Skip to main content

Privacy Policy

Last updated: April 20, 2026

1. Introduction

BOOKBIDWELL LLC (“Bidwell,” “we,” “our,” or “us”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect information when you use our website at bookbidwell.com and our platform services (collectively, the “Service”).

2. Information We Collect

2.1 Information You Provide

  • Account information: Name, email address, phone number, password
  • Couple profiles: Partner names, wedding date, guest count, city, state, budget, event preferences
  • Venue profiles: Venue name, type, description, address, capacity, pricing, amenities, photos, website
  • Bids and bookings: Bid amounts, line items, inclusions, availability, contract signatures
  • Messages: Content of messages exchanged between Couples and Venues through the platform
  • Payment information: Processed through Stripe; we do not store full credit card numbers

2.2 Information Collected Automatically

  • Usage data: Pages visited, features used, time spent, interaction patterns
  • Device information: Browser type, operating system, device type, screen resolution
  • Location data: Approximate location (city, state, country) derived from IP address via our hosting provider's edge network. Used to localize market-status messaging; we do not collect precise GPS location
  • Cookies and analytics: Google Tag Manager / Google Analytics, Meta Pixel (Facebook/Instagram), and PostHog for usage analytics and advertising performance. See Section 9 for cookie categories and your controls
  • Error telemetry: Sentry for application error monitoring (user agent, URL path, stack trace — no form-field content)

2.3 Information from Third Parties

  • Advertising platforms: If you clicked a Bidwell ad, the source network (e.g., Meta, Google) may share click/attribution identifiers (gclid, fbclid, msclkid) so we can measure campaign performance
  • Payment processor: Stripe Connect sends payment status, transfer IDs, and tax-reporting details (1099-K eligibility)
  • Contract signing: Dropbox Sign (HelloSign) returns signature status and signed-document references for executed booking contracts

3. How We Use Your Information

  • Operate and maintain the Bidwell platform
  • Match Couples with relevant Venues based on location, capacity, and preferences
  • Process bids, bookings, and payments (via Stripe Connect)
  • Send transactional notifications (bid updates, booking confirmations, messages) via email (Resend) and SMS (Twilio — see Section 10)
  • Provide AI-assisted features — including Bidwell House, bid analysis, fit scoring, pricing insights, and counter-offer coaching — by sending relevant event and bid data to our AI subprocessor (Anthropic). See Section 5 for details
  • Improve the Service through usage analysis and feedback
  • Prevent fraud, enforce our Terms, and protect user safety
  • Communicate platform updates, new features, and marketing (with opt-out)

4. How We Share Your Information

We do not sell your personal information for money. We do, however, use advertising cookies (Meta Pixel, Google Analytics) that the California Privacy Rights Act (CPRA) defines as “sharing” for cross-context behavioral advertising — California residents can opt out of this in Section 11.

We share information in these circumstances:

  • Between Couples and Venues: When a Couple shortlists a bid, the Venue's identity is revealed to that Couple. When a booking is confirmed, both parties' contact information is shared so they can coordinate the event.
  • Service providers (subprocessors): Listed in the table below. Each processes data on our behalf under a written data processing agreement.
  • Legal requirements: We may disclose information if required by law, subpoena, or court order, or to protect our rights, safety, or property.
  • Business transfers: In the event of a merger, acquisition, or sale of assets, user data may be transferred to the acquiring entity.

4.1 Subprocessors

The following third-party service providers receive personal information to help us run the Service. Each is contractually restricted to processing your data only for the purpose stated below.

SubprocessorPurposeData categories
SupabaseDatabase, authentication, row-level securityAccount, profile, bids, bookings, messages
Stripe ConnectPayment processing, venue payouts, tax reporting (1099-K)Name, email, payment method, transaction amounts, business info (Venues)
Anthropic (Claude)Bidwell House, bid analysis, fit scoring, counter-offer coaching, pricing insights. See Section 5Event details, bid content, message excerpts, venue descriptions — no payment data
Dropbox Sign (HelloSign)E-signature for booking contracts and venue agreementsName, email, contract PDFs, signature metadata
TwilioSMS verification and booking-related SMS notificationsPhone number, message content, delivery status
ResendTransactional and marketing emailName, email, message content, open/click events
VercelApplication hosting and edge networkIP address, city/state/country (for geo-localization), request logs
SentryError monitoring and performance telemetryUser agent, URL path, stack traces, support ticket metadata (message text is redacted before Sentry)
SlackInternal operational alerts for support, signups, and venue/couple workflow exceptionsContact details and request context included in operational alerts
PostHogProduct analytics (feature usage, funnels, session events)Anonymous ID, event properties, page views
Google Analytics / GTMTraffic and conversion analyticsAnonymous ID, event data, referrer
Meta PixelAd attribution and campaign measurement (Facebook, Instagram)Anonymous ID, event data, hashed identifiers

This list is updated as we add or remove subprocessors. Material changes are announced via email and the “Last updated” date above.

5. AI Processing

Bidwell uses large-language-model AI (primarily Anthropic's Claude) to power product features including Bidwell House, bid scoring, fit analysis, package completeness checks, counter-offer coaching, and pricing insights.

  • What we send: Relevant event details (date, guest count, budget band, style preferences), bid content (price, inclusions, capacity), and — where you use the AI Planner conversationally — the messages you type to the assistant. We do not send payment information, password hashes, or government IDs.
  • Training: Our AI subprocessor does not use data sent through its API to train its models, per its current standard commercial terms. We do not use your content to train any AI model ourselves.
  • Retention: AI prompt and response logs are retained for up to 30 days for abuse prevention and quality monitoring, then deleted unless flagged for a support investigation.
  • Accuracy: AI output can be inaccurate or incomplete. It is guidance, not professional, legal, or financial advice. Verify numbers and details in the written bid and contract before relying on them. See our Terms of Service.
  • Human review: Routine AI-assisted features (fit scores, insights) do not make legally significant decisions about you without human review. If we ever add a feature that does, we will update this policy.

6. Semi-Blind Auction & Data Visibility

Bidwell operates a semi-blind auction model. Key privacy protections include:

  • Venue identities are hidden from Couples until a bid is shortlisted
  • Couple identities are hidden from Venues until a booking is initiated
  • Bid amounts and details from other Venues are never shared with competing Venues
  • Venue performance scores and analytics are visible only to the respective Venue

7. Data Security

We implement industry-standard security measures to protect your data:

  • All data is encrypted in transit (TLS/SSL) and at rest
  • Database hosted on Supabase with row-level security policies
  • Authentication handled through Supabase Auth with secure password hashing
  • Payment data processed through PCI DSS-compliant Stripe infrastructure
  • Access controls and audit logging for administrative functions

No system is perfectly secure. If we become aware of a security incident that affects your personal information, we will notify you and relevant authorities as required by applicable law (including state breach-notification statutes), and will describe what happened, what data was involved, and the steps we are taking in response.

8. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Service. Specific retention windows:

  • Transaction records and contract snapshots: 7 years after the associated booking, for legal, tax, and financial compliance.
  • Messages and bid content: Retained for the life of the account; deleted or anonymized on account deletion, subject to the 7-year transaction-record rule for booked events.
  • AI prompt and response logs: Up to 30 days, then deleted unless flagged for a support investigation.
  • Error telemetry (Sentry): Up to 90 days.
  • Marketing-attribution data (UTM, click IDs): Up to 13 months, aligned with common ad-platform attribution windows.
  • Anonymized and aggregated analytics: May be retained indefinitely for product-improvement purposes.

9. SMS, Phone Verification, and TCPA Notice

Bidwell sends SMS messages for two purposes: (a) one-time phone verification during signup and when required to activate a couple request, and (b) booking-related notifications (bid alerts, shortlist updates, counter-offer timelines, and booking confirmations). SMS is delivered by our subprocessor Twilio.

  • Consent. By providing your phone number and completing verification, you consent to receive SMS from Bidwell for the purposes above. This consent is not a condition of purchase.
  • Message frequency. Frequency varies by your activity (number of bids received, messages, and booking milestones). Expect zero to a handful of SMS per day during active bidding.
  • Opt-out. Reply STOP to any Bidwell SMS to stop all non-essential messages. Reply HELP for help. You may also disable SMS notifications in your account settings.
  • Message and data rates may apply. Your mobile carrier's standard messaging and data charges apply. Bidwell does not charge you for SMS.
  • Carrier liability. Carriers are not liable for delayed or undelivered messages.
  • Essential transactional SMS. Phone-verification codes and booking-critical notices (e.g., counter-offer expiry, booking confirmation) are essential to the Service. If you opt out of SMS entirely, we may be unable to complete verification or certain booking steps, and some platform features will be unavailable.

10. Your Rights

You have the right to:

  • Access: Request a copy of the personal information we hold about you
  • Correction: Update or correct inaccurate information through your account settings
  • Deletion: Request deletion of your account and personal data (subject to legal retention requirements)
  • Portability: Request an export of your data in a machine-readable format
  • Opt-out of marketing: Unsubscribe from marketing email via the link in any marketing message, or from SMS via the STOP keyword (Section 9)
  • Opt-out of advertising cookies / “sharing”: Use the cookie banner's “Reject All” control (Section 11), which disables Meta Pixel, Google Analytics, and PostHog. California residents — see Section 13

To exercise any of these rights, email us at info@bookbidwell.com (subject line: Privacy Request). We verify your identity before acting on a request and will respond within 45 days (or 90 days with written notice if the request is complex).

11. Cookies and Tracking Controls

We use cookies and similar technologies for:

  • Essential cookies: Authentication, session management, and security. These are always on — the platform cannot function without them.
  • Analytics cookies: Google Analytics (via Google Tag Manager) and PostHog to understand usage patterns and improve the Service.
  • Advertising cookies: Meta Pixel for ad-campaign attribution (Facebook/Instagram).

Your controls. The first time you visit, a cookie banner lets you accept or reject non-essential cookies. Choosing Reject All disables analytics and advertising cookies on your device. To change your mind later, clear Bidwell's cookies in your browser settings (the banner will reappear on your next visit), or email info@bookbidwell.com with subject Cookie Preferences. You can also control cookies through your browser settings.

Do Not Track. We honor the Reject Allchoice in the cookie banner. Because industry standards for browser-level “Do Not Track” signals remain inconsistent, we do not rely on those signals alone; use the banner control for the strongest protection.

12. Children's Privacy

Bidwell is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected data from a child under 18, we will delete it promptly.

13. California Privacy Rights (CCPA/CPRA)

This section applies to California residents and supplements the rest of this Policy. This section is provided as a plain-language summary. Bidwell's counsel reviews and updates the formal California disclosure as regulations evolve; contact us if anything here is unclear or appears outdated.

13.1 Categories of personal information we collect

In the last 12 months, we have collected the following CCPA categories of personal information:

CCPA categoryExamplesCollected?
IdentifiersName, email, phone, IP address, account IDYes
Customer recordsBilling address (Venues), payment account IDsYes
Protected-class characteristicsAge (18+ confirmation); we do not collect race, religion, disability, etc.Limited
Commercial informationBids, bookings, transaction historyYes
Biometric informationNo
Internet / network activityPages viewed, clicks, referrer, device infoYes
GeolocationApproximate (city/state) from IP — no precise GPSYes (approximate)
Sensory dataVenue photos you upload; support recordings — none currentlyLimited
Professional / employmentVenue business info, EIN (Venues only)Venues only
Education informationNo
InferencesAI-derived match scores, style inferences for venue matchingYes
Sensitive PIAccount credentials and financial account identifiers (for payments)Limited (see 13.4)

13.2 Sources of personal information

  • Directly from you (account creation, profile, bids, messages, support requests)
  • Automatically from your device (cookies, analytics — see Sections 2.2 and 11)
  • From third parties (ad-network attribution identifiers, Stripe, Dropbox Sign — see Section 2.3)

13.3 Business and commercial purposes

We use personal information for the purposes listed in Section 3 (operate the Service, match Couples and Venues, process payments, provide AI features, prevent fraud, comply with law, and communicate with you).

13.4 Sensitive personal information

We collect a limited set of CPRA-defined “sensitive personal information” — specifically, account credentials (used only to authenticate you) and financial account identifiers (used only to process payments through Stripe Connect). We do not use or disclose this information for purposes other than those permitted under CPRA §7027(m) and do not need to offer a separate “limit use of sensitive PI” mechanism beyond what Section 10 already provides.

13.5 Selling and sharing — Do Not Sell or Share My Personal Information

We do not sell personal information for money. However, when our Meta Pixel or Google Analytics tags fire, California law treats the resulting data flow as “sharing” for cross-context behavioral advertising. California residents can opt out of this “sharing” at any time by:

  • Choosing Reject All in the cookie banner on your first visit (or revisiting it via the footer link), which disables Meta Pixel, Google Analytics, and PostHog on your device; or
  • Clearing Bidwell's cookies in your browser so the banner reappears, then choosing Reject All; or
  • Using the Do Not Sell or Share My Personal Information footer link (equivalent to Reject All for these purposes); or
  • Emailing info@bookbidwell.com with subject Do Not Sell or Share.

13.6 Your California rights

  • Right to know what personal information we collect, use, disclose, and share
  • Right to delete personal information we hold about you (subject to legal retention)
  • Right to correct inaccurate personal information
  • Right to opt out of sharing for cross-context behavioral advertising (see 13.5)
  • Right to limit use of sensitive PI (we do not use sensitive PI for prohibited purposes — see 13.4)
  • Right to non-discrimination — we will not deny service, charge different prices, or degrade quality because you exercised a right
  • Right to designate an authorized agent to make a request on your behalf (we will verify both your identity and the agent's authority)

13.7 How to exercise your rights

Email info@bookbidwell.com with subject California Privacy Request, or use the Do Not Sell or Sharefooter link on this page (which opens Section 13.5's opt-out channels). We verify your identity before acting on a request and respond within 45 days (or 90 days with written notice if the request is complex).

14. International Visitors

Bidwell's Service is intended for residents of the United States. We operate and store data in the United States. If you access the Service from outside the U.S., you understand and consent that your information will be transferred to and processed in the United States, which may have data-protection rules different from those in your jurisdiction.

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes via email and will update the “Last updated” date at the top. Your continued use of the Service after a material change takes effect constitutes acceptance of the revised Policy.

16. Contact

Questions about this Privacy Policy? Contact us at info@bookbidwell.com.