Draft, not legal advice. This is a working template based on how Solulu operates and has not yet been reviewed by counsel. It may change before launch.
Privacy Policy
1. Who we are and what Solulu does
Solulu is an online platform and ticketing marketplace that connects two kinds of businesses — event organizers (retreat leaders) and venues (hosts) — so they can propose, agree, and run events together, and sell tickets to guests. Solulu provides the software; it is not a party to the events, the agreements between organizers and venues, or a guest's attendance. This policy explains what personal information we collect, why, and your choices.
This policy covers three kinds of people:
- Account users — venue managers and event organizers who use the app.
- Guests — people who reserve or buy tickets to an event.
- Visitors — anyone who browses our public pages.
2. Information we collect
You give us: account & profile (name, email, phone, role, profile photo, and, for organizers/venues, business/venue details, descriptions, images, and social links); sign-in data (we support Google, GitHub, and email "magic link" sign-in via our authentication provider and receive your name and email from them — we do not receive your third-party passwords); event & listing content (venues, rooms, food menus, facilities, opportunities, event pages, schedules, pricing, policies); guest reservation data (a guest's name, email, phone, gender — optional, including "prefer not to say" — room/occupancy choice, and food sensitivities or requests); and communications you send through the platform and to support.
Collected automatically: usage & device data (log data, IP address, browser/device type, pages viewed and actions taken — for security, debugging, and analytics) and a small number of cookies (a session cookie to keep you signed in and a preference cookie to remember your active role).
From third parties / processors: card payments and payouts are handled by our payment processor ([Stripe]); we receive limited transaction metadata (e.g., amount, status, last four digits) but do not store full card numbers. Map and address features use a mapping provider ([Google Maps]).
3. How we use information
- Provide and operate the platform: accounts, opportunities, the waitlist/deposit/ticketing flow, and events.
- Facilitate connections and transactions between organizers, venues, and guests.
- Process payments (deposits, ticket purchases, refunds, payouts) through our payment processor.
- Send transactional emails (sign-in links, booking notifications, receipts) via our email provider ([Resend]).
- Platform trust & safety: monitor for fraud, abuse, and repeated failures to honor commitments, and take account-level action where needed.
- Improve, secure, and troubleshoot the service, and comply with law.
Legal bases (where GDPR / UK GDPR applies): performance of a contract, legitimate interests (security, trust, product improvement), consent (where required), and legal obligation.
4. How information is shared
Because Solulu connects parties, some data is shared between the parties to a transaction by design:
- Organizer ↔ Venue: profile, opportunity, event, and contact details needed to agree and run an event.
- Guest → Organizer & Venue: a guest's reservation details (name, contact, room, food sensitivities, etc.) are shared with the organizer and venue running that event.
We also share with service providers who process data on our behalf under contract: payments ([Stripe]), cloud hosting and storage ([Amazon Web Services]), email ([Resend]), authentication (Google, GitHub), mapping ([Google Maps]), and logging/analytics ([Axiom]). We may disclose information to comply with law, enforce our Terms, or protect users and the public, and as part of a merger or acquisition. We do not sell your personal information.
5. Solulu's role and what we are not responsible for
Solulu is an intermediary that provides software and facilitates ticketing. We do not control, and are not responsible for, the conduct of organizers, venues, or guests, the safety or quality of events, injuries or damages, or disputes between users. Personal information is processed to run the platform, not because we take responsibility for the underlying events. Disputes between users are resolved directly between them (see the Terms of Service).
6. Data retention
We keep personal information for as long as your account is active and as needed to provide the service, then for as long as necessary to meet legal, accounting, tax, dispute-resolution, and platform-trust obligations, after which we delete or anonymize it. Guest reservation and ticketing records are retained as business and financial records.
7. Security & storage
Data is stored on managed cloud infrastructure ([AWS] — database and file storage). We use industry-standard measures (encryption in transit, access controls, session-based authentication). No method of transmission or storage is 100% secure, so we cannot guarantee absolute security. Data may be processed in [COUNTRY/REGION]; where required we use appropriate safeguards for international transfers.
8. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal information, to object to certain processing, and to withdraw consent. To exercise these, contact [privacy@gosolulu.com]. You can also update most account data in the app.
Because Solulu shares transaction data between parties, some records (e.g., a completed booking) may need to be retained by the other party or by us even after you delete your account, to the extent permitted by law. California (CCPA/CPRA) and EU/UK (GDPR) residents have additional rights. [Add jurisdiction-specific language and a "Do Not Sell/Share" statement.]
9. Cookies
We use a small number of cookies: a session cookie (to keep you signed in) and a preference cookie (to remember your active role). We do not use non-essential tracking cookies without consent where consent is required. [Add cookie table / banner details as needed.]
10. Children
Solulu is not directed to children under [16/18], and we do not knowingly collect their personal information. If you believe a child has provided us data, contact us and we will delete it.
11. Changes to this policy
We may update this policy. If changes are material, we will notify you (e.g., by email or an in-app notice) and update the effective date above.
12. Contact
Questions or requests: [privacy@gosolulu.com] · [LEGAL ENTITY NAME], [REGISTERED ADDRESS].