Foreverly Privacy Policy
Last Updated: August 13, 2026
This policy explains what we collect, why, who we hand it to, and what you can do about any of it. We have tried to write it in plain English rather than legal fog, because a policy nobody can read is not really a disclosure.
1. Who We Are
Foreverly is operated by Foreverly, LLC, a Minnesota limited liability company. We run foreverlyweddings.com, the wedding planning tools on it, the dashboards venues and vendors use, and the booking widgets some venues embed on their own websites. When this policy says "we" or "Foreverly," that is who it means.
For anything in this policy, write to [email protected].
We serve couples and wedding businesses in the United States. Venues and vendors are the ones who set their own prices and policies. Any agreement for actual wedding services is between you and them, not us.
2. What We Collect
Information you give us
- Account details: your name, your partner's name, email address, phone number, and a password (stored hashed, never in readable form).
- Wedding details: your wedding date or date flexibility, guest count, budget range, the city and area you are searching, your planning stage, and which vendor categories you still need.
- What you send to venues and vendors: inquiry messages, tour requests, notes, and anything you type into a chat with a venue or with our assistant.
- Plans and estimates: the spaces, food, bar, vendors and amenities you select, and the totals we calculate from them.
- Payment details: handled by Stripe. We never see or store your full card number. We keep the customer and payment identifiers Stripe gives back to us.
- Wedding website and stationery content: photos, text, your guest list, and anything else you upload.
Information we collect automatically
- Device and connection: IP address, browser, operating system, device type, and user agent.
- Usage: pages viewed, clicks, scrolls, how far you get through the wedding builder, how long steps take, and which venues you look at.
- Approximate location: we look up your IP address to guess your city so search results are not useless on your first visit. We round the coordinates to roughly 11 kilometers and store the result in a cookie for 24 hours. This is not precise location, and we do not collect GPS location.
- Session recordings: see section 6, which covers this in detail.
- Where you came from: referring page, landing page, UTM tags, and ad click identifiers such as Meta's fbclid. We attach these to inquiries and tour bookings so we can tell which marketing actually worked.
- Cookies and similar technologies: covered in our Cookie Policy.
Information about wedding businesses
We also build and maintain business contact records for venues and vendors, including ones that have never signed up. That information comes from public websites and business listings, gathered with third-party research tools, and we use it to reach out about listing on Foreverly. If you run one of those businesses and want your record removed, email us and we will remove it.
3. How We Use It
- Running the service: creating your account, saving your plans and estimates, booking tours, and passing your inquiry to the venue or vendor you contacted.
- Pricing: calculating estimates from the pricing each venue and vendor has configured.
- Ranking and recommendations: deciding which venues to show you and in what order. See section 4.
- Communicating with you: confirmations, reminders, replies, security notices, and marketing you have opted into.
- Improving the product: understanding where people get stuck, which is what the analytics and session recording in sections 6 and 9 are for.
- Marketing: measuring our ads and reaching people who might want the product. See section 9.
- Safety and fraud: reCAPTCHA on forms, rate limiting, abuse detection, and audit logs.
- Legal: meeting our obligations, enforcing our terms, and defending claims.
4. Automated Decisions and Profiling
Some of what you see is decided by software rather than a person. We think you should know which parts:
- Venue ranking. We order search results using how well a venue fits what you told us (date, guest count, budget, location) alongside signals about the venue itself, such as how complete its profile is and how responsive it has been to other couples.
- Instant estimates. We pick sensible defaults for spaces, food, bar and vendors based on your date and guest count, then price them from the venue's own settings.
- Lead scoring. On the business side, we score and prioritize inquiries for venues so they know which to answer first.
- Email classification. For venues that connect their inbox to our CRM, software reads incoming email to sort it and pull out details like a wedding date or guest count.
None of this decides anything with a legal or similarly significant effect on you. It does not set your price, and it does not decide whether a venue will work with you. If you want to know how a particular result was reached, or you think it relied on something inaccurate, email [email protected] and we will explain it, correct the underlying data, and re-run it.
5. AI Features
Several features send your content to an AI model to generate a response. The features that do this today:
- Our planning assistant and the chat on venue and vendor pages
- Budget insights and planning checklists
- Wedding website generation and editing
- Stationery and invitation copy
- Venue and vendor profile autofill, which reads a business's own public website
- For venues that connect a mailbox to our CRM, classifying incoming email and drafting suggested replies
We use OpenAI and Anthropic as model providers, and Not Diamond to route some requests to the right model. What you type into those features, along with the context we send with it, goes to those providers. OpenAI and Anthropic do not train their models on data sent through their business APIs, which is how we use them.
We keep the conversation so you can come back to it and so we can debug problems. Please do not put anything into an AI feature that you would not want stored, including payment details or anything sensitive about your health.
When you are talking to our assistant rather than a person, we tell you so.
6. Session Recording
We record browsing sessions on our website. A session recording is a replay of what happened in your browser: pages you moved between, where you clicked, where you scrolled, and where you hesitated. We use it to find the places the product is confusing or broken.
We use three providers for this: PostHog (product analytics and replay), Contentsquare (experience analytics and replay), and Sentry (error monitoring, which records a sample of sessions and the sessions where something crashed).
What is masked. Text you type into form fields is masked before it leaves your browser, so recordings do not contain what you typed into an input box. Passwords and payment fields are never captured, and payment details are entered on Stripe's own form rather than ours.
What is not. Recordings still capture what the page displays. If a screen shows your name or your email back to you, that appears in the replay. If you are signed in, the recording is linked to your account.
Session recording is on by default. You can turn it off at any time from Your Privacy Choices, and it stops immediately, without a reload.
8. Venue Introductions and Contact Unlocks
This is the part most platforms are vague about, so we will be specific.
When you send an inquiry, request a tour, or save a plan for a venue, that business sees your first and last name, your wedding date, your guest count, your estimated budget, and the message you wrote. That happens immediately and at no cost to them.
Your email address and phone number are held back. A venue reveals them by spending credits, which they buy from us. Once a venue unlocks a couple, it can see that couple's contact details across its inquiries, messages and tours from then on.
So: we do not sell lists of couples, we do not rent your information to advertisers or data brokers, and no business can buy its way to your contact details without you having contacted it first. But money does change hands at the point a business unlocks your email and phone, and we would rather say that plainly than hide behind a narrow definition.
You can stop this. Visit Your Privacy Choices to opt out of having your contact details released to businesses, or email [email protected]. Opting out means venues will not be able to call or email you directly, so you would need to keep the conversation inside Foreverly.
Businesses that have not signed up yet. Some venue profiles are built from public information before the venue itself has joined. If you contact one of those, we still pass your inquiry on, with your contact details, to the business email address we have on file for them, so they can actually reply to you. That address comes from their own public listing. If you would rather we did not do that, opt out at Your Privacy Choices before you send an inquiry.
Venues and vendors are separate businesses. Once they have your details, their own privacy practices apply to what they do with them.
9. Advertising and Analytics
We advertise on Meta's platforms, which means Facebook and Instagram. Two things send information to Meta:
- The Meta Pixel runs in your browser and reports page views and actions, along with cookie identifiers and your IP address.
- The Conversions API reports the same kinds of events from our servers. When it reports a lead or a booking, it sends your email address, phone number and name hashed, meaning scrambled so Meta can match you to an existing account without receiving them in readable form. Your IP address and browser identifiers go unhashed, which is how Meta's system requires it.
Some venues run their own Meta pixel on their Foreverly profile or embedded booking widget. When they do, the same kind of event data goes to that venue's advertising account as well as ours.
Under several state privacy laws this counts as "sharing" personal information for cross-context behavioral advertising. It is on by default, and you can turn it off at any time from Your Privacy Choices. That stops both the browser pixel and the server-side events.
We honor Global Privacy Control. If your browser or an extension sends a GPC signal, we treat it as an opt out of selling and sharing and switch advertising off for that browser automatically. You do not need to do anything else. GPC is an advertising signal, so it does not by itself turn off our own product analytics or session recording, which have their own switches on the same page.
10. SMS, Email and Calls
Text messages
If you give us your phone number and opt in, we may text you tour confirmations and reminders, updates about a scheduled tour, account security codes, and replies from our support team.
- We use Twilio to send text messages.
- Your phone number will not be sold or shared with third parties for their marketing.
- Message frequency varies based on your bookings and account activity.
- Standard message and data rates may apply.
- Reply STOP to any message to opt out, or HELP for help. You can also email [email protected].
- Consent to receive texts is not required to use Foreverly and is not a condition of any purchase.
Transactional email, such as a tour confirmation or a password reset, is part of the service and is not marketing. Marketing email always includes an unsubscribe link, and unsubscribing from marketing does not stop transactional messages you actually need.
Calls
Calls with our sales and support team may be recorded for training and quality. If a call is being recorded, you will be told at the start of the call and you can ask us not to record it. Venues that connect their own phone line to our CRM control their own recording settings.
11. Guest and Recipient Data
If you build a wedding website or order stationery with us, you give us information about people who are not our users: your guests. That can include their names, email addresses, phone numbers, mailing addresses, RSVP responses, meal choices, and dietary restrictions.
We use that information only to run your wedding website and to print and mail what you ordered. We do not market to your guests, and we do not add them to any list. Mailing addresses go to Gelato, our print and fulfillment partner, so envelopes can be addressed and posted.
You are responsible for having a reason to hold your guests' details. If a guest contacts us directly about their information, we will point them to you, and we will help you remove it.
12. Security and Retention
We encrypt data in transit and at rest, hash passwords, restrict internal access to what each person needs, encrypt the mailbox and phone credentials venues connect to us, and keep audit logs of sensitive actions. No system is perfectly secure, and we will not pretend otherwise.
How long we keep things:
- Account and wedding data: for as long as your account is open, and afterwards until you ask us to delete it.
- Inquiries, tours and messages: kept as business records for both you and the venue, since either side may need to refer back to what was agreed.
- Saved estimates and drafts: unclaimed drafts are marked expired 30 days after they are created.
- CRM activity logs: deleted automatically after 90 days.
- Session recordings and analytics: kept according to each provider's retention setting, generally no more than a year.
- Payment and tax records: kept as long as tax and accounting rules require.
Where we do not yet delete something on a fixed schedule, we delete it when you ask. Section 13 explains how.
13. Your Rights
Wherever you live, you can ask us to:
- Show you what we hold about you
- Correct anything wrong
- Delete your information and close your account
- Send you a copy in a portable format
- Tell you the specific companies we shared your information with
- Stop advertising sharing, session recording, contact unlocks, or marketing messages
- Explain an automated result and re-run it on corrected data
Email [email protected] or use our privacy request form. We will verify it is really you, usually by confirming control of the email address on the account, and respond within 45 days. If we need longer we will tell you why. There is no charge, and we will not treat you differently for asking. An authorized agent can make a request on your behalf with written permission.
If we say no. You can appeal. Reply to our decision, or email [email protected] with "Appeal" in the subject line. A different person will review it and we will write back within 45 days with our reasoning. If we still say no, we will tell you how to complain to your state attorney general.
One limit worth flagging: if you asked us to introduce you to a venue, we cannot claw back what that venue already received. Deleting your Foreverly account does not delete you from their records. You would need to contact them directly, and we will help you do it.
14. State Privacy Rights
Several states give residents specific privacy rights. Rather than run a different policy per state, we give everyone the rights in section 13, which covers what those laws require. A few state-specific notes:
- California. You have the right to know, delete, correct, and opt out of the sale or sharing of personal information, and not to be discriminated against for exercising them. We share personal information for cross-context behavioral advertising as described in section 9, and you can opt out at Your Privacy Choices. We honor Global Privacy Control. We do not knowingly sell or share the personal information of anyone under 16.
- Minnesota. On top of the above, you can ask for a list of the specific third parties we disclosed your personal data to, and you can question the result of profiling, ask us to explain it, correct the data behind it, and have it re-run. Section 4 covers where we profile.
- Texas. We do not sell sensitive personal data or biometric data.
- Colorado, Connecticut, and other states with comprehensive privacy laws. The same rights and the same opt-out mechanisms apply, including universal opt-out signals.
- Nevada. You may tell us not to sell your covered information by emailing us.
We do not process sensitive personal information for the purpose of inferring characteristics about you, and we do not use it for advertising.
15. Children's Privacy
Foreverly is for adults planning a wedding. Our services are not directed to anyone under 18, and you must be 18 to create an account. We do not knowingly collect personal information from children under 13, and if we learn we have, we delete it. If you believe a child has given us information, email [email protected] and we will remove it.
Guest lists on a wedding website may include children as invitees. That information comes from you, not from them, and we use it only to manage your RSVPs and mailing.
16. Where Your Data Lives
Foreverly is built for the United States, and our databases, file storage and servers are hosted in the United States on Google Cloud.
One exception worth naming: if you order printed stationery, the names and mailing addresses needed to print and post it go to Gelato, whose fulfillment infrastructure includes facilities in the European Union. Some of our other providers also operate globally and may process data outside the United States as part of running their service.
We are not currently set up for GDPR, and we do not target the EU or UK. If you are in Europe and have used Foreverly, email us and we will delete your information.
17. Changes and Contact
We will update this policy as the product changes. When we change something material, we will update the date at the top and email account holders before it takes effect. Smaller corrections are posted here without notice.