This Privacy Policy explains how YENKO BUDDY (PTY) LTD, registration number 2025/302541/07, trading as Gatherlane ("Gatherlane", "we", "us" or "our"), collects, uses, stores, shares and protects personal information when you use the Gatherlane website, application, event pages, wedding invitation tools, RSVP tools, wedding update tools, guest media tools, vendor tools, gift registry features, donation-related features, payment-related features and related services (collectively, the "Platform").
Gatherlane is a product of YENKO BUDDY (PTY) LTD. The company was registered and commenced business on 9 April 2025 and is recorded as an in-business private company with CIPC. This Policy commences on 10 July 2026.
This Policy is drafted primarily for South Africa and is intended to align with the Protection of Personal Information Act 4 of 2013 ("POPIA"), the Promotion of Access to Information Act 2 of 2000 ("PAIA"), and applicable provisions of the Electronic Communications and Transactions Act 25 of 2002 ("ECTA") where electronic communications, online services, payment information and electronic transactions are involved.
Although Gatherlane may be designed for future use beyond South Africa, this Policy is drafted primarily for South Africa. If Gatherlane expands into another jurisdiction, Gatherlane may publish additional country-specific terms or notices.
This Policy applies to couples, event owners, hosts, users who create or manage events ("Event Owners"), guests and invitees ("Guests"), vendors and service providers listed, promoted, contacted or booked through the Platform ("Vendors"), and all other visitors or users of the Platform.
This Policy should be read together with our Terms of Service, Cookie Policy, Refund Policy, Vendor Agreement, Donation or Gift Registry Terms, and any feature-specific terms that apply to the relevant service.
For purposes of POPIA, the party that determines why and how personal information is processed is generally the "Responsible Party". A party that processes personal information for, or on behalf of, a Responsible Party is generally an "Operator".
| Role | When it applies | Practical meaning |
|---|---|---|
| Gatherlane as Responsible Party | Where Gatherlane processes information to create accounts, operate the Platform, process payments, manage vendors, provide support, secure and improve the Platform, perform analytics, keep business records, comply with the law, and send lawful service or marketing communications. | Gatherlane is responsible for ensuring that its processing complies with POPIA. |
| Gatherlane as Operator | Where an Event Owner uploads or enters Guest details and instructs Gatherlane to send invitations, wedding updates, RSVP reminders or related event communications to those Guests. | The Event Owner is the Responsible Party for that Guest information and Gatherlane processes it on the Event Owner's instructions, subject to POPIA and the Platform terms. |
| Event Owner as Responsible Party | Where the Event Owner decides which Guests to invite, what Guest information to upload, what event updates to send, and how to use RSVP, dietary, donation, seating or media information. | The Event Owner must have a lawful basis to collect and share Guest personal information and must provide any required notices to Guests. |
| Vendor as Responsible Party | Where a Vendor independently collects, stores or uses personal information for quotations, bookings, service delivery, invoicing, marketing or customer management. | The Vendor must comply with POPIA in respect of its independent processing and should maintain its own privacy notice. |
| Field | Details |
|---|---|
| Legal entity name | YENKO BUDDY (PTY) LTD |
| Trading name / product name | Gatherlane |
| Registration number | 2025/302541/07 |
| Enterprise type and status | Private company; in business |
| Registered office / physical address | 25 Hill Park, 27 Carisbrook Street, Cape Town, Western Cape, 8001, Republic of South Africa |
| Email for privacy requests | privacy@gatherlane.events |
| Information Officer | Frank Boateng, Director, or any duly authorised replacement registered with the Information Regulator |
| Deputy Information Officer | Not appointed as at the commencement date of this Policy, unless otherwise published by Gatherlane |
Gatherlane will take reasonable steps to ensure that its Information Officer and any Deputy Information Officer details are registered or updated with the Information Regulator where required and that those details remain accurate.
| Term | Meaning in this Policy |
|---|---|
| Personal information | Information relating to an identifiable natural person and, where applicable under POPIA, an identifiable juristic person. This includes names, contact details, identifiers, location data, account data, payment references, images, messages and technical data. |
| Processing | Any operation concerning personal information, including collecting, receiving, recording, storing, updating, using, sharing, deleting, destroying or otherwise handling it. |
| Special personal information | Sensitive categories of information regulated by POPIA, including religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health, sex life, biometric information and criminal behaviour. |
| Child | A person under the age of 18 years. |
| Competent person | A parent, guardian or other person who is legally competent to consent to action or decision-making in respect of a child. |
| Data subject | The person or juristic person to whom personal information relates. This may include an Event Owner, Guest, Vendor, employee, representative or website visitor. |
We collect only the personal information that is reasonably necessary for the purposes described in this Policy, unless the law allows or requires otherwise. Depending on how you use the Platform, we may collect the categories below.
| Category | Examples |
|---|---|
| Account and profile information | Name, surname, email address, cellphone number, password or authentication credentials, profile image, Google sign-in details, role on the Platform and account preferences. |
| Event and wedding information | Event title, names of the couple or hosts, wedding date and time, venue name and address, event schedule, cover images, dress code, travel information, accommodation details and other wedding or event updates uploaded by the Event Owner. |
| Guest list information | Guest name, email address, cellphone number, invitation status, relationship or category tag, plus-one information, table or seating information, invitation link information and communication preferences. |
| RSVP and attendance information | Attendance response, number of attendees, plus-one count, meal selection, dietary requirements, accessibility requests, notes to the couple or host, and any related update submitted by a Guest. |
| Donation, gift registry and payment information | Donation or gift amount, payment status, payment reference, transaction date, payer name, email address, billing details, payout reference, refund or chargeback status and limited payment metadata. Gatherlane does not intend to collect or store full card numbers, CVV numbers or online banking login details. |
| Vendor information | Business name, contact person, email address, cellphone number, business address or service area, service category, descriptions, portfolio images, pricing information, bookings, ratings, reviews, payout reference and support correspondence. |
| Media and content | Photos, videos, captions, guest messages, event gallery uploads, moderation status, timestamps and related metadata. |
| Support and communications | Emails, chat messages, help requests, complaint details, dispute information, call notes and correspondence sent to or from us. |
| Technical and usage information | IP address, device information, browser type, operating system, pages viewed, referring URL, session data, error logs, cookie identifiers, analytics events, security logs and approximate location derived from technical data. |
The Platform is not designed to collect special personal information as its main purpose. However, some event management features may incidentally involve sensitive information, for example dietary requirements that may reveal religious beliefs or health information, accessibility requests that may reveal health information, photographs that may reveal race, religious attire or cultural background, and information about child Guests.
Where special personal information or children's information is processed, Gatherlane and the relevant Event Owner must ensure that there is a lawful basis under POPIA. This may include consent of the data subject, consent of a competent person in the case of a child, processing necessary for the establishment, exercise or defence of a right or obligation in law, or another basis allowed by POPIA.
Under POPIA, we must have a lawful justification for processing personal information. Depending on the context, we process personal information on one or more of the following grounds: consent; performance of a contract or taking steps before entering into a contract; compliance with a legal obligation; protection of a legitimate interest of the data subject; our legitimate interests or those of a third party; or another lawful basis recognised by POPIA.
| Purpose | Examples of information used | Main POPIA basis |
|---|---|---|
| Create and manage accounts | Name, email, password/authentication details and account preferences. | Contractual necessity and legitimate interests in operating a secure user account. |
| Create and publish event pages | Couple/host details, event information, venue details, cover images and schedule information. | Contractual necessity and legitimate interests of the Event Owner. |
| Send wedding invitations, reminders and updates | Guest names, email addresses, phone numbers, RSVP status and event update content. | Event Owner's legitimate interests, contractual necessity between Gatherlane and the Event Owner, and consent where required by law or by the nature of the communication. |
| Manage RSVPs, seating and guest logistics | Attendance, plus-one information, dietary requirements, accessibility notes, seating/table information and guest messages. | Contractual necessity, legitimate interests of the Event Owner and Guest, and consent or another lawful basis for sensitive information where applicable. |
| Process gifts, donations, payments, refunds and chargebacks | Payment references, transaction amount, payer details, billing details, payout references and fraud indicators. | Contractual necessity, legal obligations and legitimate interests in preventing fraud and resolving disputes. |
| Provide vendor marketplace and vendor page features | Vendor profiles, booking details, reviews, contact details, payout references and support correspondence. | Contractual necessity and legitimate interests in operating the vendor service. |
| Host, moderate and display photos or videos | Uploaded media, captions, submitter details, timestamps and moderation decisions. | Consent at upload, contractual necessity for the event service, and legitimate interests in moderation and platform safety. |
| Provide customer support and resolve disputes | Support correspondence, account details, payment references and event records. | Legitimate interests, contractual necessity and legal obligations. |
| Secure and improve the Platform | Technical data, logs, error reports, IP addresses, device data and usage data. | Legitimate interests in security, fraud prevention, service improvement and compliance. |
| Comply with legal and regulatory obligations | Records required for tax, accounting, audit, anti-fraud, disputes, litigation, information requests or lawful requests from authorities. | Legal obligation and legitimate interests. |
| Send marketing communications | Name, email address, phone number, marketing preferences and consent records. | Consent, or the limited existing-customer basis allowed by POPIA for electronic direct marketing, with an opt-out/unsubscribe mechanism. |
Event-related communications, such as wedding invitations, RSVP reminders, venue updates, schedule changes, seating changes and guest logistics, are service communications sent for the purpose of managing the relevant event. They are not intended to be marketing communications from Gatherlane.
Where an Event Owner uploads or enters Guest details, the Event Owner confirms that the Event Owner has a lawful basis to provide that information to Gatherlane and to request Gatherlane to send event-related communications to the relevant Guests.
Guests may request that their details be corrected or removed from an event by contacting the Event Owner or Gatherlane at privacy@gatherlane.events. Gatherlane may need to verify the request and may refer certain requests to the Event Owner where the Event Owner is the Responsible Party for the relevant Guest information.
Where the Platform allows Guests or other users to make gifts, donations, registry contributions, ticket purchases or other payments, payment processing may be handled by a third-party payment provider. Gatherlane does not intend to store full card numbers, CVV numbers, online banking login details or equivalent sensitive payment credentials.
We may process limited payment-related information such as payer name, email address, payment reference, payment status, transaction amount, date, refund status, payout reference, support correspondence and fraud or chargeback indicators. This information is used to process payments, issue confirmations, reconcile payments, support payouts, deal with refunds or disputes, maintain accounting records, prevent fraud and comply with legal obligations.
Donation, gift registry and payment features must also be governed by separate commercial terms dealing with fees, refund rules, payment gateway terms, chargebacks, payout timing, abandoned payments and the role of Gatherlane in relation to funds. If Gatherlane receives, holds or transfers funds on behalf of couples, Vendors or Guests, Gatherlane should maintain appropriate payment, financial, tax, consumer and anti-fraud controls and obtain feature-specific legal advice before launching or materially expanding that functionality.
The Platform may allow Event Owners and Guests to upload photos, videos, captions or other media to an event gallery. When a Guest uploads media, the upload form should explain who can view the media, whether it will first be moderated, whether the Event Owner may download it, and how the Guest can request deletion.
Unless expressly stated otherwise, uploading media does not transfer copyright in the media to Gatherlane or to the Event Owner. The uploader remains responsible for ensuring that they have the right to upload the media and that the media does not unlawfully infringe another person's rights, privacy, dignity, intellectual property or image rights.
Approved media may be displayed on the relevant event page, depending on the Event Owner's settings. We may remove or restrict media where required by law, by a valid complaint, by the Event Owner's instructions, or to protect the rights, privacy, safety or security of users or third parties.
Gatherlane may allow Vendors to create vendor profiles or pages and to submit information through the Platform. Vendors may receive personal information where necessary to respond to enquiries, provide quotes, manage bookings, provide services, issue invoices or deal with disputes.
Where a Vendor independently decides how to use personal information, the Vendor may be a separate Responsible Party under POPIA. Vendors must process personal information lawfully, securely and only for the purposes for which it was shared or collected. Vendors should maintain their own privacy notices and must comply with POPIA and any Vendor Agreement or operator/data processing terms that apply.
Gatherlane may require Vendors to accept service provider, operator, data processing, confidentiality, security and privacy obligations through their vendor page, onboarding form, Vendor Agreement or related documentation.
We do not sell personal information. We may share personal information only where necessary for the purposes described in this Policy, where you have consented, where the Event Owner has instructed us to do so, where sharing is required by law, or where POPIA otherwise allows it.
| Recipient / category | Purpose | Examples of information shared |
|---|---|---|
| Event Owners | To manage the event, invitations, RSVPs, guest lists, seating, meals, donations and media galleries. | Guest names, contact details, RSVP responses, dietary or accessibility notes, gift/donation confirmations, uploaded media and guest messages. |
| Guests and public event page visitors | To display event information and approved public content according to the event settings. | Event details, venue information, schedule, approved gallery content and public vendor/profile information where applicable. |
| Vendors | To facilitate vendor bookings, enquiries, quotes, service delivery and reviews. | Contact details, event details, booking details and communications necessary for the relevant service. |
| Payment providers | To process payments, refunds, chargebacks, fraud checks and payouts. | Payer details, transaction amount, payment reference, billing information and payout details required by the provider. |
| Hosting, database and cloud storage providers | To host the Platform, store data and deliver media. | Account data, event data, guest data, media files, technical logs and related records. |
| Email, WhatsApp, SMS and communication providers | To send invitations, updates, reminders, confirmations and support messages. | Name, email address, phone number and message content. |
| Authentication providers | To allow sign-in through third-party services such as Google sign-in. | Name, email address, profile image and authentication identifiers. |
| Analytics, security and error monitoring providers | To monitor performance, prevent abuse, detect errors and improve the Platform. | Technical data, usage data, IP address, device information and error logs. |
| Professional advisers, auditors and insurers | To obtain legal, accounting, audit, insurance and compliance assistance. | Relevant records necessary for the advice, audit, claim or compliance matter. |
| Regulators, courts, law enforcement and public authorities | To comply with legal processes, lawful requests, statutory obligations and regulatory requirements. | Information required by law or reasonably necessary to protect rights, safety or legal interests. |
| Business transfer recipients | For a merger, acquisition, financing, restructuring or sale of all or part of the business. | Relevant business records and user information subject to appropriate confidentiality and privacy safeguards. |
The service provider list below reflects the current Platform information made available for the drafting of this Policy. Gatherlane must keep this list reasonably accurate and update it when material service providers or data locations change.
| Provider | Purpose | Information involved | Likely location / transfer |
|---|---|---|---|
| Paystack | Payment processing and payouts, including ticket sales, tier upgrades, add-ons and vendor payouts. | Name, email address, payment reference, transaction information, vendor payout/bank details. | Nigeria / Africa / other provider locations. |
| Cloudinary | Photo and video storage and delivery. | Media files, upload metadata and related technical data. | United States / European Union / other provider locations. |
| Resend | Transactional email delivery. | Name, email address and email content. | United States / other provider locations. |
| Twilio | WhatsApp invitations, confirmations and reminders. | Phone number and message content. | United States / global provider locations. Messages are relayed via Meta's WhatsApp Business platform. |
| Google sign-in authentication and related account features. | Google profile data and authentication identifiers. | United States / global provider locations. | |
| Sentry | Application error monitoring. | Error logs, technical data and possible partial request data. | United States / other provider locations. |
| Neon PostgreSQL | Primary database hosting for production. | Stored platform data and related records. | European Union, Neon eu-west-2 region / United States / other provider locations. |
| Redis Cloud | Caching, rate limiting and session support. | Session identifiers, IP addresses and technical data. | European Union / United States / other provider locations. |
| Anthropic / Claude API | AI-assisted event creation, seating arrangement and design-style features. | User-submitted event content/prompts and generated design data. | United States. |
| Cloudflare Turnstile | Bot/CAPTCHA verification on login and registration. | IP address, browser/device signals and interaction data. | United States / global provider locations. |
Where a third-party service provider processes personal information on our behalf, we require appropriate contractual safeguards, including obligations to process personal information only on documented instructions, keep it confidential, apply appropriate security measures, assist with data subject requests where appropriate, notify us of security incidents, and return, delete or securely retain personal information when the service ends, subject to lawful retention requirements.
Where Gatherlane acts as an Operator for an Event Owner, Gatherlane will process Guest information only for the agreed event-management purposes and in accordance with POPIA, the Platform terms and any applicable data processing agreement or operator terms.
Some service providers, systems or support personnel may be located outside South Africa. This means that personal information may be transferred to, stored in or accessed from countries outside South Africa.
Where POPIA applies to a cross-border transfer, we will take reasonable steps to ensure that the transfer is permitted under POPIA. This may include confirming that the recipient is subject to a law, binding corporate rules or contract that provides an adequate level of protection, obtaining consent where appropriate, transferring information where necessary for performance of a contract, or relying on another basis allowed by POPIA.
By using the Platform, you acknowledge that international transfers may be necessary to provide the Platform, including cloud hosting, email delivery, payment processing, media storage, security monitoring and analytics.
We take reasonable, appropriate technical and organisational measures to protect personal information against loss, damage, unauthorised access, unauthorised disclosure and unlawful processing. Measures may include:
No electronic platform is completely secure. Users must protect their own accounts, devices and login credentials and should notify us immediately if they suspect unauthorised access or misuse.
If there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will take steps required by POPIA, including assessing the incident, taking containment and remedial measures, notifying the Information Officer, notifying the Information Regulator and affected data subjects where required, and providing information reasonably necessary for affected data subjects to take protective measures.
Where a security compromise occurs at one of our Operators or service providers, that Operator or service provider must notify us as soon as reasonably possible so that we can comply with our POPIA obligations.
We use cookies and similar technologies to operate the Platform, keep users signed in, remember preferences, secure the Platform, understand performance and usage, and improve our services. Some cookies are essential for the Platform to work. Others, such as analytics or marketing cookies, may depend on your cookie preferences and applicable law.
For more details, including how to manage cookie choices, please read our Cookie Policy.
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected or further processed, unless the law requires or permits a longer period. Retention periods may depend on the nature of the information, the relevant feature, legal obligations, accounting requirements, dispute risks, security needs and user choices.
When personal information is no longer required, we will delete, destroy, de-identify or anonymise it in a lawful and secure manner, subject to backup cycles and legal retention exceptions.
| Information category | Indicative retention period |
|---|---|
| Account information | For the duration of the account and for a reasonable period after deletion, generally up to 30 to 90 days, unless required for legal, accounting, security or dispute purposes. |
| Event pages and wedding details | For the duration of the event and the archive period selected by the Event Owner, then deleted or anonymised unless a longer period is required or requested. |
| Guest lists and RSVP information | For the duration of the event and a reasonable post-event period, generally 6 to 12 months unless the Event Owner selects a different archive period, the Guest requests earlier deletion, or retention is required for legal or dispute purposes. |
| Photos, videos and event media | For the duration of the event archive or until removed by the Event Owner, the uploader or Gatherlane in accordance with the Platform terms, subject to technical backup cycles and lawful retention exceptions. |
| Payment, donation, registry and payout records | For as long as required for payment reconciliation, refunds, chargebacks, tax, accounting, audit and legal obligations. This may generally be 5 to 7 years depending on the record and applicable law. |
| Support correspondence and complaints | Generally up to 3 years after the last interaction, or longer where needed for legal claims, complaints or regulatory matters. |
| Security logs and audit logs | For a reasonable period required for security, fraud prevention, platform integrity, disputes and compliance, generally at least 2 years where appropriate. |
| Marketing records and consent records | Until you unsubscribe or withdraw consent, plus a reasonable period to maintain suppression lists and proof of consent or opt-out. |
| Anonymised or aggregated analytics | May be kept indefinitely where it can no longer reasonably identify a data subject. |
Subject to POPIA and other applicable laws, you may have the following rights in relation to your personal information:
Some rights may be limited where we are required or permitted to retain information by law, where another person's rights would be affected, where the request is manifestly unfounded or excessive, or where another lawful exception applies.
To exercise a privacy right, please contact us at privacy@gatherlane.events with the subject line "Privacy Request - [Your Name]" and provide enough information for us to identify you and understand your request.
We may ask you to verify your identity before acting on a request. Where the request relates to Guest information controlled by an Event Owner, we may involve or refer the request to the relevant Event Owner. We aim to respond as soon as reasonably practicable and generally within 30 days, unless the nature of the request or applicable law requires a different period.
We will not send electronic direct marketing to you unless POPIA allows it. This generally means that we will obtain your consent before sending marketing communications, unless you are an existing customer and POPIA permits limited marketing of our own similar products or services, subject to a clear opportunity to opt out.
Every marketing email, SMS, WhatsApp message or similar electronic marketing communication should identify the sender and include a simple unsubscribe or opt-out mechanism. Service communications about an event, account, payment, security matter, booking or support request are treated separately from marketing communications.
The Platform is not directed at children under the age of 18. We do not knowingly create accounts for children or market the Platform to children.
Event Owners may include child Guests in a guest list or event arrangement. Where children's personal information is processed, the Event Owner must ensure that a parent, guardian or competent person has provided consent where required, or that another lawful basis under POPIA applies. If you believe that a child's personal information has been provided to us unlawfully, please contact us at privacy@gatherlane.events.
Event Owners play an important role in protecting Guest personal information. By using the Platform to upload, enter or process Guest information, Event Owners agree to:
The Platform may link to third-party websites, payment gateways, gift registries, vendor websites, accommodation sites, map services, social media platforms or other external services. Those third parties may process personal information under their own privacy policies and terms. We are not responsible for the privacy practices of third-party websites or services that we do not control.
We may use automated tools for security, fraud detection, spam prevention, rate limiting, analytics, error monitoring and platform performance. We do not intend to make decisions based solely on automated processing that have legal or similarly significant effects on users, unless we notify you and POPIA allows it.
Where required, Gatherlane will make available a PAIA Manual containing information about how to request access to records held by Gatherlane. Requests for access to records may be directed to the Information Officer using the details in this Policy or the PAIA Manual.
Gatherlane may publish a short summary on the website and provide the full PAIA Manual as a downloadable document or make it available on request. The publication approach may depend on the Platform design, but the full manual should remain available and kept up to date.
We may update this Policy from time to time. The latest version will be published on the Platform with the effective date or last updated date. Where changes are material and POPIA or another applicable law requires notice, we will take reasonable steps to notify affected users, for example by email, platform notice or another appropriate method.
For privacy questions, requests or complaints, please contact:
| Contact | Details |
|---|---|
| Gatherlane privacy email | privacy@gatherlane.events |
| Information Officer | Frank Boateng, Director, or any duly authorised replacement registered with the Information Regulator |
| Registered office / physical address | 25 Hill Park, 27 Carisbrook Street, Cape Town, Western Cape, 8001, Republic of South Africa |
If you are not satisfied with our response, you may complain to the Information Regulator (South Africa):
| Regulator | Contact details |
|---|---|
| Information Regulator (South Africa) | Website: www.inforegulator.org.za · POPIA complaints: POPIAComplaints@inforegulator.org.za · General enquiries: enquiries@inforegulator.org.za |