, as a processor,
  • Mollie B.V. (the Netherlands): payments and refunds, as an independent controller,
  • Plausible Analytics as self-hosted software; the data does not leave our servers.

We do not transfer data to countries outside the EU and the EEA.

11. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20; the handoff is meant for this too) and to object to processing based on legitimate interests (Art. 21). Write to us at the email address above. For content in a wedding app, guests can contact the couple or us; we then pass the request on.

You can also lodge a complaint with a data protection supervisory authority, for example the one responsible for us: Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit, Ludwig-Erhard-Str. 22, 20459 Hamburg, Germany.

12. Whether you must provide data

Without an email address and the details of the wedding we cannot provide an app. Guests do not have to give their real name. There is no automated decision-making or profiling.