Privacy Policy

Effective: May 11, 2026

Last Updated:May 11, 2026 — DPIA reference (Phase 1.7), EU / UK Article 27 representative disclosure (designation in progress), pre-renewal email reminder commitment.

1.Services Provided "AS IS / AS AVAILABLE"

The Services provide AI-assisted party planning, venue recommendations, and related features. We strive to provide helpful and accurate information, but the Services are provided "AS IS" and "AS AVAILABLE" without warranties of any kind.

Service Nature

Venue availability, pricing, and other information may change without notice. We recommend confirming details directly with venues before making reservations or commitments.

2.Scope

This Privacy Policy applies to information we collect when you use our website, mobile applications, and other online products and services that link to this Privacy Policy (collectively, the "Services"), or when you otherwise interact with us.

This Privacy Policy does not apply to third-party websites, products, or services, even if they are linked from our Services. Please review the privacy policies of any third-party services you access.

3.Eligibility / Minors

The Services are not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you are under 13, please do not use the Services or provide any information to us.

Age verification at signup.Before you can finish creating an account, we ask for your date of birth. We use that information only to enforce the eligibility rules in this section and to comply with the U.S. Children's Online Privacy Protection Act (COPPA). If the date you provide indicates you are under 13, your account is automatically rejected and any information already entered (such as your email address and any failed signup attempts) is deleted from our systems.

If you are between 13 and 17 years of age, you may only use the Services with the consent and supervision of a parent or legal guardian who agrees to be bound by our Terms of Use. As part of the age-verification step, users 13 to 17 must confirm that a parent or legal guardian has reviewed this Privacy Policy. We do not separately collect a parent's contact information at signup; we rely on this self-attestation, and you represent and warrant that the attestation is truthful.

We retain the date of birth, the country you select at signup, and (for users 13 to 17) the timestamp of the parental-supervision confirmation as compliance evidence. The date of birth is treated as sensitive personal information and is not exposed in our public APIs.

If we learn that we have collected personal information from a child under 13, we will take steps to delete such information as quickly as possible. If you believe we may have collected information from a child under 13, please contact us at privacy@cheerfully.ai.

4.Categories of Information We Collect

We collect information in several ways, as described in the following subsections.

A.Information You Provide

We collect information you provide directly to us, including:

  • Account Information: Name, email address, phone number, and other contact details when you create an account.
  • Party Details: Information about your event including party type, date, location, guest of honor details, number of guests, and preferences.
  • Payment Information: Payment card details and billing information processed through our payment processor (Stripe).
  • Communications: Information you provide when you contact us for support or other inquiries.
  • User Content: Photos, videos, messages, and other content you upload or create using the Services.
  • Marketing Consent: If you opt in to receive marketing emails at signup or in your notification settings, we record the timestamp of your opt-in, a truncated form of your IP address (the last octet is zeroed), and the version of this Privacy Policy in effect at the time. We retain this record as proof of consent under Canada's Anti-Spam Legislation (CASL §13) and the GDPR's demonstrability requirement (Art. 7(1)). We do not sell or share your contact information with third parties for their own marketing purposes; every marketing email we send includes a one-click unsubscribe link.

B.Automatically Collected Information

When you use our Services, we automatically collect certain information, including:

  • Device Information: Device type, operating system, unique device identifiers, and browser type.
  • Usage Information: Pages visited, features used, time spent on pages, and other interaction data.
  • Location Information: General location based on IP address, and with your permission, more precise location data.
  • Log Information: Access times, error logs, and referring URLs.

C.Information from Third Parties

We may receive information about you from third parties:

  • Venue Partners: Information about venue availability and services.
  • Payment Processors: Transaction and payment verification information.
  • Analytics Providers: Information about how users interact with our Services, including Vercel Analytics(cookieless web analytics that processes IP address, user-agent, derived geo and device class). Vercel Analytics only loads after you grant the “Analytics” consent category at /privacy/preferences. The full list of third parties we share data with is published at /legal/sub-processors.

D.Derived Information

We may derive additional information or draw inferences about you based on the information we collect. For example, we may infer your preferences based on your search history and interactions with the Services.

E.Aggregated Information

We may aggregate information collected from multiple users so that it no longer identifies any individual user. We use aggregated information for analytics, research, and to improve our Services.

5.How We Use Information

We use the information we collect to:

  1. Provide and Improve Services: Operate, maintain, and enhance our Services, including AI-powered venue recommendations and party planning features.
  2. Personalize Your Experience: Tailor content and recommendations based on your preferences and usage patterns.
  3. Process Transactions: Process payments, send transaction notifications, and manage your account.
  4. Communicate With You: Send service-related communications, respond to your inquiries, and provide customer support.
  5. Marketing: Send promotional communications about products, services, and events (with your consent where required).
  6. Safety and Security: Detect, prevent, and address fraud, abuse, and security issues.
  7. Legal Compliance: Comply with applicable laws, regulations, and legal processes.

Measurement and Billing

Our records and determinations may control for measurement and billing purposes. If there is a discrepancy between your records and ours, our records will be considered accurate for billing and usage tracking.

6.AI Processing; Content Rights

Our Services use artificial intelligence and machine learning technologies. This section describes how we process content in connection with these features.

A.AI-Powered Features

We use AI to provide venue recommendations, generate party planning suggestions, and power our conversational assistant. These features analyze the information you provide to generate personalized outputs.

B.Submitted Content License

By submitting content to our Services, you grant us a non-exclusive, worldwide, royalty-free license to use, process, modify, and create derivative works from your content for the purpose of providing and improving our Services.

Important Notice

Submitted Content should not be considered confidential. Do not submit information you consider confidential, proprietary, or sensitive. Information you provide may be processed by AI systems and used to improve our Services.

C.AI Output Ownership

Subject to our Terms of Use, you may use AI-generated outputs (such as party planning suggestions and venue recommendations) for your personal, non-commercial purposes. We make no claims to ownership of original content you create based on AI suggestions.

D.Training and Improvement

We may use aggregated and de-identified data derived from user interactions to train and improve our AI models. This helps us provide better recommendations and enhance the overall quality of our Services.

7.How We Share Information

We do not sell your personal information. We may share your information in the following circumstances:

A.Service Providers

We share information with third-party service providers who perform services on our behalf, such as payment processing (Stripe), cloud hosting, analytics, customer support, and error monitoring (Sentry — Functional Software Inc.). Sentry receives diagnostic data when an unexpected error occurs in our applications: stack traces, request URL pathnames, browser user agent, and breadcrumbs of recent actions. Before the error event leaves our infrastructure we run a PII redactor that strips any payload field matching email, phone, token, cookie, authorization, password, OTP, recovery code, MFA secret, or similar — see our Sub-Processors page for the full list and the regions each provider operates in. All providers are contractually obligated to protect your information.

B.Business Transfers

If we are involved in a merger, acquisition, financing, or sale of business assets, your information may be transferred as part of that transaction. We will notify you of any change in ownership or uses of your personal information.

C.Legal Requirements

We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., court orders, subpoenas, or government regulations).

D.With Your Consent

We may share your information with third parties when you give us explicit consent to do so.

E.Aggregated or De-identified Data

We may share aggregated or de-identified information that cannot reasonably be used to identify you with third parties for research, analytics, or other purposes.

F.Invitation Links and Shareable URLs

When you create an invitation, RSVP link, or co-planner invite, we generate a unique URL that lets the recipient view or respond to the party without logging in. Anyone with the URL can RSVP and view the guest details we've associated with the link, so share carefully — treat the URL as a password. If you suspect a link has been shared too widely, you can rotate it from the invitation list, which invalidates the previous URL immediately. We store these tokens hashed at rest, so even our own staff cannot recover the original URL after issuance.

8.Cookies, SDKs, and Similar Technologies

We use cookies, web beacons, SDKs, and similar technologies to collect information about your interactions with our Services. These technologies help us:

  • Remember your preferences and settings
  • Authenticate users and prevent fraud
  • Analyze usage patterns and improve our Services
  • Deliver relevant content and measure its effectiveness

We group cookies and tracking technologies into four categories: strictly necessary, functional, analytics, and marketing. Strictly necessary cookies are always on (without them, the site can't authenticate you or remember your consent decision). The other three categories are off until you opt in. You can review and change your choices any time at /privacy/preferences. We honor the Global Privacy Control (Sec-GPC) header — when your browser sends it, we set analytics and marketing to off automatically, even before you interact with the banner.

9.Your Choices and Rights

You have several choices regarding your information:

  • Account Information: You can review and update your account information through your account settings.
  • Marketing Communications: You can opt out of promotional emails by following the unsubscribe instructions in those messages. Note that you may still receive service-related communications.
  • Cookies and tracking: Manage which cookie categories load (functional, analytics, marketing) at /privacy/preferences. The same page is also linked from the footer as “Do Not Sell or Share My Personal Information.”
  • Global Privacy Control: If your browser sends the Sec-GPC signal we treat it as an opt-out of analytics and marketing without requiring a banner click.
  • Download my data:Signed-in users can request a ZIP archive of their account data — profile, parties, invitations, planning sessions, chat, payments, media — by clicking “Download my data” in account settings. We'll email a 6-digit verification code to confirm the request, then assemble the archive and email a private download link valid for 7 days. We rate-limit data-export requests to one per 24 hours.
  • Delete your account (with a 14-day cooling-off period): Signed-in users can schedule their account for permanent deletion from account settings. We email a 6-digit code to confirm, then schedule the cascade for 14 days later and send you a confirmation with a one-click cancel link. You can cancel any time within the 14 days from the same settings page; once the grace window elapses your account and all associated data are permanently removed.
  • Privacy rights request form: Submit access, deletion, portability, correction, opt-out of sale or share, and limit-sensitive-PI requests at /privacy/rights-request. Every request is verified by emailing a single-use link to the address you supply — your request is not escalated to our privacy team until you click that link, which short- circuits drive-by impersonation. We respond within 30 days (the shortest of the GDPR / CCPA / state-law SLAs we're subject to); complex requests can extend up to 90 days under those laws and we'll tell you when that applies. Email-only is the v1 verification standard; for higher-risk request types we may ask for additional identity proof.
  • Data Deletion (alternative channel): You can also email privacy@cheerfully.ai directly. The in-product flows above are the recommended channels — they give you a tracking reference and a faster turnaround — but the email alternative satisfies the CCPA §1798.130(a)(1)(A) “two designated methods” requirement.

Guest List Responsibility

If you create invitations and share guest information with us, you are responsible for ensuring you have the appropriate permissions to share that information. Please inform your guests that their information may be processed through our Services.

10.Data Retention

We retain your information for as long as your account is active or as needed to provide you with our Services. We may also retain information as required by law, to resolve disputes, enforce our agreements, and for legitimate business purposes.

When we no longer need to retain your information, we will securely delete or anonymize it. The retention period may vary depending on the context and our legal obligations.

11.Security

We implement appropriate technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction. These measures include encryption, access controls, structured server-side logs with automatic PII redaction, regular security assessments, and a published security disclosure file at /.well-known/security.txt.

Data Protection Impact Assessment.We have conducted a Data Protection Impact Assessment under GDPR Article 35 covering our processing of children’s data, AI-driven recommendations, geolocation, and the embedded widget’s third-party-site footprint. The DPIA is reviewed at least annually and on any material change to the processing operations described in this policy.

Security Limitations

While we strive to protect your information, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee absolute security of your data.

12.International Processing

Your information may be transferred to, stored, and processed in the United States and other countries where we or our service providers operate. These countries may have different data protection laws than your country of residence.

By using our Services, you consent to the transfer of your information to the United States and other countries. We take steps to ensure that your information receives an adequate level of protection in the jurisdictions in which we process it.

EU / UK Article 27 Representative.Under GDPR Article 27 and UK GDPR §27, we are designating an in-region representative authorised to receive correspondence from EU / UK data subjects and supervisory authorities. The designation is currently in progress, with a target completion date of June 10, 2026. The representative’s name and contact details will appear in this section and on /legal/contacts §4 once the engagement is finalised. In the meantime, EU and UK data subjects may direct GDPR / UK GDPR rights requests to dpo@cheerfully.ai or via the verified form at /privacy/rights-request; we respond directly as the controller within Art. 12(3)’s 30-day window.

13.Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by posting the updated policy on our website and updating the "Last Updated" date at the top of this page.

We encourage you to review this Privacy Policy periodically to stay informed about how we collect, use, and protect your information. Your continued use of the Services after any changes indicates your acceptance of the updated policy.

14.Contact

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us. Under the Personal Information Protection and Electronic Documents Act (PIPEDA) and Quebec Law 25, we have designated an individual accountable for our compliance with applicable privacy laws.

Cheerfully

9100 S. Nicholson Rd.

Oak Creek, WI 53154

Privacy Officer:Aaron Fischer (Founder & Privacy Officer, Cheerfully)

Privacy Inquiries: privacy@cheerfully.ai

General Support: support@cheerfully.ai

See /legal/contacts for the full list of privacy, DPO, security, and abuse contact addresses and our designated Privacy Officer’s contact details.