Draft — pending legal review. This template must be reviewed by counsel and finalized (legal entity, data-retention periods, jurisdiction-specific rights) before launch.

Privacy Policy

Last updated: July 8, 2026

This policy explains how VenueSite (“we”) handles information for two groups: venue owners who use our platform, and the couples and clients who submit inquiries on a venue site we host.

Information we collect

  • From venue owners: name, email, phone, business details, venue attributes, photos, and content you enter; account and authentication data; subscription and billing metadata.
  • From couples/clients: the contact and event details submitted through an inquiry form (name, email, phone, event type and date, guest count, budget range, message).
  • Automatically: basic request data such as IP address and timestamps, used for security, rate limiting, and abuse prevention.

How we use information

  • To build, host, and operate your venue website and generate draft marketing copy from the facts you provide.
  • To capture inquiries and deliver them to the venue's CRM and notification email.
  • To authenticate sign-ins and send transactional email (preview links, sign-in links, lead notifications).
  • To secure the service — rate limiting, moderation, and fraud/abuse prevention.
  • To bill subscriptions and provide support.

Roles

For inquiry data submitted on a venue site, the venue is the controller of that data and VenueSite processes it on the venue's behalf to deliver the lead. Venues are responsible for their own lawful use of client contact information, including any follow-up marketing or SMS.

Service providers

We share information only with providers that help us run the service:

  • Neon — database hosting.
  • Vercel — application hosting and delivery.
  • Resend — transactional email.
  • OpenRouter / Anthropic — AI generation of marketing copy from the facts you provide, and automated review of uploaded photos.
  • Cloudflare — image storage and delivery (when photo features are enabled).
  • Sightengine — automated image moderation (when enabled).
  • Google — address autocomplete during intake (when enabled).
  • Stripe — subscription billing (when enabled).

We do not sell personal information.

Cookies

We use strictly necessary cookies for authentication and session management. We do not use third-party advertising cookies on venuesite.us.

Data retention

We keep venue account data for as long as the account is active and as needed to provide the service. Draft sites that are never verified are removed after a period of inactivity. Inquiry data is retained in the venue's CRM until the venue deletes it or closes the account. (Specific retention windows to be finalized before launch.)

Security

We use row-level security, scoped access controls, encrypted transport, and least-privilege service credentials. No system is perfectly secure; we cannot guarantee absolute security.

Your choices & rights

You may access, correct, or delete your account information from the dashboard or by contacting us. Depending on your location, you may have additional rights (access, deletion, portability, objection). Clients who inquired with a venue should contact that venue, the controller of their data; we will assist venues in responding.

Children

The service is not directed to children under 18 and we do not knowingly collect their information.

SMS consent

Mobile numbers provided through an inquiry form are used by the venue to respond about the inquiry, tours, and bookings. Consent is not a condition of purchase; reply STOP to opt out. Mobile opt-in data is not shared with third parties for their marketing and is never sold.

Changes & contact

We may update this policy; changes are effective when posted here. Questions? Email privacy@venuesite.us.