HomePrivacy

The Aisle legal

Privacy policy

How The Aisle handles account, venue, enquiry, message, saved-list and security data while building the South African wedding venue marketplace.

Last updated: 3 September 2026

This is the product baseline for launch readiness. Before a public production launch, confirm the responsible-party details and privacy contact mailbox.

What we collect

The Aisle keeps the information needed to operate a venue-first wedding marketplace: public venue details, account records, claim records, saved venues, enquiries, messages, quotes, availability, package data, booking records and security logs.

Venue pages may include public business information from sources such as Google listings and venue websites. Couple and manager data comes from account forms, enquiry forms, dashboard edits and messages.

Why we use it

We use this data to show accurate venue listings, let couples shortlist and contact venues, let venue managers claim and maintain listings, keep messages attached to the right venue, prevent duplicate quote acceptance, secure accounts and improve marketplace quality.

  • We do not invent prices, capacities or availability.
  • Manager-maintained package data is treated differently from scraped hints.
  • Unknown pricing remains unknown until a venue manager verifies it or the couple sends a structured enquiry.

Who sees it

Public venue facts are visible on marketplace pages. Couple enquiries and messages are visible to the participating couple, the assigned venue manager and authorised The Aisle operators who need access for support, safety or quality control.

We may use infrastructure, hosting, database, email, storage and security providers to run the service. They should only receive the data needed for their role.

Your choices and rights

You can correct your account details from your dashboard where the product exposes the field. Venue managers can correct claimed listing data through the manager dashboard. Couples can remove saved venues and choose what they send in an enquiry.

South African users may have rights under POPIA to ask for access, correction, deletion or objection where the law allows it. The Information Regulator is the South African authority for POPIA and PAIA complaints.

Security

Account sessions use an opaque HttpOnly cookie, server-side session lookup and same-origin mutation checks. Write APIs validate input and check ownership before mutating marketplace data.

No website can promise absolute security. The practical standard here is least-necessary collection, explicit validation, limited access and fast removal of data that should not be held.