Skip to main content

Legal

Privacy policy

Initial template — requires legal review before production use

This page is a starting point written to describe how the product actually behaves. It has not been reviewed by an attorney and is not legal advice. Before launch it must be reviewed against Tennessee consumer-protection law, marketplace and payment-facilitator obligations, and applicable privacy regulation. Last updated January 2026.

What this covers

This describes what Semicircl does with information when you browse the site, submit an event brief, apply as a provider or complete a booking. It is written to match how the product actually behaves rather than to be maximally permissive.

Information we collect

  • Account information. Name, email address, phone number and, for company or nonprofit buyers, an organization name.
  • Event brief content. Everything you enter in a brief — date, guest count, budget, requirements, dietary and accessibility needs, and free-text notes.
  • Messages. Content of messages you send through the platform, including messages flagged by our contact-detail detection.
  • Booking and payment records. What you booked, from whom, for how much, and the status of each payment. Card details are handled entirely by Stripe — we store only Stripe identifiers and never see or store a card number.
  • Provider information. For vendors: business details, insurance and license status, pricing structure, portfolio content and quote history.
  • Technical information. Standard server logs and, where enabled, privacy-respecting analytics. We do not run third-party advertising trackers.

How we use it

  • To source venues and vendors against your brief and build proposals.
  • To process deposits, balances, refunds and provider payouts.
  • To operate messaging and to support you when something changes.
  • To send transactional email about your brief, proposal, booking and payments.
  • To detect abuse, and to review messages flagged for contact-detail sharing.
  • To improve the product in aggregate.

What we share, and with whom

Providers we invite to quote receive the contents of your brief, because they cannot quote without it. Before a booking, they do not receive your name, email address or phone number. Once you pay a deposit, the providers on your booking receive your contact details so the event can actually be run.

Service providers we rely on: Stripe for payments and payouts, Resend for transactional email, Supabase for database and authentication, and our hosting provider. Each processes data on our instructions.

We do not sell personal information, and we do not share it with advertising networks.

Retention

Booking, payment and accepted-terms records are retained for as long as required for tax, accounting and dispute-resolution purposes. Briefs that never become bookings, and the messages attached to them, are retained while your account is active. You can ask us to delete an account and we will, except where a record must be kept for the reasons above.

Your choices

  • Access, correct or delete your account information by contacting us.
  • Opt out of marketing email at any time. Transactional email about a live booking cannot be switched off while that booking is active.
  • Ask what we hold about you and receive a copy.

Security

Access to customer data is restricted to the people who need it to operate the marketplace, and administrative actions on bookings, payments and provider records are written to an audit trail. Payment card data never touches our servers.

Children

The service is not directed at children and we do not knowingly collect information from anyone under 18.

Changes

If this policy changes materially we will tell account holders by email before the change takes effect.

Contact

Questions about privacy: hello@semicircl.com.


Items requiring legal confirmation before launch

  • Whether the platform is a “controller” or “processor” for brief content shared with providers, and what that requires contractually.
  • Applicability of state privacy law (including Tennessee's Information Protection Act) and whether any consumer-rights request workflow is mandated.
  • Data-processing agreements with Stripe, Supabase, Resend and the hosting provider.
  • Retention periods for payment records under applicable tax rules.
  • Cookie and analytics disclosure requirements for the analytics tool finally chosen.