Privacy Policy
Last updated: September 30, 2025
Introduction
At Nowadays AI ("we," "us," or "our"), we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our event planning platform and services (collectively, the "Services").
By accessing or using our Services, you agree to the terms of this Privacy Policy. If you do not agree with our policies and practices, please do not use our Services.
This Privacy Policy should be read in conjunction with our Terms of Service and our Security Policy.
Information We Collect
1. Information You Provide Directly
- Account Information: When you create an account, we collect your first name, last name, email address, and password (stored securely using bcrypt hashing).
- Event Information: Details about your events including event type, dates, locations, number of attendees, budget, preferences, and any other information you provide when planning events.
- Communication Data: Information from your communications with us, including support requests, feedback, and any correspondence through our platform or email.
- Payment Information: When you make payments, our payment processor Stripe collects your payment card information. We do not store your complete payment card details on our servers.
2. Information We Collect Automatically
- Usage Information: We collect information about how you interact with our Services, including pages visited, features used, time spent on pages, and navigation patterns.
- Device Information: We collect information about the device you use to access our Services, including device type, operating system, browser type, IP address, and unique device identifiers.
- Analytics Data: We use PostHog to collect analytics and error tracking data to improve our Services and user experience.
- Log Data: Our servers automatically record information including access times, pages viewed, IP addresses, and the page you visited before navigating to our Services.
3. Information from Third-Party Services
- Email Integration: If you connect your Gmail account, we access your emails to extract venue quotes, manage RFP communications, and facilitate event planning. We only access emails necessary for providing our Services.
- Google Maps: We use Google Maps API to help you discover and evaluate venue locations.
How We Use Your Information
We use the information we collect for the following purposes:
- Provide Services: To create and manage your account, process event planning requests, source venues, send RFPs, manage communications with venues, and deliver the core functionality of our platform.
- Process Payments: To process transactions, send invoices, and manage billing through our payment processor Stripe.
- AI-Powered Features: To use AI models (OpenAI via BAML) for email parsing, venue analysis, and RFP generation. Your data is not used to train AI models.
- Communications: To send you service-related emails, event updates, venue proposals, notifications, and respond to your inquiries.
- Improve Services: To analyze usage patterns, understand user preferences, fix bugs, improve features, and enhance overall user experience.
- Customer Support: To provide technical support, answer questions, and resolve issues through our support channels including Slack and email.
- Security: To detect, prevent, and respond to fraud, unauthorized access, security incidents, and other potentially harmful activities.
- Legal Compliance: To comply with legal obligations, respond to legal requests, enforce our Terms of Service, and protect our rights and interests.
- Analytics: To understand how users interact with our Services and make data-driven improvements using PostHog analytics.
How We Share Your Information
We do not sell your personal information. We share your information only in the following limited circumstances:
1. Service Providers
We share your information with trusted third-party service providers who help us deliver our Services:
- Supabase: Database hosting and management (PostgreSQL) for storing your event data and account information.
- OpenAI: AI-powered features for email parsing, venue analysis, and RFP generation. Your data is not used for training AI models.
- Stripe: Secure payment processing for handling transactions and subscriptions.
- Google: Gmail API for email integration and Google Maps API for venue discovery and location services.
- SendGrid: Email delivery service for transactional emails and notifications.
- PostHog: Product analytics and error tracking to improve our Services.
- Vercel: Application hosting and content delivery network (CDN) for serving our platform.
All service providers are bound by data processing agreements and are required to protect your information and use it only for the purposes we specify.
2. Venues and Event Service Providers
When you use our Services to plan events, we share relevant event information with venues and service providers to obtain quotes and facilitate bookings on your behalf. This includes event details such as dates, attendee count, and your contact information.
3. Legal Requirements
We may disclose your information if required to do so by law or in response to:
- Valid legal processes (court orders, subpoenas, search warrants)
- Legal requests from government authorities
- Circumstances necessary to protect our rights, property, or safety, or that of our users or the public
- Enforcement of our Terms of Service or investigation of potential violations
4. Business Transfers
If we are involved in a merger, acquisition, sale of assets, or bankruptcy, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your personal information.
5. With Your Consent
We may share your information with other parties when you have given us explicit consent to do so, such as when you authorize us to share information with event collaborators you invite to your account.
Data Retention
We retain your personal information for as long as necessary to provide our Services and fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
- Account Data: We retain your account information for as long as your account is active or as needed to provide you Services.
- Event Data: Event information is retained to maintain your event history and for compliance purposes.
- After Account Deletion: When you delete your account, we will make your data available for electronic retrieval for 30 days. After this period, we may delete your data, though we may retain certain information for legal compliance, dispute resolution, and enforcement of our agreements.
- Log Data: Access logs and security logs are retained for security monitoring and incident response purposes.
Your Privacy Rights
Depending on your location, you may have certain rights regarding your personal information. These rights may include:
Your Rights Include:
- Access: You can request access to the personal information we hold about you.
- Correction: You can request that we correct inaccurate or incomplete personal information.
- Deletion: You can request that we delete your personal information, subject to certain legal exceptions.
- Data Portability: You can request a copy of your personal information in a structured, machine-readable format.
- Objection: You can object to certain processing of your personal information.
- Restriction: You can request that we restrict the processing of your personal information in certain circumstances.
- Withdraw Consent: Where we rely on consent to process your personal information, you can withdraw that consent at any time.
GDPR Rights (European Users)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR), including the rights listed above. Our legal basis for processing your information includes:
- Performance of a contract (providing our Services to you)
- Legitimate interests (improving our Services, security, fraud prevention)
- Consent (where you have provided it)
- Legal obligations (compliance with applicable laws)
CCPA Rights (California Users)
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information we collect, use, disclose, and sell
- Right to request deletion of your personal information
- Right to opt-out of the sale of personal information (we do not sell your information)
- Right to non-discrimination for exercising your CCPA rights
How to Exercise Your Rights
To exercise any of these rights, please contact us at support@getnowadays.com. We will respond to your request within 30 days (or as required by applicable law). You have the right to complain to a data protection authority about our collection and use of your personal information.
Cookies and Tracking Technologies
We use cookies and similar tracking technologies to collect information about your browsing activities and to personalize your experience on our Services.
Types of Cookies We Use:
- Essential Cookies: Required for the Services to function properly, including authentication and security.
- Analytics Cookies: Help us understand how users interact with our Services through PostHog analytics.
- Functional Cookies: Remember your preferences and settings to enhance your experience.
You can control cookies through your browser settings. However, if you disable cookies, some features of our Services may not function properly.
Third-Party Links and Services
Our Services may contain links to third-party websites, services, or applications that are not operated by us. This Privacy Policy does not apply to these third-party services. We are not responsible for the privacy practices of third parties. We encourage you to review the privacy policies of any third-party services before providing them with your personal information.
When you connect third-party services (such as Gmail) to our platform, you should review their privacy policies to understand how they collect, use, and share your information. You can revoke access to third-party integrations at any time through your account settings or the third party's settings.
Data Security
We take the security of your personal information seriously and implement comprehensive security measures to protect it. For detailed information about our security practices, please visit our Security Policy.
Key security measures include:
- AES-256 encryption for data at rest
- TLS 1.3 encryption for data in transit
- Secure authentication using bcrypt password hashing
- Regular security audits and monitoring
- Access controls and authorization checks
- Automated threat detection and prevention
While we implement strong security measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security but are committed to protecting your information using industry best practices.
Children's Privacy
Our Services are not intended for children under the age of 16, and we do not knowingly collect personal information from children under 16. If we become aware that we have collected personal information from a child under 16 without parental consent, we will take steps to delete that information as soon as possible.
If you believe we have collected information from a child under 16, please contact us at support@getnowadays.com.
International Data Transfers
Your information may be transferred to, stored, and processed in countries other than your country of residence, including the United States, where our servers and service providers are located. These countries may have data protection laws that differ from those in your country.
When we transfer personal information internationally, we implement appropriate safeguards to protect your information in accordance with this Privacy Policy and applicable data protection laws. For transfers from the EEA, UK, or Switzerland, we rely on:
- Standard Contractual Clauses approved by the European Commission
- Adequacy decisions by the European Commission
- Other legally approved transfer mechanisms
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will update the "Last updated" date at the top of this Privacy Policy.
If we make material changes to this Privacy Policy, we will notify you by email (to the email address associated with your account) or by posting a notice on our platform before the changes take effect. We encourage you to review this Privacy Policy periodically to stay informed about how we collect, use, and protect your information.
Your continued use of our Services after any changes to this Privacy Policy indicates your acceptance of the updated policy.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
- Email: support@getnowadays.com
- Security concerns: eng@nowadays.ai
We will respond to your inquiry within a reasonable timeframe. For data subject requests under GDPR or CCPA, we will respond within the timeframes required by applicable law (typically 30 days).
Data Protection Officer (for GDPR inquiries): For questions specifically related to GDPR compliance or to exercise your GDPR rights, you may contact us at the email addresses above with "GDPR Request" in the subject line.
