Skip to content
Ever

Data Processing Addendum

Last updated 2026-07-13 · version 2026-07-13-draft

Draft — pending legal review. Not yet binding.

1. Purpose and scope

This Data Processing Addendum ("DPA") describes how Ever processes personal data submitted to the platform (including guest data couples add or that guests submit) when acting as a processor on behalf of the couple's wedding account. [COUNSEL: confirm whether a signed, standalone DPA is required for EU/UK customers and add execution mechanics (order form reference, signature block) if so.]

2. Roles

The couple (wedding account owner and collaborators) is the controller of the guest data they collect and enter. Ever is the processor, acting only on the couple's documented instructions as expressed through the product's normal functionality.

3. Data processed

Categories: guest names, contact details, RSVP responses, dietary/accessibility notes, plus-one and household data, and any free-text the couple or guests enter (messages, notes). No special-category data is intentionally collected; couples should avoid entering it in free-text fields beyond what's needed (e.g. dietary restrictions).

4. Sub-processors

Ever uses the following sub-processors to provide the service. We'll update this list as our infrastructure changes; material additions will be reflected here with an updated "last updated" date. [COUNSEL/PRIVACY: confirm whether advance notice + objection rights are required for EU/UK customers, and add processing-region detail per vendor.]

  • StripePayment processing, Stripe Connect payouts, and PCI-scope card handling for registry/cash-fund contributions.
  • ResendTransactional email delivery (RSVP confirmations, invites, receipts, and account notifications).
  • NeonManaged Postgres database hosting for wedding, guest, budget, and account data.
  • ClerkAuthentication, session management, and account identity.
  • AnthropicAI concierge, drafting, and contract-summary features (model inference on user-provided context).
  • CloudflareHosting, CDN, and edge-network protection for the marketing site (ever.wedding).
  • SentryError monitoring and crash diagnostics.
  • UpstashRate-limiting and short-lived caching (Redis) to protect the API from abuse.
  • PostHogProduct analytics (page views, feature usage) — only after consent where required. See the Cookie Policy.

5. Security measures

Encrypted transport (TLS) for all traffic; Stripe-hosted card entry (out of PCI scope for Ever); access-controlled infrastructure; audit logging of sensitive account actions. [COUNSEL: insert the full security-measures annex expected under Art. 28 GDPR / equivalent, and confirm incident-notification timelines.]

6. International transfers

Sub-processors may process data outside your region. [COUNSEL: confirm the transfer mechanism (e.g. SCCs, UK IDTA) required for each sub-processor and region combination.]

7. Your rights and contact

Data-subject requests (access, correction, deletion, portability) can be made per the Privacy Policy. DPA-specific questions: [COUNSEL: insert contact + mailing address.]

Terms of Service·Privacy Policy·Cookie Policy·Data Processing Addendum·Acceptable Use Policy·Vendor Agreement