Beloved Promises
How It WorksSamplesPricingFAQAboutContact Us
How It WorksSamplesPricingFAQAboutContact Us

Privacy Policy

Effective date: 14 July 2026
Last updated: 12 August 2026

1. About this Privacy Policy

Corevia Studios Pte. Ltd., trading as Beloved Promises, respects your privacy and is committed to handling personal data responsibly.

This Privacy Policy explains how we collect, use, disclose, store, protect, transfer and otherwise process personal data when you:

  • visit the Beloved Promises website;
  • create or use a Beloved Promises account;
  • create, edit, publish or manage a wedding digital experience;
  • view a published digital experience;
  • submit an RSVP or another response;
  • make a payment;
  • communicate with us; or
  • otherwise use our digital experience builder, digital experience pages and related services.

This Privacy Policy is primarily intended to address our obligations under the Singapore Personal Data Protection Act 2012, including its applicable regulations and amendments.

In this Privacy Policy:

  • “Beloved Promises”, “we”, “us” and “our” refer to Corevia Studios Pte. Ltd.
  • “Experience Creator” refers to a couple or authorised account holder who creates or manages a digital experience.
  • “Guest” refers to an individual who views or responds to a digital experience.
  • “Services” refers to our website, accounts, digital experience builder, published digital experience pages, RSVP functions and related services.
  • “Personal data” means data, whether true or not, about an individual who can be identified from that data alone or together with other information to which an organisation has or is likely to have access.

2. Our details

Company: Corevia Studios Pte. Ltd.
UEN: 202624870W
Trading name: Beloved Promises
Registered address: 07 Seletar Road, Singapore 807014
Data Protection Officer: Marcus Tan
Privacy contact: hello@coreviastudios.com

3. Who this Privacy Policy applies to

This Privacy Policy applies to:

Experience Creators

Couples or authorised account holders who create, edit, publish and manage digital experiences through Beloved Promises.

Guests

People who view a published digital experience, submit an RSVP, provide Guest information, leave a message or otherwise respond through a digital experience.

Website visitors and enquirers

People who browse our website, contact us, submit an enquiry or otherwise interact with Beloved Promises without creating an account.

4. Our role in handling Guest information

Experience Creators decide which RSVP questions are presented to their Guests and generally determine why Guest information is collected for their wedding.

When Beloved Promises processes RSVP and Guest information solely to provide the digital experience and RSVP management service for an Experience Creator, we may act as a data intermediary processing personal data on behalf of that Experience Creator.

The Experience Creator remains responsible for:

  • ensuring that the Guest information requested is appropriate;
  • informing Guests how their information will be used;
  • obtaining any consent required from Guests;
  • protecting exported or downloaded Guest information; and
  • complying with applicable obligations relating to their own use of Guest information.

Beloved Promises remains responsible for the obligations that apply to us when acting as a data intermediary.

Where we use limited Guest information independently for purposes such as operating and securing the Services, investigating misuse, responding to support requests or complying with the law, we process that information in our own capacity for those purposes.

5. Personal data we collect

The information we collect depends on how you use Beloved Promises.

5.1 Account and authentication information

When you create or use an account, we may collect:

  • your name;
  • email address;
  • telephone number;
  • account identifiers;
  • login and authentication information;
  • one-time password and verification records;
  • account settings and preferences;
  • account status;
  • dates and times of account activity; and
  • communications associated with your account.

5.2 Digital experience and wedding information

Experience Creators may enter, upload or publish information including:

  • the couple’s names;
  • photographs and images;
  • videos;
  • music and audio files;
  • wedding dates and times;
  • venue names and addresses;
  • maps, directions and transport information;
  • wedding schedules and programmes;
  • family information;
  • contact details;
  • stories, messages and written content;
  • important notices;
  • bank transfer, gift or payment information;
  • design, colour and display preferences; and
  • other information voluntarily included in a digital experience.

Experience Creators decide what information is included in their digital experiences and are responsible for ensuring that they have permission to provide and publish information concerning other people.

5.3 RSVP and Guest information

When a Guest responds through a digital experience, we may collect:

  • the Guest’s name;
  • attendance response;
  • telephone number or email address;
  • dietary requirements or meal preferences;
  • plus-one details;
  • names or details of accompanying Guests;
  • transport requirements;
  • messages or wishes;
  • responses to custom questions;
  • the date and time of the response; and
  • other information voluntarily submitted through the RSVP form.

Some RSVP answers, including dietary requirements, may reveal private information. Experience Creators should only ask questions that are reasonably necessary to organise their wedding or related event.

5.4 Payment and transaction information

Payments are processed through Stripe.

Beloved Promises does not directly store complete payment card numbers, card security codes or online banking passwords.

We may collect or retain limited payment and transaction information, including:

  • billing name;
  • transaction reference;
  • payment status;
  • product or service purchased;
  • amount paid;
  • invoice information;
  • receipt information;
  • refund information; and
  • payment dispute information.

Information submitted directly to Stripe is also processed under Stripe’s own terms and privacy practices.

5.5 Communications and support information

When you contact us, we may collect:

  • your name;
  • email address;
  • telephone number;
  • the contents of your enquiry;
  • screenshots, documents or files you provide;
  • support and communication history;
  • feedback;
  • survey responses;
  • complaint information; and
  • other information needed to investigate or respond to your request.

5.6 Technical, security and usage information

When you use the Services, we may automatically collect information including:

  • internet protocol address;
  • browser type;
  • device type;
  • operating system;
  • device and browser settings;
  • referring page;
  • pages and features accessed;
  • date and time of access;
  • session and authentication information;
  • approximate location derived from technical information;
  • performance and diagnostic information;
  • error records;
  • security and access logs; and
  • cookie, local storage or similar technology information.

5.7 Marketing preferences and consent records

Where marketing features are introduced, we may collect:

  • whether you agreed to receive marketing;
  • the channels to which you agreed;
  • the date, time and method of consent;
  • changes to your marketing preferences;
  • unsubscribe requests; and
  • records reasonably required to demonstrate consent or withdrawal.

6. How we collect personal data

We may collect personal data:

  • directly from you;
  • when you create or access an account;
  • when you build or publish a digital experience;
  • when you submit an RSVP;
  • when an Experience Creator provides information about you;
  • when you contact our support team;
  • through payment, authentication, hosting and email providers;
  • automatically through analytics, logs, cookies and similar technologies;
  • through security and fraud-prevention systems; and
  • from other sources where collection is permitted by law.

If you provide personal data about another person, you confirm that:

  • the information is accurate to the best of your knowledge;
  • you are authorised to provide it;
  • you have informed the person of the relevant purposes where required; and
  • you have obtained any necessary permission or consent.

This applies to photographs, contact details, Guest information, family information, information about children and other content relating to another person.

7. Why we collect, use and disclose personal data

We collect, use and disclose personal data only for purposes that are reasonable and appropriate in the circumstances.

7.1 Providing and administering the Services

We may use personal data to:

  • register and maintain accounts;
  • authenticate account access;
  • send one-time passwords;
  • provide the digital experience builder;
  • save digital experience drafts and settings;
  • publish and host digital experiences;
  • display content selected by Experience Creators;
  • collect and organise RSVP responses;
  • display RSVP information to the relevant couple;
  • allow RSVP information to be exported in CSV format;
  • process payments, refunds and purchases;
  • issue invoices and receipts;
  • send operational notifications;
  • respond to enquiries;
  • provide support; and
  • administer account or digital experience deletion.

7.2 Communicating with users

We may use contact information to send:

  • one-time passwords;
  • account verification messages;
  • payment confirmations;
  • invoices and receipts;
  • RSVP-related notifications;
  • security alerts;
  • changes affecting an active digital experience;
  • service announcements;
  • responses to support enquiries; and
  • notices about material changes to our terms or policies.

These are service-related communications and are not treated as optional marketing messages.

7.3 Operating and improving Beloved Promises

We may use information to:

  • understand how the Services are used;
  • monitor platform performance;
  • diagnose and correct errors;
  • improve usability and reliability;
  • test features and system changes;
  • develop new functions;
  • maintain our internal analytics dashboard;
  • conduct internal research;
  • produce aggregated statistics; and
  • improve the experience for Experience Creators and Guests.

Where reasonably possible, we use aggregated or anonymised information for analytics and product development.

7.4 Security and prevention of misuse

We may process information to:

  • protect accounts and digital experiences;
  • prevent unauthorised access;
  • detect suspicious activity;
  • prevent fraud, spam and abuse;
  • investigate security incidents;
  • enforce our Terms of Service;
  • maintain security and audit records;
  • protect Beloved Promises and its users; and
  • resolve disputes or complaints.

7.5 Legal and administrative purposes

We may process information to:

  • comply with applicable laws and regulations;
  • maintain accounting and tax records;
  • respond to lawful requests from public authorities;
  • establish, exercise or defend legal claims;
  • manage complaints and investigations;
  • conduct audits and risk assessments;
  • protect our legal rights;
  • manage insurance matters; and
  • support a merger, acquisition, financing, restructuring or transfer of our business.

8. Consent and other permitted processing

Where consent is required, we will inform you of the purposes for which personal data is being collected, used or disclosed on or before collecting that information.

By voluntarily providing personal data after being informed of the relevant purposes, you consent to our collection, use and disclosure of that information for those purposes.

In appropriate circumstances, we may also collect, use or disclose personal data:

  • where consent is deemed under applicable law;
  • where processing is necessary to perform a contract or take steps requested by you;
  • where necessary to respond to an emergency;
  • for legitimate interests where the legal requirements are satisfied;
  • for business improvement purposes where permitted;
  • for investigations or legal proceedings; or
  • where another exception under applicable law applies.

We will not rely on an exception merely because it is convenient. We will assess whether the relevant legal conditions apply.

9. Withdrawal of consent

You may withdraw consent for our continued collection, use or disclosure of personal data by contacting our Data Protection Officer.

Before completing the request, we may:

  • verify your identity;
  • clarify which consent you wish to withdraw;
  • explain the likely consequences of withdrawal; and
  • request information reasonably required to process the request.

After receiving reasonable notice of withdrawal, we will stop collecting, using or disclosing the relevant personal data unless continued processing is permitted or required by law.

Withdrawal of consent does not affect processing that occurred before the withdrawal.

Depending on the information involved, withdrawal may mean that we can no longer:

  • maintain your account;
  • host your digital experience;
  • process RSVP responses;
  • provide particular features; or
  • continue providing some or all of the Services.

10. Experience Creator responsibilities

Experience Creators must:

  • request only Guest information reasonably needed for their wedding;
  • explain how Guest information will be used;
  • avoid collecting unnecessary or excessively intrusive information;
  • ensure that information included in a digital experience is accurate;
  • obtain permission before uploading another person’s personal data;
  • protect exported RSVP information;
  • securely store downloaded CSV files;
  • limit access to Guest information;
  • avoid using Guest information for unrelated purposes without consent; and
  • delete downloaded information when it is no longer needed.

When an Experience Creator exports information from Beloved Promises, the Experience Creator becomes responsible for protecting that exported copy.

11. Published and unpublished digital experiences

Experience Creators can publish or unpublish a digital experience.

11.1 Published digital experiences

When a digital experience is published:

  • anyone who has or obtains the digital experience link may view it;
  • the digital experience link may be forwarded to other people;
  • recipients may copy, download or take screenshots of digital experience content;
  • the digital experience may be discovered or indexed by search engines or other online services; and
  • Beloved Promises cannot control how recipients independently use information after accessing it.

A published digital experience should not be treated as confidential merely because its link was originally shared with a limited group.

Experience Creators should carefully consider whether to display:

  • personal telephone numbers;
  • residential addresses;
  • banking or gift details;
  • information about children;
  • private family information;
  • sensitive photographs; or
  • any information they would not want unintended recipients to see.

11.2 Unpublished digital experiences

When a digital experience is unpublished:

  • it is not available to Guests through the public digital experience page;
  • people who previously received the public link cannot use that page to view the unpublished digital experience; and
  • access through the user interface is limited to the authorised account holder.

Unpublished digital experience data may still be accessed by authorised Beloved Promises personnel and service providers where reasonably necessary for security, maintenance, support, legal compliance or service operation.

Unpublishing a digital experience does not remove screenshots, downloads or copies previously made by other people.

12. Marketing communications

Beloved Promises does not automatically enrol Experience Creators or Guests in marketing merely because they create an account, publish a digital experience or submit an RSVP.

If we introduce marketing communications:

  • marketing consent will be requested separately where required;
  • accepting this Privacy Policy will not automatically amount to marketing consent;
  • Guests will not automatically receive marketing because they submitted an RSVP;
  • users will be able to select or manage their marketing preferences;
  • each applicable marketing communication will provide a reasonable way to unsubscribe; and
  • withdrawal from marketing will not stop essential service communications.

Marketing channels may include:

  • email;
  • SMS;
  • WhatsApp;
  • telephone calls; and
  • push notifications.

For marketing sent to Singapore telephone numbers, we will comply with the applicable Do Not Call provisions. Where required, we will either obtain clear and unambiguous consent in a form that can be evidenced or check the relevant Do Not Call Register before sending the message.

We will also provide the sender’s required contact information and will not conceal calling-line identity where the law prohibits this.

This section covers marketing messages we send to you directly. Online advertising, including how we measure our advertising and reach people who may be interested in the Services, is described in section 15.

13. Community posts and promotional content

Beloved Promises may invite individuals to allow selected digital experience content, photographs, testimonials, stories or messages to be featured in community posts, social media or promotional materials.

Such use is not automatic.

We will obtain separate and specific consent from the person whose identifiable personal data is being used.

In particular:

  • a couple may consent to the use of content and personal data relating to the couple;
  • a Guest must separately consent before we use that Guest’s name, photograph, message, contact information or RSVP information;
  • consent from the couple does not automatically authorise us to use a Guest’s personal data;
  • a person providing a photograph must have appropriate permission from other identifiable people shown in it; and
  • consent may be withdrawn for future uses by contacting us.

Where content has already been lawfully published or distributed before consent is withdrawn, we may not be able to retrieve every existing copy. We will take reasonable steps to stop future use under our control.

14. Artificial intelligence

Beloved Promises does not currently use artificial intelligence systems to:

  • analyse RSVP responses;
  • process Guest personal data;
  • generate digital experience text;
  • edit uploaded images;
  • process uploaded digital experience content; or
  • provide automated customer support.

If we introduce an artificial intelligence feature that processes personal data, we will update this Privacy Policy and provide any additional notice or consent controls required before using personal data for the new purpose.

15. Analytics, cookies and similar technologies

We currently use:

  • Vercel Analytics;
  • Google Analytics 4;
  • Meta Pixel; and
  • an internal analytics dashboard.

These tools may help us understand:

  • page visits;
  • feature usage;
  • device and browser information;
  • platform performance;
  • errors;
  • referral sources; and
  • aggregated usage patterns.

Google Analytics 4 receives only general website-usage information such as the page visited, the referring source, and device, browser and approximate location information. We do not send names, email addresses, phone numbers, account details, guest or RSVP information, digital experience content, uploaded files or payment information to Google Analytics.

Meta Pixel is provided by Meta Platforms. We use it to measure how well our advertising works and to help us reach people who may be interested in the Services. It receives only general website-usage information such as the page visited, the referring source, and device, browser and approximate location information, together with identifiers that Meta sets or reads through cookies and similar technologies. We do not send names, email addresses, phone numbers, account details, guest or RSVP information, digital experience content, uploaded files or payment information to Meta. We have not enabled Meta’s advanced matching features, which would transmit contact details in hashed form.

Meta differs from our other analytics providers in one respect worth stating plainly: it also processes the information it receives for its own purposes under its own terms and privacy practices, including advertising measurement and the creation of advertising audiences. You can manage how Meta uses information about you for advertising through the ad preferences in your Meta account, and you can block or delete cookies through your browser settings as described below.

Published digital experience pages and the RSVP form are part of the Services and may load the Meta Pixel in the same way as our other pages. Nothing a Guest enters in an RSVP is sent to Meta.

We do not currently use:

  • TikTok Pixel;
  • Microsoft Clarity; or
  • third-party session-recording tools.

We may use cookies, local storage and similar technologies to:

  • maintain secure sessions;
  • keep users signed in;
  • remember preferences;
  • operate digital experience and RSVP features;
  • prevent fraud and misuse;
  • measure performance;
  • support analytics;
  • measure and improve our advertising; and
  • diagnose technical problems.

You may block or delete cookies through your browser settings. Disabling technologies that are necessary for the Services may prevent certain account, digital experience or RSVP features from working properly.

Where applicable law requires consent for non-essential cookies or similar technologies, we will provide an appropriate notice or preference control before using them.

If we introduce additional analytics, advertising pixels or session-recording tools, we will update this Privacy Policy and provide any required controls.

16. Who we disclose personal data to

We may disclose personal data only where reasonably necessary for the purposes described in this Privacy Policy.

16.1 Experience Creators and Guests

RSVP information is made available to the Experience Creator responsible for the relevant digital experience.

Information included in a digital experience is displayed to people who access it once it is published.

16.2 Technology and service providers

We use service providers including:

  • Vercel for website hosting, deployment and analytics;
  • Google for website analytics (Google Analytics 4);
  • Meta for advertising measurement (Meta Pixel);
  • DigitalOcean for application, database and infrastructure services;
  • Cloudflare for domain, network, security and content-delivery services;
  • Cloudflare R2 for storing uploaded photographs, videos, music and other files;
  • Resend for one-time passwords and transactional email delivery;
  • Stripe for payment processing; and
  • other security, infrastructure, professional or backup providers required to operate the Services.

These providers may process personal data for us under their applicable agreements and data-protection terms.

Meta is an exception to that description: as explained in section 15, Meta also processes the information it receives through the Meta Pixel for its own purposes, and not solely on our instructions.

Using a service provider does not remove our responsibility to take reasonable steps to select, manage and oversee providers appropriately.

16.3 Professional advisers

We may disclose information to:

  • lawyers;
  • accountants;
  • auditors;
  • insurers; and
  • other professional advisers.

16.4 Public authorities and legal recipients

We may disclose information where required or permitted by law, including to:

  • courts;
  • government agencies;
  • regulators;
  • law-enforcement authorities; and
  • parties involved in legal proceedings.

16.5 Business transactions

If Corevia Studios Pte. Ltd. is involved in a proposed or completed merger, acquisition, financing, restructuring, transfer or sale of its business or assets, personal data may be disclosed to relevant parties subject to appropriate confidentiality and data-protection arrangements.

We do not sell personal data to third parties for monetary consideration.

17. Transfers outside Singapore

Our primary application databases may be hosted in Singapore.

However, our cloud and technology service providers may operate infrastructure, support teams or processing systems in multiple countries. Personal data may therefore be transmitted to, processed in, stored in or accessed from locations outside Singapore.

Where personal data is transferred outside Singapore, we will take appropriate steps to ensure that the transferred personal data receives a standard of protection comparable to that required under the Singapore Personal Data Protection Act.

Depending on the circumstances, these steps may include:

  • contractual data-protection obligations;
  • data-processing agreements;
  • binding corporate rules;
  • specified certifications recognised under applicable regulations;
  • technical and organisational security measures;
  • access restrictions;
  • encryption where appropriate;
  • assessments of the recipient and transfer; and
  • limiting the type and amount of information transferred.

We will not claim that a service provider holds a particular privacy certification unless we have verified that certification.

18. Retention of personal data

We retain personal data only for as long as it is reasonably required for a legal or business purpose.

18.1 Unpaid digital experiences

An unpaid digital experience or unpaid digital experience draft is scheduled for deletion seven days after its creation.

18.2 Paid digital experiences

A paid digital experience and its associated digital experience content will generally remain available until the earlier of:

  • 330 days after the digital experience’s creation date; or
  • 30 days after the wedding date.

18.3 RSVP and Guest information

RSVP responses, Guest details and related information will be deleted when the relevant digital experience expires or is deleted, subject to:

  • temporary backup retention;
  • unresolved disputes;
  • security investigations; and
  • applicable legal requirements.

18.4 Uploaded photographs, videos and music

Uploaded photographs, videos, music and other digital experience files will be deleted when the related digital experience expires or is deleted, subject to temporary backup retention and applicable legal requirements.

18.5 Account deletion

When an account-deletion request has been verified and completed, we will delete information associated with the account from our active systems, including:

  • published digital experiences;
  • unpublished digital experiences;
  • RSVP responses;
  • Guest information;
  • photographs;
  • videos;
  • music; and
  • other digital experience content.

Certain information may continue to be retained where necessary for:

  • accounting and tax requirements;
  • payment and transaction records;
  • fraud prevention;
  • security investigations;
  • dispute resolution;
  • legal claims; or
  • compliance with applicable law.

18.6 Backups

Backup copies may be retained for up to 90 days before being overwritten or deleted through the applicable backup cycle.

Information retained only in backups will not ordinarily be used for regular business activities.

18.7 Security and access logs

Security, system and access logs may be retained for up to 12 months.

18.8 Support communications

Support enquiries and associated communications may be retained for up to two years after the enquiry is resolved.

18.9 Payment and accounting records

Payment, invoice, receipt and transaction records may be retained for the period required under applicable accounting, tax and legal obligations.

18.10 Consent and privacy-request records

Records relating to consent, withdrawal of consent, access requests, correction requests, complaints and privacy investigations may be retained for as long as reasonably required to:

  • demonstrate compliance;
  • respond to a dispute;
  • establish legal rights; or
  • meet legal obligations.

When information is no longer required for a legal or business purpose, we will take reasonable steps to securely delete, destroy or anonymise it.

19. Account and digital experience deletion

Account holders may request deletion through the Contact Us page or by emailing our Data Protection Officer.

Before processing a deletion request, we may:

  • verify the requester’s identity;
  • confirm which account is concerned;
  • request information reasonably required to locate the account;
  • explain the consequences of deletion; and
  • address outstanding payments, disputes or security matters.

Once completed, account deletion is permanent. The account, digital experiences, RSVP information and uploaded content may not be recoverable.

Some copies may remain temporarily in backups for up to the backup retention period. Certain legal, transaction, security and accounting records may also be retained as explained in this Privacy Policy.

20. Security of personal data

We use reasonable administrative, organisational and technical measures designed to protect personal data against:

  • unauthorised access;
  • unauthorised collection, use or disclosure;
  • accidental loss;
  • copying;
  • alteration;
  • misuse;
  • destruction; and
  • similar risks.

Depending on the circumstances, our measures may include:

  • account authentication;
  • one-time password verification;
  • access restrictions;
  • secure communications;
  • encryption where appropriate;
  • infrastructure and application monitoring;
  • logging;
  • backups;
  • software updates;
  • vulnerability management;
  • internal access controls; and
  • confidentiality and data-protection obligations for service providers.

No internet transmission, website or data-storage system can be guaranteed to be completely secure.

Users are responsible for:

  • protecting access to their email account;
  • not sharing one-time passwords;
  • limiting who receives a digital experience link;
  • keeping downloaded RSVP files secure;
  • using secure devices; and
  • promptly notifying us of suspected unauthorised access.

21. Accuracy of personal data

We take reasonable steps to ensure that personal data is accurate and complete where the information is likely to:

  • be used to make a decision affecting the individual; or
  • be disclosed to another organisation.

Experience Creators are responsible for reviewing and updating their account and digital experience information.

Guests who wish to correct an RSVP response may:

  • contact the relevant Experience Creator; or
  • submit a request to our Data Protection Officer.

22. Access and correction requests

Subject to applicable exceptions, you may request:

  • access to personal data about you that is in our possession or under our control;
  • information about how that data has been or may have been used or disclosed within the period covered by applicable law; or
  • correction of an error or omission in your personal data.

Requests may be submitted through our Contact Us page or by emailing hello@coreviastudios.com.

Your request should include sufficient information for us to:

  • verify your identity;
  • identify the relevant account, digital experience or RSVP;
  • understand the information requested; and
  • respond securely.

We will respond as soon as reasonably possible.

If we are unable to respond within 30 days after receiving a valid request, we will inform you in writing within that period of the time by which we expect to respond.

Access or correction may be refused or limited where an exception under applicable law applies.

We may charge a reasonable fee for processing an access request where permitted. If a fee applies, we will provide a written estimate before processing the request.

Where the requested information is controlled by an Experience Creator and Beloved Promises processes it solely as a data intermediary, we may refer or coordinate the request with the relevant Experience Creator.

23. Privacy complaints

Privacy complaints may be submitted through our Contact Us page or to our Data Protection Officer.

Please include:

  • your name and contact details;
  • a description of the concern;
  • the account, digital experience or response concerned;
  • relevant dates;
  • any supporting screenshots or documents; and
  • the outcome you are requesting.

We may contact you for additional information and will investigate the complaint in a fair and reasonable manner.

24. Personal data breaches

We maintain procedures for identifying, containing, assessing, investigating and responding to suspected personal data breaches.

Where we have reason to believe that a data breach has occurred, we will assess whether it is notifiable under applicable law.

A breach may be notifiable where it:

  • is likely to result in significant harm to affected individuals; or
  • is of a significant scale under applicable requirements.

Where notification is required, we will notify the Personal Data Protection Commission as soon as practicable and no later than the applicable statutory deadline after determining that the breach is notifiable.

We will notify affected individuals as soon as practicable where notification to those individuals is required.

Notifications may include information about:

  • what happened;
  • the personal data affected;
  • the potential consequences;
  • the steps we have taken;
  • recommended protective actions; and
  • how affected individuals can contact us.

Suspected breaches, exposed digital experience information or unauthorised account access should be reported promptly to hello@coreviastudios.com.

25. Users below 18 years old

An individual must be at least 18 years old to create and manage a Beloved Promises account independently.

An individual below 18 may use Beloved Promises only where:

  • a parent or legal guardian has given permission;
  • the parent or guardian has reviewed the applicable terms and privacy information; and
  • the parent or guardian supervises the individual’s use where appropriate.

Beloved Promises is not designed primarily for children.

Experience Creators may include a child’s personal data in a digital experience or RSVP list only where they have appropriate authority or permission.

This may include:

  • the child’s name;
  • photograph;
  • attendance information;
  • dietary requirements; or
  • family relationship.

Please contact our Data Protection Officer if you believe a child’s personal data was provided without appropriate permission.

26. Third-party websites and services

Digital experiences may contain links to third-party websites or services, including:

  • maps and navigation services;
  • messaging applications;
  • social media platforms;
  • wedding venues;
  • hotels;
  • transport providers;
  • payment services; and
  • other websites selected by the Experience Creator.

Beloved Promises does not control the privacy or security practices of these third parties.

Their own privacy policies and terms apply when you visit or use their services.

27. International users

Beloved Promises may be accessed by users in Southeast Asia, North America, the Pacific region and Europe.

This Privacy Policy is primarily structured around the Singapore Personal Data Protection Act.

Depending on your location and the circumstances, other privacy laws may provide additional rights or impose additional obligations. Where another applicable law grants you additional rights, we will consider and process valid requests in accordance with that law.

28. Changes to this Privacy Policy

We may update this Privacy Policy to reflect:

  • changes to the Services;
  • new features;
  • new service providers;
  • changes to our data practices;
  • security developments;
  • regulatory guidance; or
  • changes to applicable law.

The revised version will be published with an updated effective date.

Where a change materially affects how we collect, use or disclose personal data, we may provide additional notice through:

  • the website;
  • the account interface;
  • email; or
  • another appropriate communication method.

Where fresh consent is required, we will request it separately.

29. Contacting our Data Protection Officer

Questions, access or correction requests, withdrawal requests, complaints and suspected data breaches may be directed to:

Data Protection Officer
Marcus Tan
Corevia Studios Pte. Ltd.
UEN: 202624870W
07 Seletar Road
Singapore 807014
Email: hello@coreviastudios.com

Please provide sufficient information for us to identify and respond to your request.

Do not send passwords, one-time passwords, complete payment-card details or other unnecessary confidential information by email.

Corevia Studios Pte. Ltd. UEN 202624870W. All rights reserved.
Terms and Conditions|Privacy Policy