Skip to main content
Vereli

Vereli Trust & Security

This page describes how the Vereli wedding directory and gift registry protect the information people give us, where it lives, and which other companies handle it. It goes with the Privacy Policy, which says what we collect and why.


Where your data lives

Australia. Vereli's database and file storage (Supabase) run in the Sydney region, and our web hosting (Vercel) runs in Sydney. Email is the exception: our email delivery provider (Resend) processes messages in Ireland, because it offers no Australian region. Enquiries and sign-in emails pass through it on the way to the person they are for.

How your data is protected

Sub-processors

Every third party that processes personal information in the course of running the wedding directory and registry, and what it is used for. It matches the list of providers in the Privacy Policy.

Sub-processorPurposeData involvedLocation
SupabaseDatabase, file storage (business photos) and sign-inEverything Vereli holds for the wedding servicesSydney, Australia
VercelApplication hostingApplication traffic; no persistent personal data storageSydney, Australia (syd1, re-checked 3 September 2026; a response header records where a request was served, so this is worth re-confirming against the project's region setting)
ResendEmail delivery: sign-in links, an enquiry passed to a wedding business, and notices about a report or a removalA person's email address and the message content (for an enquiry: name, email, optional wedding date and message)Ireland (no Australian region exists for email delivery)
Cloudflare (Turnstile)Bot check on the public enquiry form, to tell a person from a scriptThe visitor's IP address and browser signals, seen by Cloudflare when the check loads in their browser. Our server sends Cloudflare only the check's result, never a name, email or messageGlobal network; a request may be handled outside Australia
Google (sign-in)Optional "Continue with Google" sign-in for wedding businesses. Not used unless the person chooses itName, email address and whether Google has verified the address, passed to us by Google. Google learns that the person signed in to Vereli; nothing about a listing or an enquiryGlobal network; may be handled outside Australia
Link-safety service (provider to be named when chosen)Checks the web address of a gift link against known-dangerous sitesThe web address only; never a name or email. Nothing is sent if the check is switched offTo be stated when the provider is chosen
AhrefsWebsite analytics on Vereli's own public pages onlyPage views. Cookieless, and no personal data is collectedSingapore-headquartered
Vercel Speed InsightsPage-performance measurement (Core Web Vitals) on public pagesAnonymous performance timings. No personal data, no cookiesSame provider as the hosting row

We use each of these only where we need it to run the service: storing information, delivering the emails people are meant to receive, checking that a person and not a script is using a form, and, if someone chooses it, signing them in. Each is sent only what that task needs.

Sending information to a provider outside Australia is a cross-border disclosure under Australian privacy law, and Vereli remains accountable for how that provider handles it. Where a provider offers a choice of region, we choose the more privacy-protective one rather than the default.

Data retention

This matches the Privacy Policy. Some deletion is automatic today and some is not yet, and the policy says which.

WhatKeptAutomatic today?
A registry you have not publishedDeleted 12 months after the wedding date, or 12 months after the last edit if no date was givenYes
A registry you have publishedUntil you delete it, which you can do yourself at any timeOn your action
An enquiry you sentWe delete our copy 90 days after the enquiry (later if you enquired again more recently); the business's own copy is theirsYes
A vendor listingWhile listed; taken down when removed, and the rest deleted within 30 daysTakedown yes; clean-up by hand
A reportDeleted 12 months after it is closed; an open report is not deletedYes
FeedbackDeleted 12 months after it was sentYes

Incident and breach response

This describes Vereli's intended process. It has not yet been exercised against a real incident.

  1. Detection. Structured logging and alerting on known failure signals are the first line of detection. A breach may also be reported by a user or a sub-processor.
  2. Triage. Assessed within a target of 1 hour of detection during business hours: is personal information actually exposed, to whom, and how much.
  3. Containment. The specific access path or defect is closed first; root-cause analysis follows, not the other way around.
  4. Notification. Affected people are told, within a target of 72 hours of confirmation, what happened, what information was involved and what we are doing about it. Where the Notifiable Data Breaches scheme applies, the Office of the Australian Information Commissioner is notified as that scheme requires.
  5. Post-incident. A written postmortem for any incident that reached containment: root cause, what was affected, and what changed to prevent it recurring.

Service availability

The directory and registry are free and provided as they are. We aim to keep them available but do not promise a level of uptime.

Questions

support@vereliapp.com