Introduction
At Creators of Ellie(“we”, “us”, or “our”), we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use Ellie, our AI-assisted wedding-planning platform and related services (collectively, the “Services”).
By accessing or using our Services, you agree to the terms of this Privacy Policy. If you do not agree with our policies and practices, please do not use our Services. This Privacy Policy should be read in conjunction with our Terms of Service.
Information we collect
1. Information you provide directly
- Account information — your name, email address, and authentication credentials, handled by our authentication provider (Supabase). We never store your password in plain text.
- Wedding information— details about your wedding, including the couple’s names, wedding date, location, guest count, budget, style and vendor preferences, and any notes you enter while planning.
- Sensitive preferences — some details you choose to share (for example, dietary requirements for catering or the style of ceremony you want) may reveal religious beliefs or health information in certain jurisdictions. We collect these only when you provide them and handle them with additional care.
- Files — documents or images you upload, such as inspiration photos, vendor quotes, or contracts.
- Vendor information — contact details and notes for vendors you add yourself, and the content of messages you approve for us to send.
- Communication data — information from your communications with us, including support requests and feedback.
- Payment information — when you make payments, our payment processor Stripe collects your payment card information. We do not store your complete payment card details on our servers.
2. Information we collect automatically
- Usage and log data — our servers record access times, pages viewed, IP addresses, and similar technical information needed to operate and secure the Services.
- Device information — device type, operating system, and browser type.
- Error and diagnostics data — we use Sentry to collect error reports so we can find and fix problems.
- Vendor communications — emails sent to vendors on your behalf and the replies we receive, so your planning history stays in one place.
3. Information from public sources
To suggest vendors for your wedding, we retrieve publicly available business listings — such as venue and vendor names, categories, locations, websites, and contact details — from sources including Google Places, Yelp, and OpenStreetMap. This is business contact information about wedding vendors, not information about you.
How we use your information
- Provide the Services — create and manage your account, build your wedding brief, source and match vendors, draft outreach, and — with your approval — send and manage vendor communications, quotes, and bookings on your behalf.
- AI-powered features — we use Anthropic Claude to draft vendor outreach, parse vendor replies and quotes, and suggest matches. Your data is not used to train AI models. Drafts are shown to you for approval before anything is sent.
- Process payments — process transactions, send receipts, and manage billing through Stripe.
- Communications — send you service-related emails such as vendor replies, quote updates, and account notifications, and respond to your inquiries.
- Improve the Services — understand how the Services are used, fix bugs, and improve features.
- Security — detect, prevent, and respond to fraud, unauthorized access, and other potentially harmful activity.
- Legal compliance — comply with legal obligations, respond to lawful requests, and enforce our Terms of Service.
Email sent on your behalf
A core function of the Services is contacting wedding vendors on your behalf. With your approval, we send emails that identify you as the couple and route replies back into your account. Every message includes an unsubscribe link; vendors who unsubscribe are suppressed from future sends.
How we share your information
We do not sell your personal information. We share your information only in the following limited circumstances:
1. Service providers
We share information with trusted third-party providers who process it on our behalf to deliver the Services:
- Supabase — database hosting and authentication for your account and wedding data.
- Anthropic (Claude) — AI features such as drafting outreach, parsing vendor replies, and suggesting matches. Your data is not used to train AI models.
- Stripe — secure payment processing.
- Resend — outbound email delivery.
- Postmark — inbound email processing for vendor replies.
- Cloudflare R2 — file storage for documents and images you upload.
- Google (Places), Yelp, and OpenStreetMap — vendor discovery and location services.
- Sentry — error monitoring and diagnostics.
- Upstash — Redis used for rate limiting. It briefly holds the IP address a request came from, so we can tell one visitor from another for abuse protection.
- Our hosting providers — application hosting and content delivery (currently Vercel and Fly.io).
These providers are required to protect your information and use it only for the purposes we specify.
2. Wedding vendors
When you use the Services to plan your wedding, we share relevant details with vendors to obtain quotes and facilitate bookings on your behalf. This includes information such as your wedding date, location, guest count, budget range for that vendor, and relevant preferences. Your direct contact details are shared with a vendor only when you confirm that vendor and the booking handoff takes place.
3. Legal requirements
We may disclose your information if required to do so by law or in response to valid legal processes (court orders, subpoenas, warrants), lawful requests from public authorities, or where necessary to protect our rights, property, or safety, or that of our users or the public, or to enforce our Terms of Service.
4. Business transfers
If we are involved in a merger, acquisition, sale of assets, or bankruptcy, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your personal information.
5. With your consent
We may share your information with other parties when you have given us explicit consent to do so — for example, when you invite a partner or collaborator to your wedding plan.
Data retention
- Account data — retained for as long as your account is active or as needed to provide the Services.
- Wedding and booking data — retained to maintain your planning history and for record-keeping related to quotes, bookings, and payments.
- After account deletion — when you delete your account, we delete or anonymize your data within a reasonable period, though we may retain certain information where required for legal compliance, dispute resolution, or enforcement of our agreements.
- Log data — access and security logs are retained for security monitoring and incident response.
Your privacy rights
Depending on your location, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete information.
- Delete your personal information, subject to certain legal exceptions.
- Export a copy of your information in a structured, machine-readable format.
- Object to or restrict certain processing of your information.
- Withdraw consent at any time where processing is based on consent.
Canada (PIPEDA and provincial law)
We comply with applicable Canadian privacy law, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and the British Columbia Personal Information Protection Act. You may request access to or correction of your personal information, and you may complain to the Office of the Privacy Commissioner of Canada or your provincial commissioner.
European users (GDPR)
If you are in the European Economic Area, United Kingdom, or Switzerland, you have the rights listed above under the GDPR. Our legal bases for processing are: performance of a contract (providing the Services), legitimate interests (improving the Services, security, fraud prevention), consent (where you have provided it), and legal obligations.
California users (CCPA)
If you are a California resident, you have the right to know what personal information we collect, use, and disclose; to request deletion; to opt out of the sale of personal information (we do not sell your information); and to non-discrimination for exercising these rights.
To exercise any of these rights, email us at hello@elliewed.com. We will respond within the timeframe required by applicable law (typically 30 days). You can also delete your account at any time from within the Services.
Cookies
We use cookies that are essential for the Services to function — primarily for authentication and security. We do not use advertising or cross-site tracking cookies. You can control cookies through your browser settings, but disabling essential cookies will prevent you from signing in.
Third-party links and services
The Services may contain links to vendor websites and other third-party services that are not operated by us. This Privacy Policy does not apply to those services, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party services before providing them with your personal information.
Data security
We implement industry-standard measures to protect your information, including:
- Encryption in transit (TLS) and at rest.
- Secure authentication through our identity provider.
- Row-level access controls on user data.
- Access controls and authorization checks throughout the Services.
- An audit trail of actions taken on your behalf.
No method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security, but we are committed to protecting your information using industry best practices.
Children’s privacy
The Services are not directed to anyone under 18, and we do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us at hello@elliewed.com and we will delete it.
International data transfers
Your information is stored and processed in the United States, not in Canada. That is true of essentially all of it, not an edge case: our database and file storage (Supabase, US West), our application servers (Fly.io, Los Angeles), our email providers (Resend and Postmark), our payment processor (Stripe), and the language model that drafts vendor messages (Anthropic) all operate in the United States.
One exception, stated so the paragraph above is exact: when you use the map to pick a location, the place name or postal code you type is sent to Nominatim — the OpenStreetMap Foundation’s geocoding service, hosted in Europe — to turn it into coordinates. That request is not stored there, and it carries no name, email, or account identifier; only the location text itself.
We say this plainly because the consequence is real rather than technical: while your information is held in the United States it is subject to the laws of that country, and may be accessible to US courts, law enforcement, and national security authorities under their legal processes — potentially without notice to you. Canadian privacy law permits this transfer but requires that you be told about it before you decide to use the service. We remain accountable for information we transfer and use contractual safeguards, but no contract overrides a foreign court order.
If you would prefer your wedding details not to leave Canada, this service cannot offer that today.
Who is accountable, and how to reach them
Canadian privacy law requires an organisation to designate a specific individual who is accountable for its compliance, and to make that person reachable. Ours is our Privacy Officer, contactable at hello@elliewed.comwith “Privacy” in the subject line. Naming a role rather than a person is deliberate — the role outlives any individual holding it — but a real person answers it.
How we handle requests:
- Access or correction. Write to the Privacy Officer. We respond within thirty (30) days, which is the deadline Canadian law sets. If we need an extension we will tell you within those thirty days, and why. If we refuse any part of a request we will tell you which part, the reason, and how to complain to the Office of the Privacy Commissioner of Canada.
- Deletion. See Data retention above. Some records — billing and audit trails — we are required to keep, and we will say so rather than quietly retaining them.
- If you are a wedding vendor and we hold your business contact details, you can ask us to delete them and to stop contacting you. See Vendors: where your details came from below.
If something goes wrong
If a breach of our security safeguards creates a real risk of significant harm to you, we will report it to the Office of the Privacy Commissioner of Canada and notify you as soon as feasible. We keep a record of every breach of security safeguards for at least twenty-four (24) months, whether or not it met the reporting threshold, and we will provide that record to the Commissioner on request.
Vendors: where your details came from
If you are a wedding vendor who received an email from us, you did not sign up for anything, and you are entitled to know how we got your address.
- Where it came from.Publicly listed business contact details, from OpenStreetMap, Google Places, Yelp, and vendors’ own published websites. We do not buy lists.
- Why we are allowed to hold it. Canadian privacy law treats business contact information — a name, title, work address, work phone, work email, collected and used solely to contact someone in a business capacity — differently from personal information, and the consent rules do not apply to it. That is the basis we rely on. It is a narrower basis than it sounds: if you are a sole proprietor whose business email is also your personal one, tell us and we will treat it as personal information.
- How to make it stop. Use the unsubscribe link in any message we sent you. It is honoured across every kind of email we send, not just the one you clicked from. You can also write to the Privacy Officer above and ask us to delete your record outright; we will do it and confirm.
- Attribution. Vendor data derived from OpenStreetMap is © OpenStreetMap contributors and available under the Open Database License. Map tiles are © OpenStreetMap contributors and © CARTO.
Automated drafting, and what the model sees
Ellie drafts vendor messages using a large language model operated by Anthropic(in the United States). To do that, the model receives the details needed to write the message: your names, your wedding date and region, your brief, and the vendor’s replies. Under our agreement with Anthropic, this content is not used to train their models.
Every message we send a vendor on your behalf says, in the message itself, that it was drafted by an automated assistant and sent under your name. We think a vendor is entitled to know that without having to ask, and you are entitled to know that we tell them.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date above. If we make material changes, we will notify you by email or by posting a notice in the Services before the changes take effect. Your continued use of the Services after changes take effect indicates your acceptance of the updated policy.
Contact us
If you have questions, concerns, or requests regarding this Privacy Policy, email us at hello@elliewed.com. The Services are operated by Creators of Ellie and governed by the laws of British Columbia, Canada. For GDPR-specific inquiries, include “GDPR Request” in the subject line.