Vereli Privacy Policy
Published 20 August 2026; rewritten for the wedding directory and registry 22 September 2026; booking agreements added 24 September 2026. Accurate against what Vereli actually does, and reviewed against the code rather than adapted from a template and left there. See the correction history below.
Correction history, kept rather than tidied away:
-
22 September 2026 — rewritten to cover the wedding directory and registry only, which is what Vereli offers today. Earlier versions of this policy covered other services that are not currently offered; that text has been set aside, not lost, and will be added back or published separately if those services are released.
-
24 September 2026 (booking agreements) — added the record kept when a couple agrees to a booking's terms, and how long it is kept.
-
25 September 2026 — added the help-centre contact form (what it collects, the 90-day deletion) and said that the Turnstile bot check now also runs on sign-in, sign-up, the sign-in link request and the report form, not only the enquiry form.
-
25 September 2026 (later) — said plainly why each provider is used and that each is sent only what its task needs, next to the cross-border disclosure.
-
25 September 2026 — added Google (sign-in) to "Who else handles it", ahead of "Continue with Google" being switched on for wedding businesses.
-
24 September 2026 — added Cloudflare (Turnstile) to "Who else handles it", because the enquiry form now checks that a person, not a script, is sending it.
-
21 September 2026 (wedding launch) — added the wedding directory and registry, which this policy had not mentioned at all although the directory was about to go public. Written against the code and the migrations, and against the compliance review of the wedding launch. Where something is a plan and not yet a running mechanism, the section says so (chiefly the automatic deletion of old enquiries, reports and feedback, which has since been built and is running). Needs a lawyer's read before the public couple launch.
-
21 September 2026 — corrected the cookie section, which said the website set no cookies beyond two short-lived install cookies. Sign-in now sets a seven-day session cookie. Rewritten by kind rather than naming each cookie, so it does not go stale each time a sign-in flow is added.
ABN and registered address are deliberately not included (founder decision, 18 August 2026): neither is a legal requirement for this document, and Vereli is a sole trader. An ABN is registered under the individual's own name, and publishing it here would de-anonymise the founder for no compliance benefit.
Last updated: 24 September 2026
Who we are
Vereli ("Vereli", "we", "us", "our") is an Australian sole trader. Vereli runs a wedding directory and gift registry: a directory of Australian wedding businesses that couples can browse and send enquiries to, and a registry where a couple can list gifts and share the page with guests. We decide what personal information is collected and why. This policy explains what we collect, why, who sees it, how long we keep it, and what rights you have over it.
The wedding directory and registry
This section covers the wedding directory and the gift registry. We handle this information in line with the Australian Privacy Principles, whether or not they strictly apply to a business of our size. We do not sell it, and we do not use it for advertising. Vereli does not take payment, hold money or sell any gift or service through the wedding directory or registry.
What we collect, and who sees it
If you list a wedding business:
- Your business name, category, region, description, website and price sheet, a logo and up to six photos, any deposit and cancellation terms you choose to publish, and (if you give one) your ABN. This is shown publicly on your listing. We do not check it: the page says the details are provided by the business. Where you give an ABN we check only that it is well-formed, and the page says "ABN provided", not that we verified it.
- Your sign-in email and, if different, a business contact email where enquiries are sent. These are not shown on your public page.
- The time you confirmed the statement you make when you list, so we can show we asked.
- Counts of visits and enquiries to your page, including those that arrive through your own share link. These are counts, not a record of who visited.
If you send an enquiry to a wedding business:
- Your name, email address, wedding date (if you give one) and message, and the wording of the consent you agreed to. We pass these to the business you chose, and to no one else, by email to their own inbox. From that moment the business holds its own copy, and how it uses it is up to that business.
- Your enquiry is not verified: we do not check that the email address is yours, and the email to the business says so.
If you agree to a booking's terms:
- A record of exactly what you agreed to: the deposit and cancellation wording that was shown to you at that moment, the date and time you agreed, and a one-way code made from your IP address (not the address itself). We keep this so that, if there is ever a dispute, you, the business and we can show what was agreed, even if the business later changes its terms.
If you make a gift registry:
- Your names, your sign-in email, an optional wedding date (shown on your published page as the month and year only, unless you choose to show the exact day, and only if you give one), and the gifts you list, each with the name and web link you type in. We do not fetch or copy the pages your links point to. A registry is private (a draft) until you publish it. Once published it can be opened by anyone who has its link; it is kept out of search results and out of our sitemap, but a link you share can be passed on.
- We collect no delivery address and no payment details, and the registry asks for none. Do not put any in a gift note.
If you visit a published registry as a guest:
- Nothing personal. Marking a gift "I'm buying this" needs no name or email. It is an anonymous mark that says only that a guest marked it. We cannot confirm a gift was bought, and the page says so. A keyed, one-way code derived from your connection is used to limit repeated clicks; it is not your address and cannot be turned back into it.
If you report a listing or a gift link:
- Your report text, an email address only if you choose to give one, and a keyed, one-way code derived from your connection (and your email, if given) to spot abuse. The business is told only the reason for a report, never your words or who you are.
If you write to us through the help centre:
- Your name, your email address (so we can answer), the topic you picked, a listing or registry link only if you choose to give one, and your message. We answer by email. We keep the message for 90 days, then delete it. The email we send to our own inbox to tell us a message arrived names you and the topic but does not contain your message.
If you send us feedback:
- Your message, the page it came from, and an optional email address if you want a reply. No name is collected.
About every visitor: ordinary technical logs (IP address and request details, kept for security and debugging), and the cookie described under "Cookies and our website".
Why we use it
- To show the directory and let couples contact a business.
- To deliver an enquiry to the business it was addressed to, and to email vendors and couples their sign-in links and the notices that go with their own listing or registry.
- To run the registry and let a guest see what has been marked.
- To handle reports, decide whether to hide a listing or a link, and remove abusive or fake content.
- To measure, in counts only, whether the service is used, so we can improve it.
We only send the emails above. The sign-in emails, the enquiry email to a business, and the notices about a report or a removal are service messages. We do not use these addresses for marketing, and we do not put promotions in those emails. If we ever want to send you anything else, we will ask separately first.
There is no AI in this part of the service today. Enquiries and registries are not read, replied to or written by AI.
Checking a gift link
When a couple adds a gift link, we may check the web address (only the address, never the couple's name or email) with a link-safety service, so that links to known dangerous sites can be flagged. If the check cannot be made, the link is saved and the couple is told it could not be checked. This is not a guarantee that a link is safe. Following a gift link takes you to the retailer's own website. That purchase, delivery and return is between you and the retailer, under the retailer's own privacy policy.
How long we keep it, and how to have it removed
We keep it for the shortest period we can. The table says how long, and whether we delete it automatically or you do it yourself:
| What | How long | Automatic today? |
|---|---|---|
| A vendor listing | While it is listed. When you remove your listing (from your dashboard, or by email to us) it is taken down at once. 30 days later your details are deleted: your profile, price sheet and images (including the image files), your sign-in, and the business name on our records. The enquiries that were sent to you follow the enquiry rule below, not this one | Yes (a removal you ask for by email starts its 30 days when we record it) |
| A record that a listing was removed | Two one-way codes (one of your login email, one of your business name) and the date, kept so a removal can be shown to have happened. They hold no name or address and cannot be turned back into either. They do not stop you signing up again, but if you do, a person at Vereli checks it before it is listed | Yes |
| A registry you have not published | Deleted 12 months after the wedding date you gave, or 12 months after your last edit if you gave none | Yes |
| A registry you have published | Until you delete it. You can delete it yourself at any time from your registry screens | On your action |
| A record that you deleted a registry | A one-way code of your email and a time, kept so a removal can be shown to have happened. It does not stop you making a new registry | Yes |
| An enquiry you sent | Our copy (your name, email address, date and message, and the record of what you agreed to) is deleted 90 days after the enquiry. If you enquired again more recently, your details are kept until that latest enquiry is 90 days old. You can ask us to delete it sooner. The business's own copy is theirs | Yes |
| A record of terms you agreed to | Kept for 6 years after the wedding date (or after you agreed, if the booking has no date), then deleted. It stays even if the business later removes its listing | Yes |
| A report | Deleted 12 months after it is closed. A report that is still open is not deleted. Also deleted on request | Yes |
| A help-centre message | Deleted 90 days after you sent it. Also deleted on request | Yes |
| Feedback | Deleted 12 months after you sent it. Also deleted on request | Yes |
| Guest marks | Cleared with the registry. The abuse-limiting record for a mark is cleared after a day | Yes |
| Counts of visits and enquiries | Kept as counts. They identify no one | n/a |
Nothing in this table is waiting to be built: each line is either automatic or done when you act.
To ask for your information to be deleted or corrected, or to ask what we hold, write to support@vereliapp.com. We reply within 30 days.
Who else handles it
- Supabase: our database and file storage, in Sydney. It also holds the photos a business uploads.
- Vercel: our web hosting, in Sydney. It holds no personal information beyond what passes through a request.
- Resend: our email delivery provider, in Ireland (there is no Australian region for email). Enquiries and sign-in emails pass through it on the way to the person they are for.
- Cloudflare (Turnstile): a bot check on the enquiry form, the help-centre contact form, sign-in and sign-up, and the report form. It loads in your browser from Cloudflare, which sees your IP address and browser signals so it can tell a person from a script. Our server sends Cloudflare only the result of that check, never your name, email or message. Cloudflare runs a global network, so a request may be handled outside Australia.
- Google (sign-in): only if you choose "Continue with Google". Google confirms who you are and passes us your name and email address; it is told that you signed in to Vereli, and nothing about your listing or any enquiry. Signing in by email link does not involve Google. Google runs a global network, so a request may be handled outside Australia.
- A link-safety service: sent only the web address of a gift link, never a name or email. Nothing is sent if the check is switched off.
- The business you enquired with: receives your enquiry, by design. They are responsible for what they do with it.
- The public. What a wedding business publishes on its listing, and a registry a couple has published, is visible to anyone with the page or link.
We use these providers only where we need them to run the service you asked for: storing your information (Supabase), delivering the emails you are meant to receive (Resend), telling a person from a script on the enquiry form (Cloudflare), and, only if you choose it, signing you in (Google). We send each one only what that task needs, and nothing more.
Sending information to a provider outside Australia (Resend, in Ireland, and Cloudflare and Google, whose networks operate in many countries, so we cannot name each one) is a cross-border disclosure under Australian privacy law, and we remain accountable for how that provider handles it. We do not sell personal information, and we do not share it for third-party advertising or marketing. We may disclose information if required by law, or to protect the rights, safety or property of Vereli, our users or others.
Cookies and our website
We only use cookies that the site needs to work. We do not use cookies for advertising, for tracking you across other sites, or for analytics.
When you sign in to your Vereli account (for example with a link we email you), we set a cookie that keeps you signed in. It is not readable by scripts on the page, it lasts up to seven days, and it is cleared when you sign out.
Our analytics are deliberately cookieless and collect no personal information. Because we set no cookies beyond the one above, you have not been shown a cookie banner: a banner asking permission for tracking we do not do would be theatre.
If that ever changes, if we adopt anything that sets a cookie you would reasonably want a say in, this section changes first, and a banner comes with it.
Your rights
If you use the wedding directory or registry (a business, a couple, a guest or someone who sent an enquiry or a report):
- Remove your listing, or delete your registry, yourself from your own screens, at any time.
- Ask what we hold about you, or have it corrected or deleted, at support@vereliapp.com. We reply within 30 days. A business that receives an enquiry holds its own copy, and you will need to ask that business to delete it.
- If you sent a report and gave no email, we cannot contact you about it.
General rights (where applicable under the Privacy Act 1988 or another
law that applies to you): access, correction, and complaint. To make a
complaint about how we've handled your information, contact us first at
support@vereliapp.com; if unresolved, Australian individuals can complain to
the Office of the Australian Information Commissioner (OAIC),
oaic.gov.au.
Children
Vereli is used by businesses, and by couples planning a wedding, and is not directed at children. We do not knowingly collect personal information from children.
Security
We use industry-standard measures to protect personal information, including encryption in transit and at rest and Australian data residency for our own database (which includes uploaded photos). No system is perfectly secure, and we cannot guarantee absolute security of information transmitted to us.
Changes to this policy
We may update this policy from time to time. We'll update the "Last updated" date above and, for material changes, take reasonable steps to notify people who use the wedding services.
Contact
Questions about this policy, or to exercise any of the rights above, contact us at support@vereliapp.com.