PRIVACY POLICY
What LET’S GET collects, why, who else sees it, and how to make us stop. Written plainly, because a policy nobody finishes reading protects nobody.
01THE SHORT VERSION
- We do not sell personal data, to anyone, ever.
- We do not use the contents of your events to train AI models.
- A schedule you upload is passed to our reading provider, turned into cues, and not kept as a file by us.
- Everyone on an event sees only their own part. That is enforced on the server, not just hidden in the interface.
- You can ask for your data, or its deletion, and get it.
02WHO IS RESPONSIBLE FOR WHAT
West Design Lab AB is the controller of the data about you as a customer: your account, your billing, your use of the service.
For the data you put into an event — your vendors, the wedding party, your guests — you are the controller and we are your processor. You decide who goes on the list and what they are told; we store it and deliver it under your instructions. If you need a data processing agreement, write to us and we will sign one.
03WHAT WE COLLECT
From you
- ACCOUNT — your email address, and your name and profile photo if you sign in with Google.
- BILLING — your billing address, tax id if you give one, and a record of what you paid. Stripe holds the card; we never see it.
- YOUR EVENTS — the schedule, the cues, the people on it, and the messages the service sent for you.
- UPLOADS — a schedule you drop in, as a document, image, or pasted text.
About the people you add
Their name and contact detail, the group they belong to, what they are responsible for, and whether they confirmed. Nothing more is asked for, and nothing sensitive should be put in a cue.
Automatically
- IP ADDRESS — recorded against a daily counter to limit how many schedules one machine can send for reading. It exists to stop abuse of a costly operation, and is kept for no other purpose.
- SESSION — a sign-in token so you stay signed in. We do not run advertising or analytics trackers.
04WHY, AND ON WHAT BASIS
- To provide the service you asked for — performance of a contract.
- To take payment and keep the accounts — contract, and a legal obligation to retain records.
- To keep the service working and to prevent abuse, including the rate limit — legitimate interests.
- To message the people on your event — done on your instruction as controller; you are responsible for the basis on which you contact them.
05THE UPLOAD, AND THE AI
When you drop in a schedule it is sent to Anthropic, which reads it and returns it as structured cues. That is the whole of what the AI is used for, plus a second pass that reads the finished schedule and raises questions about it — portraits after sunset, a gap nobody owns.
We do not keep the uploaded file. It is passed through the request and discarded; what persists is the cues you approve. Anthropic does not use data sent through its business API to train its models, and we have not opted into anything that would change that.
The AI proposes. Nothing it produces becomes part of your event until you approve it.
06WHO ELSE PROCESSES IT
These are every processor we use. Nothing is added to this list quietly.
- Google (Firebase) · EU and US
- Accounts, sign-in, and the database the run of show lives in.
- Anthropic · US
- Reads an uploaded schedule and returns it as structured cues. The upload is passed through and not stored by us.
- Stripe · EU and US
- Takes payment and holds the card details. We never receive a card number.
- Resend · US
- Delivers the emails the service sends on a planner's behalf.
- Twilio · US
- Delivers the text messages (SMS) the service sends on a planner's behalf.
Some of these are in the United States, so data may be transferred outside the EU. Those transfers rely on the European Commission’s standard contractual clauses, or on the EU–US Data Privacy Framework where the provider is certified under it.
We will also disclose data if the law requires it, and would tell you unless prohibited from doing so.
07WHO CAN SEE AN EVENT
The planner who owns an event sees all of it. Everyone else reached by a link sees only what concerns them: a vendor sees their own cues and the ones immediately around them, someone in the wedding party sees the cues they are named in, and a guest sees only the public timeline.
Those boundaries are enforced by the database’s own rules, so a modified browser cannot read past them. The link in a message is the credential — treat it as private, and tell us if one goes astray.
The couple are muted by default: they are on the schedule, but the working traffic about their own wedding does not reach them unless the planner turns that on.
08HOW LONG WE KEEP IT
- EVENTS — for as long as your account exists, so you can look back at a past season. Delete one and it goes, along with the people on it.
- ACCOUNT — until you ask us to delete it. Ask, and it is removed within 30 days.
- BILLING RECORDS — seven years, because Swedish accounting law requires it. This is the one thing we cannot delete on request.
- RATE-LIMIT COUNTERS — they are keyed by day and are of no use after it.
09YOUR RIGHTS
You can ask for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict or stop a particular use, and ask for it in a portable form. If you are in the EU or UK you have these under the GDPR; several US states give similar rights, and we apply them to everyone rather than sorting people by geography.
Write to support@letsget.io. We answer within 30 days. If you are on someone’s event rather than a customer, write to us anyway and we will pass it to the planner responsible and help make it happen.
If we get it wrong you can complain to your data protection authority. In Sweden that is IMY, Integritetsskyddsmyndigheten.
10SECURITY, AND ITS LIMITS
Data is encrypted in transit and at rest. Access rules are enforced on the server. Card details never touch our systems. Access links are long random tokens that no client can list.
No service is perfectly secure. If there is a breach affecting your data we will tell you, and the authorities, as the law requires.
11CHILDREN
The service is for professionals and is not directed at children. We do not knowingly collect data from anyone under 16. Children may of course be named on a schedule — a flower girl is a person on a run of show — and that is the planner’s judgement to make.
12MESSAGING, AND HOW PEOPLE OPT IN
The service sends messages by email and SMS on the planner’s instruction, to the people the planner has added to their own event — the vendors, staff, and invited guests working or attending that day. A recipient’s number or address is only ever entered by the planner who runs the event, and that planner confirms, at the moment of adding it, that the person agreed to receive coordination messages about that event. There is no public sign-up and no keyword: nobody is added to messaging except by their own event’s planner.
Every message is transactional and tied to that one event — a private link to the person’s run of show, a request to confirm their part, or an alert when a cue’s time or place changes. We never send marketing or promotional content on these channels. Message and data rates may apply.
Anyone can opt out at any time by replying STOPto a text, or using the unsubscribe link in an email. They are removed immediately and hear nothing further. A phone number or address given for messaging is used only to send that event’s own messages — it is never sold, and never shared for anyone else’s marketing.
13CHANGES, AND CONTACT
If we change this policy in a way that matters, we will email you before it takes effect. The date at the top is the version in force.
West Design Lab AB, Vitmossvägen 296, 754 72 Uppsala, Sweden. Privacy: support@letsget.io. Everything else: Terms of Service.
West Design Lab AB · ORG. 559583-3319 · VAT SE559583331901 · Vitmossvägen 296, 754 72 Uppsala, Sweden