Security & trust

    How we handle your data.

    Venues store contracts, payment schedules, client details, and staff information in Plan The Aisle. This page describes, in plain language, the practices that are actually in place today. Last reviewed September 6, 2026.

    Authentication

    Sign in with email and password, Google, or Apple. Passwords are never stored in plain text; authentication is handled by our managed identity provider.

    Password resets and email confirmations use single-use, expiring links.

    Account access & roles

    Venue teams use role-based access (owner, manager, coordinator, staff, finance). Finance and billing screens are limited to owner and finance roles.

    Couples only see their own wedding. Staff only see the venues and events they're assigned to.

    Data isolation

    Every database table is protected by row-level security policies. Each request is checked against the signed-in user's identity and role before any row is returned or changed.

    Public pages (couple portal links, contract signing links) use unguessable tokens and expose only the fields those pages need.

    Encryption

    All traffic between your browser or the Android app and our servers uses TLS (HTTPS).

    Data and file storage are encrypted at rest by our cloud infrastructure provider.

    Payments

    Web subscriptions are processed by PayPal; Android subscriptions are processed by Google Play Billing. We never see or store card numbers.

    Venue invoices inside Venue Ops record payments your venue receives; Plan The Aisle does not move money between your couples and your venue.

    Backups

    Our database provider performs automated daily backups. Backups are used for disaster recovery, not for restoring individual records on request.

    Data export

    Guest lists, budgets, timelines, and venue reports can be exported from within the app (CSV/PDF). Contact us for a full account export.

    Data deletion

    You can request deletion of your account and its data at any time from Account settings or by emailing us. Deletion removes your records from the live database; backups age out on their normal schedule.

    Third-party processors

    Cloud database, authentication, and file storage (managed infrastructure); PayPal and Google Play (payments); transactional email delivery; Google Analytics, Google Ads, and Meta Pixel (website analytics on public marketing pages); an AI gateway for optional AI writing features (prompts are not used to train models by us).

    We do not sell personal information. See the Privacy Policy for the full list and purposes.

    What we don't claim

    Plan The Aisle has not completed a SOC 2, HIPAA, or PCI assessment. We describe our practices plainly rather than using certification language we haven't earned.

    Support & disclosure

    Questions or a security concern? Email hello@plantheaisle.com. We respond to security reports within two business days.

    See also: Privacy Policy · Terms of Service