Who we are
We Chose Forever builds and hosts wedding websites, and runs a planner and vendor marketplace alongside them. Under the Protection of Personal Information Act 4 of 2013 ("POPIA") we are the responsible party for the information described below, except where this policy says otherwise.
- Trading name
- We Chose Forever
- Registered name
- QA Culture (Pty) Ltd
- Registration number
- 2022/315022/07
- Information Officer
- To be confirmed
- Privacy contact
- info@qaculture.co.za
Kept out of the page so they are not collected automatically. One click shows them, and nothing is asked of you in return.
Who this policy is for
Three different groups of people appear in this policy, and they are not treated the same way:
- Couples — people who create an account and build a wedding site.
- Vendors — businesses who list themselves in the marketplace.
- Guests — people who reply on a couple's published wedding page. Guests never create an account with us, and most of what follows about accounts does not apply to them. The short version for guests is in the section called "If you are a wedding guest".
What we collect
From a couple, when you sign up and use the planner:
- Your email address and a password, which is stored only as a cryptographic hash — we never see or hold the password itself.
- Both of your first names, your wedding date, and where the wedding is.
- The web address (slug) you chose for your site.
- Optionally, your total wedding budget and a rough guest count.
- Photographs you upload, up to five.
- The vendors you shortlist or book, and the categories you mark as already arranged.
- Anything you type into your site's own text, or into notes on your guest list.
From a vendor, when you set up a listing:
- Your email address and a hashed password.
- Your business name, category, service area, price and pricing basis, and your description.
- Your answers to the standard questions in your category — the tick boxes on your listing. They are optional and they are shown to couples exactly as you set them.
- Portfolio photographs you upload.
- Your listing tier.
From a vendor, to confirm who is behind a listing. We do this before a listing is shown to any couple, and there are two paths:
- If your business is registered: your company registration number. We check it against the CIPC register, and we keep it, because we re-check the register once a year and because a registration number is public information about a business. It is never shown to couples.
- If you trade in your own name: your South African ID number. We use it once to confirm your identity, and then we delete it. It is never stored against your listing, never shown to a couple, and never re-checked — an identity does not lapse. What survives the check is the fact that it passed, the date, and a one-way hash we cannot read the number back out of.
- Either way, we record which path you took and when the check was done, so your listing can show a couple what was confirmed and when.
The check confirms identity and nothing else. It is not an assessment of a vendor's work, insurance, pricing or conduct, and we do not present it to couples as one.
From a wedding guest, when you RSVP on a couple's page:
- Your name, whether you are attending, and how many are coming.
- Your email address, if you give one — it is optional.
- Allergies and dietary needs, if you choose to give them and tick the box that allows us to keep them. See “Health and dietary information” below.
- Anything you write in the free-text note.
- The version of this policy that was in force when you replied, and the moment you agreed to it, so that we can tell what you actually agreed to.
- Whether you agreed that the couple may email you about the wedding. This is off unless you tick it.
Automatically, from everyone who uses the site:
- Your IP address, which our server sees on every request and which we use only for abuse prevention. We store it in a one-way hashed form, so we cannot recover the address itself.
- Standard server logs kept by our hosting provider.
- The cookies described below.
- When a signed-in couple opens a vendor's profile, we record that a view happened, which vendor it was, and which site it came from.
Why we process it, and on what basis
We process personal information because it is necessary to perform the contract we have with you (POPIA s11(1)(b)), because you have consented (s11(1)(a)), or because it is necessary for our legitimate interests in running and protecting the service (s11(1)(f)). Specifically:
- Your account
- Necessary for the contract — we cannot give you a site without one.
- Your wedding site
- Necessary for the contract. You choose what goes on it, and you choose to publish it.
- Budget and guest count
- Necessary for the planner features you asked for. Never disclosed to anyone else.
- Sharing your name and date with a vendor
- Your consent — see below. You can withdraw it at any time.
- Guest RSVPs
- Necessary to provide the couple with the guest list they asked for.
- Hashed IP addresses
- Our legitimate interest in stopping automated abuse of the sign-up and RSVP forms.
- Vendor profile views
- Our legitimate interest, and the vendor's, in knowing whether their listing works.
- Confirming a vendor's identity
- Necessary for the contract with the vendor — a listing is not shown to couples until it is done — and our legitimate interest, and every couple's, in knowing that a business on this marketplace is a real one.
Your budget is never shared with anyone
Nobody but you sees what you can spend. Not a vendor you shortlist, not a vendor you book, not one you have already paid. Your budget is used for exactly one purpose — filtering the marketplace so you are only shown vendors you can actually afford — and it never leaves your account.
This is enforced in the database, not merely omitted from the pages we build. A vendor's account has no read access to the field at all, so the figure cannot be reached even by someone deliberately looking for it. We mention the mechanism because a privacy promise that depends on us remembering to hide something is a weaker promise than one the system cannot break.
What a vendor does see
If you shortlist or book a vendor, and you have agreed to it, that vendor can see your first names, your wedding date and where the wedding is — enough to answer you properly. Nothing about money.
We ask you to choose this explicitly when you sign up rather than burying it here, and you can change it whenever you like on your dashboard. If you decline, vendors you shortlist see only that an anonymous couple has shortlisted them.
A vendor only ever sees a couple who has actively chosen them. Browsing a listing does not expose you. Vendors cannot search for couples, cannot see couples who have not picked them, and cannot see your guest list, your photographs or your site content at any point.
Messages work the same way, and only in one direction to begin with: you write to a vendor from their listing, and they may answer you. A vendor can never open a conversation with you. You each have five messages in one conversation, they are kept so both of you can read them back, and neither of you can delete the other's.
You may also ask us to send those messages to your email address, and to accept your emailed replies back into the conversation. It is off unless you switch it on, and it does nothing unless the vendor has switched the same thing on. Your email address is never given to the vendor and theirs is never given to you: mail goes out from a We Chose Forever address in both directions, and a reply comes back to us. No mail provider is connected, so today every message is delivered by appearing on the other person's dashboard.
Once a vendor receives your details they become a responsible party in their own right for what they then do with them. Our vendor terms require them to use those details only to respond to your enquiry.
Your planner and how suggestions are made
To suggest vendors and budgets, we process the details you enter — your date, location, budget and the categories you are still filling. This happens to provide the service you asked for. Your budget is never disclosed to any vendor. You can see and delete everything we hold from the Account page in your dashboard.
Nothing about this leaves your account. The province you filter on, the budget you set and the categories you have ticked off are read to decide what to put in front of you and in what order, and none of it is sent to a vendor — a vendor learns you exist only when you write to them or favourite them, and then only what the section above describes.
Who else receives personal information
We do not sell personal information, and we do not share it for advertising. We use a small number of service providers, who process it only on our instructions as operators under POPIA s20:
- Supabase
- Database, authentication and photo storage. Hosted in: United Kingdom (eu-west-2).
- Render
- Application hosting and server logs. Hosted in: Germany (Frankfurt).
We may also disclose information where the law requires it, or where it is necessary to establish, exercise or defend a legal claim.
Information sent outside South Africa
None of it is hosted in South Africa, and it is not all in one country. database, authentication and photo storage in the United Kingdom (eu-west-2); application hosting and server logs in Germany (Frankfurt). Your personal information therefore leaves the country. POPIA s72 permits this where the recipient is bound by an agreement that upholds principles substantially similar to POPIA, and we have a written data processing agreement in place with each provider for exactly that purpose.
If you are a wedding guest
When you reply on a couple's wedding page, the couple is the person deciding to collect your reply — under POPIA they are the responsible party for their guest list. We only store it for them, as their operator. Your reply goes to that couple and to nobody else.
Your reply is never readable from the public internet. There is no way to read a guest list without signing in to the account that owns it, and there is no public search of guests. If you want your reply corrected or removed, ask the couple — they can delete it directly. You can also write to us at the privacy address below and we will pass it on.
Health and dietary information
Information about allergies or dietary needs is health information, which POPIA treats as special personal information and restricts more tightly. The RSVP asks for it in its own step, and it is stored only if you tick the box beside it — that tick is the explicit consent POPIA s27(1)(a) requires, and it names the purpose: so the couple can cater for you at their wedding. Leave the field blank, or leave the box unticked, and nothing is kept. The couple sees it on their guest list and cannot edit it. It is never used for anything else, and it is deleted with the rest of the reply.
Children
Our service is not directed at children and we do not knowingly create accounts for anyone under 18. A guest list may name children who are attending a wedding. Where it does, the couple is responsible for having the consent of a competent person, as POPIA s34 requires. If you believe a child's information is held here without that consent, write to us and we will remove it.
Cookies
We use a small number of cookies, all of them necessary for the site to work. We do not use advertising cookies and we do not run third-party analytics.
- Authentication
- Keeps you signed in. Set by our authentication provider. Cleared when you log out.
- fa_device
- Remembers whether to serve the phone layout or the desktop one.
- fa_device_pin
- Records which layout you picked yourself, for the rest of the browsing session, so we do not overrule you.
- fa_vendor_theme
- Remembers a vendor's choice of light or dark console.
- fa_season
- Remembers which season a couple's site is on, so the navigation is in their colours before the page paints.
Full detail is on our cookie page.
The help bot
When the help bot cannot answer something, we keep the individual words it did not recognise, with names and numbers removed, for 90 days, so we can work out what to write next. We do not keep the question you typed, who asked it, or anything that identifies you — no address, no account, no device.
If you send us feedback through the help bot, we keep what you wrote, together with the answer that was on screen and the question you had just asked, for 180 days. The form tells you that before you type, and asks you not to include personal details. We do not keep your address, your account or your device with it.
If you report someone
Either side of a conversation between a couple and a vendor can report the other from that conversation. When you do, we keep what you wrote, a copy of the conversation as it stood at that moment, and which accounts were on each side of it. The dialog tells you the conversation is attached before you send it.
We do this on the basis of our legitimate interest in keeping the service safe for the people using it, and in some cases our legal obligations — section 11(1)(d) and (f) of POPIA. It is not consent, and you cannot withdraw a report that has already been sent, because a copy of what happened is the only record of it.
A report reaches us and nothing else. Nobody is suspended, blocked or notified automatically, and we do not tell the person reported who reported them. If we write to either of you about it, that letter goes through us — neither party is given the other's email address at any point.
How long we keep it
- Your account and site: for as long as your account is open. Delete your account and it goes with it.
- Free accounts that nobody uses: an account nobody has signed in to for 90 days is deleted, together with everything in it — a couple's site, photographs and guest list, or a vendor's listing and its enquiries. We write first, and nothing is deleted without that letter having gone.
- A vendor's company registration number: for as long as the listing exists, because we re-check the register once a year. A vendor's ID number is not on this list — it is deleted as soon as the check finishes, whether it passed or failed.
- Guest replies: for as long as the couple's account exists, or until the couple deletes them.
- Hashed IP addresses used for abuse prevention: 30 days, and they are cleared whenever we deploy.
- Help bot keyword fingerprints: 90 days, then deleted automatically.
- Help bot feedback you send us: 180 days, then deleted automatically.
- Abuse reports, and the copy of the conversation attached to one: for as long as we may need them to act on the matter or to answer a complaint about how we handled it. A report outlives the conversation it is about, and it outlives an account that is deleted — with the account's identity removed from it.
- Records we are required by law to keep, such as tax records: for the period the law requires.
How we protect it
- All traffic is encrypted in transit over HTTPS.
- Passwords are stored only as hashes, never in a readable form.
- Access to every record is enforced in the database itself with row-level security, not only in the application — so a mistake in our code cannot expose another user's data.
- Guest lists have no public read path at all.
- Only staff who need access to operate the service have it.
If a security compromise occurs that affects your personal information, POPIA s22 requires us to notify the Information Regulator and you. We will do so as soon as reasonably possible, and tell you what happened and what to do about it.
Your rights
Under POPIA you may:
- Ask what personal information we hold about you, and get a copy of it.
- Ask us to correct anything inaccurate, or complete anything missing.
- Ask us to delete information we no longer have a reason to keep.
- Object to processing we do on the basis of legitimate interest.
- Withdraw a consent you gave, including consent to share your name and date with vendors.
- Complain to the Information Regulator.
Most of this you can do yourself and immediately: your dashboard lets you edit your details, delete your photographs and guests, change the vendor-sharing setting, download a copy of the data we hold — your site details, guest list and vendor choices, with links to your photographs — and delete your account outright. For anything else, write to info@qaculture.co.za and we will answer within a reasonable time and at no charge.
Complaints
If you think we have handled your personal information unlawfully, please tell us first — we would rather fix it. You are entitled to complain to the Information Regulator regardless:
- Regulator
- Information Regulator (South Africa)
- Complaints
- complaints.IR@inforegulator.org.za
- General enquiries
- inforeg@inforegulator.org.za
- Address
- JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
- Website
- https://inforegulator.org.za
Marketing
We will not send you marketing by email unless you are already a customer or you have asked us to. Every marketing message we send will identify us and carry a one-click way to stop receiving them. Service messages about your own account — a password reset, a notice that your trial is ending — are not marketing and you cannot unsubscribe from those while you have an account.
Changes to this policy
We version this policy. If we change it in a way that affects what you agreed to, we will tell you and ask you to accept the new version rather than assuming your old agreement still covers it. The version number and date are at the top of this page.
Contact us
- Privacy and data requests
- info@qaculture.co.za
- Everything else
- info@qaculture.co.za
- Information Officer
- To be confirmed
Kept out of the page so they are not collected automatically. One click shows them, and nothing is asked of you in return.
Version history
- 1.0 — 25 August 2026
- The first published version.