Last updated: [14/09/2026]
The short version
2. What we collect and why
When you buy from us
What we collect: your name, email address, phone number, billing address and, for printed cards, your delivery address; your and your partner’s names, your wedding date and your venue (if you give it); what you ordered, the price and your order number; payment confirmation from Stripe (for example the card type and its last four digits); and the IP address and browser details recorded with the order.
Why: to process, deliver and support your order, send you order and receipt emails, handle refunds, prevent fraud and keep the business and tax records the law requires.
Legal basis: it is necessary to perform our contract with you; where we must keep records, it is a legal obligation; fraud prevention is in our legitimate interests in protecting you and our business.
You can check out as a guest. We do not create a shop account for you.
Your wedding photo portal
When you buy a portal package or start a free trial, we create your account on our photo-sharing app at app.takenplace.com.
What we use: your and your partner’s names, your email address, your wedding date, your venue and the package you bought. Once you are set up, the portal also holds what you add to it, such as your welcome message, your couple photo and your settings, and the photos and videos your guests upload.
Why: to set up and run your portal, email you a sign-in link (each link works once and expires after 24 hours), produce your QR code designs, show your guests’ photos in your gallery and live slideshow, and support you.
Legal basis: it is necessary to perform our contract with you.
Where it is kept: the app is hosted by Amazon Web Services in its Ireland region, so this data stays in the European Union. Emails from the app are sent through Amazon’s email service in the same region.
If you are a guest uploading to a couple’s portal
What we collect: the photos and videos you upload, the time of the upload and, if you enter it, your name.
How we use it: your uploads appear in the couple’s gallery and can be shown on the live slideshow at the wedding. Uploads are checked automatically for inappropriate content before they appear. We remove location data (such as GPS coordinates) from photos when they are uploaded.
Legal basis: our legitimate interest, and the couple’s, in providing the shared wedding album you chose to contribute to.
How long: uploads are kept for the storage period of the couple’s package and then deleted. If you want a photo of you, or one you uploaded, removed sooner, contact the couple or email us.
Our mailing list
If you tick “Receive helpful email from us” at checkout, or sign up another way, we add your name and email address to our mailing list, which is run by Mailchimp. We use your order history to make the emails relevant to you.
The box is never ticked for you. You can unsubscribe with the link in every email, or by emailing us.
Legal basis: your consent, which you can withdraw at any time.
Mailchimp also keeps a record of shop orders so that we do not send you offers for things you have already bought. We do not send marketing emails to customers who have not subscribed.
When you contact us
If you email us, call us, message us on WhatsApp or use a form on our website, we use your name, contact details and message to reply and help you. Our website forms are protected by Google reCAPTCHA, which checks that a person, not a bot, is sending the form. To do this it collects information about your device and how you use the page.
Legal basis: our legitimate interest in answering your enquiry, or taking steps you ask for before you buy.
When you use our website
Security and running the site: our servers and security services record technical information such as your IP address, browser type, the pages you request and the time. We use it to keep the site working and secure, for example to block attacks. We also use your IP address to work out which country you are in so we can show the right prices and delivery options. This lookup happens on our own server. Legal basis: our legitimate interests in running a secure and working shop.
Cookies and similar technologies: we use essential cookies to make the basket, checkout, live chat and your cookie choices work. On pages where you can pay, Stripe uses its own cookies and security checks to prevent fraud. With your permission only, we also use:
- analytics: Google Analytics and Jetpack Stats, to understand how the site is used;
- advertising and marketing: Google Ads, Google Merchant Center, the Meta (Facebook) Pixel and Mailchimp’s website tracking, to measure our adverts and emails and show relevant adverts on other sites.
You choose in our cookie banner and can change your mind at any time. Our pages also load fonts from Google Fonts, and our forms are protected by Google reCAPTCHA. See our Cookie Policy for the full list. Legal basis: your consent, apart from essential cookies and fraud prevention.
3. Who we share your data with
We only share personal data with organisations that help us run the business, and only what they need. They process it on our instructions under data processing terms.
- Stripe Payments Europe, Limited (Ireland): takes your card, Link, Apple Pay and Google Pay payments and screens them for fraud. If you use Link, Apple Pay or Google Pay, those services’ own privacy terms also apply.
- Amazon Web Services EMEA SARL: hosts our shop and the wedding photo app, delivers our web pages, sends app emails and stores backups.
- Intuit Mailchimp: runs our mailing list.
- Google (Google Ireland Limited): Analytics, Ads, Merchant Center, Tag Manager, reCAPTCHA and Google Fonts.
- Meta Platforms Ireland Limited: the Meta Pixel (with your consent), and WhatsApp if you choose to message us there.
- Automattic (Jetpack): website security, performance and visitor statistics.
- [Print and delivery partners, e.g. printer name, An Post / courier name]: to print and deliver your cards.
- Professional advisers (such as our accountant), and public authorities where the law requires it.
- A buyer of our business, if we ever sell it, under the same protections.
We do not sell your personal data.
4. Transfers outside the European Economic Area
Most of your data stays in the EU: our shop, our photo app and our payment provider are based in Ireland. Some of our providers (Mailchimp, Google, Meta and Automattic) may process data in the United States. Where they do, the transfer is protected by the EU-US Data Privacy Framework and/or the European Commission’s Standard Contractual Clauses.
5. How long we keep your data
- Orders: the personal details on a completed order (your name, contact details and addresses) are anonymised 1 year after the order, and on a refunded order after 2 years. Unpaid, failed and cancelled orders are deleted after 1 year. The anonymised record of each sale (what was sold, the amount and the date) is kept for 6 years after the end of the financial year, as Irish tax law requires.
- Your wedding portal account: while your portal is active, then for [X months] after your storage period ends, so we can answer questions about it.
- Photos and videos in a portal: until the end of the storage period in the package (between 30 and 365 days after the wedding date, depending on the package), then deleted.
- Mailing list: until you unsubscribe. After that we keep only your email address on a “do not email” list, so we do not add you back by mistake.
- Messages and enquiries: [24 months] after our last contact with you.
- Analytics data: [14 months], then deleted by Google.
- Backups: backups are overwritten on a rolling basis and kept for no more than [X days/weeks].
6. Your rights
Under data protection law you have the right to:
- access the personal data we hold about you and get a copy;
- correct data that is wrong or incomplete;
- erase your data, where there is no good reason for us to keep it (we must keep order records for tax purposes, for example);
- restrict how we use your data while a concern is looked into;
- object to us using your data on the basis of our legitimate interests; you can always object to direct marketing;
- data portability: receive data you gave us in a common electronic format, or have it sent to another organisation;
- withdraw consent at any time, where we rely on consent (this does not affect what we did before you withdrew it).
We do not make decisions about you based solely on automated processing that have legal or similarly significant effects. Stripe’s automatic fraud screening is used to protect payments.
To use any of these rights, email [privacy contact email]. It is free. We will reply within one month, and we may ask you to confirm your identity first.
If you are unhappy with how we have handled your data, please tell us so we can put it right. You also have the right to complain to the Data Protection Commission, Ireland’s data protection authority: www.dataprotection.ie.
7. How we protect your data
Our website uses encrypted connections (HTTPS). Card payments are handled entirely by Stripe, which is certified to the payment card industry’s security standard (PCI DSS). Access to customer data is limited to the people who need it. Portal sign-in links expire after 24 hours, and location data is removed from uploaded photos. No system is completely secure, but we take reasonable steps to protect your data, and we will tell you and the Data Protection Commission about a breach where the law requires it.
8. Children
Our shop is for adults planning their wedding. We do not knowingly collect personal data from children through the shop. Wedding photos can include children: please upload them thoughtfully, and ask us to remove any photo you are concerned about.
9. Changes to this policy
We will update this policy when the way we use personal data changes, and change the “last updated” date at the top. If a change significantly affects how we use data we already hold, we will tell you by email.
10. Contact us
Takenplace Ltd trading as takeNplace Weddings
BKK Heritage Business Park, Cork, T12 P1HX, Ireland
Email: info@takenplace.com
Phone: 021 2514 598