This Privacy Policy replaces the prior version (effective February 17, 2026). You may obtain a copy of the prior version by emailing support@eventsinminutes.com with the subject line “Prior Privacy Policy Request.” This Privacy Policy is incorporated into and forms part of the Events in Minutes Terms of Service.
Events in Minutes Privacy Policy
Effective Date: July 16, 2026
Last Updated: August 24, 2026
Privacy Policy
Table of Contents
- 1. Introduction, Scope, and Our Role
- 2. Definitions
- 3. Information We Collect
- 4. How We Use Information
- 4.1 Providing and Operating the Platform
- 4.2 Trust, Safety, and Quality
- 4.3 AI Development and Training — and Your Opt-Out
- 4.4 Automated Decision-Making and Profiling — and How to Get Human Review
- 4.5 Personalization, Marketing, and Advertising
- 4.6 Communications Monitoring and Analysis
- 4.7 Payments, Tax, and Financial Compliance
- 4.8 Legal Purposes
- 5. How We Disclose Information
- 5.1 Between Members When a Booking Is Confirmed
- 5.2 Public Content — and a Warning About Search Engines
- 5.3 To Vendors — Subject to Strict Limits
- 5.4 Service Providers (Processors)
- 5.5 Corporate Affiliates and Professional Advisors
- 5.6 Advertising and Analytics Partners
- 5.7 Legal, Safety, and Compliance Disclosures
- 5.8 Business Transfers
- 5.9 With Your Consent or at Your Direction
- 5.10 Aggregated and De-Identified Data
- 6. Data Retention
- 7. Data Security
- 8. Your Privacy Choices (All Users)
- 9. California Privacy Rights (CCPA/CPRA)
- 9.1 Notice at Collection — Categories, Sources, Purposes, Retention, Recipients, and Sale/Sharing
- 9.2 Our "Sale" and "Sharing" Position — Stated Honestly
- 9.3 Your Right to Limit Use of Sensitive Personal Information
- 9.4 Your California Rights
- 9.5 How to Exercise Your California Rights
- 9.6 California "Shine the Light"
- 9.7 Notice of Financial Incentives
- 10. Consumer Health Data Privacy Notice (Washington and Nevada)
- 11. Privacy Rights in Other U.S. States
- 12. Cookies and Tracking Technologies
- 13. SMS / Text Message Communications
- 14. European Economic Area, United Kingdom, and Switzerland
- 15. Canada (PIPEDA, Quebec Law 25, and CASL)
- 16. Australia (Privacy Act and Australian Privacy Principles)
- 17. Data Breach Notification
- 18. Children's Privacy
- 19. Third-Party Links and Services
- 20. Vendor Data Handling Obligations
- 21. Accessibility and Languages
- 22. Changes to This Privacy Policy
- 23. Contact Us
1. Introduction, Scope, and Our Role
1.1 Who We Are
Events in Minutes, Inc. ("Events in Minutes," "EIM," "we," "us," or "our") is a Delaware C-Corporation headquartered at 999 Baker Way, San Mateo, CA 94404, USA. We operate a two-sided marketplace that connects people planning events with event professionals, through our website at www.eventsinminutes.com, our mobile applications, our AI Event Planner ("Emma"), our email and SMS communications, and our customer support channels (collectively, the "Platform").
1.2 Who and What This Policy Covers
This Privacy Policy describes how Events in Minutes, Inc. and its corporate affiliates collect, use, disclose, retain, and protect personal information relating to:
- Event Hosts — people who plan events and book Vendor Services through the Platform;
- Vendors — event professionals (caterers, venues, DJs, photographers, florists, and other service providers) who offer and provide Vendor Services through the Platform;
- Guests — event attendees and other individuals whose personal information we receive in connection with a Booking (for example, on guest lists or in event details); and
- Website visitors — anyone who browses or interacts with the Platform, including visitors who do not have an account.
It applies to personal information collected through the Platform, our marketing communications (including our newsletter), customer support interactions, and any other interaction with Events in Minutes.
What this Policy does not cover. This Privacy Policy does not apply to third-party websites, applications, or services that we do not own or control, even if you reach them through the Platform. It also does not apply to Vendors' own off-platform data practices: when a Vendor collects personal information from you directly (for example, on the Vendor's own website or at your event), the Vendor's own privacy policy governs that collection. Please review the privacy policies of any third party before providing personal information to them.
1.3 What "Personal Information" Means
In this Privacy Policy, "personal information" means any information that relates to an identified or identifiable individual — for example, your name, email address, phone number, device identifiers, or event details that can be linked to you. It does not include information that has been aggregated or de-identified so that it can no longer reasonably be linked to you.
1.4 Our Role — and the Roles of Stripe and Vendors
- Events in Minutes is the "business" (under the California Consumer Privacy Act) and the "controller" (under the GDPR, UK GDPR, and similar laws) for personal information we collect and process to operate the Platform, manage accounts, facilitate Bookings, provide Emma, conduct our own analytics and marketing, and provide support.
- Stripe, our payment processor, processes payment card data and Vendor payout data as an independent, PCI-DSS-compliant payment processor. For certain activities (such as its own fraud prevention and regulatory compliance obligations), Stripe acts as an independent controller of that data under its own privacy policy.
- Vendors act as independent controllers/businesses for the personal information they collect or receive in order to perform Vendor Services. Their handling of that information is subject to the obligations in Section 20 and to their own privacy policies.
2. Definitions
Capitalized terms used but not defined in this Privacy Policy — including Platform, Member, Event Host, Vendor, Guest, Booking, Event, and Vendor Services — have the meanings given in our Terms of Service. In brief: a "Member" is any registered account holder (an Event Host or a Vendor); a "Booking" is a confirmed engagement of a Vendor's services for an Event; and "Vendor Services" are the event-related services a Vendor offers through the Platform.
3. Information We Collect
We collect information in four ways: (1) information we need to provide the Platform; (2) information you choose to give us; (3) information collected automatically; and (4) information we receive from third parties.
3.1 Information Needed to Use the Platform
(a) Account and Contact Information
- Name, email address, phone number, and mailing address.
- Password (stored in hashed form only — never in plaintext) and date of birth or age attestation where collected to confirm eligibility.
- For Vendors: business name, business type, business address, and service area.
(b) Identity, Tax, and Credential Verification Information
- Government-issued identification documents (e.g., driver's license, passport) when required for Vendor verification or fraud prevention.
- Tax identification numbers (SSN or EIN for IRS Form W-9; foreign TIN for Form W-8BEN) as required for tax reporting.
- Business registration documents, professional licenses, permits, certifications, and insurance information (including certificates of insurance).
Identity, tax, and credential verification is currently performed in-house by our Trust & Safety team; we do not currently use a third-party identity-verification provider, and we do not collect biometric identifiers or biometric information (such as facial geometry scans, fingerprints, or voiceprints). If we adopt a third-party verification provider or introduce biometric verification in the future, we will update this Privacy Policy first and provide any legally required notices and consents before collection.
(c) Payment and Payout Information
- Payment method details (card number, expiration date, CVV, billing address) are collected and processed by Stripe, our PCI-DSS-compliant payment processor. Events in Minutes does not store full payment card numbers or CVV codes on its servers.
- For Vendors: bank account and routing numbers for payouts (processed through Stripe Connect).
- Transaction history, invoices, receipts, payout records, and chargeback/dispute records.
(d) Booking and Event Information
- Event details provided by Event Hosts: event type, date, time, location, estimated headcount, budget range, special requests, and other event specifications.
- Please note: some event details — such as dietary restrictions, food allergies, accessibility or disability accommodations, and religious meal requirements (e.g., kosher or halal catering) — may reveal information about health, disability, or religious beliefs. We treat this "health-adjacent" information with heightened care: see Section 9.3 (sensitive personal information), Section 10 (consumer health data notice for Washington and Nevada residents), and Section 14.2 (GDPR special category data).
- Booking history, reservation details, confirmations, and modifications.
3.2 Information You Choose to Give Us
- Profile and content: profile photo, biography, service descriptions, portfolio images and videos (Vendors), and other content you upload.
- Reviews and ratings: reviews, ratings, feedback, and dispute information.
- Communications: messages sent between Members through the Platform's messaging system, and messages, emails, phone calls, and chat transcripts with our support team. We may monitor and review communications sent through the Platform for fraud prevention, detection of attempts to move transactions off-platform, safety, Terms of Service enforcement, and support purposes (see Section 4.6).
- Surveys and promotions: survey responses, feedback, feature requests, and contest or promotion entries.
- Information about other people: if you provide personal information about other individuals — for example, co-planners, guests of honor, or attendee/guest lists — you represent and warrant that you have their permission to share that information with us and with the Vendors you book, and that we may process it as described in this Privacy Policy.
3.3 Information Processed by Emma, Our AI Event Planner
When you interact with Emma or other AI-powered features, we collect and process:
- Your conversational inputs, prompts, questions, event preferences, and instructions.
- AI-generated outputs, including vendor recommendations, pricing estimates, and event plans.
- Interaction metadata (session duration, query count, recommendations selected).
How Emma data is used — including our AI-training practices and your opt-out — is described in Section 4.3. Emma conversations may be processed by third-party AI infrastructure providers (large-language-model API providers) acting as our service providers, as described in Section 5.4.
3.4 Information Collected Automatically
We collect some information automatically whenever you use the Platform — including from visitors who do not have an account:
(a) Device and Usage Information
- IP address, device type and model, operating system and version, browser type and version, unique device identifiers and advertising identifiers (e.g., IDFA, GAID), and mobile network information.
- Pages and screens visited, features used, actions taken (clicks, taps, scrolls), search queries, links clicked, referring and exit URLs, time spent on pages, and date/time stamps.
- App version, crash logs, performance data, and diagnostic information.
- Session replay: we use PostHog session replay technology to understand how visitors use the Platform. It records interactions such as pages viewed, clicks, scrolling, and mouse movement. Text you type into sensitive fields is masked, and payment details are never recorded (full payment card numbers never touch our systems — see Section 3.6).
- Engagement measurement: we measure how long visitors actively use the Platform (for example, cumulative active time across pages during a visit).
(b) Location Information
- Approximate location derived from your IP address (country, state/region, city, postal code) — collected whenever you use the Platform.
- Precise geolocation (GPS coordinates) — collected only if you grant permission through your device or browser settings, and used for location-based features such as finding nearby Vendors. You can revoke this permission at any time in your device settings; doing so may limit location-based features but will not prevent you from using the Platform.
(c) Cookies and Similar Technologies
- Cookies (first-party and third-party), pixel tags, web beacons, software development kits (SDKs), and local storage. See Section 12 of this Privacy Policy for a summary and our separate Cookie Policy for full details.
- Marketing attribution: we store the marketing source that brought you to our site (such as campaign tags in the link you clicked and the referring page) in your browser's local storage, and associate it with your account and Bookings, so we can understand which content and campaigns are useful.
3.5 Information from Third Parties
- Social login providers: if you sign in using Google, Apple, or Facebook, we receive your name, email address, and profile photo, as authorized by you and the provider.
- Stripe: transaction confirmations, payment status, chargeback notifications, and fraud/risk signals.
- Advertising and analytics partners: campaign performance data, conversion tracking data, and audience-segment information.
- Referrals and other users: information other people provide about you — for example, when an Event Host adds you to a guest list, a Member refers you to the Platform, or a Member or third party submits a complaint or report involving you.
- Publicly available sources: business registry databases, public review platforms, and publicly accessible social media and web profiles (used primarily to verify Vendor businesses).
3.6 Data Minimization
We collect only what we reasonably need for the purposes described in Section 4. For high-risk fields: CVV codes are never stored by us or retained by Stripe after authorization; passwords are stored only in hashed form; full payment card numbers never touch our servers; and Social Security numbers are collected only where required for tax reporting.
4. How We Use Information
4.1 Providing and Operating the Platform
- Create, maintain, authenticate, and secure your account.
- Facilitate Bookings, Member-to-Member communications, and transactions between Event Hosts and Vendors.
- Process payments, payouts, refunds, and chargebacks through Stripe.
- Provide Emma's AI-powered event planning assistance, vendor matching, and recommendations.
- Display Vendor listings, profiles, reviews, and ratings to Event Hosts and the public.
- Provide customer support and respond to inquiries.
4.2 Trust, Safety, and Quality
- Verify Member identities and Vendor credentials, licenses, permits, and insurance.
- Detect, prevent, and investigate fraud, unauthorized access, money laundering, and other illegal or harmful activity.
- Conduct risk assessments and compute trust and risk scores (see Section 4.4 regarding automated decisions).
- Enforce our Terms of Service, Community Guidelines, and other policies.
- Monitor for, and respond to, security incidents and vulnerabilities.
4.3 AI Development and Training — and Your Opt-Out
We are transparent about how data is used to develop and improve our AI features, including Emma:
- What we use: We may use aggregated and de-identified Platform data, including de-identified Emma interaction data, to develop, train, evaluate, and improve our own AI models and recommendation algorithms.
- What we do not do: We do not use your individual, identifiable Emma conversations or other identifiable personal information to train general-purpose AI models — ours or any third party's — without your consent. Where third-party AI infrastructure providers process Emma conversations to generate responses, we configure and contract for those services so that your identifiable conversations are not used to train the providers' general-purpose models.
- Safeguards: de-identification and aggregation before training use; pseudonymization; encryption in transit and at rest; and access restricted to personnel who need it.
- Your opt-out: You may opt out of the use of your data (including your de-identified Emma interaction data) for AI training and improvement at any time by emailing support@eventsinminutes.com with the subject line "AI Training Opt-Out" from the email address associated with your account. We will honor your request prospectively and confirm when it has been applied. This opt-out does not affect Emma's ability to respond to you in real time.
4.4 Automated Decision-Making and Profiling — and How to Get Human Review
Some of our trust, safety, and fraud systems use automated processing, including automated risk scoring, that can result in actions with significant effects on you — for example, restricting, suspending, or declining an account or Booking, holding a payout pending review, or removing a listing. Emma's recommendations and vendor rankings are also generated by automated systems, but Emma does not by itself make decisions that produce legal or similarly significant effects about you.
Your right to human review. If an automated system restricts, suspends, or otherwise significantly affects your account or a transaction, you may request human review, contest the decision, and provide information supporting your position by contacting support@eventsinminutes.com with the subject line "Automated Decision Review" or by calling +1 (415) 634-4617. A member of our Trust & Safety team — a human — will review the decision, consider the information you provide, and communicate the outcome to you. Residents of certain states and jurisdictions have additional rights to opt out of, or appeal, profiling in furtherance of decisions that produce legal or similarly significant effects: see Sections 9, 11, 14, and 15.
4.5 Personalization, Marketing, and Advertising
- Personalize your experience, including inferring preferences from your usage and Emma interactions and recommending Vendors, packages, and content.
- Send promotional emails and our newsletter (delivered via Beehiiv), and marketing SMS where you have separately opted in (see Section 13). You can opt out of marketing at any time (see Section 8.2).
- Operate referral and promotional programs.
- Deliver and measure interest-based (personalized) advertising through partners such as Google Ads and Meta — see Section 9.2 for what this means under U.S. privacy laws and how to opt out.
4.6 Communications Monitoring and Analysis
- Scan and analyze Platform messages to detect fraud, spam, scams, attempts to steer transactions off-platform, and threats to safety, and to enforce our Terms of Service.
- Scan uploaded content for illegal material and report it to appropriate authorities where required by law.
- Review support communications for quality assurance and training.
We will never sell the contents of your Member-to-Member communications.
4.7 Payments, Tax, and Financial Compliance
- Process payments and payouts; screen transactions for fraud, anti-money-laundering (AML), and sanctions compliance.
- Fulfill tax reporting and withholding obligations, including issuing IRS Forms 1099-K and 1099-NEC to Vendors as required.
- Manage collections, refunds, and chargebacks.
4.8 Legal Purposes
- Comply with applicable laws, regulations, legal process, and governmental requests.
- Respond to subpoenas, court orders, and law enforcement requests (see Section 5.7).
- Establish, exercise, or defend legal claims.
- Maintain records as required by applicable law.
5. How We Disclose Information
5.1 Between Members When a Booking Is Confirmed
When a Booking is confirmed, we share information between the Event Host and the Vendor because it is necessary to perform the booked services:
- The Vendor receives: the Event Host's name and contact information; the Event location, date, time, and details; headcount; and any special requirements submitted with the Booking — including dietary restrictions, allergy information, accessibility needs, and similar health-adjacent details where the Event Host provides them.
- The Event Host receives: the Vendor's name and contact information, business name and details, service descriptions, and relevant service-area information.
This sharing happens at Booking confirmation. Vendors' use of this information is limited by Section 20.
5.2 Public Content — and a Warning About Search Engines
Vendor profiles, listings, portfolios, reviews, and ratings are publicly visible on the Platform. Publicly visible content may be indexed, cached, and republished by search engines and other third parties we do not control. Even after you or we remove content from the Platform, copies may remain visible in search-engine caches, archives, or third-party sites, and we cannot guarantee its removal from those external sources.
5.3 To Vendors — Subject to Strict Limits
Vendors that receive personal information about Event Hosts or Guests through the Platform may use it only to perform the booked Vendor Services and related communications, and are bound by the obligations described in Section 20, which we may audit and enforce through suspension or removal from the Platform.
5.4 Service Providers (Processors)
We disclose personal information to service providers that process it on our behalf under contracts requiring confidentiality and data protection, including:
- Payments and payouts: Stripe (including Stripe Connect for Vendor payouts).
- Cloud hosting and infrastructure: Amazon Web Services (AWS) and Google Cloud Platform.
- Product and web analytics: PostHog, Google Analytics, and Amplitude.
- Email and newsletter delivery: Beehiiv (our newsletter platform) and transactional email providers.
- SMS delivery: SMS/text messaging delivery providers.
- Advertising platforms: Google Ads and Meta, for campaign management, measurement, and remarketing (see Section 9.2 — these disclosures are treated differently from service-provider disclosures under some state laws).
- Workflow automation: n8n, where automated workflows process personal information.
- AI infrastructure providers: third-party large-language-model API providers that process Emma conversational inputs to generate responses, configured and contracted so that identifiable conversations are not used to train their general-purpose models (see Section 4.3).
- Customer support tooling: ticketing and live-chat platforms.
5.5 Corporate Affiliates and Professional Advisors
We may share personal information with our corporate affiliates (entities under common ownership or control with Events in Minutes, Inc.), who must handle it consistently with this Privacy Policy, and with our professional advisors — attorneys, accountants, auditors, and insurers — as necessary to obtain professional services or protect our legal interests.
5.6 Advertising and Analytics Partners
As described in Sections 9.2 and 12, cookies, pixels, and SDKs on the Platform (including the Meta Pixel and Google Ads tags) transmit certain identifiers and activity data to advertising and analytics partners. Under the CCPA/CPRA and similar state laws, some of these disclosures constitute "sharing" for cross-context behavioral advertising and may constitute a "sale." You can opt out — see Sections 8.5 and 9.2.
5.7 Legal, Safety, and Compliance Disclosures
We may disclose personal information if we believe in good faith that disclosure is reasonably necessary to: (a) comply with applicable law, regulation, legal process, or governmental request; (b) respond to a lawful subpoena, court order, or law enforcement request; (c) respond to tax authorities in connection with our reporting obligations; (d) protect the rights, property, or safety of Events in Minutes, our Members, Guests, or the public; (e) detect, prevent, or address fraud, security, or technical issues; (f) enforce our Terms of Service; or (g) protect against imminent harm to any person.
Notice to you. Unless we are legally prohibited from doing so (for example, by a nondisclosure order), or notice would be futile, ineffective, or would create a risk of harm to any person, we will make reasonable efforts to notify you of legal requests for your personal information so that you have an opportunity to object.
5.8 Business Transfers
If Events in Minutes is involved in a merger, acquisition, financing, reorganization, bankruptcy, receivership, sale of assets, or transition of service to another provider, your personal information may be disclosed, transferred, or acquired as part of that transaction. Before your personal information becomes subject to a different privacy policy as a result of such a transaction, we will notify you by email to the address associated with your account and/or by posting a prominent notice on the Platform, and we will describe any choices you have regarding your personal information.
5.9 With Your Consent or at Your Direction
We share personal information with other parties when you direct us to or provide your consent.
5.10 Aggregated and De-Identified Data
We may use and share aggregated, anonymized, or de-identified data — data that cannot reasonably be used to identify you — for analytics, research, benchmarking, AI development (Section 4.3), and other lawful purposes. We maintain de-identified data in de-identified form, we do not attempt to re-identify it (except as permitted by law solely to test whether our de-identification processes work), and we contractually require recipients to commit to the same.
6. Data Retention
We retain personal information for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law. Our standard retention periods are:
| Data Category | Retention Period | Reason |
|---|---|---|
| Account and profile information | Duration of account + 3 years | Dispute resolution; fraud prevention; legal compliance |
| Booking and transaction records | 7 years after the transaction — excluding identifiable health-adjacent fields (dietary restrictions, allergies, accessibility needs), which follow the shorter consumer-health-data row below | IRS/tax; financial audit; dispute resolution |
| Payment card data | Not stored by EIM (held by Stripe per PCI-DSS) | PCI compliance |
| Vendor payout and tax information (W-9/1099) | 7 years after last payout | IRS reporting requirements |
| Member messages and support communications | Duration of account + 2 years | Dispute resolution; safety |
| Identity verification documents | 3 years after verification or account closure | Fraud prevention; legal compliance |
| Device, usage, and analytics logs | 24 months (rolling) | Analytics; security; debugging |
| Emma (AI) interaction data | 24 months in identifiable form; de-identified thereafter | Product and AI improvement (subject to the Section 4.3 opt-out) |
| Consumer health-adjacent data (dietary restrictions, allergies, accessibility needs) | Life of the Booking + 1 year, after which it is segregated and deleted, or redacted/de-identified within any retained booking record. The 7-year booking-record retention does not extend to identifiable health-adjacent fields | Health-data minimization (see Section 10) |
| Marketing and newsletter preferences | Until you opt out; we then retain a record of the opt-out itself on a suppression list | Honoring opt-outs; CAN-SPAM/CASL compliance |
| Reviews and ratings | While published, per our content policies | Platform trust and transparency |
| Security and fraud logs | 3 years | Security investigations; legal compliance |
Where no fixed period applies, we determine retention based on: the duration of our relationship with you and ongoing business need; legal, tax, accounting, and AML obligations; and litigation holds or active investigations, which may extend retention until resolved.
Honest notes on retention. Content you shared publicly (such as reviews) may remain visible after account deletion, and copies may persist in search-engine caches (Section 5.2). Deleted data may also persist in encrypted backups for a limited period until those backups are purged on our routine cycle. When personal information is no longer needed, we securely delete, anonymize, or de-identify it.
7. Data Security
We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, alteration, disclosure, or destruction, including:
- Encryption: data encrypted in transit (TLS 1.2+) and at rest (AES-256 or equivalent).
- Access controls: role-based access control (RBAC) with least-privilege principles; multi-factor authentication for internal systems.
- Infrastructure: hosted with SOC 2-audited cloud providers (AWS and Google Cloud), with network segmentation and firewalls.
- Monitoring: security monitoring, intrusion detection, and logging.
- Vendor security: security and privacy assessments of third-party service providers.
- Training: security awareness training for personnel with access to personal information.
- Incident response: a documented incident response plan with a designated response team (see Section 17).
No guarantee. No method of electronic transmission or storage is completely secure. While we use commercially reasonable measures designed to protect your personal information, we cannot guarantee absolute security. You are responsible for safeguarding your login credentials, using a strong and unique password, and promptly reporting any suspected unauthorized access to your account to support@eventsinminutes.com.
8. Your Privacy Choices (All Users)
8.1 Account Settings
You can access, review, update, and correct your account information at any time by logging into your account settings. You may request account deletion through your account settings or by emailing support@eventsinminutes.com.
8.2 Marketing Communications
Opt out of promotional emails and our newsletter by clicking "unsubscribe" in any promotional email, or by emailing support@eventsinminutes.com. Opting out of marketing does not stop transactional and service messages (booking confirmations, receipts, security alerts). For SMS, reply STOP (see Section 13).
8.3 AI Training Opt-Out
Email support@eventsinminutes.com with the subject line "AI Training Opt-Out" (see Section 4.3).
8.4 Location
Control precise location access through your device or browser settings (see Section 3.4(b)).
8.5 Opting Out of Targeted Advertising, "Sale," and "Sharing"
You can opt out of the disclosure of your personal information for targeted (cross-context behavioral) advertising — which may constitute a "sale" or "sharing" under U.S. state privacy laws — by any of the following, none of which requires you to log in or create an account:
- Clicking the "Do Not Sell or Share My Personal Information" / "Your Privacy Choices" link in the footer of www.eventsinminutes.com and setting your preference;
- Enabling the Global Privacy Control (GPC) in your browser or extension — we honor GPC signals as a valid opt-out request for the browser or device sending the signal (and, where we can reasonably associate the signal with your account, for your account);
- Rejecting advertising cookies through our cookie preference center (Section 12) — our cookie tool is wired to this opt-out, so rejecting advertising cookies also effects your opt-out of sale/sharing via cookies on that browser; or
- Emailing support@eventsinminutes.com with the subject line "Opt Out of Sale/Sharing."
You can also use industry tools: the Digital Advertising Alliance opt-out page (www.aboutads.info/choices), the Network Advertising Initiative (www.networkadvertising.org/choices), and your mobile device's advertising settings.
8.6 Do Not Track and Global Privacy Control
Some browsers transmit "Do Not Track" (DNT) signals. Because there is no uniform standard for DNT, we do not respond to DNT browser signals. We do honor the Global Privacy Control (GPC) signal as a valid opt-out of "sale," "sharing," and targeted advertising in California, Colorado, Connecticut, Texas, Montana, Oregon, Delaware, New Hampshire, New Jersey, Minnesota, Nebraska, Maryland, and every other state whose law requires recognition of universal opt-out preference signals.
8.7 Consent Practices — No Dark Patterns
Where we ask for your consent, we design the choice to be genuine: consent checkboxes are never pre-ticked; marketing SMS consent is never bundled with account creation or purchase (Section 13); our EU/UK cookie banner presents "Accept" and "Reject" options with equal prominence (Section 12.2); and our opt-out mechanisms do not require you to log in. Declining consent for optional processing will not degrade the core service you receive.
9. California Privacy Rights (CCPA/CPRA)
This section applies to California residents and supplements the rest of this Privacy Policy. It is provided under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the "CCPA").
9.1 Notice at Collection — Categories, Sources, Purposes, Retention, Recipients, and Sale/Sharing
The table below describes our practices during the preceding 12 months and currently. Retention periods match Section 6; where multiple periods apply within a category, each is noted.
| CCPA Category | Examples | Categories of Sources | Business/Commercial Purposes | Retention Period or Criteria | Categories of Recipients | Sold or Shared? |
|---|---|---|---|---|---|---|
| Identifiers | Name, email, phone, postal address, account ID, IP address, device and advertising IDs | Directly from you; automatically from your device; social login providers (Google, Apple, Facebook); Stripe; advertising/analytics partners; referrals and other users; public sources | Operate the Platform; facilitate Bookings; communications; security and fraud prevention; advertising and analytics | Account data: account life + 3 years; device identifiers/IP in logs: 24 months rolling | Other Members (at Booking); service providers (hosting, analytics, email/SMS, support, workflow automation, AI infrastructure); advertising partners; legal authorities | Yes — shared for cross-context behavioral advertising (device IDs, IP, hashed identifiers via advertising tags); may constitute a "sale" |
| Commercial information | Booking history, transactions, payments, invoices, services considered | Directly from you; generated by your Platform transactions; Stripe | Payments and payouts; tax compliance; dispute resolution; analytics; conversion measurement | 7 years post-transaction (identifiable health-adjacent fields excluded — see Sensitive PI row and Section 6) | Stripe; tax authorities; service providers; advertising partners (limited conversion events) | Yes — shared (limited conversion-event data sent to advertising partners); may constitute a "sale" |
| Financial information | Bank account/routing numbers (Vendors), tax IDs, payout records | Directly from you (Vendors); Stripe | Vendor payouts; tax reporting (1099-K/1099-NEC); AML/sanctions screening | W-9/payout/tax records: 7 years after last payout; card data not stored by EIM | Stripe; IRS and tax authorities | No |
| Internet or other electronic network activity | Browsing/search history on the Platform, clicks, app usage, crash logs, Emma conversation text and interaction metadata | Automatically from your device, cookies, and SDKs; analytics providers | Analytics; security; debugging; product and AI improvement; personalization; advertising measurement | Logs: 24 months rolling; Emma interaction data: 24 months identifiable, then de-identified | Analytics providers (PostHog, Google Analytics, Amplitude); advertising partners; security providers; AI infrastructure providers | Yes — shared for cross-context behavioral advertising and analytics; may constitute a "sale" |
| Geolocation data | Approximate location (IP-derived); precise GPS location (only with your device permission) | Automatically from your IP address; your device (with permission) | Location-based features (nearby Vendors); analytics; fraud prevention | 24 months | Analytics and advertising partners (approximate only); map service providers | Yes — shared (approximate location only); precise geolocation is not sold or shared |
| Audio, electronic, visual, or similar information | Profile photos, portfolio images/videos, review photos, recorded support calls | Directly from you; support interactions | Display of profiles/listings/reviews; customer support; quality assurance | Profile/portfolio content: account life + 3 years; reviews: while published; support recordings: account life + 2 years | Cloud hosting providers; other Members and the public (content you post publicly); support tooling | No |
| Professional or employment-related information | Business name/type, licenses, permits, certifications, insurance details (Vendors) | Directly from Vendors; public sources (business registries, review platforms) | Vendor vetting; trust and safety; display of Vendor qualifications | Account life + 3 years; verification documents: 3 years after verification or account closure | Event Hosts and the public (listing content); cloud hosting providers | No |
| Inferences | Preferences, interests, and recommendation profiles derived from usage and Emma interactions; advertising audience segments | Derived internally from your usage and Emma interactions; advertising/analytics partners (audience segments) | Personalization; Vendor recommendations; product improvement; advertising | 24 months | Service providers; advertising partners (audience segments) | Yes — shared (audience segments used for cross-context behavioral advertising); may constitute a "sale" |
| Sensitive personal information | Government ID documents; SSN/EIN; account log-in with password/credentials; precise geolocation (with permission); health-adjacent booking details (dietary restrictions, allergies, accessibility needs) | Directly from you; automatically from your device (precise geolocation, with permission) | Identity and tax verification; tax reporting; account security; location features; fulfilling Booking requirements you specify | ID documents: 3 years after verification or closure; SSN/EIN: 7 years after last payout; credentials: account life; precise geolocation: 24 months; health-adjacent data: life of Booking + 1 year, then deleted or de-identified | Stripe and tax authorities (SSN/EIN); Vendors (health-adjacent Booking details, at your direction to fulfill your Booking); cloud hosting providers | No |
We do not collect or process sensitive personal information for the purpose of inferring characteristics about you.
Actual knowledge of minors' data: we do not knowingly collect, and therefore do not sell or share, personal information of consumers under 16 years of age (see Section 18).
9.2 Our "Sale" and "Sharing" Position — Stated Honestly
We do not sell personal information for money. However, like most online businesses, we use advertising and analytics tools — including the Meta Pixel, Google Ads tags, PostHog, Google Analytics, and Amplitude — that collect identifiers and activity data from our website and apps. Under the CCPA, disclosures to advertising partners for cross-context behavioral advertising are "sharing," and the California Attorney General and California Privacy Protection Agency treat certain of these pixel-based disclosures as a "sale." Accordingly:
- We "share" (and may be deemed to "sell") the categories marked "Yes" in the table above.
- You have the right to opt out, and we provide the "Do Not Sell or Share My Personal Information" / "Your Privacy Choices" link in our website footer, honor the Global Privacy Control, and offer the additional opt-out methods in Section 8.5.
- We do not knowingly sell or share the personal information of consumers under 16.
9.3 Your Right to Limit Use of Sensitive Personal Information
We use sensitive personal information only for the purposes permitted by CCPA regulations section 7027(m) — performing the services you request (including transmitting dietary/allergy/accessibility details to the Vendor you book), security and integrity, short-term transient use, quality verification, and legal compliance — and we do not use or disclose it to infer characteristics about you. Although the CCPA's "Right to Limit" therefore does not currently require an opt-out for our uses, we nonetheless provide a "Limit the Use of My Sensitive Personal Information" link in our website footer, and we will honor limitation requests submitted there or via support@eventsinminutes.com.
9.4 Your California Rights
- Right to Know / Access: request disclosure of the categories and specific pieces of personal information we collected, the categories of sources, our purposes, and the categories of third parties to whom we disclosed, sold, or shared it.
- Right to Delete: request deletion of personal information we collected from you, subject to statutory exceptions (completing your transaction, security and fraud prevention, legal compliance, and other exceptions in Civil Code § 1798.105(d)).
- Right to Correct: request correction of inaccurate personal information.
- Right to Opt Out of Sale/Sharing: see Sections 9.2 and 8.5.
- Right to Limit Use of Sensitive Personal Information: see Section 9.3.
- Right to Data Portability: request your personal information in a portable and, to the extent technically feasible, readily usable format.
- Right to Non-Discrimination: we will not discriminate or retaliate against you for exercising any CCPA right — no denial of services, different prices, or reduced quality.
9.5 How to Exercise Your California Rights
Submit a request by:
- Email: support@eventsinminutes.com with the subject line "California Privacy Request"; or
- Phone: +1 (415) 634-4617 (a standard-rate line). Because Events in Minutes operates exclusively online and has a direct relationship with the consumers whose information it collects, the CCPA permits us to accept requests by email (Civil Code § 1798.130(a)(1)(A)); the phone line is offered as an additional convenience.
Verification. We will verify your identity to a reasonable degree of certainty before acting on a request — typically by matching two or more data points you provide (such as your account email and recent Booking details) against our records, or by asking you to respond from the email address associated with your account. We may request additional information for higher-sensitivity requests; we use that information only for verification. Opt-out requests do not require verification.
Authorized agents. You may designate an authorized agent to submit requests on your behalf. We will require the agent to provide your signed written permission (or a power of attorney), and we may ask you to verify your own identity or confirm the authorization directly with us.
Timing. We will confirm receipt within 10 business days and respond within 45 calendar days. If we need more time (up to an additional 45 days), we will notify you of the extension and the reason. We will act on opt-out requests within 15 business days.
Request metrics. Events in Minutes does not buy, receive, sell, or share the personal information of 10 million or more California residents in a calendar year, so the CCPA's request-metrics compilation and publication requirement (regulations § 7102) does not currently apply to us. If that changes, we will publish the required metrics.
9.6 California "Shine the Light"
Under California Civil Code § 1798.83, California residents may request information about disclosures of personal information to third parties for those third parties' own direct marketing purposes. We do not disclose personal information to third parties for their own direct marketing purposes within the meaning of that statute. (Our separate practices regarding advertising partners, and your opt-out rights, are described in Section 9.2.) Questions may be directed to support@eventsinminutes.com.
9.7 Notice of Financial Incentives
We do not currently offer financial incentives, loyalty programs, or price or service differences in exchange for the collection, retention, sale, or sharing of personal information. If we introduce such a program (for example, a referral reward program conditioned on providing personal information), we will provide a notice of financial incentive describing its material terms and obtain your opt-in consent before enrolling you, and you will be able to withdraw at any time.
10. Consumer Health Data Privacy Notice (Washington and Nevada)
This section is our consumer health data notice for residents of Washington (under the Washington My Health My Data Act, "MHMD") and Nevada (under Nevada SB 370), and for anyone whose consumer health data is collected in those states.
10.1 What Consumer Health Data We Collect
Event details you choose to provide when planning an event may qualify as "consumer health data" because they can reveal health status, including: dietary restrictions and food allergies; accessibility or disability accommodation needs; and similar health-adjacent event requirements (for example, a request for a wheelchair-accessible venue or a nut-free menu).
10.2 Sources, Purposes, and Sharing
- Sources: this data comes directly from you (or from an Event Host who provides it about a Guest, with the warranty described in Section 3.2).
- Purposes: we collect and use it only to provide the products and services you request — communicating your requirements to the Vendor you book, fulfilling the Booking, and providing support — and to comply with law.
- Sharing: it is shared only with the Vendor you book (to fulfill your requirements), with our cloud hosting and support service providers under contract, and as required by law. We do not use consumer health data for advertising, and we do not sell it.
10.3 Consent
We collect and share consumer health data only (a) with your consent, or (b) to the extent necessary to provide a product or service that you (or the Event Host acting for your event) have requested. Providing dietary, allergy, or accessibility details is always optional. We will obtain your separate, voluntary consent before collecting or sharing consumer health data for any purpose beyond what is necessary to provide the service you requested, and we will not sell consumer health data without the signed, valid authorization required by RCW 19.373.070 — which, as stated above, we do not do.
10.4 Your Consumer Health Data Rights
If you are a Washington or Nevada resident (or your consumer health data was collected there), you have the right to:
- Access your consumer health data, including a list of the third parties and affiliates with whom we have shared it and an active contact (email address or hyperlink) for each;
- Withdraw consent to our collection and sharing of your consumer health data;
- Delete your consumer health data (including from our backups on their routine purge cycle and, by instruction, from our processors).
Exercise these rights by emailing support@eventsinminutes.com with the subject line "Consumer Health Data Request." We will verify and respond within 45 days, extendable once by 45 days where reasonably necessary (with notice to you).
10.5 Right to Appeal
If we deny your consumer health data request, you may appeal by replying to our denial or emailing support@eventsinminutes.com with the subject line "Consumer Health Data Appeal" within a reasonable time after our decision. We will respond in writing within 45 days of receiving your appeal, explaining any action taken or not taken and the reasons. If your appeal is denied, you may contact the Washington State Attorney General (www.atg.wa.gov/file-complaint) or, for Nevada residents, the Nevada Attorney General (ag.nv.gov) to submit a complaint.
10.6 Retention
Consumer health-adjacent data is retained for the life of the Booking plus 1 year, then segregated and deleted or de-identified/redacted within any retained booking record (see Section 6). The longer 7-year retention of booking and transaction records does not extend to identifiable health-adjacent fields.
11. Privacy Rights in Other U.S. States
11.1 Who This Section Covers
This section applies to residents of states with comprehensive consumer privacy laws, including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MTCDPA), Iowa (ICDPA), Indiana (INCDPA), Tennessee (TIPA), Delaware (DPDPA), New Jersey (NJDPA), New Hampshire (NHDPA), Kentucky (KCDPA), Nebraska (NDPA), Minnesota (MCDPA), Maryland (MODPA), and Rhode Island (RIDTPPA, effective January 1, 2026), and residents of other states as their laws take effect.
11.2 Your Rights
Subject to your state's law, you have the right to:
- Confirm and access whether we process your personal data and obtain a copy;
- Correct inaccuracies in your personal data;
- Delete personal data provided by or obtained about you;
- Data portability — obtain a copy in a portable, readily usable format;
- Opt out of (i) targeted advertising, (ii) the "sale" of personal data, and (iii) profiling in furtherance of decisions that produce legal or similarly significant effects.
Because we use advertising tools described in Section 9.2, our disclosures to advertising partners constitute "targeted advertising" (and in some states a "sale") under these laws, and the opt-out methods in Section 8.5 apply. We honor the Global Privacy Control as a universal opt-out preference signal in every state that requires it (see Section 8.6). For profiling, see Section 4.4: you may opt out of profiling in furtherance of significant decisions and request human review via the channel described there.
Voluntary uniform treatment; state-by-state accuracy. We voluntarily extend the rights above to residents of all of the listed states. Note, however, that some statutes are narrower than our voluntary practice: Utah's UCPA does not itself grant a correction right, a profiling opt-out, or an appeal right, and Iowa's ICDPA does not itself grant a correction right or a profiling opt-out — for residents of those states, we honor those additional rights voluntarily, beyond what UCPA and the Iowa law require.
State-specific additional rights:
- Oregon: Oregon residents may additionally request a list of the specific third parties (not just categories) to which we have disclosed personal data.
- Minnesota: Minnesota residents who are subject to profiling in furtherance of decisions with legal or similarly significant effects may additionally question the result of the profiling, be informed of the reasons the decision was made, be told what actions they could take (where feasible) to secure a different result, and have the data used in the profiling reviewed for accuracy.
- Nevada: independent of the consumer health data rights in Section 10, Nevada's website-operator law (SB 220) gives Nevada consumers the right to opt out of the sale of covered information by website operators. Nevada residents may exercise this right through the same channels in Section 8.5 or by emailing support@eventsinminutes.com with the subject line "Nevada Opt-Out."
11.3 How to Exercise These Rights
Email support@eventsinminutes.com with the subject line "State Privacy Request" (or use the opt-out methods in Section 8.5), or call +1 (415) 634-4617. We will verify your identity using the process described in Section 9.5 and respond within 45 days, extendable once by 45 days where reasonably necessary (with notice to you). Authorized agents may submit opt-out requests where your state's law permits.
11.4 Your Right to Appeal
If we decline to take action on your request, we will tell you why and how to appeal. To appeal, email support@eventsinminutes.com with the subject line "Privacy Rights Appeal" (or reply directly to our denial) within a reasonable period after receiving our decision. We will respond in writing within the period your state's law requires — 45 days in Colorado and Oregon, and 60 days in most other listed states — explaining any action taken or not taken and the reasons. If your appeal is denied, our response will include a way to contact your state Attorney General to submit a complaint (for example, Virginia: www.oag.state.va.us; Colorado: coag.gov/file-complaint; Connecticut: portal.ct.gov/ag; Texas: www.texasattorneygeneral.gov/consumer-protection).
12. Cookies and Tracking Technologies
This is a summary. Full details — including a current list of the specific cookies we and our partners set, their lifespans, and their purposes — are in our separate Cookie Policy.
12.1 Types of Cookies and Similar Technologies We Use
- Strictly necessary: required for the Platform to function (authentication, session management, security tokens, load balancing, CSRF protection, remembering your cookie choices). These cannot be disabled without breaking core functionality.
- Functional/preference: remember your settings, language preferences, and recently viewed listings.
- Analytics/performance: help us understand how visitors use the Platform. We use PostHog, Google Analytics, and Amplitude.
- Advertising: deliver and measure relevant advertising and build audience profiles. Placed by our advertising partners, including Google Ads and the Meta Pixel. Because these technologies transmit identifiers and activity data to those partners, they trigger the "sale"/"sharing" opt-out rights described in Sections 8.5 and 9.2.
12.2 Cookie Consent (EU/UK and Other Consent Jurisdictions)
For visitors in the European Union, European Economic Area, United Kingdom, and other jurisdictions requiring prior consent for non-essential cookies, our cookie banner presents "Accept" and "Reject" options with equal prominence, and non-essential cookies are not set until you affirmatively consent — continued browsing is not treated as consent. You may withdraw or modify your consent at any time via the "Cookie Preferences" link in the website footer. Consent choices are stored for twelve (12) months, after which we ask again.
12.3 Managing Cookies — Wired to Your Opt-Out Rights
You can manage cookies through:
- Our cookie preference center ("Cookie Preferences" link in the footer, available to all visitors) — rejecting advertising cookies there also functions as a CCPA/state-law opt-out of sale/sharing via cookies for that browser (Section 8.5);
- Browser settings (blocking or deleting cookies);
- Industry opt-outs: DAA (www.aboutads.info/choices) and NAI (www.networkadvertising.org/choices);
- Mobile device advertising settings (iOS ad tracking permissions; Android "Delete advertising ID" / ads personalization settings);
- Global Privacy Control (Section 8.6).
Disabling certain cookies may affect Platform functionality.
12.4 Google Analytics Specifics
We use Google Analytics with IP anonymization enabled. Google's use of data is governed by Google's own privacy policy. You can opt out of Google Analytics across websites by installing the Google Analytics Opt-out Browser Add-on (tools.google.com/dlpage/gaoptout).
12.5 PostHog and Session Replay Specifics
We use PostHog to understand how visitors use the Platform, including session replay technology that records interactions such as pages viewed, clicks, scrolling, and mouse movement. Text you type into sensitive fields is masked and payment details are never recorded. PostHog also processes the analytics events and marketing-attribution information described in Section 3.4. This data is stored on PostHog's U.S. cloud infrastructure and is retained per the windows described in Section 6. You can limit this collection using the cookie and opt-out controls in Sections 8.5, 8.6, and 12.3, and you may request deletion of this data through the rights-request channels in Sections 9 and 11.
13. SMS / Text Message Communications
13.1 Opt-In and Consent
We send SMS/text messages only if you provide your mobile number and affirmatively opt in through a separate, clearly labeled, un-pre-ticked checkbox or opt-in mechanism on our registration, booking, or account settings pages. Message types include:
- Transactional: booking confirmations, reminders, updates, payment and payout notifications, and account security alerts.
- Marketing: promotional messages and special offers — sent only if you separately opt in to marketing SMS. Your consent to marketing SMS is obtained separately from transactional SMS consent and separately from your acceptance of the Terms of Service.
13.2 Required Disclosures (TCPA / CTIA)
- Consent to receive SMS — including marketing SMS — is not a condition of purchasing any goods or services, creating an account, or using the Platform.
- Message and data rates may apply; check with your carrier.
- Message frequency varies based on your activity, preferences, and settings.
- Reply STOP to any message to opt out (you will receive a single confirmation message and no further texts of that type).
- Reply HELP for help, or contact support@eventsinminutes.com.
- We do not share your phone number or SMS opt-in/consent data with third parties or affiliates for their own marketing purposes.
13.3 Carriers
SMS services are available on major U.S. carriers. Events in Minutes and its SMS delivery providers are not liable for delayed or undelivered messages caused by carrier network issues.
14. European Economic Area, United Kingdom, and Switzerland
This section applies if you are in the EEA, the United Kingdom, or Switzerland. References to the GDPR include the UK GDPR, and, for Switzerland, the revised Swiss Federal Act on Data Protection (FADP, in force September 1, 2023), as applicable.
14.1 Legal Bases for Processing
| Legal Basis | What We Process Under It |
|---|---|
| Contract performance (Art. 6(1)(b)) | Creating and managing your account; facilitating Bookings and Member communications; processing payments and payouts; providing Emma's planning assistance; support |
| Legitimate interests (Art. 6(1)(f)) | Fraud prevention and platform safety; securing our systems; product improvement and analytics; direct marketing to existing customers (soft opt-in); enforcing our terms; defending legal claims. In each case we balance our interests against your rights and freedoms, and you may object (Art. 21) |
| Consent (Art. 6(1)(a)) | Non-essential cookies and tracking; marketing to non-customers; precise geolocation; optional data you choose to provide. You may withdraw consent at any time without affecting prior processing |
| Legal obligation (Art. 6(1)(c)) | Tax reporting; AML/sanctions compliance; responding to lawful requests; statutory record retention |
14.2 Special Category Data
We do not intentionally collect "special categories of personal data" (Art. 9). However, event details you volunteer — such as dietary restrictions, allergies, accessibility needs, or religious meal requirements — may reveal health, disability, or religious information. We process such data only to the extent strictly necessary to fulfill the Booking you have requested (including transmitting it to your chosen Vendor), on the basis of your explicit consent given when you choose to provide it (Art. 9(2)(a)). You can decline to provide it, and you may withdraw consent at any time.
14.3 Your Rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection — including to direct marketing (Art. 21); the right not to be subject to solely automated decisions with legal or similarly significant effects except as permitted by Art. 22 (see Section 4.4 for our automated-processing disclosure and human-review channel); the right to withdraw consent at any time; and the right to lodge a complaint with your supervisory authority — your local EEA data protection authority, the UK Information Commissioner's Office (ico.org.uk), or, in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC) (edoeb.admin.ch).
To exercise these rights, email support@eventsinminutes.com. We will respond within one month, extendable by up to two further months for complex or numerous requests, with notice to you within the first month.
14.4 International Data Transfers
Your personal data is transferred to and processed in the United States and other countries that may not provide the same level of data protection as your home jurisdiction. We use the following safeguards:
- EU-U.S. Data Privacy Framework (DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF: several of our downstream processors — including Google, Meta, Stripe, and AWS — are certified under the DPF, and for transfers to those providers we may rely on their DPF certification as the transfer mechanism, with SCCs as a fallback.
- Standard Contractual Clauses (SCCs) adopted by the European Commission (Implementing Decision (EU) 2021/914), supported by transfer risk assessments and supplementary measures (encryption, pseudonymization, access controls) where needed.
- UK: the UK International Data Transfer Agreement (IDTA) and/or the UK Addendum to the EU SCCs, with transfer risk assessments per ICO guidance.
- Switzerland: transfers rely on the Swiss-U.S. DPF or on the EU SCCs with the FDPIC-recognized Swiss addendum (adapting references to the FADP and recognizing the FDPIC as the competent authority).
You may request a copy of the applicable transfer safeguards by emailing support@eventsinminutes.com.
14.5 Data Protection Officer and Representatives
We have assessed our processing activities and determined that we are not currently required to appoint a Data Protection Officer under Article 37 GDPR or a representative under Article 27 GDPR/UK GDPR, given the nature and scale of our EEA/UK processing. All data protection inquiries should be directed to support@eventsinminutes.com, Attn: Privacy & Data Protection, and we will re-assess these appointments as our operations evolve.
15. Canada (PIPEDA, Quebec Law 25, and CASL)
If you are in Canada, we handle your personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial laws.
15.1 PIPEDA Principles
- Meaningful consent: we obtain meaningful consent for collection, use, and disclosure, except where the law permits otherwise (e.g., fraud prevention, legal compliance).
- Access and correction: you may request access to your personal information and correction of inaccuracies via support@eventsinminutes.com.
- Accountability for cross-border transfers: your personal information is processed by service providers in the United States (Section 5.4). We remain accountable for it and use contracts requiring a comparable level of protection.
- Withdrawal of consent: you may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice; withdrawal may limit certain features.
- Breach reporting: we report breaches of security safeguards creating a real risk of significant harm to the Office of the Privacy Commissioner of Canada (OPC) and affected individuals, and we keep records of all breaches for at least 24 months (see Section 17).
15.2 Quebec (Law 25)
For Quebec residents:
- Person in charge of the protection of personal information: as provided by Law 25, this function is exercised by Events in Minutes' highest-ranking officer, the Chief Executive Officer, who may be contacted at support@eventsinminutes.com, Attn: Person in Charge of the Protection of Personal Information / Responsable de la protection des renseignements personnels, 999 Baker Way, San Mateo, CA 94404, USA.
- Automated decision-making: if we make a decision about you based exclusively on automated processing (see Section 4.4), we will inform you at or before the time of the decision, and you may submit observations to a member of our staff who can review the decision, and ask what personal information was used, the principal factors involved, and to have that information corrected.
- Cross-border communication: before communicating personal information outside Quebec, we conduct a privacy impact assessment considering the sensitivity of the information, its intended use, the protections applied, and the legal regime of the destination, and we proceed only where the information will receive adequate protection, under a written agreement.
- French language: Quebec residents may request a French-language version of this Privacy Policy and conduct privacy-related communications with us in French by contacting support@eventsinminutes.com (subject: "Version française / French Version").
15.3 CASL (Commercial Electronic Messages)
We comply with Canada's Anti-Spam Legislation: we send commercial electronic messages (including our Beehiiv newsletter) to Canadian recipients only with express or valid implied consent; every message identifies Events in Minutes, Inc. and provides our contact information; and every message includes a functional unsubscribe mechanism that we honor within 10 business days (in practice, promptly).
16. Australia (Privacy Act and Australian Privacy Principles)
If you are in Australia, we handle your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs):
- Collection (APPs 3–5): we collect personal information only by lawful and fair means, only where reasonably necessary for our functions, and with appropriate notice (this Privacy Policy).
- Use and disclosure (APP 6): we use and disclose personal information for the primary purpose of collection or related secondary purposes you would reasonably expect, or otherwise with consent or as permitted by law.
- Access and correction (APPs 12–13): you may request access to, and correction of, your personal information via support@eventsinminutes.com; we will respond within a reasonable period.
- Cross-border disclosure (APP 8): personal information is processed in the United States by the providers in Section 5.4; before disclosing personal information overseas we take reasonable steps to ensure the recipient handles it consistently with the APPs.
- Notifiable Data Breaches: see Section 17.
- Complaints: you may complain to us first at support@eventsinminutes.com; if unresolved, you may complain to the Office of the Australian Information Commissioner (OAIC, www.oaic.gov.au).
17. Data Breach Notification
We maintain a documented incident response plan and a designated response team to detect, contain, assess, and remediate security incidents. If a data breach affects your personal information, we will notify you and the appropriate regulators as required by applicable law, including:
| Jurisdiction | Our Notification Obligation |
|---|---|
| EEA / UK (GDPR / UK GDPR) | Notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a notifiable breach; notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms |
| Switzerland (FADP) | Notify the FDPIC as soon as possible where the breach is likely to result in a high risk to affected persons; inform affected persons where necessary for their protection or where the FDPIC so requests |
| California (Civ. Code § 1798.82) | Notify affected California residents in the most expedient time possible and without unreasonable delay, in the statutory form; notify the California Attorney General if more than 500 California residents are affected |
| Other U.S. states | Notify affected residents and, where required, state regulators and consumer reporting agencies, within the timeframes and in the manner required by each applicable state breach-notification law |
| Canada (PIPEDA) | Report to the OPC and notify affected individuals as soon as feasible where the breach creates a real risk of significant harm; maintain breach records for at least 24 months |
| Australia (NDB scheme) | Notify the OAIC and affected individuals where an eligible data breach is likely to result in serious harm |
Timelines and content of notifications are governed by the applicable statutes above; where laws differ, we follow the requirements of each jurisdiction whose residents are affected.
18. Children's Privacy
The Platform is for adults. You must be at least 18 years old to create an account or use the Platform, consistent with our Terms of Service. The Platform is not directed to children, and we do not knowingly collect personal information from anyone under the age of 16.
Because of these restrictions, the following statutory rules should never be triggered — but we state our compliance position for completeness:
- COPPA (U.S.): we do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13 without verifiable parental consent, we will delete it promptly.
- CCPA (California): because we do not knowingly collect personal information from consumers under 16, we do not sell or share their personal information. If we ever knowingly collected personal information from consumers under 16, we would not sell or share it without the affirmative authorization the CCPA requires (a parent or guardian's opt-in for consumers under 13; the consumer's own opt-in for consumers aged 13–15).
- UK GDPR (Art. 8): the UK's age of consent for information society services is 13; our 18+ eligibility requirement exceeds it, and we do not rely on the consent of anyone under 18 to offer the Platform.
Deletion on discovery; parents and guardians. If we learn that we have collected personal information from anyone under 18 in violation of these restrictions, we will promptly delete it and close any associated account. If you are a parent or guardian and believe your child has provided personal information to us, contact us at support@eventsinminutes.com (subject: "Child Privacy") or +1 (415) 634-4617 and we will promptly investigate and delete the information as required.
Note: Guests' personal information received through Bookings (such as guest lists) may incidentally relate to minors attending an event (e.g., a child's dietary needs at a family event, provided by an adult Event Host). We process such information only to fulfill the Booking, under the Event Host's warranty in Section 3.2, and it is never used for marketing or profiling.
19. Third-Party Links and Services
The Platform may contain links to third-party websites, applications, and services that we do not own or control — including Vendor websites, social media platforms, and payment services. This Privacy Policy does not apply to those third parties, and we are not responsible for their privacy practices, content, or security. The practices of Stripe, social login providers (Google, Apple, Facebook), and advertising and analytics partners are governed by their own privacy policies, which we encourage you to review.
20. Vendor Data Handling Obligations
When Vendors receive personal information about Event Hosts or Guests through the Platform (names, contact information, event details, dietary/allergy/accessibility information, guest lists), each Vendor is an independent controller of that information and must:
- Use it only to perform the booked Vendor Services and related communications — never for unsolicited marketing, never to sell it, and never for any unrelated secondary purpose;
- Comply with all applicable privacy laws (including the CCPA, other state privacy laws, the Washington My Health My Data Act where applicable, the GDPR, and PIPEDA, as applicable to the Vendor);
- Secure it with reasonable administrative, technical, and physical safeguards against unauthorized access, disclosure, or loss;
- Delete or return it when it is no longer needed for the Booking, except as retention is required by law; and
- Cooperate with verification: Events in Minutes may audit or require verification of a Vendor's compliance with these obligations.
Enforcement: a Vendor's failure to comply with these obligations may result in suspension or removal from the Platform, in addition to any remedies available under our Terms of Service and applicable law. These obligations are also imposed contractually on Vendors through our Terms of Service and vendor data-protection terms.
21. Accessibility and Languages
We want everyone to be able to read and use this notice:
- Accessibility: this Privacy Policy and our privacy notices are designed to be reasonably accessible to consumers with disabilities. Our website, including this policy, is built to conform to the Web Content Accessibility Guidelines (WCAG) 2.1 Level AA. If you use assistive technology and have difficulty accessing this policy, or if you would like it in an alternative format (such as large print or screen-reader-friendly plain text), contact us at support@eventsinminutes.com or +1 (415) 634-4617 and we will provide it promptly at no charge.
- Languages: we ordinarily conduct business in English, and this Privacy Policy is provided in English. Quebec residents may request a French version (Section 15.2).
22. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, or legal requirements. If we make material changes, we will notify you at least thirty (30) days before the changes take effect by (a) emailing the address associated with your account and/or (b) posting a prominent notice on the Platform — except where a shorter period is required by law or necessary for urgent legal or safety reasons. If you do not agree with the updated policy, you should stop using the Platform and may close your account before the changes take effect. Your continued use of the Platform after the effective date constitutes acceptance of the updated Privacy Policy. Each revision will be indicated by an updated "Effective Date / Last Updated" date at the top of this page, and prior versions are available on request (see the note above the Table of Contents).
23. Contact Us
Events in Minutes, Inc. (a Delaware C-Corporation)
Attn: Privacy & Data Protection
999 Baker Way, San Mateo, CA 94404, USA
- Email: support@eventsinminutes.com (privacy inquiries may also be sent to privacy@eventsinminutes.com, which routes to the same Privacy & Data Protection team)
- Phone: +1 (415) 634-4617 (standard-rate line)
- Website: www.eventsinminutes.com
Where to send requests and appeals. All privacy rights requests (Sections 8–11, 14–16), consumer health data requests and appeals (Section 10), state privacy appeals (Section 11.4), automated-decision review requests (Section 4.4), AI-training opt-outs (Section 4.3), and child-privacy reports (Section 18) should be sent to support@eventsinminutes.com using the subject lines indicated in those sections, or by mail to the address above, Attn: Privacy & Data Protection.