Privacy Policy
Effective: May 11, 2026
Last Updated:May 11, 2026 — DPIA reference (Phase 1.7), EU / UK Article 27 representative disclosure (designation in progress), pre-renewal email reminder commitment.
1.Services Provided "AS IS / AS AVAILABLE"
The Services provide AI-assisted party planning, venue recommendations, and related features. We strive to provide helpful and accurate information, but the Services are provided "AS IS" and "AS AVAILABLE" without warranties of any kind.
Service Nature
2.Scope
This Privacy Policy applies to information we collect when you use our website, mobile applications, and other online products and services that link to this Privacy Policy (collectively, the "Services"), or when you otherwise interact with us.
This Privacy Policy does not apply to third-party websites, products, or services, even if they are linked from our Services. Please review the privacy policies of any third-party services you access.
3.Eligibility / Minors
The Services are not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you are under 13, please do not use the Services or provide any information to us.
Age verification at signup.Before you can finish creating an account, we ask for your date of birth. We use that information only to enforce the eligibility rules in this section and to comply with the U.S. Children's Online Privacy Protection Act (COPPA). If the date you provide indicates you are under 13, your account is automatically rejected and any information already entered (such as your email address and any failed signup attempts) is deleted from our systems.
If you are between 13 and 17 years of age, you may only use the Services with the consent and supervision of a parent or legal guardian who agrees to be bound by our Terms of Use. As part of the age-verification step, users 13 to 17 must confirm that a parent or legal guardian has reviewed this Privacy Policy. We do not separately collect a parent's contact information at signup; we rely on this self-attestation, and you represent and warrant that the attestation is truthful.
We retain the date of birth, the country you select at signup, and (for users 13 to 17) the timestamp of the parental-supervision confirmation as compliance evidence. The date of birth is treated as sensitive personal information and is not exposed in our public APIs.
If we learn that we have collected personal information from a child under 13, we will take steps to delete such information as quickly as possible. If you believe we may have collected information from a child under 13, please contact us at privacy@cheerfully.ai.
4.Categories of Information We Collect
We collect information in several ways, as described in the following subsections.
A.Information You Provide
We collect information you provide directly to us, including:
- Account Information: Name, email address, phone number, and other contact details when you create an account.
- Party Details: Information about your event including party type, date, location, guest of honor details, number of guests, and preferences.
- Payment Information: Payment card details and billing information processed through our payment processor (Stripe).
- Communications: Information you provide when you contact us for support or other inquiries.
- User Content: Photos, videos, messages, and other content you upload or create using the Services.
- Marketing Consent: If you opt in to receive marketing emails at signup or in your notification settings, we record the timestamp of your opt-in, a truncated form of your IP address (the last octet is zeroed), and the version of this Privacy Policy in effect at the time. We retain this record as proof of consent under Canada's Anti-Spam Legislation (CASL §13) and the GDPR's demonstrability requirement (Art. 7(1)). We do not sell or share your contact information with third parties for their own marketing purposes; every marketing email we send includes a one-click unsubscribe link.
B.Automatically Collected Information
When you use our Services, we automatically collect certain information, including:
- Device Information: Device type, operating system, unique device identifiers, and browser type.
- Usage Information: Pages visited, features used, time spent on pages, and other interaction data.
- Location Information: General location based on IP address, and with your permission, more precise location data.
- Log Information: Access times, error logs, and referring URLs.
C.Information from Third Parties
We may receive information about you from third parties:
- Venue Partners: Information about venue availability and services.
- Payment Processors: Transaction and payment verification information.
- Analytics Providers: Information about how users interact with our Services, including Vercel Analytics(cookieless web analytics that processes IP address, user-agent, derived geo and device class). Vercel Analytics only loads after you grant the “Analytics” consent category at /privacy/preferences. The full list of third parties we share data with is published at /legal/sub-processors.
D.Derived Information
We may derive additional information or draw inferences about you based on the information we collect. For example, we may infer your preferences based on your search history and interactions with the Services.
E.Aggregated Information
We may aggregate information collected from multiple users so that it no longer identifies any individual user. We use aggregated information for analytics, research, and to improve our Services.
5.How We Use Information
We use the information we collect to:
- Provide and Improve Services: Operate, maintain, and enhance our Services, including AI-powered venue recommendations and party planning features.
- Personalize Your Experience: Tailor content and recommendations based on your preferences and usage patterns.
- Process Transactions: Process payments, send transaction notifications, and manage your account.
- Communicate With You: Send service-related communications, respond to your inquiries, and provide customer support.
- Marketing: Send promotional communications about products, services, and events (with your consent where required).
- Safety and Security: Detect, prevent, and address fraud, abuse, and security issues.
- Legal Compliance: Comply with applicable laws, regulations, and legal processes.
Measurement and Billing
6.AI Processing; Content Rights
Our Services use artificial intelligence and machine learning technologies. This section describes how we process content in connection with these features.
A.AI-Powered Features
We use AI to provide venue recommendations, generate party planning suggestions, and power our conversational assistant. These features analyze the information you provide to generate personalized outputs.
B.Submitted Content License
By submitting content to our Services, you grant us a non-exclusive, worldwide, royalty-free license to use, process, modify, and create derivative works from your content for the purpose of providing and improving our Services.
Important Notice
C.AI Output Ownership
Subject to our Terms of Use, you may use AI-generated outputs (such as party planning suggestions and venue recommendations) for your personal, non-commercial purposes. We make no claims to ownership of original content you create based on AI suggestions.
D.Training and Improvement
We may use aggregated and de-identified data derived from user interactions to train and improve our AI models. This helps us provide better recommendations and enhance the overall quality of our Services.
9.Your Choices and Rights
You have several choices regarding your information:
- Account Information: You can review and update your account information through your account settings.
- Marketing Communications: You can opt out of promotional emails by following the unsubscribe instructions in those messages. Note that you may still receive service-related communications.
- Cookies and tracking: Manage which cookie categories load (functional, analytics, marketing) at /privacy/preferences. The same page is also linked from the footer as “Do Not Sell or Share My Personal Information.”
- Global Privacy Control: If your browser sends the Sec-GPC signal we treat it as an opt-out of analytics and marketing without requiring a banner click.
- Download my data:Signed-in users can request a ZIP archive of their account data — profile, parties, invitations, planning sessions, chat, payments, media — by clicking “Download my data” in account settings. We'll email a 6-digit verification code to confirm the request, then assemble the archive and email a private download link valid for 7 days. We rate-limit data-export requests to one per 24 hours.
- Delete your account (with a 14-day cooling-off period): Signed-in users can schedule their account for permanent deletion from account settings. We email a 6-digit code to confirm, then schedule the cascade for 14 days later and send you a confirmation with a one-click cancel link. You can cancel any time within the 14 days from the same settings page; once the grace window elapses your account and all associated data are permanently removed.
- Privacy rights request form: Submit access, deletion, portability, correction, opt-out of sale or share, and limit-sensitive-PI requests at /privacy/rights-request. Every request is verified by emailing a single-use link to the address you supply — your request is not escalated to our privacy team until you click that link, which short- circuits drive-by impersonation. We respond within 30 days (the shortest of the GDPR / CCPA / state-law SLAs we're subject to); complex requests can extend up to 90 days under those laws and we'll tell you when that applies. Email-only is the v1 verification standard; for higher-risk request types we may ask for additional identity proof.
- Data Deletion (alternative channel): You can also email privacy@cheerfully.ai directly. The in-product flows above are the recommended channels — they give you a tracking reference and a faster turnaround — but the email alternative satisfies the CCPA §1798.130(a)(1)(A) “two designated methods” requirement.
Guest List Responsibility
10.Data Retention
We retain your information for as long as your account is active or as needed to provide you with our Services. We may also retain information as required by law, to resolve disputes, enforce our agreements, and for legitimate business purposes.
When we no longer need to retain your information, we will securely delete or anonymize it. The retention period may vary depending on the context and our legal obligations.
11.Security
We implement appropriate technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction. These measures include encryption, access controls, structured server-side logs with automatic PII redaction, regular security assessments, and a published security disclosure file at /.well-known/security.txt.
Data Protection Impact Assessment.We have conducted a Data Protection Impact Assessment under GDPR Article 35 covering our processing of children’s data, AI-driven recommendations, geolocation, and the embedded widget’s third-party-site footprint. The DPIA is reviewed at least annually and on any material change to the processing operations described in this policy.
Security Limitations
12.International Processing
Your information may be transferred to, stored, and processed in the United States and other countries where we or our service providers operate. These countries may have different data protection laws than your country of residence.
By using our Services, you consent to the transfer of your information to the United States and other countries. We take steps to ensure that your information receives an adequate level of protection in the jurisdictions in which we process it.
EU / UK Article 27 Representative.Under GDPR Article 27 and UK GDPR §27, we are designating an in-region representative authorised to receive correspondence from EU / UK data subjects and supervisory authorities. The designation is currently in progress, with a target completion date of June 10, 2026. The representative’s name and contact details will appear in this section and on /legal/contacts §4 once the engagement is finalised. In the meantime, EU and UK data subjects may direct GDPR / UK GDPR rights requests to dpo@cheerfully.ai or via the verified form at /privacy/rights-request; we respond directly as the controller within Art. 12(3)’s 30-day window.
13.Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by posting the updated policy on our website and updating the "Last Updated" date at the top of this page.
We encourage you to review this Privacy Policy periodically to stay informed about how we collect, use, and protect your information. Your continued use of the Services after any changes indicates your acceptance of the updated policy.
14.Contact
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us. Under the Personal Information Protection and Electronic Documents Act (PIPEDA) and Quebec Law 25, we have designated an individual accountable for our compliance with applicable privacy laws.
Cheerfully
9100 S. Nicholson Rd.
Oak Creek, WI 53154
Privacy Officer:Aaron Fischer (Founder & Privacy Officer, Cheerfully)
Privacy Inquiries: privacy@cheerfully.ai
General Support: support@cheerfully.ai
See /legal/contacts for the full list of privacy, DPO, security, and abuse contact addresses and our designated Privacy Officer’s contact details.