Privacy Policy
Last updated 26 September 2026
What ohmykad collects, why, who else handles it, and how long we keep it. This describes what the service actually does today, not what we intend it to do later.
About this policy
ohmykad lets you create a digital invitation card, pay once to publish it, and share the link with your guests. Running that service means holding personal information about you, and about the people you invite.
We handle that information under Malaysia's Personal Data Protection Act 2010 (PDPA). ohmykad is operated from Malaysia, and we are the data user for everything described below.
This policy is written for two audiences: hosts, who create and pay for a card, and guests, who open one and may reply to it. Where the two are treated differently, we say so.
Who decides what goes on a card
A card's content is chosen by its host. We provide the builder, the design and the hosting; we do not choose the names, photographs, phone numbers or bank details that appear on any card.
So the host decides what information about other people is published: a family member listed as a contact, a child named as a celebrant, a guest in a photograph. If you appear on a card and want to be taken off it, the quickest route is to ask the host, who can edit the card themselves while its editing window is open.
We remain responsible for that information once it is on our systems, and you can always come to us instead. The section on your rights explains how.
What we collect from hosts
When you create and publish a card, we hold:
- Your sign-in details: the email address you register with, or the Google account you sign in with, and whether you have set a password. Passwords are held by our authentication provider as one-way hashes and we never see them. If you start a card without registering, we create an anonymous session tied to nothing but your browser.
- What you put on the card: celebrant and parent names, the event's dates, venue and directions, dress code, the names and phone numbers of the people you list as contacts, your invitation and blessing text, and the settings you choose.
- Money-gift details: if you switch the money-gift widget on, the bank name, account number and account holder name you type, and any e-wallet QR image you upload. They are yours, they are shown on your card exactly as you entered them, and we never use them to move money.
- Gift registry details: if you switch the registry on, the delivery address and phone number you give for guests to send gifts to.
- Photographs: the images you upload for the card's gallery, and any QR code image. They are kept in public file storage so the card can display them, which means anyone holding an image's web address can open it.
- Your orders: the order code, the amount, any voucher applied, the status, and the reference we record when we confirm your bank transfer. We never see or store a card number, an account you paid us from, or online banking credentials. Payment happens outside ohmykad.
What we collect from guests
You can read a card without giving us anything. If you use one of its reply features, what you send is stored with that card:
- RSVP: the name you give, whether you are attending, how many people are coming (and how many of them are children, if the host asks), which session you are attending, your phone number where the host asks for it, any dietary note, and any private message you write. The phone number, the dietary note and the private message are shown to the host and to our operators only, never on the public card.
- Wishes: the name you give and the message you write. A wish is published on the card once the host's moderation setting allows it, so treat a wish as public.
- Registry reservations: the name you give, an optional message to the host, and how many units you reserved.
- How often a card is opened: we count how many times each card was opened each day so its host can see a trend. That count carries no name, no address, and nothing that identifies who opened it.
- A note kept on your own device: so you can come back and change your RSVP or see what you reserved, your browser keeps a small record of your own submission. It stays on your device and we do not read it.
Information we collect automatically
Running the site produces a small amount of technical information:
- Cookies: a session cookie from our authentication provider while you are signed in, a short-lived cookie remembering where to send you after you sign in, and a cookie remembering that you have an unfinished card. We set no advertising or analytics cookies. Cloudflare may set its own cookie as part of the bot check described below.
- Your address, while a request is being counted: our server reads the IP address of each request so that one visitor cannot flood the service. It is held in memory for that purpose and is not written to our database.
- Error reports: when something breaks we record the error message, the technical trace, the page or route it happened on, that request's query string, and your browser's user-agent string. Only our operators see them.
A published card is a public page
A published card lives at a public web address. Anyone holding the link can open it, forward it, and see everything on it: names, dates, the venue, the contact phone numbers, the gallery, and the bank account or QR code if the money-gift widget is on.
We do not ask search engines to stay away from published cards, so a card can turn up in search results.
Approved wishes are part of that public page. RSVP replies, phone numbers, dietary notes and private messages are not. They are visible to the host and to our operators only.
Why we hold it
Under the PDPA we rely on the consent you give when you create a card or send a reply, and on what is necessary to perform the agreement between us when you buy a card.
We use the information for these purposes and no others:
- To provide the card: to build, preview, publish and display the invitation, and to collect the replies its widgets exist for.
- To take payment: to raise an order, apply a voucher, confirm your bank transfer over WhatsApp, and email you a confirmation.
- To keep the service standing: to stop abuse and spam, to moderate wishes, to find and fix faults, and to see what the AI features cost us.
- To answer you: to reply when you contact us about a card, an order, or your own data.
The AI step, and what is sent to OpenAI
The quickest way to make a card here is to write or paste a description of your event and let us turn it into a draft. That step sends the text you wrote to OpenAI, which returns a structured draft. Whatever you put in that text (names, dates, a venue, a phone number) goes with it.
We keep a record of each AI call, including the text that was sent and how much it cost, so we can see what the feature costs us and diagnose failures. Only our operators see those records.
If you buy a card you can also generate cover artwork. That request sends only a fixed, pre-written style description from our own design catalogue. No names, no guest details and no photographs go with it.
Nothing a guest submits (no RSVP, no wish, no reservation) is ever sent to an AI provider.
Who else handles it
We do not sell anything about you and we do not share it for advertising. These are the companies that process it on our behalf so that the service can run:
- Supabase: our database, our file storage, and the authentication that holds your email address and password hash. The data sits in Supabase's Singapore region.
- Amazon Web Services: hosting and delivery of the site, in AWS's Singapore region, served through Amazon's global content delivery network.
- Amazon SES: sends our email (sign-in codes, password resets and order confirmations) from that same Singapore region.
- OpenAI: processes the AI step described above. OpenAI is based in the United States and processes the request there.
- Cloudflare: runs the Turnstile bot check protecting the card builder and the sign-in screens. One of the two checks is invisible, so you may never see it happen: it collects your IP address, a TLS fingerprint, your user-agent string and our site key, and Cloudflare states it cannot identify individuals from those signals. Cloudflare's handling is set out in its Privacy Policy and in the Turnstile Privacy Addendum at cloudflare.com/turnstile-privacy-policy.
- Google: if you choose to sign in with Google, Google confirms who you are and gives us your email address. Separately, a card showing a venue map loads that map from Google, so Google sees that a browser requested it.
- Links a card can open: a card can link out to YouTube for background music, to Google Calendar, to Waze or Google Maps for directions, and to WhatsApp to message a contact. Follow one of those and you are on that company's service under its own policy, not ours.
Where it is kept, and when it leaves Malaysia
Our database, our file storage and our servers are in Singapore, and our email is sent from Singapore. So although ohmykad is operated from Malaysia, the information is stored outside it.
The AI step sends your text to OpenAI in the United States. The bot check, the sign-in with Google and the venue map involve companies that operate globally.
The PDPA sets conditions on transferring personal data out of Malaysia. We keep the transfers to the providers listed above and rely on the data-protection commitments they publish. If you would rather your text was not sent to an AI provider, fill the card in by hand instead of using the AI step.
How long we keep it
A card has two clocks, both six months long by default and both stamped when you publish: an editing window, after which the card can no longer be changed, and a validity window, after which the public page stops showing the invitation and shows a short note that the event has passed.
Expiry closes the public page. It does not delete anything. The card, its RSVPs, its wishes and its reservations remain in our database afterwards.
Deleting a card does not delete them either. A deletion marks the card as deleted and hides it everywhere, and we keep the record so that we can answer "where did my card go" months later and hand it back if the deletion was a mistake. The RSVPs, wishes and reservations attached to it stay with it. We have no automatic deletion schedule today: there is no job that erases this data after a set period. We would rather say that plainly than promise a clean-up that does not happen.
Erasure is therefore something we do by hand, on request, and we do it. Ask us and your data goes; the section on your rights explains how to ask. Two things we keep regardless: records of payments actually made, held for about seven years because tax law requires it, and error logs, which carry no names.
- Card content and guest replies: kept while the card exists and after it expires, until someone asks us to delete them or we run a clean-up.
- Account details: kept while your account is open. When you ask us to close it, your sign-in details are removed after a seven-day grace period.
- Payment records: kept for about seven years, as tax law requires. They hold the order, the amount and the reference, never a bank card number.
Your rights, and how to use them
Under the PDPA you may ask for a copy of the personal data we hold about you, ask us to correct it, withdraw the consent you gave, or ask us to limit how we use it. The Act gives us 21 days to answer such a request.
Requests reach us on WhatsApp: hosts see the number at checkout and on their account page. There is no support mailbox: the ohmykad.com domain does not receive email at all. If you are a guest and cannot reach us, ask the host who invited you: they can remove your RSVP, wish or reservation from their own dashboard, and they can pass your request on to us.
- See what we hold: tell us which card and the name you used, and we will tell you what is stored.
- Correct it: a host can edit their card while the editing window is open; a guest can update their own RSVP from the same device, or ask us.
- Delete it: ask us and we will delete it. We do this by hand, so allow us a few days.
- Close your account: ask us on WhatsApp. Your cards stop working straight away, and your sign-in details are removed after seven days.
How it is protected
Traffic to the site is encrypted. Nothing in your browser talks to our database directly: every read and write goes through our own server, which checks who you are first, and the database's public access is switched off entirely.
A card page may only load from a short list of approved sources, so an injected script has nowhere to send anything. Uploads are limited by type and size and pass through our server rather than straight into storage.
A small number of operators can see everything stored here, including guest phone numbers and private notes, because moderating wishes and confirming payments requires it. No security is perfect. If we discover a breach affecting you, we will tell you.
Children
ohmykad is for adults. If you are under 18, do not create a card or reply to one without a parent or guardian doing it for you.
Cards often involve children all the same: a birthday, an aqiqah, a child named beside their parents, a count of how many children are attending. A host who publishes a child's name or photograph is making it public, and should think about that first. Ask us and we will take a child's details down.
Changes to this policy
We will update this page when what we do changes. The date at the top is the date of the version you are reading.
If a change materially affects information you have already given us, we will say so at the top of this page rather than change it quietly.
Contact us
ohmykad is operated from Malaysia. WhatsApp is our only inbound channel: the number appears at checkout and on your account page once you have registered.
If your question is about a particular card, send us its link: it is the fastest way for us to find what you are asking about.
If you are not satisfied with how we have handled your personal data, you may complain to the Personal Data Protection Commissioner of Malaysia.