Entangled

Entangled Privacy Policy

Last Updated: August 25, 2026

This Privacy Policy describes how Entangled Events LLC ("Entangled," "we," "us," or "our") collects, uses, discloses, and protects personal information in connection with entangled.events, event websites hosted by Entangled, the planning console, the vendor portal, and all related applications and services we offer now or in the future (collectively, the "Services"). It applies to weddings, celebrations, and events of every kind planned or operated on the platform. By using the Services you acknowledge this Privacy Policy; it is incorporated into our Terms of Use.

I. Whose Information We Process; Our Role

  • Account holders — hosts, couples, planners, and staff who register to manage an event.
  • Guests and event participants — individuals whose information an account holder submits or who interact with an event's pages (for example, submitting an RSVP or travel details). Guests do not hold accounts.
  • Vendors — businesses and their personnel coordinating with an event.
  • Visitors — individuals browsing our marketing site.

For guest, participant, and vendor information submitted by an account holder in connection with their event, the account holder determines the purposes of that processing and Entangled processes it on the account holder's behalf and instructions to provide the Services. For account, billing, usage, and marketing-site information, Entangled determines the purposes of processing. Account holders are independently responsible for complying with laws applicable to the personal information they collect and the communications they send.

II. Personal Information We Collect

Information you or your event provide directly:

  • Identifiers and contact information: name, email address, phone number, postal address, account credentials, role.
  • Event content: guest lists and household groupings; RSVP responses; dietary preferences and accessibility notes; seating assignments; schedules, tasks, and checklists; photographs, images, video, and audio; event website content; notes and messages composed in the Services.
  • Travel and logistics information: flight, lodging, and transportation details associated with guests and participants, entered manually or extracted from connected accounts.
  • Vendor and transaction records: contracts, proposals, invoices, payment milestones, budgets, and related documents and correspondence.
  • Payment and subscription information: plan, billing records, and payment method details (processed by our payment processors; we do not store full card numbers).
  • Communications: messages, inquiries, and support requests, and, where offered, recordings or transcripts disclosed at the time.

Information from connected services (at the account holder's direction):

  • Connected email accounts (e.g., Gmail via Google OAuth): messages, attachments, and metadata synced from the connected mailbox to organize event correspondence, extract documents, and route travel and vendor information. See Section V.
  • Financial account information via Plaid: account, balance, and transaction data from institutions the account holder connects. We do not receive or store banking credentials; access tokens are stored encrypted. Plaid's processing is governed by Plaid's End User Privacy Policy.
  • Messaging platforms (e.g., WhatsApp via our providers): message content and delivery metadata for conversations routed through the Services.

Information collected automatically:

  • Internet and device activity: IP address, approximate (IP-derived) location, browser and device type, operating system, pages viewed, features used, referring pages, and interaction data, collected via cookies, pixels, local storage, and similar technologies. See Section VII.
  • Log and security data: access logs, authentication events, and abuse-prevention signals.

Information from other sources: other users of your event (for example, a co-host adding guest details or a guest submitting information about members of their party), vendors, public sources, and service providers supporting fraud prevention and analytics.

Inferences: we may derive information from the above (for example, RSVP or budget summaries) to provide the Services.

Sensitive information: certain data we process may be sensitive under applicable law (for example, financial account data, precise dietary or accessibility notes that could imply health or religious information, or message content). We process sensitive information only as necessary to provide the features an account holder uses, to maintain security, and as otherwise permitted by law, and not to infer characteristics for advertising.

III. How We Use Personal Information

We use personal information to: create and administer accounts; provide, operate, personalize, maintain, and improve the Services; deliver messages composed or scheduled by account holders to their guests and vendors; process transactions and subscriptions; power AI-assisted features (Section VI); provide customer support; secure the Services, including authentication, tenant isolation, fraud and abuse prevention, and enforcement of our Terms; maintain records and comply with legal obligations; communicate with account holders about the Services, including service announcements and, subject to opt-out, marketing about our own products; administer surveys or promotions we may offer; and establish, exercise, or defend legal claims.

We do not use event content to market to guests, and we do not sell personal information.

IV. How We Disclose Personal Information

  • Service providers and processors acting on our instructions: cloud hosting and infrastructure, database and storage, file upload and delivery, email delivery, SMS/WhatsApp and telephony, payment processing, AI processing (Section VI), financial data aggregation (Plaid), analytics, security, and customer support tooling. Each is bound to use the information only to provide services to us.
  • Within your event, as directed by its configuration: information is visible to the event's account holders and staff according to their roles; guests see what the event's pages display to them; vendors see the information pertaining to their engagement. Public event websites are visible to anyone with the link unless protected by the event's access controls.
  • At an account holder's direction: for example, when they export data, share links, or connect third-party services.
  • Legal and safety: to comply with law, regulation, legal process, or governmental request; to enforce our Terms; or to protect the rights, property, or safety of Entangled, our users, or the public.
  • Corporate transactions: in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, personal information may be transferred as permitted by law, subject to this Policy or successor commitments and, where required, notice to you.

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising as those terms are defined under applicable U.S. state privacy laws. If that ever changes, we will update this Policy, provide any legally required notice, and honor required opt-out mechanisms (including the Global Privacy Control) before doing so.

V. Connected Google Accounts — Limited Use Disclosure

When an account holder connects a Google account, Entangled's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We use Google user data (including Gmail message content, attachments, and metadata) only to provide and improve user-facing features of the Services that are prominent in the account holder's experience — organizing event correspondence, extracting contract documents and travel details, and surfacing items for review.
  • We do not transfer Google user data to third parties except as necessary to provide or improve those user-facing features (for example, to our cloud infrastructure and the AI providers described in Section VI, acting on our instructions), for security purposes, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with prior notice to users.
  • We do not use Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising.
  • We do not allow humans to read Google user data unless: the account holder gives affirmative agreement for specific data; it is necessary for security purposes (such as investigating abuse); it is necessary to comply with applicable law; or the data has been aggregated and anonymized for internal operations.
  • We do not use Google user data to develop, improve, or train generalized artificial-intelligence or machine-learning models.

Account holders may disconnect a Google account at any time in Settings, which stops all further syncing; previously synced copies may be deleted using the deletion tools and rights described in Sections VIII and IX.

VI. AI Processing

The Services use artificial-intelligence models (currently including models provided by Anthropic) to classify and organize correspondence, extract structured information (such as contract terms and travel itineraries), generate drafts and summaries, and answer questions. Content is transmitted to AI providers solely to produce the requested output for the account holder, under contractual terms that prohibit the provider from using it to train their models. AI output may be imperfect; significant automated determinations (for example, filed contract records) are surfaced for human review within the Services. We do not use your personal information or event content to train generalized AI models.

VII. Cookies, Analytics, and Tracking

We use cookies and similar technologies that are strictly necessary for the Services (authentication and session cookies, event passcode cookies, security), for preferences, and for first-party analytics that help us understand usage and improve the Services. We do not use third-party advertising cookies on the Services. You can control cookies through your browser settings; disabling necessary cookies may impair the Services. Where required, we honor opt-out preference signals such as the Global Privacy Control. Except for such recognized signals, our systems do not respond to "Do Not Track" browser settings, for which no industry standard exists.

VIII. Your Choices; Deletion and Self-Service Controls

  • Access, export, correction, and deletion: account holders may access and correct their information in the product, export their event data, and delete specific records or their entire account and event data using in-product tools ("Delete my account" and related controls) or by contacting privacy@entangled.events. Deletion requests are honored subject to Section X (retention) and applicable law.
  • Integrations: connected email accounts, financial institutions, and messaging integrations can be disconnected at any time in Settings.
  • Marketing communications: you may opt out of our marketing emails via the unsubscribe link in each message or by contacting us; operational and transactional messages will continue while you use the Services.
  • Text messages: reply STOP to cancel and HELP for help; message and data rates may apply.
  • Guests and participants: if your information appears in an event, you may contact the event's hosts (who control their event's records) or privacy@entangled.events; we will honor verified requests directed to information we control and will assist and direct requests to the responsible account holder where they control the information.

IX. U.S. State Privacy Rights

Residents of California and of other U.S. states with comprehensive privacy laws (including, as applicable, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and others) have some or all of the following rights with respect to personal information we control, subject to legal limits:

  • Right to know/access: to confirm whether we process your personal information and to access it, including (in California) the categories collected, the sources, the purposes, and the categories of third parties to whom it is disclosed.
  • Right to portability: to obtain a copy in a portable and readily usable format.
  • Right to correct inaccurate personal information.
  • Right to delete personal information, subject to statutory exceptions.
  • Right to opt out of the sale of personal information, of sharing/processing for targeted advertising, and of profiling in furtherance of decisions producing legal or similarly significant effects. (As stated in Section IV, we do not sell or share personal information for cross-context behavioral advertising; should that change, opt-outs — including the Global Privacy Control — will be honored as required.)
  • Right to limit use of sensitive personal information to purposes permitted by law (we already limit our use as described in Section II).
  • Right to non-discrimination for exercising any right.
  • Right to appeal a refusal of a request, where provided by state law, by replying to our decision or contacting privacy@entangled.events with subject "Privacy Appeal."

Exercising rights. Submit requests through the in-product privacy tools or to privacy@entangled.events. We must verify your identity — typically by verifying control of the email address associated with the information and, where necessary, requesting additional matching information — before acting. An authorized agent may submit a request on your behalf with written proof of authorization and verification of your identity. We respond within the timelines required by applicable law. Categories disclosure: the categories of personal information we collect, the sources, purposes, and disclosure recipients are as described in Sections II through IV; we collect no categories beyond those described, and we have not sold or shared personal information within the preceding twelve (12) months. We do not knowingly sell or share the personal information of consumers under sixteen (16) years of age. California's "Shine the Light" law: we do not disclose personal information to third parties for their direct marketing purposes.

X. Retention

We retain personal information for as long as reasonably necessary for the purposes described in this Policy — generally, for the life of the account and event plus a reasonable wind-down period — and thereafter delete or de-identify it, except where longer retention is required or permitted by law (for example, tax, accounting, security, or dispute records). Backup copies age out on a rolling schedule. Criteria for retention periods include the sensitivity of the information, the risk of harm from unauthorized use, the purposes of processing, and legal requirements. Upon verified deletion requests or account deletion, we delete or de-identify the covered information within the timelines required by applicable law, subject to these exceptions.

XI. Security

We maintain administrative, technical, and physical safeguards designed to protect personal information appropriate to its sensitivity, including encryption in transit (TLS), encryption of stored credentials and tokens, role-based access controls, and logical isolation between events (tenants). No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for maintaining strong, unique credentials for your account. We will notify affected individuals and regulators of security incidents as required by applicable law.

XII. Children's Privacy

The Services are not directed to children, and persons under 18 may not create accounts. We do not knowingly collect personal information directly from children under 13; if we learn that we have, we will delete it promptly. Event records may include information about minor guests (for example, a child's name and meal preference) supplied by an account holder responsible for them; such information is processed solely to provide the Services to that event. We do not sell or share the personal information of any individual we know to be under 16.

XIII. International Users and Data Transfers

Entangled is based in the United States, and personal information is processed in the United States and may be processed in other countries whose data-protection laws differ from those of your jurisdiction. Where the EU/UK General Data Protection Regulation or similar laws apply, we process personal information under the legal bases of contract performance, legitimate interests (such as securing and improving the Services), consent (where relied upon), and legal obligation; individuals have rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with a supervisory authority; and we use appropriate safeguards, such as standard contractual clauses, for cross-border transfers where required. Requests may be directed to privacy@entangled.events.

XIV. Changes to This Policy

We may modify this Privacy Policy at any time. Changes are effective upon posting of the revised Policy with an updated "Last Updated" date. For material changes, we will provide notice to account holders (such as by email or in-product notice) and, where required by law, obtain consent or provide an opportunity to opt out before the change applies.

XV. Contact Us

privacy@entangled.events (privacy requests) · support@entangled.events (general) · legal@entangled.events (legal notices) — Entangled Events LLC.

Entangled Events·Terms·Privacy© Entangled. Every wedding, run for you.