How we protect your guests
Last updated 5 September 2026
Draft. The company details in this document are not yet confirmed, so it does not bind anyone. If you are considering buying Ponte and need the final terms first, write to hello@ponte.events.
The short version
A wedding on Ponte is one event, walled off from every other event at the database. Guests sign in with a link, never a password. Their phone numbers are not shown to other guests unless they choose to share them. Card details never touch Ponte. Everything the couple and their guests put in can be downloaded in one click and is deleted thirty days after the event is closed.
One event, one boundary
Every table in the database has row-level security switched on, and every rule binds a row to the signed-in person’s own event. There are no rules open to the world. The same is true for files: no public buckets, every file filed under its event, and every read a short-lived signed link minted from the viewer’s own session. Since September 2026 the database itself refuses a row that names another event’s file or another event’s person, so a bug in the application cannot cross the line either.
What other guests can see
A guest sees names, and whatever a person has chosen to show — where they are staying, that they have arrived, a note. Phone numbers, email addresses and sign-in links are not readable by other guests at all: they are excluded from what the application is allowed to select, and the live stream carries the same list. Organisers see contact details for their own guests, because they invited them.
No passwords
Nobody sets a password on Ponte, so there is no password database to breach. Guests sign in with a personal link or the event’s join code; organisers with a link from their own email. Sessions are bound to the event’s own address. An email address that belongs to another event is refused at sign-up.
Payments
Cards are entered on Stripe’s hosted page and stay with Stripe; Ponte holds a reference, never a number. Every message from Stripe is checked against its signature before it is trusted. The record of what was charged is append-only: it cannot be edited or deleted, even by us.
The concierge
The assistant answers from what the couple wrote and from the public web. It learns which event and which guest it is speaking to from the session, never from the conversation, and anything that would change the schedule or message everyone is proposed for the organiser to approve, never done inside a reply. Conversations are not used to train models.
Your data, and leaving
Organisers can download everything — guests, schedule, photographs, files — at any time from the account page. Closing the event keeps the data for thirty days in case of a change of heart, then deletes it, files included. The billing record is kept as long as the law requires.
Where it runs, and who else touches it
Ponte runs on Vercel and Supabase, with Stripe for payments, Resend for email, Anthropic for the concierge and Mapbox for the map. The full list, and what each one sees, is in the privacy policy.
Reporting a problem
Found something? Write to hello@ponte.events. We answer within two working days, fix real findings first, and will credit you if you want to be credited. Our security.txt says the same in the standard form.
Ponte LLC · a Minnesota limited liability company · 8167 9th St N, Oakdale, MN 55128, USA · hello@ponte.events