Legal
Privacy Policy
Last updated: July 8, 2026
This Privacy Policy explains how CuratedLove (“CuratedLove,” “we,” “us”) collects, uses, and shares personal information when you visit curatedlove.party, join our waitlist, book a demo, or use our supper-club management tools (the “Service”).
Our data promise, in plain language
Before the legal detail, here is exactly what we do and don't do, on every plan including Free:
- Your guest list is yours. We store and process guest information only to run your dinners. We never sell it, never share it with other hosts, and never use one host's guest list to benefit anyone else.
- We use platform data to improve the product. To improve CuratedLove and build new features for hosts, we analyze how the platform is used — for example, dietary-need trends across dinners, and how quickly dinners fill at different price points. One host's guest list is never sold and never shared with another host.
- You can leave with everything. Ask and we'll export your data; ask and we'll delete it. Deleted means deleted.
Information we collect
Information you give us. When you join the waitlist we collect your name, email, role, budget range, club or company, city, website or social handle, and the workflows you want help with. When you sign in we process your email and a securely hashed credential. When you use the Service you may add organization details and event information.
Information collected automatically. We collect limited technical data such as IP address, browser type and user agent, referring page, and general usage, primarily to keep the Service secure and working.
Information from third parties. If you book a demo, cal.com collects your name, email, and chosen time and shares the booking with us. If you or your guests pay through the Service — your subscription or a guest's dinner payment — Stripe processes that payment and shares limited details (such as amount and payment status, never your full card number) with us.
Guest information you add
Hosts may store information about their guests (such as names, contact details, and dietary preferences). For that data, you are the controller and CuratedLove is a processor acting on your instructions. You are responsible for having a lawful basis and any required consent before adding guest information — especially dietary or allergy notes, which may be treated as sensitive data in some regions.
How we use information
- To operate, maintain, and improve the Service.
- To process your subscription and any guest payments you collect, through Stripe.
- To respond to waitlist requests, schedule and run demos, and contact you about the Service.
- To power AI features you or your guests trigger — for example, drafting a menu or event, or answering a question in the AI concierge. The prompt you submit, and any of your own account or booking data the feature needs to answer accurately (which can include guest details you've stored, such as a name on a booking), is sent to our AI provider, Anthropic, solely to generate that response. It is not used to train Anthropic's models.
- To secure the Service, prevent abuse, and meet legal obligations.
Legal bases (EEA/UK)
Where the GDPR or UK GDPR applies, we rely on: your consent (e.g. joining the waitlist or visiting the /demo booking page); performance of a contract (providing the Service); and our legitimate interests (securing and improving the Service), balanced against your rights.
How we share information
We do not sell your personal information. We share it only with service providers that help us run the Service, under appropriate terms:
- Stripe — payment processing for subscriptions and guest dinner payments. Stripe receives payment details directly; we never see or store your full card number.
- Anthropic — AI generation for features you or your guests trigger (event/menu drafting, the AI concierge). See “How we use information” above.
- Resend — transactional and waitlist email.
- Kroger — real-time grocery product names and store pricing used to build shopping-list suggestions. We send a product search, not personal or guest information, and Kroger does not receive any of your guest data.
- cal.com — demo scheduling, embedded on our /demo page.
- Cloudflare — hosting, security, and database storage.
- YouTube — embedded video, loaded in privacy-enhanced mode only when you press play.
We do not currently have a live integration for point-of-sale providers (such as Square) that shares data with them — if and when a POS connection goes live for customers, we will update this list first.
We may also disclose information to comply with law or to protect our rights, users, and the public.
Cookies
We use a small number of essential cookies, and third-party cookies are set by cal.com only on our /demo page, where its booking calendar is embedded. See our Cookie Policy for details.
Data retention
We keep personal information for as long as needed to provide the Service and for legitimate business or legal purposes, then delete or anonymize it. You can ask us to delete your data at any time.
Security
Data is transmitted over HTTPS and stored with our infrastructure providers using access controls. No method of transmission or storage is perfectly secure, but we work to protect your information and limit access to it. We do not currently hold formal security certifications (such as SOC 2 or ISO 27001); if that changes, we will state it here accurately.
Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict use of your personal information, and to withdraw consent or object to certain processing. California residents may exercise rights under the CCPA/CPRA, including the right not to be discriminated against for exercising them. To make a request, email reach@curatedlove.me.
International transfers
We and our providers may process information in countries other than yours. Where required, we use appropriate safeguards for international transfers.
Children
The Service is intended for adults and is not directed to children. We do not knowingly collect personal information from anyone under 18.
Health information and HIPAA
CuratedLove is a hospitality and events platform. It is not a healthcare provider, health plan, or healthcare clearinghouse, and is not a “covered entity” or “business associate” under HIPAA. The Service is not intended to collect or process protected health information (PHI). Please do not submit medical or health records through the Service.
Changes to this policy
We may update this policy from time to time. We will revise the “Last updated” date above and, for material changes, take additional steps where required.
Contact
Questions or requests? Email reach@curatedlove.me.
About this policy
This policy is written to describe accurately, in plain language, what CuratedLove actually does with data today. It is not a substitute for legal advice, and having this policy does not by itself guarantee compliance with every law that may apply to you. CuratedLove recommends having this policy reviewed by a licensed attorney, particularly if you operate in a jurisdiction with specific requirements (such as the GDPR or CCPA/CPRA), before relying on it.