Privacy
Mehfilbox hosts wedding films and photographs on behalf of the studio that produced them. The studio decides who may see a catalogue; we store it and serve it.
What a wedding guest gives us
No account and no email address. A guest opening a catalogue chooses a display name and an avatar. We keep that name, how far through a film they watched so it can resume, which photographs they liked, and anonymous playback quality measurements used to tell whether video is starting quickly enough. Nothing here identifies a person beyond the name they typed.
What a studio gives us
An email address and a password for signing in, the studio’s name and branding, and the media uploaded for each wedding. Sign-in is handled by Supabase Auth; we never see the password itself.
Who else touches it
Video and photographs are stored and delivered by Bunny.net. Application data is stored in Supabase (Postgres), hosted in Singapore. The application runs on Vercel, served from Mumbai. Transactional email is sent through Resend. We do not sell data, and there is no advertising or third-party analytics on a wedding page.
How long it is kept
For as long as the catalogue’s plan is active, and through archive if the studio keeps it. Nothing is deleted at expiry — a catalogue goes cold and is restored on payment. Deletion happens on an explicit, recorded request from the couple or the studio.
Asking for a copy, or for deletion
A couple should ask their studio first, since the studio controls the catalogue. If the studio is no longer reachable, write to us and we will act on it directly.