Privacy notice
Draft · not yet legally reviewed. Highlighted details will be completed before launch.
This notice explains which personal data Couvert processes when couples run a wedding gift list and guests give through it. It follows the EU General Data Protection Regulation (GDPR) and, for people in Switzerland, the Swiss Federal Act on Data Protection (FADP).
1. Controller
First name Last name, sole proprietorship "Couvert"
Street and number, Postcode Berlin, Germany
Email: datenschutz@lecouvert.ch
Couvert has not appointed a data protection officer, as the legal requirements for doing so are not met.
2. Visiting the website
Whenever a page is requested, our hosting provider processes technically necessary data: IP address, date and time, requested address, browser and operating system. This serves to deliver the page, keep it secure and fix errors. The legal basis is our legitimate interest in secure operation (Art. 6 (1) (f) GDPR). These logs are deleted after number days.
We serve the website's fonts ourselves. Visiting the site does not connect you to Google or any other font provider.
3. Cookies and local storage
Couvert only stores what is needed for it to work, and sets no advertising or analytics cookies:
- Sign-in for couples: a cookie ("couvert_session") keeps couples signed in for up to 30 days. The dashboard cannot be used without it.
- Guests' basket: the browser stores the selected wishes locally until they are paid for or removed. They are only sent to Couvert at checkout.
The legal basis is § 25 (2) no. 2 TDDDG, as this storage is strictly necessary for the service requested, and Art. 6 (1) (b) GDPR for the processing that follows.
4. Couples: account and gift list
When a couple creates a list, we process: email address, both partners' first names, date and place of the wedding, programme, the letter to guests, the wishes and their prices, the page language and the address of the couple's page. Couples sign in with a link we send by email, valid for 30 minutes.
The couple's page can be reached by anyone who knows its address. It is not indexed by search engines. The couple decides what it shows.
The legal basis is the contract for using Couvert (Art. 6 (1) (b) GDPR).
5. Couples: payouts via Stripe
So that gifts can be paid out, the couple opens an account with Stripe through Couvert. The couple enters identity, date of birth, address and bank details directly with Stripe. Stripe verifies these details under its own legal obligations (including anti-money-laundering rules) and on its own responsibility. Couvert only receives the account ID and its status, for example whether payouts are possible.
6. Guests: gifts and payment
When a guest gives a gift, we process: name, email address, the message to the couple, the selected wishes and amounts, whether the service fee was covered, the payment method, and the time and status of the payment.
The couple sees the name, message and amounts in their dashboard so they can say thank you. We do not pass the guest's email address to the couple. We use it to send the gift confirmation.
Payment takes place on a Stripe payment page. Guests enter card and TWINT details directly with Stripe, Couvert does not see them. Stripe may run an automated risk assessment to prevent fraud.
The legal basis is the contract for the gift (Art. 6 (1) (b) GDPR) and, for keeping payment records, our legal obligation (Art. 6 (1) (c) GDPR).
7. Emails
We send sign-in links and confirmations via email provider, registered office. These are service emails about a specific list or gift, not a newsletter.
8. Recipients and processors
We only share personal data where Couvert needs to:
- Hosting: provider, registered office, server location
- Database: provider, registered office, server location (planned: Supabase, Frankfurt)
- Email delivery: provider, registered office
- Payments: Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. Stripe processes payment and account data partly as an independent controller, see Stripe's privacy policy.
- Tax advisors and authorities, where required by law.
Data processing agreements (Art. 28 GDPR) are in place with the hosting, database and email providers.
9. Transfers to third countries
Some providers are based in the USA or access data from there. Such transfers rely on the EU-US Data Privacy Framework or the Swiss-US Data Privacy Framework where the provider is certified, and otherwise on the European Commission's standard contractual clauses. The EU has recognised Switzerland as providing adequate protection, and Swiss law in turn recognises EU countries as adequate.
10. Retention
- A couple's account and list: until the couple deletes them, at the latest number months after the wedding date.
- Records of gifts and fees: as long as commercial and tax retention rules require (8 or 10 years), then deleted.
- Server logs: see section 2.
11. Your rights
You can ask for access to your data, for it to be corrected or erased, for processing to be restricted and for a copy in a common format. You can object to processing based on our legitimate interest. Write to datenschutz@lecouvert.ch.
You can also complain to a supervisory authority. The authority responsible for Couvert is the Berlin Commissioner for Data Protection and Freedom of Information, Alt-Moabit 59–61, 10555 Berlin. In Switzerland, the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, is responsible.
12. Security
All pages are transmitted encrypted. Sign-in links and sessions are signed and expire. Payment data is held only by Stripe.
13. Changes
We update this notice when Couvert or the law changes. The version published here applies.