Privacy Policy
Gatherix LLC, a South Carolina limited liability company · Version v1.1 · Last updated August 6, 2026
This Privacy Policy explains how Gatherix LLC (“Gatherix,” “we,” “us,” or “our”) collects, uses, shares, and protects personal information when you use the Gatherix platform, website, and mobile applications (the “Service”). By using the Service, you agree to this Privacy Policy. If you do not agree, do not use the Service.
1. Who This Policy Covers
This Policy applies to all users of the Service, including planners, clients, vendors, attendees, and administrators. Because the Service is designed for events, some information is provided directly by you, and some is provided about you by others—for example, when a planner invites you to an event or adds your information as an attendee.
Account holders must be at least 18 years old. The Service is not directed to children under 18, and we do not knowingly collect personal information directly from children under 18. If you upload information about an attendee under 18, you are responsible for having obtained any required parental or guardian consent (see Section 8).
2. Information We Collect
2.1 Account information.
When you create or use an account, we collect identifiers and profile details, including your email, name, avatar, phone number, role, plan tier, and your communication and notification preferences. Authentication is handled by our identity provider, which assigns a unique account identifier.
2.2 Planner and vendor profile information.
If you create a planner or vendor profile, we collect business details you provide, such as business name, location, website, bio, years in business, events per year, event types, vendor categories, price range, dietary and accessibility information, cover and portfolio images, and social media handles (for example, Instagram, Facebook, TikTok, and YouTube).
2.3 Attendee and guest information.
When you are invited to or added to an event, we may process your name, email, role or organization, dietary needs, plus-one count, RSVP status, check-in status, and planner notes about you. This information is typically provided by the planner who manages the event.
2.4 Payment information.
Payments are processed by Stripe. We do not store full payment card numbers. We store payment-related references and records, such as customer and subscription identifiers, price identifiers, connected-account identifiers and capability flags, payment and session identifiers, receipt URLs, amounts paid or refunded, and pointers to saved payment methods used for autopay.
2.5 Contracts, proposals, and invoices.
When agreements are signed through the Service, we collect clickwrap audit records, including the signer’s name, IP address, and acknowledgment and acceptance timestamps, along with client name and email. For invoices, we process client name, email, line items, and amounts. These records may be retained as evidence of the agreement even after an account is closed.
2.6 Inquiries, bookings, and consultations.
When you contact a vendor or book a consultation, we process information such as your message, event type and date, guest count, budget range, and for consultations your name, email, phone, notes, and meeting location.
2.7 Messaging.
We process messages sent through the Service, including thread subjects, recipient names and emails, message contents, and author names.
2.8 Reviews.
If you submit a review, we collect your rating, title, and comment.
2.9 Connected accounts (OAuth integrations).
If you connect a third-party account such as Google, we store access and refresh tokens, the scope of access you grant, and the connected account email so we can provide the integration (for example, syncing calendar events). You can disconnect an integration at any time, which revokes our ongoing access. Section 5 describes our handling of Google user data in full.
2.10 Information collected automatically.
We automatically collect certain technical and usage data, including profile-view records, security telemetry such as content-security-policy violation reports (which may include user agent and source URLs), calendar event identifiers, and time-zone information. We and our providers may use cookies or similar technologies to operate and secure the Service.
3. How We Use Information
We use personal information to:
- Provide, operate, maintain, and secure the Service;
- Create and manage accounts, profiles, and events;
- Facilitate communication, bookings, payments, contracts, and invoices between users;
- Process subscriptions, commissions, and other fees;
- Send transactional messages and, where permitted, service updates;
- Provide optional AI-assisted features, such as event-planning suggestions;
- Personalize and improve the Service and develop new features;
- Detect, prevent, and respond to fraud, abuse, and security issues;
- Maintain records of agreements and transactions; and
- Comply with legal obligations and enforce our Terms.
Google user data is excepted from several of the uses above. Information obtained through Google APIs is used only as described in Section 5, and is never used for AI-assisted features, advertising, or model training.
4. How We Share Information
We do not sell your personal information. We share information in the following circumstances:
4.1 With other users.
The Service is collaborative. Information you provide is shared with the users you interact with—for example, a planner can see attendee RSVP details, and a vendor can see a client’s inquiry. Profile and listing information may be visible to users who can access the relevant event or marketplace listing.
4.2 With service providers (sub-processors).
We use trusted third parties to operate the Service. They process information on our behalf under their own terms and privacy practices:
| Provider | Purpose |
|---|---|
| Clerk | User authentication and account management |
| Stripe | Payment processing, payouts, and related identity/KYC checks |
| Supabase | Database hosting and storage of uploaded files and documents |
| Resend | Sending transactional email |
| Anthropic | Processing inputs for AI-assisted event-planning features. Google user data is never sent to this provider. |
| Calendar integration (when you connect a Google account) |
4.3 For legal and safety reasons.
We may disclose information to comply with law, respond to lawful requests, enforce our Terms, or protect the rights, property, or safety of Gatherix, our users, or others.
4.4 Business transfers.
If Gatherix is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.
5. Google User Data
Gatherix’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. This section governs Google user data specifically and controls over any more general statement elsewhere in this Policy.
5.1 What we access, and why.
Connecting a Google account is entirely optional. The Service functions fully without it. When you choose to connect one, we request only the following scopes:
| Scope requested | Why we need it |
|---|---|
| https://www.googleapis.com/auth/calendar.events | Create, read, and update calendar events so that bookings, consultations, and event dates managed in Gatherix appear on your Google Calendar and stay in sync. We do not access, read, or modify any other part of your Google account. |
| https://www.googleapis.com/auth/userinfo.email | Identify which Google account you connected, so the integration can be displayed and disconnected correctly. |
5.2 How we use it.
Google user data is used solely to provide and improve the calendar-sync feature you enabled, which is visible and prominent in the Gatherix interface. We do not use it for any other purpose.
5.3 Limited Use commitments.
We affirmatively commit to the following, without exception:
- We use Google user data only to provide and improve the user-facing calendar features you have enabled.
- We do not transfer Google user data to any third party except as necessary to provide those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets in which users are notified.
- We do not use Google user data for advertising of any kind, and we do not serve advertising in the Service.
- We do not use Google user data to develop, train, improve, or evaluate any artificial intelligence or machine learning model, whether generalized or personalized. Google user data is never sent to our AI provider or to any AI-assisted feature of the Service.
- We do not allow humans to read Google user data, except with your explicit consent for a specific issue you have raised, where necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and anonymized for internal operations.
5.4 How it is stored and protected.
Google access and refresh tokens are stored encrypted at rest on our infrastructure, are accessible only to the systems that perform calendar synchronization, and are never exposed to your browser or to other users of the Service. Calendar content itself is not copied into our database beyond the event identifiers required to keep records linked.
5.5 How to revoke access, and what happens to the data.
You may disconnect the integration at any time from Settings within Gatherix, or by revoking access from your Google Account’s security settings at myaccount.google.com/permissions. On disconnection we delete the stored access and refresh tokens and stop all further access to your Google account. Calendar events previously created remain on your Google Calendar for you to keep or delete as you choose; Gatherix no longer manages them.
6. AI-Assisted Features
Certain optional features use a third-party AI provider (Anthropic) to generate suggestions, such as event-planning ideas. When you use these features, the inputs you provide are sent to the provider to generate a response. Do not enter sensitive personal information you do not wish to be processed in this way. These features are provided as helpful tools and you are responsible for reviewing any output before relying on it.
Google user data is excluded from these features entirely. No information obtained through Google APIs is sent to our AI provider, used to generate AI output, or used to develop, train, improve, or evaluate any AI or machine learning model. See Section 5.3.
7. Data Retention
We retain personal information for as long as your account is active or as needed to provide the Service, and afterward as needed to comply with legal obligations, resolve disputes, enforce agreements, and maintain business records. Certain records—such as transaction histories and signed-agreement audit records (including signer name, IP address, and timestamps)—may be retained after account closure where we have a legal or legitimate business reason. Backup copies may persist for a limited period. Google access and refresh tokens are an exception: they are deleted promptly when you disconnect the integration or close your account, and are not retained in backups beyond the ordinary backup rotation.
8. Information About Others and Minors
If you upload or share information about another person (such as an attendee), you represent that you have the authority and any necessary consent to do so. You agree not to upload personal information of anyone under 18 without verifiable consent from that individual’s parent or legal guardian. If you believe a minor’s information has been provided to us without proper consent, contact us and we will take appropriate steps to address it.
9. Your Privacy Rights
Depending on where you live, you may have rights regarding your personal information. We extend the following core rights to our users:
- Access — request a copy of the personal information we hold about you;
- Correction — request that we correct inaccurate information;
- Deletion — request that we delete your personal information, subject to legal and record-keeping exceptions;
- Portability — request a copy of certain information in a portable format;
- Opt-out of marketing — unsubscribe from non-essential communications at any time; and
- Non-discrimination — we will not discriminate against you for exercising your rights.
9.1 California residents.
If you are a California resident, you have rights under the California Consumer Privacy Act, as amended, including the rights to know, delete, correct, and opt out of the “sale” or “sharing” of personal information. We do not sell personal information. You may exercise these rights as described below, and you may use an authorized agent.
9.2 Other U.S. state residents.
Residents of other states with comprehensive privacy laws may have similar rights to access, correct, delete, and opt out of certain processing. We honor these rights as required by applicable law.
9.3 Users outside the United States.
The Service is operated from the United States. If you access it from outside the U.S., you understand your information will be processed in the U.S. Where applicable laws such as the GDPR apply, we process personal data on lawful bases including performance of a contract, legitimate interests, consent, and legal obligations, and you may have additional rights including the right to object and to lodge a complaint with a supervisory authority.
9.4 How to exercise your rights.
To make a request, contact us at the email in Section 13. We will verify your request and respond within the time required by applicable law. We may need to retain certain information to comply with legal obligations even after a deletion request.
10. Security
We use administrative, technical, and physical safeguards designed to protect personal information, and we rely on reputable providers for authentication, payment processing, and hosting. Data is encrypted in transit using industry-standard TLS, and credentials and integration tokens are encrypted at rest. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. You are responsible for keeping your login credentials confidential.
11. Your Choices
You can update your profile and notification preferences in your account settings, disconnect third-party integrations, unsubscribe from non-essential emails, and request account deletion. Some communications are essential to the Service (such as transaction and security notices) and cannot be turned off while you maintain an account.
12. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the Service or by email. The “Last Updated” date and version number above reflect the most recent revision. Your continued use of the Service after changes take effect means you accept the updated Policy.
13. Contact Us
Gatherix LLC
6650 Rivers Ave, Suite 100, Charleston, SC 29406
Privacy requests and general contact: legal@gatherixapp.com
We respond to privacy and data-access requests at this address.