LEGAL

Privacy Policy

Draft — last generated July 25, 2026

This is a draft prepared for attorney review — it is not final and has not been reviewed by a lawyer. In particular, the tasker document retention period, DPA status with Supabase/Stripe, and cookie-consent requirement are flagged below and need counsel input before this goes live.

1. Scope

This Privacy Policy explains what information Fever Dream Events ("Fever Dream," "we," "us") collects, how we use it, and the choices you have. It applies to the Fever Dream Events application and website, and covers planners, their clients, vendors, and taskers who use any part of the Service.

2. Information we collect

  • Account information: name, email, phone, password (encrypted), profile photo.
  • Event and business data: event details, guest lists, budgets, vendor information, contracts, vision boards, and any content you upload to plan an event.
  • Client and lead data: if you're a planner, information about your leads and clients that you or they enter into the Service (name, email, event details, messages, proposals, signed contracts).
  • Payment information: processed directly by Stripe. Fever Dream does not receive or store raw credit card numbers — see Section 9.
  • Tasker identity and tax documents: if you're a tasker, a signed work agreement, tax information (e.g. a W-9), a photo ID, and any certifications you choose to upload — see Section 6 for how this category is handled differently.
  • Messages: content sent through the Service's planner-client messaging feature.
  • AI-assisted feature inputs: if you use an AI-assisted feature (e.g. draft contract language, message summaries, vendor recommendations), the inputs and outputs of that feature may be processed as described in Section 5.
  • Usage and device data: pages visited, actions taken, browser/device type, and IP address, collected automatically to operate and secure the Service.

3. How we use information

  • To provide, maintain, and improve the Service.
  • To process payments and manage subscriptions.
  • To send transactional emails (contract activity, payment confirmations/failures, account notifications) and, if you've opted in, product updates.
  • To detect, prevent, and respond to fraud, abuse, and security incidents.
  • To comply with legal obligations, such as tax reporting related to payments facilitated through the Service.

4. Legal basis for processing (GDPR)

If you're in the European Economic Area or UK, we process your information under one or more of these legal bases: performance of a contract (providing the Service you signed up for), our legitimate interests (securing and improving the Service), your consent (e.g. marketing emails), and compliance with legal obligations. [Attorney note: confirm whether a formal Data Processing Agreement with Supabase and Stripe is needed, and whether Standard Contractual Clauses are required for any EU-resident users — see legal checklist, item 4. If Fever Dream doesn't intend to serve EU customers at launch, this can be scoped down accordingly.]

5. Who we share information with

  • Service providers: Supabase (database and authentication), Stripe (payments), Resend (transactional email), Unsplash and Canva (photo/design content you choose to use), and, if used, an AI provider for AI-assisted features. Each processes data on our behalf, only as needed to provide their part of the Service.
  • Other users, in context: if you're a planner, your client sees the proposal/contract/messages you send them. If you're a tasker, your documents are visible to any planner who accepts you onto their event — not the general public.
  • Legal and safety reasons: if required by law, subpoena, or to protect the rights, property, or safety of Fever Dream, our users, or the public.
  • Business transfers: if Fever Dream is involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction, subject to this Policy or a successor policy.

6. Tasker identity and tax documents — handled differently

Tasker profiles can include a W-9 (which contains a Social Security Number or EIN) and a photo government ID — more sensitive than the rest of the data in the Service. By submitting these documents, a tasker consents that they become visible to any planner who accepts them onto an event, not just the planner who first invited them. Taskers may request deletion of these specific documents at any time by emailing privacy@feverdreamapp.com.

[Attorney/product note: given the sensitivity of this category, we recommend this data eventually sit behind additional safeguards beyond the rest of the Service — separate encrypted storage, stricter role-based access, access/download audit logging, and automatic expiration after a defined inactivity period. These are recommended hardening steps, not yet confirmed as implemented; see legal checklist, item 14, before real W-9s/IDs are treated as fully launch-ready.]

7. Data retention

We keep your information for as long as your account is active, plus a reasonable period afterward to comply with legal, tax, and dispute-resolution obligations. As a general practice, intended (but not yet finalized) retention periods are:

  • Deleted account data: removed within 30–90 days of your deletion request, except where we're legally required to retain it longer.
  • Payment records: retained as required by tax and financial recordkeeping law — Stripe separately retains records under its own policies.
  • System and security logs: approximately 12 months.
  • Database backups: currently up to 7 days, per our hosting provider's backup retention.

[Attorney/founder note: these periods are drafted defaults, not yet finalized business decisions — confirm actual intended retention before publishing, particularly for payment records and tasker documents (Section 6).]

8. Your privacy rights

If you're a California resident (CCPA/CPRA): you have the right to know what personal information we've collected about you, request deletion of it, correct inaccurate information, and opt out of the "sale" or "sharing" of personal information. Fever Dream does not sell your personal information for money; under California's broad definition of "sale," we also do not share it with third parties for their own advertising purposes.

If you're in the EEA/UK (GDPR): you have the right to access, correct, delete, restrict, or port your personal data, and to object to certain processing.

To exercise any of these rights — including requesting an export of your account or event content — email privacy@feverdreamapp.com. We'll respond within the time required by applicable law.

9. Payment card security

We use Stripe, Inc. to process all payments. Fever Dream does not store, process, or have access to your raw credit card number — Stripe's hosted checkout and payment forms handle that directly. This keeps Fever Dream's PCI DSS compliance scope minimal (SAQ A). [Attorney note: confirm SAQ A applies once Stripe Connect is live — see legal checklist, item 5.]

10. Cookies and similar technologies

We currently use only essential cookies— the kind needed to keep you logged in and the Service functioning. We don't currently use analytics, functional, or marketing cookies. If that changes in the future, we'll update this section and ask for your consent where required by law before doing so. [Attorney note: confirm whether a cookie consent banner is required for your user base given current usage — see legal checklist, item 4.]

11. Data security

We maintain reasonable administrative, technical, and physical safeguards designed to protect your information, including encrypted connections in transit (HTTPS/TLS), encryption at rest provided by our database host, row-level database access controls, and regular database backups (currently retained up to 7 days). We don't currently hold formal certifications such as SOC 2, ISO 27001, or HIPAA, and we don't represent that we do.

No system is completely secure, and we can't guarantee absolute security, but we work to protect your data and will notify affected users as required by law in the event of a breach.

12. International data transfers

Fever Dream's infrastructure providers may process and store data in the United States and other countries. By using the Service, you consent to your information being transferred to and processed in these locations. [Attorney note: if Fever Dream serves EU/UK residents, Standard Contractual Clauses with relevant processors may be required — see legal checklist, item 4. If not currently targeting that market, this can remain a placeholder.]

13. Children’s privacy

The Service is intended for users 18 and older and is not directed to children under 13. We don't knowingly collect personal information from anyone under 13, consistent with the Children's Online Privacy Protection Act (COPPA). If we learn a minor has created an account, we'll take steps to remove it and the associated data.

14. Deleting your account

You can delete your account and associated data at any time from your account settings, or by emailing privacy@feverdreamapp.com if you don't see a self-service option yet. See Section 7 for how long some data may be retained afterward.

15. Changes to this Policy

We may update this Privacy Policy from time to time. If we make material changes, we'll notify you by email or in-app notice before they take effect.

16. Contact us

Questions about this Policy, or want to exercise a privacy right? Email privacy@feverdreamapp.com.