Clear Planner
Privacy Policy
Last updated [Month DD, YYYY]
Draft — not yet legal advice
This document is a working template to speed up your lawyer’s work — it is not legal advice and is not yet in force. Every highlighted field (like [Legal Entity Name]) must be completed, and the whole document reviewed by a qualified attorney in your jurisdiction, before you publish it or rely on it.
This Privacy Policy explains how [Legal Entity Name] (“Clear Planner,” “we,” “us,” or “our”) collects, uses, and shares information when you use our platform and websites (the “Service”). It also explains the choices you have. Terms not defined here have the meaning given in our Terms of Service.
1.Our two roles
Clear Planner handles information in two capacities:
- For our own account holders (coordinators, planners, and venues) and website visitors, we act as the controller of your account and usage information.
- For the personal information that account holders enter or collect about couples, guests, and vendors (for example, questionnaire responses), we act as a processor on the account holder's behalf. That account holder is the controller of that information, and its own privacy notice governs it.
If you are a couple, guest, or vendor and have questions about your information, please contact the coordinator or business that invited you; we will support their handling of your request.
2.Information we collect
- Account information — name, email address, organization name, and authentication details when you create an account.
- Customer content — questionnaires you build; event details; and the responses and personal information you or your clients submit, which may include couples', guests', and vendors' names, contact details, preferences, and files you upload.
- Communications — records of emails (and, in the future, text messages) sent through the Service, and delivery and engagement signals such as sends and opens.
- Usage and device information — log data, IP address, browser type, pages viewed, and similar information collected automatically when you use the Service.
- Cookies and similar technologies — used to keep you signed in and to operate and improve the Service (see “Cookies” below).
3.How we use information
- to provide, maintain, secure, and improve the Service;
- to authenticate users and validate tokenized links for questionnaires, portals, and vendor maps;
- to send transactional and Service-related communications on behalf of account holders, including questionnaire invitations, portal links, and reminder nudges;
- to provide support and respond to your requests;
- to monitor for fraud, abuse, and security incidents; and
- to comply with legal obligations and enforce our Terms.
We do not sell personal information, and we do not use couples’, guests’, or vendors’ personal information for our own advertising.
4.Legal bases (where applicable)
Where the GDPR, UK GDPR, or similar laws apply, we rely on these legal bases: performance of a contract; our legitimate interests in operating and securing the Service; your consent where required; and compliance with legal obligations. For personal information we process on behalf of an account holder, that account holder is responsible for establishing the legal basis. [Confirm applicable frameworks and bases with counsel.]
5.How we share information
We share information only as described here:
- Subprocessors — service providers that host and operate the Service on our behalf under contract (see the list below).
- At an account holder's direction — for example, delivering communications and links to the couples, guests, and vendors they choose.
- Legal and safety — when required by law or to protect the rights, property, or safety of our users, the public, or us.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.
Current subprocessors
- [Supabase] — database, authentication, and file storage.
- [Vercel] — application hosting and content delivery.
- [MailerSend] — email delivery.
- [Add any others, e.g. SMS or analytics providers, before launch.]
6.Cookies & engagement signals
We use strictly necessary cookies to keep you signed in and to operate the Service, and we may use limited cookies to remember preferences and improve performance. Emails sent through the Service may include standard open and click signals; because mail-privacy features can inflate open rates, we treat “started” and “submitted” as the meaningful signals. [If you add analytics or non-essential cookies, provide a cookie banner/consent mechanism where required.]
7.Data retention
We retain account and Customer content for as long as your account is active and as needed to provide the Service, then for a reasonable period afterward to comply with legal obligations, resolve disputes, and enforce agreements. Account holders can delete much of their content within the Service. [State specific retention periods and post-termination deletion timelines.]
8.Security
We use technical and organizational measures designed to protect information, including encryption in transit, access controls, and tenant isolation enforced at the database level. Tokenized share links are stored only as hashed values. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9.Your rights & choices
Depending on where you live, you may have rights to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent. Account holders can exercise many of these directly in the Service or by contacting us. If your information was provided to a coordinator or business that uses Clear Planner, please direct your request to them as the controller. [Add jurisdiction-specific disclosures, e.g. CCPA/CPRA “Do Not Sell or Share” and appeal rights, as advised.]
10.Children's information
The Service is intended for professionals and is not directed to children. We do not knowingly collect personal information from children under [13/16, per jurisdiction]. If you believe a child has provided personal information, contact us and we will take appropriate steps.
11.International data transfers
We and our subprocessors may process information in countries other than your own. Where required, we use appropriate safeguards for cross-border transfers. [Identify hosting regions and transfer mechanisms, e.g. Standard Contractual Clauses, with counsel.]
12.Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will provide notice by reasonable means. The “Last updated” date above shows when this Policy was last revised.
13.Contact us
For privacy questions or to exercise your rights, contact [Legal Entity Name] at [privacy@yourdomain.com], [mailing address]. [Name a data protection officer or EU/UK representative if required.]
See also Terms of Service. Questions? Write to us at [support@yourdomain.com].