Legal
Privacy policy
Initial template — requires legal review before production use
This page is a starting point written to describe how the product actually behaves. It has not been reviewed by an attorney and is not legal advice. Before launch it must be reviewed against Tennessee consumer-protection law, marketplace and payment-facilitator obligations, and applicable privacy regulation. Last updated January 2026.
What this covers
This describes what Semicircl does with information when you browse the site, submit a request, apply as a service or complete a booking. It is written to match how the product actually behaves rather than to be maximally permissive.
Information we collect
- Account information. Name, email address, phone number and, for company or nonprofit buyers, an organization name.
- Request content. Everything you enter in a request — date, guest count, budget, requirements, dietary and accessibility needs, and free-text notes.
- Messages. Content of messages you send through the platform, including messages flagged by our contact-detail detection.
- Booking and payment records. What you booked, from whom, for how much, and the status of each payment. Card details are handled entirely by Stripe — we store only Stripe identifiers and never see or store a card number.
- Service information. For services: business details, insurance and license status, pricing structure, portfolio content and quote history.
- Technical information. Standard server logs and, where enabled, privacy-respecting analytics. We do not run third-party advertising trackers.
How we use it
- To source venues and services against your request and build proposals.
- To process deposits, balances, refunds and service payouts.
- To operate messaging and to support you when something changes.
- To send transactional email about your request, proposal, booking and payments.
- To detect abuse, and to review messages flagged for contact-detail sharing.
- To improve the product in aggregate.
What we share, and with whom
Services we invite to quote receive the contents of your request, because they cannot quote without it. Before a booking, they do not receive your name, email address or phone number. Once you pay a deposit, the services on your booking receive your contact details so the event can actually be run.
Service providers we rely on: Stripe for payments and payouts, Resend for transactional email, Supabase for database and authentication, and our hosting service. Each processes data on our instructions.
We do not sell personal information, and we do not share it with advertising networks.
Retention
Booking, payment and accepted-terms records are retained for as long as required for tax, accounting and dispute-resolution purposes. Requests that never become bookings, and the messages attached to them, are retained while your account is active. You can ask us to delete an account and we will, except where a record must be kept for the reasons above.
Your choices
- Access, correct or delete your account information by contacting us.
- Opt out of marketing email at any time. Transactional email about a live booking cannot be switched off while that booking is active.
- Ask what we hold about you and receive a copy.
Security
Access to customer data is restricted to the people who need it to operate the marketplace, and administrative actions on bookings, payments and service records are written to an audit trail. Payment card data never touches our servers.
Children
The service is not directed at children and we do not knowingly collect information from anyone under 18.
Changes
If this policy changes materially we will tell account holders by email before the change takes effect.
Contact
Questions about privacy: hello@semicircl.com.
Items requiring legal confirmation before launch
- Whether the platform is a “controller” or “processor” for request content shared with services, and what that requires contractually.
- Applicability of state privacy law (including Tennessee's Information Protection Act) and whether any consumer-rights request workflow is mandated.
- Data-processing agreements with Stripe, Supabase, Resend and the hosting service.
- Retention periods for payment records under applicable tax rules.
- Cookie and analytics disclosure requirements for the analytics tool finally chosen.