Privacy
Last updated September 10, 2026. This notice describes how the Lovely on Paper Team uses information to create and deliver your digital files. Lovely on Paper is operated by Chief Culture LLC.
Information you provide
We use guest labels, wedding names, date, venue, address, RSVP details, and your design choices to create invitations. Recipient email addresses are not required. We use your checkout email for order delivery and support. Upload only information you are authorized to use, and avoid unnecessary sensitive details.
Drafts and previews
Your draft is stored in this browser tab’s session storage so it can be restored while you work. It may include names, details, images where supported, and checkout information. Clear the site’s browser storage to remove it; browser session restoration may preserve a closed tab’s data. Preview and proof requests send your input to our server for rendering but do not intentionally save an order. A draft is not a permanent backup.
Orders and private links
Starting checkout stores your batch details, email, order amount and status, and download authorization in Cloudflare-hosted storage. Generated PDFs may be cached there. The order database stores a hash of the access token; a protected delivery record retains the token so we can email your link. Anyone with the complete link can access and correct the order. Share individual files rather than the private link.
Access periods and deletion
Pending orders have a seven-day expiry from creation. The first confirmed payment starts a new seven-day download period; duplicate payment notifications do not extend it. Expired order records and files are deleted when accessed or during hourly cleanup or later cleanup requests. Deletion is not guaranteed at the exact expiry instant; a cleanup backlog or failed run may delay removal until a later run. Downloads you save and browser drafts are separate copies. Provider logs, backups, payment records, and support correspondence may have different retention periods.
Hosting, payment, and delivery providers
Cloudflare hosts the website, handles network requests, and stores order records and files. It processes technical information such as network addresses and request data. Stripe receives payment and billing details through its checkout, plus your email, order reference, and purchase amount; our form does not collect full card details. Resend receives your email address and transactional email content, including the private order link, to deliver your message. We do not send your uploaded recipient list to Stripe or Resend as a list; the delivery link grants access to the order.
These providers may process information in countries other than yours and retain records under their own policies. See Cloudflare’s privacy policy, Stripe’s privacy policy, and Resend’s privacy policy.
Earlier AI design sessions
The AI designer is no longer available. When it was used, it sent the message you typed and your current supported design choices to OpenAI. Uploaded names, recipient lists, and images are not automatically included. Anything you type into chat is included, so do not enter private recipient information. Requests ask OpenAI not to store the response as application state; this does not mean zero provider retention, and provider security and abuse-monitoring policies may still apply.
We keep design-session authorization, a hashed network address, usage counts, and timestamps to limit abuse. Sessions expire after 24 hours; expired records are removed on a subsequent design request. The current chat is displayed in browser memory. Your chosen custom design is saved with the order when you start checkout.
Your choices and support
You can clear local drafts, download your files, and contact the Lovely on Paper Team at support@lovelyonpaper.com about access, correction, deletion, or other privacy questions. Include an order reference where relevant, not card details or your full private link. We may need to verify that the request concerns your information. Requests concerning independent payment or other provider records may also need to be directed to that provider.