1. Scope
This policy explains what Beetrothed LLC ("Beetrothed", "we") collects, why, who else touches it, and what you can do about it. It covers beetrothed.com and the Beetrothed service.
The Service is offered in the United States, the European Economic Area, the United Kingdom, and Switzerland. If you are in the EEA, the UK or Switzerland, Section 15 is written for you: it names the lawful basis for everything we do, your rights under the GDPR and UK GDPR, our representatives, where your data goes, and how to complain. It wins over anything else here that disagrees with it.
If you are a wedding guest and someone added you to their plan, the short version written for you is the Appendix at the end of this policy.
If you use Beetrothed as a business — a vendor or a planner — this policy covers your own account information. Data about your clients that you process in the Service is governed by the Data Processing Addendum.
2. The short version
Your wedding plan is yours. We collect what the product needs to work, we show each person only their slice of a plan, and we do not sell personal information and we do not use it for targeted advertising. If you ask us for help, someone here may open your plan to answer — every time that happens is logged, and §7 says exactly what they can and cannot see. Guest details never leave the couple who entered them: not to vendors, not to staff, not to the AI assistant.
3. What we collect
3.1 From you
| Category | What it is |
|---|---|
| Account | Your email address, used to sign you in with a one-time link. There is no password. Your display name and language preference. |
| Your plan | Everything you put in it: names, wedding date, locations, budgets, decisions, tasks, timeline, notes about providers, and files you upload. |
| Guest information | Names, and — where a couple enters them — contact details, household groupings, RSVP responses, meal choices, dietary needs, and whether a guest is a child. |
| Provider and planner accounts | Business name, contact details, service descriptions, photos, offerings, pricing, availability, team members. |
| Payment information | For our own subscriptions: we do not collect or store card numbers — Stripe does; we hold the fact and amount of a charge, its status, and what it was for. For payments you make to a provider: those are made directly between you and them, never through us — what we hold is the record you enter (amount, date, what it settled). |
| What you send us | Support emails, feedback, and anything you paste into the assistant. |
3.2 Automatically
| Category | What it is |
|---|---|
| Operational logs | Requests, errors, and diagnostics needed to keep the Service working and secure. Error reports are scrubbed of tokens and identifying values before they leave our systems. |
| Analytics | Page views and usage, collected with self-hosted, cookieless analytics that never follows you across sites. When you are signed in and have allowed analytics, your visits are linked to your account identifier so we can see how the Service is used and help you when something goes wrong. |
3.3 From other people
If a couple invites you as a collaborator, adds you as a guest, or engages you as a provider, we receive what they entered about you.
4. How we use it
- To run the product: keeping your plan current; deriving what the plan computes — headcounts, budgets, deadlines, lead times; showing collaborators and providers their scoped view.
- To send the emails you ask for: sign-in links, invitations, RSVP messages, receipts, and service notices.
- To take subscription payments, and to apply the refund terms that govern them (Refund Policy §11).
- To answer your questions through the assistant (§8).
- To keep the Service secure, debug failures, and prevent abuse and fraud.
- To comply with law and to establish or defend legal claims.
We do not sell personal information. We do not share it for cross-context behavioral advertising. We do not build advertising profiles. We do not show your activity to providers.
5. Cookies and similar technologies
We do not use advertising or tracking cookies, and we never will without asking you first.
Nothing optional runs until you say yes. When you first arrive we ask, with "Accept all" and "Reject all" as the same size of button, and you can change the answer from Cookie settings at the top of this policy, which the footer of every page links to. We ask everyone, wherever you are, rather than only asking Europeans.
We keep a record of what you chose and when, because the law asks us to be able to show it. That record holds your choice, the date, and a random number your own browser made up. It does not hold your IP address, and it does not hold anything that identifies you — a log kept to prove you refused tracking must not itself be tracking.
Two things are optional, and both start off:
| You choose | What it does | Off by default |
|---|---|---|
| Analytics | Which pages get visited, so we know what to fix — and, when you are signed in, linked to your account so we can support you and understand how the Service is used. Self-hosted by us, sets no cookies, and never follows you to another site | Yes — and until you allow it, the analytics script is not sent to your browser at all |
| Embedded video | Where a couple has added a video, letting it load means the video's host can see you watched it | Yes — and you can still play any video once without turning this on |
The cookies we set ourselves are strictly necessary ones, and are not part of that choice because the site cannot work without them:
| Cookie | Why |
|---|---|
| Authentication | Keeps you signed in after you use your sign-in link. |
| Language | Remembers the language you chose. |
| Active plan and workspace | Remembers which plan or workspace you had open, so you return to it. |
| Pending invite | Carries an invitation you clicked until you finish signing in, then it is cleared. |
Two things beyond our own cookies, disclosed because you would find them:
- Payments. When a subscription checkout loads, our payment processor (Stripe) sets its own fraud-prevention cookies. They exist to protect the payment, not to advertise to anyone.
- Embedded video. Where a couple embeds a video on a page you visit, nothing is requested from its host until you choose to load it. When you do, it loads from the provider's privacy-enhanced domain.
Our analytics is self-hosted and sets no cookies, and does not track anyone across sites. When you are signed in and have allowed analytics, your visits carry your account identifier — a random ID, never your name or email — so we can see how the Service is used and help you when something goes wrong. Nobody outside Beetrothed receives it. Signed out, or with analytics off, nothing is linked to you at all. Our error monitoring records no session replays and no page traces.
Global Privacy Control
If your browser sends the Global Privacy Control signal, we honor it — and we give it more to do than the law strictly requires.
The obligation attaches to selling and sharing personal information, and we do neither, so on a strict reading the signal has nothing of ours to switch off. Rather than say that and stop, we treat GPC as turning analytics off and keeping it off, even if you previously said yes. Someone who has since turned the signal on has changed their mind in the most explicit way a browser allows, and holding them to a click from six months ago would be perverse.
The check happens on our server, so when the signal is present the analytics script is never sent to your browser at all, rather than sent and then suppressed. Embedded video is deliberately left alone: GPC is an opt-out of sale and sharing, not a blanket refusal, and if you asked for a video you should get the video.
We are not a data broker. We do not sell personal information, we have no arrangement with anyone who does, and we are not registered as one because we are not one.
6. Who else touches your data
We use a small number of service providers, each processing data only to provide
their service to us and under contract terms that forbid other uses. The
categories of recipient are: hosting and database, email delivery, payment
processing, error monitoring, self-hosted analytics, and model inference for the
assistant. The current list by name — with what each one does and where it
processes — is Exhibit A to 04-data-processing-addendum.md, kept current,
attached to that Addendum, and sent to anyone who asks us for it. At the time of
writing the providers are:
| Provider | What they do |
|---|---|
| Supabase | Database, authentication, file storage |
| Railway | Application hosting, and the analytics we self-host |
| Sentry | Error monitoring (scrubbed before send) |
| ZeptoMail | Delivery of every email we send you, including sign-in links |
| Zoho Mail | Our own mailboxes — email you send to hello@ is processed there |
| Stripe | Subscription payments. Card details go to Stripe, not to us |
| DeepInfra | Serves the model that answers assistant questions (§8) |
| Anthropic | Answers an assistant question on a paid plan when the first model's answer fails our checks (§8) |
| Tavily | Web search behind vendor discovery on paid couple plans |
We also disclose information when the law requires it, to protect rights and safety, and in a business transfer — if Beetrothed is acquired or merges, your information may transfer with the business, subject to this policy.
7. When we look at your plan
People who work at Beetrothed can open a couple's plan to answer a support request — to see why a payment was declined, why an invitation did not arrive, or why something on the board is not behaving.
- Every open is recorded: who opened it, when, and a stated reason. A reason is required — the system refuses a blank one. The record cannot be edited or deleted by anyone here.
- The record is written before the plan is read, and before we even know the plan exists, so an attempt that matches nothing is still recorded.
- Guest details are not part of it. On this path, staff see guest counts and totals — how many are invited, expected, or have replied — and never the guest list itself. This is enforced in the database function, not by policy.
- We do not open plans to browse them, to build profiles, to train anything, or to show your activity to providers or anyone else.
8. The assistant, and what it reads
The assistant answers questions about your own plan.
What it reads: the plan's name and date; the cells you have added; the answers you have given; the vendors you have engaged, with their rates, quotes, open offers, and meeting requests; your payment schedule; your timeline; your open tasks; guest counts (how many invited, confirmed, or vegetarian — numbers, never names); and anything you paste in yourself.
What it never reads: your guest list. The assistant is given counting summaries only and does not read the guest table at all.
Where the question goes. Questions are answered by an open-weights model served for us by DeepInfra. On a paid plan, when that model's answer does not pass our checks, that request is sent to Anthropic (Claude) instead. Both process it only to answer it.
We do not use your plan to train anyone's model.
9. Guests, specifically
If a couple added you to their plan, they are the people with your details and we hold those details for them.
- Your RSVP page is reachable only through the private link they send you.
- Vendors never see you. They receive counts and totals, never names.
- Staff never see you. See §7.
- The assistant never sees you. See §8.
- We do not market to you and do not send you anything except what the couple asks us to send.
You can ask the couple to change or remove your details, or ask us directly at
hello@beetrothed.com. We will verify that the address is yours and then
remove your details from the plan, and tell the couple that a guest asked to be
removed without relaying anything else about you. Full detail is in the Guest
Privacy Notice.
10. How long we keep things
| What | How long |
|---|---|
| Your account and plan | Until you delete them |
| Data you delete | Removed from the live system immediately |
| Backups | Deleted data persists in rotating backups and ages out within 7 days |
| Subscription payment and refund records | 7 years from the transaction — the outer edge of the tax and accounting periods that reach us, and long enough to answer a dispute |
| Administrative audit records | Kept indefinitely — see below |
| Error reports | 90 days, then deleted by our error-monitoring provider |
| Analytics | 13 months, and only if you allowed analytics at all |
| Server and request logs | 30 days |
| Consent records | 3 years from the answer, so we can show what you chose and when |
| Marketing and waitlist email | Until you unsubscribe, then a suppression record so we do not write to you again |
The audit record keeps a deleted person's name. When an administrator deletes a person's records, the audit entry recording that deletion contains the name of the person deleted — including where the deletion happened because that person asked to be erased. This is deliberate: "a person was deleted" is not an audit trail, and the alternative makes the single action most worth auditing the one action nobody can audit. The record is append-only and readable only by the company.
11. Security
We restrict every person and every provider to their own slice of a plan, enforced in the database rather than in the interface. Access to production is limited and logged. Error reports are scrubbed before they leave. We describe these plainly rather than as a guarantee: no service is perfectly secure, and we do not promise that ours is.
If a breach affects your information, we will notify you as required by applicable law.
12. Your choices and your rights
What you can do yourself, inside the Service:
- Remove a guest — Guests tab. Deletes their details from the plan immediately.
- Delete your account — The Wedding → Your account. If your partner is also an owner, the plan stays with them; if you are the only owner, the plan and everything in it is deleted with you.
- Take your information out — if you are planning a wedding: download your
guest list as a file, and share a provider brief. If you use Beetrothed as a
business: Your settings → Your data downloads a single file holding your
profile and photos, your catalog, your availability, your templates and their
contents, your team, the reviews couples wrote about you, and every booking
and payment on your bookings. A planner who runs a client's wedding on
Beetrothed gets that wedding's own contents in the same file. It is available
at any time, including while an account is suspended, and it does not go
through us. Ask us at
hello@beetrothed.comfor a copy of anything else. - Unsubscribe — every waitlist or marketing email carries a one-click unsubscribe link. Service emails (sign-in links, receipts, notices about your plan) are not marketing and continue.
What you can ask us for, at hello@beetrothed.com: a copy of the personal
information we hold about you; correction of it; deletion of it; and an
explanation of how it was used. We will verify that the request comes from you —
for a request about an email address, from that address — and we will not
discriminate against you for making one.
These rights are not conditional on where you live. If you are in the EEA, the UK or Switzerland they are also statutory — see Section 15, which adds the lawful bases, the complaint route and the timescales the law attaches to them. Everywhere else we honor the same list voluntarily.
A note on US state privacy laws. We give you these rights whether or not a statute currently requires us to. Beetrothed is under the applicability thresholds of the California Consumer Privacy Act and comparable state statutes today, and it makes no difference to what you can ask for: the rights above are offered on the same terms and the same timescales to everyone, and they do not switch on when we grow. If a threshold is crossed, nothing here changes for you.
13. Children
Beetrothed is not directed to children and we do not knowingly collect information from anyone under 13, or allow anyone under 18 to hold an account.
A couple may note that a guest is a child, for meals and seating. That note is provided by the couple, not collected from the child, and it is held under §9. If you believe a child has given us information directly, contact us and we will delete it.
14. Changes
If this policy changes in a way that matters, we will say so on this page and, for a material change, notify account holders before it takes effect. The version and date at the top always reflect the current text.
15. If you are in the EEA, the UK, or Switzerland
This Section is the GDPR and UK GDPR layer. Where it disagrees with anything else in this policy, this Section wins.
15.1 Who is responsible for what
For your own account information — your email, your plan, your settings, what you type into the assistant — Beetrothed LLC is the controller.
For a guest's information, the couple decides what to collect and why, so the couple is the controller and Beetrothed is their processor. That allocation is the whole subject of Section 9 and of the Appendix. Where a planner or a vendor works on a plan, the Data Processing Addendum says which of us is which.
15.2 The lawful basis for each thing we do
| What we do | Lawful basis | Why that one |
|---|---|---|
| Give you the Service you signed up for — your plan, your comb, your bookings | Contract, Art. 6(1)(b) | You asked us to; without it there is no product |
| Send sign-in links, receipts, and notices about your own plan | Contract, Art. 6(1)(b) | These are the Service, not marketing |
| Take a subscription payment, and apply its refund terms | Contract, Art. 6(1)(b), and legal obligation for tax and accounting records, Art. 6(1)(c) | |
| Keep the Service secure, prevent fraud and abuse, and keep an admin audit trail | Legitimate interests, Art. 6(1)(f) | Running a service people trust with a guest list. Balanced against you in §15.3 |
| Answer an assistant question | Contract, Art. 6(1)(b) | You asked it a question; answering it is the feature |
| Analytics — which pages are visited, linked to your account while you are signed in | Consent, Art. 6(1)(a) | You choose, and nothing runs until you do (§5) |
| Load an embedded video | Consent, Art. 6(1)(a) | Same |
| Marketing email, including the waitlist | Consent, Art. 6(1)(a) | Withdrawable in one click from every message |
| Hold a guest's details on a couple's instruction | The couple's basis, not ours — we act as their processor | See §15.1 |
We do not ask for special category data and the Service has no field for it. Where a guest tells a couple about an allergy or an accessibility need, it reaches us inside a free-text note the couple wrote; we treat it as the couple's data on the couple's instruction, we never use it for anything but showing it back to them, and the assistant never reads it (§8).
15.3 The legitimate-interests balance, stated rather than asserted
Naming Art. 6(1)(f) without showing the balance is the part everyone skips, so: the interests are security, fraud prevention, and being able to prove what a member of staff did. The processing is narrow — access to a plan for support returns counts and totals, never a guest's details, and every such access is logged and shown to the plan's owners. The impact on you is small and visible, and you can object at any time under §15.4. We concluded the interest is not overridden. You may disagree, and objecting costs you nothing.
15.4 Your rights, and what happens when you use one
Access · rectification · erasure · restriction of processing · portability · objection (including to processing based on legitimate interests) · withdrawal of consent at any time, which does not affect what was lawful before you withdrew.
How. Email hello@beetrothed.com, or contact a representative in §15.6.
Cookie and video consent is changed from "Cookie settings" at the top of this
policy, which is reachable from the footer of every page.
When. Within one month. If a request is genuinely complex we may take up to two further months, and we will tell you why inside the first month. It is free; we will only charge for a request that is manifestly unfounded or excessive, and we will explain before we do.
Automated decisions. We do not make decisions about you by automated means alone that produce legal or similarly significant effects. The assistant drafts and suggests; a person decides.
15.5 Where your data goes, and what protects it there
Beetrothed is in the United States, and so are most of the processors in Section 6. Every transfer of EEA or UK personal data to a processor outside the EEA or the UK is made under the European Commission's Standard Contractual Clauses, and the UK International Data Transfer Addendum where the UK half applies, together with the technical measures in Section 11. We keep the executed copies and will show you the relevant ones on request.
The subprocessor list, kept current, is Exhibit A to the Data Processing Addendum. It is attached to that Addendum rather than published, and we send a current copy to anyone who asks.
15.6 Our representatives in the Union and the United Kingdom
We have designated representatives under Article 27 of the GDPR and of the UK GDPR. You may contact them about anything to do with your personal data instead of contacting us, in your own language.
Representative details are published here on appointment (
B-0058). Until that line names a firm and an address, the appointment is not complete: Art. 27 requires the details be reachable, so a designation nobody can find is half a designation. Write tohello@beetrothed.comin the meantime and we will answer on the same timescales as §15.4.
15.7 Complaining
You can complain to the supervisory authority in the country where you live, work, or where you think something went wrong — in the UK, the Information Commissioner's Office. You do not have to come to us first, though we would rather you did, because most things we can simply fix.
15.8 A data protection officer
We have assessed whether one is required under Art. 37 and concluded not: we are not a public authority, our core activities are not regular and systematic monitoring of people on a large scale, and we do not process special category data on a large scale. We will reassess at every material change in what the Service does, and this paragraph is here so the assessment is on the record rather than assumed.
16. Contact
hello@beetrothed.com · Beetrothed LLC, 5071 Ball Rd, #4838, Cypress, CA 90630
Legal notices: Beetrothed LLC, 2108 N St, STE N, Sacramento, CA 95816.
If you are in the EEA, the UK or Switzerland, see also §15.6 — you may write to our representative there instead.
See also the Terms of Service and the Cancellation & Refund Policy.
Appendix — For wedding guests
This Appendix is written for someone who did not sign up for anything. It is part of this policy, and every RSVP page — the only Beetrothed surface most guests ever see — links to it in its footer. It is rendered from the text below rather than maintained separately, so the short version and the full policy cannot drift apart. It is also an Article 14 notice: guest details never come from the guest, they come from the couple, which is the case Art. 14 governs and which demands more than Art. 13 does.
Nothing here may contradict the policy above. Where the two could be read differently, the policy governs and this Appendix is the defect.
When you are reading this, and why that matters
This notice reaches you with the first message we ever send you — the invitation or RSVP link the couple asked us to send — and the page that link opens carries a link to it, in the footer, every time.
Article 14 of the GDPR gives a choice: within a month of getting your details, or at the first time we contact you, whichever comes first. We take the second one, which is the earlier of the two in every case here. You should not learn what we hold about you after we have already written to you.
Why we have your details
Someone you know is getting married, and they added you to their plan.
Beetrothed is the tool they are using to plan their day. We hold their guest list for them. We did not get your details from anywhere else, and nobody bought or sold them.
What they entered
Whatever they needed to plan around you. Usually your name. Depending on the wedding, that may also include your email address or phone number, who you are attending with, whether you have replied, what you chose to eat, any dietary needs, and whether you are a child.
What we do with it
We hold it, we show it to the couple, and we count it — how many people are coming, how many need a vegetarian meal, how many tables are needed. That is all.
We do not sell it. We do not advertise to you. We do not send you anything except the messages the couple asks us to send. Where the couple embeds a video on a page you visit, nothing loads from that video's host until you choose it — you can play it once, or allow video generally, and until then the host never learns you were there.
We do not decide anything about you automatically, and there is no profiling of you at all.
Who does not see you
This is the part worth knowing, because it is unusual:
- The wedding's vendors do not see you. The caterer, the venue, the photographer — they get numbers, never names. "Ninety attending, twelve vegetarian" is what a caterer receives.
- People who work at Beetrothed do not see you. Our staff can open a couple's plan to answer a support question, and every time they do it is logged — but on that path they see counts and totals only, never the guest list. This is built into the system, not just promised.
- The planning assistant does not see you. The AI feature that answers a couple's questions about their plan is given counts only and cannot read the guest list at all.
- A wedding planner sees you only if the couple decides to share the list, deliberately and separately, so that seating can be built. The couple can undo that at any time.
What you can do
Ask the couple. They can change or remove your details themselves, in a couple of taps. Removing you deletes your details from their plan immediately.
Or ask us directly — hello@beetrothed.com.
Here is exactly what happens if you do:
- We check it is really you. The request has to come from the email address you want removed. If it reaches us second-hand, we will write to that address and ask you to confirm. No confirmation, no deletion — this protects you.
- We remove your records from that couple's plan: your details, your RSVP, your seat, your meal.
- We tell the couple that a guest asked to be removed, and nothing else about you or why.
- We confirm to you when it is done.
You can also ask us what we hold about you, ask us to correct it, ask for a copy of it, ask us to stop or limit what we do with it, or object to it. We answer within a month and it is free.
If you are in the EEA, the UK or Switzerland, those are your rights under the GDPR and UK GDPR, and two more come with them. You may complain to the data protection authority where you live — you do not have to ask us first. And you may write to our representative in the Union or the UK instead of writing to us, in your own language; their details are in §15.6 of the privacy policy.
Because the couple decides what to collect about you, some requests are properly theirs to answer. We will not use that as a way to avoid you: if you write to us, we act on the parts we can act on ourselves, and we tell you plainly which part had to go to the couple and that we have passed it on.
How long it stays
| What | How long |
|---|---|
| Your details in the couple's plan | While they are planning. The couple can remove you at any time, and so can you |
| After removal | Gone from the live system immediately |
| Backups | 7 days, then aged out |
| If the couple deletes their plan or account | Everything goes with it, on the same 7-day backup tail |
There is no other copy. We do not keep a shadow record of a guest who was removed, and there is nothing to reactivate if the same couple adds you again — they would be entering you afresh.
Where your details are held
Beetrothed is a United States company and your details are held on servers in the United States. If you are in Europe or the UK, that transfer is covered by the European Commission's Standard Contractual Clauses (and the UK Addendum where it applies), which is the arrangement the law provides for exactly this. The companies that help us run the Service are named in Section 6, and the full current list is Exhibit A to our Data Processing Addendum — write to us and we will send it.
Your RSVP link
The link the couple sent you is private. Anyone who has it can see and change your RSVP, so treat it like a ticket. If you think the wrong person has it, tell the couple or tell us and we will replace it.
Children
If a couple noted that a guest is a child — for meals and seating — that note came from the couple, not from the child. We do not knowingly collect anything from anyone under 13, and in Europe we do not knowingly collect anything from anyone under the age of consent where they live (13 to 16, depending on the country). A child does not hold an account, is never asked anything directly, and is never marketed to. If you are a parent or guardian and want a child's details removed, use the route above and we will handle it the same way.
The formal version, in one place
Everything above is the plain-English version. If you want the same facts in the shape the law asks for:
| Who decides what is collected | The couple who invited you. They are the controller |
| Who holds it for them | Beetrothed LLC, their processor, at the address below |
| Where it came from | The couple. Never a list, a broker, or another website |
| What is held | Your name; and depending on the wedding, contact details, who you are attending with, your reply, meal choice, dietary needs, and whether you are a child |
| Why | So the couple can plan and host their wedding, and so the people cooking and seating can be given counts |
| The lawful basis | The couple's, not ours — usually their legitimate interest in organizing their own wedding |
| Who else sees it | Nobody outside the plan. Vendors get counts, never names. Our staff get counts. The assistant gets counts. A planner only if the couple deliberately grants it |
| Where it goes | The United States, under Standard Contractual Clauses |
| How long | The table above |
| Your rights | Access, correction, deletion, restriction, portability, objection — and a complaint to your data protection authority, without asking us first |
| Automated decisions | None. No automated decision-making, and no profiling with legal or similarly significant effects |
Questions
hello@beetrothed.com · Beetrothed LLC, 5071 Ball Rd, #4838, Cypress, CA 90630
The full privacy policy is at beetrothed.com/privacy.