Legal

Privacy Policy.

Last revised: March 6, 2026

Your privacy is not a checkbox to us. This policy explains exactly what data we collect, why we collect it, and the firm commitments we make to protect it. We do not sell your personal information. We do not share it with advertisers. We use it only to operate and improve Vynue.

1.Introduction

Vynue, LLC (“Vynue,” “we,” “us,” or “our”) operates the Vynue platform — a marketplace that connects clients with live entertainment performers, experiential event staff, and curated experience providers for events and celebrations (the “Services”). This Privacy Policy describes how we handle personal information when you access or use our website, mobile applications, and all related services.

By using the Services you acknowledge that you have read, understood, and agree to the practices described in this policy. If you do not agree, please discontinue use of the Services.

This policy covers information collected through Vynue-operated channels only. It does not apply to third-party websites or services, even if linked from our platform.

2.Who We Are

Vynue is an online marketplace headquartered in the United States. We operate as a neutral platform and technology intermediary — we facilitate connections and transactions between clients and independent performers/venues. Performers and venue operators who list on Vynue are independent contractors, not employees or agents of Vynue.

For questions about this policy or your personal data, see Section 21 (Contact Us).

3.Age Requirement

Vynue is strictly for adults. You must be at least 18 years old to create an account or use any Services. Certain features or performer categories may carry a higher age threshold (21+) and will be indicated accordingly during onboarding.

We do not knowingly collect personal information from anyone under 18. If we discover that a user is under 18, we will immediately suspend the account and delete associated personal data. If you believe a minor has created an account, contact us immediately at privacy@vynue.com.

4.Information We Collect

We collect only the information necessary to provide, secure, and improve our Services. Below are the categories of personal information we may collect:

4.1 Account & Identity Information

  • Full name and display name / username
  • Email address and phone number
  • Date of birth or age attestation (for age verification)
  • Profile photographs and promotional media you upload
  • Bio, service descriptions, pricing, and tags
  • City, state, and general location (not precise GPS)
  • Social account connections (e.g., Google, if you sign up via OAuth)

4.2 Verification Information (Performers & Venues)

  • Government-issued ID documents (submitted for identity verification — stored encrypted and deleted after review)
  • Social media profile links used as trust signals
  • Professional references or credentials you voluntarily submit

4.3 Booking & Transaction Information

  • Booking details: date, time, duration, event type, guest count, location
  • Communication between parties related to a booking
  • Booking status, history, and payment records
  • Payment information — we do not store your full card number, CVV, or bank credentials. Card processing is handled by Stripe, Inc., a PCI-DSS Level 1 certified payment processor. Cryptocurrency payments are handled by Coinbase Commerce. We store only tokenized references and transaction identifiers.

4.4 User-Generated Content

  • Messages sent through our in-platform messaging system
  • Reviews and ratings submitted after completed bookings
  • Photos, videos, or promotional materials uploaded to your profile
  • Support tickets and correspondence with our team

4.5 Technical & Usage Data

  • IP address and approximate geolocation derived from it
  • Browser type, device type, and operating system
  • Pages visited, features used, and time spent on the platform
  • Referral source (how you found Vynue)
  • Error logs and crash reports

4.6 Information From Third Parties

  • If you sign in via Google OAuth, we receive your name, email, and profile photo from Google, subject to the permissions you grant.
  • We may receive limited information from payment processors to confirm transaction status.

5.How We Collect It

We collect information in three ways:

  1. Directly from you — when you register, complete onboarding, fill out your profile, make a booking, send a message, submit a review, or contact support.
  2. Automatically — as you navigate the platform, we collect technical and usage data through server logs, cookies, and similar technologies. See Section 10 for details.
  3. From third parties — from OAuth providers (Google) when you choose to sign in via those services, and from payment processors to confirm transaction status.

6.How We Use Your Information

We use the information we collect to:

  • Create and manage your account and authenticate your identity
  • Display your profile to other users of the platform
  • Facilitate bookings between clients and performers/venues
  • Process payments and send booking confirmations
  • Send transactional emails (booking confirmations, payment receipts, status updates, password resets)
  • Verify the identity and eligibility of performers and venues
  • Enforce our content standards and platform policies
  • Respond to support requests, disputes, and appeals
  • Detect, investigate, and prevent fraud, abuse, and illegal activity
  • Moderate user-uploaded content for compliance with our policies and applicable law
  • Analyze aggregate, anonymized usage trends to improve platform performance and user experience
  • Comply with legal obligations and respond to lawful government requests

We will only use your data for the purposes described above or for a purpose that is compatible with those stated at the time of collection. If we intend to use your data for a materially new purpose, we will notify you in advance and, where required by law, obtain your consent.

7.What We Never Do With Your Data

These are firm commitments, not aspirations. If this ever changes, we will notify you by email no less than 30 days in advance and provide you the right to delete your account before the change takes effect.
  • We do not sell your personal information. Ever. To anyone. For any price.
  • We do not share your data with advertisers or ad networks for targeted advertising purposes.
  • We do not use tracking pixels or third-party ad tags that share your behavior with advertising platforms.
  • We do not build behavioral profiles about you to sell to data brokers.
  • We do not use your identity verification documents for any purpose other than verifying your identity. ID documents are deleted from our systems after the review process is complete, regardless of outcome.
  • We do not read your private messages except where required by law, or when a specific message is reported by a party to the conversation for safety/abuse review.
  • We do not use your data to train AI models for commercial purposes external to Vynue. Our AI usage is limited to content moderation within the platform (see Section 9).

8.When We Share Information

We share personal information only in the limited circumstances described below. In all cases, sharing is governed by contractual obligations that prohibit recipients from using your data beyond the specified purpose.

8.1 With Other Users (As Required by the Service)

When you book a performer or venue, certain information is shared between the parties to facilitate the booking — such as your name, event date, location, and contact information. Performers' public profile information (name, photos, rates, reviews) is visible to all users. Clients' profiles are visible to performers when a booking request is made.

8.2 With Service Providers (Data Processors)

We use a limited set of trusted third-party service providers who process data on our behalf, under strict data processing agreements that prohibit them from using your data for their own purposes:

  • Supabase — database hosting and user authentication (PostgreSQL, encrypted at rest)
  • Stripe, Inc. — payment processing (PCI-DSS Level 1 certified)
  • Coinbase Commerce — cryptocurrency payment processing
  • Resend — transactional email delivery
  • OpenAI — image content moderation (submitted photos are analyzed and not stored by OpenAI for training under our enterprise agreement)
  • Vercel — platform hosting and edge network

8.3 Business Transfers

In the event of a merger, acquisition, or sale of substantially all assets, your personal information may be transferred as part of that transaction. We will notify you via email and provide an opportunity to delete your account before any such transfer takes effect.

8.4 Legal Compliance & Safety

We may disclose personal information when:

  • Required by applicable law, court order, or valid legal process
  • Necessary to comply with regulatory obligations
  • Required to detect, prevent, or address fraud, security, or safety issues
  • Necessary to protect the rights, property, or safety of Vynue, our users, or the public

Where legally permitted, we will notify you before disclosing your data in response to a government or legal request.

8.5 Aggregated & De-identified Data

We may share aggregated, anonymized data (e.g., “X% of bookings are for bachelorette parties”) that cannot reasonably be used to identify any individual. This type of data is not subject to the restrictions in this policy.

9.AI & Content Moderation

Vynue uses artificial intelligence tools solely for platform safety and content integrity. We are transparent about every use:

9.1 Photo Moderation

Profile photos and promotional images you upload are automatically analyzed by an AI image moderation system to detect content that violates our policies (e.g., non-consensual intimate imagery, content involving minors, or illegal material). This analysis occurs at upload time. The image is submitted to our content moderation provider and the result (approve / flag / reject) is returned. Images are not stored by our AI provider beyond the immediate analysis request under our service agreement.

9.2 No AI Profiling

We do not use AI to make automated decisions about users that produce significant legal or similarly significant effects without human review. Performer verification decisions, account suspensions, and dispute resolutions are reviewed by human staff.

9.3 No Training on Your Data

Your content, messages, and personal information are not used to train AI models for commercial purposes beyond Vynue's own internal safety tooling. We do not license your data to AI companies.

9.4 What AI Cannot Do

Our AI systems are prohibited from: tracking individuals across the internet, performing facial recognition for identification purposes, classifying users based on protected characteristics, or making employment or creditworthiness decisions.

10.Cookies & Tracking

We use a minimal set of cookies and similar technologies to operate the platform. We do not use third-party advertising cookies.

10.1 Essential Cookies

Required for the platform to function — managing your logged-in session, remembering authentication state, and maintaining security tokens. These cannot be disabled without breaking core functionality.

10.2 Performance Cookies

Used to understand how pages perform and to identify errors. Data collected is anonymous and aggregated. You may opt out by adjusting your browser settings.

10.3 What We Do NOT Use

  • Third-party advertising cookies or tracking pixels
  • Social media retargeting pixels (Facebook Pixel, Google Ads tags, etc.)
  • Cross-site behavioral tracking
  • Fingerprinting techniques

10.4 Managing Cookies

You can control cookies through your browser settings. Disabling essential cookies will impair your ability to log in and use core features.

11.Data Security

We design our security posture to exceed industry baseline standards, not merely to meet them.

We implement the following technical and organizational security measures:

  • Encryption in transit: All data transmitted between your browser and our servers uses TLS 1.2+ (HTTPS enforced everywhere).
  • Encryption at rest: Your personal data is stored in an encrypted database. Sensitive fields (e.g., verification documents) use additional application-level encryption.
  • Access controls: Internal access to personal data is role-based and limited to staff with a legitimate operational need. All access is logged and auditable.
  • PCI-DSS compliance: Payment data is processed by Stripe (PCI-DSS Level 1). We never store full card numbers, CVV codes, or unencrypted financial credentials on our servers.
  • Rate limiting: Authentication endpoints are rate-limited by IP to prevent brute-force attacks.
  • Security headers: Our application enforces strict security headers including Content-Security-Policy, X-Frame-Options, X-XSS-Protection, and HSTS.
  • Breach notification: In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected users within 72 hours of becoming aware, in compliance with applicable breach notification laws.
  • Vendor security: Third-party service providers are evaluated for security practices before engagement and operate under contractual data processing agreements.

While we implement robust security measures, no system is completely immune to breach. We encourage you to use a strong, unique password and to enable any multi-factor authentication options we offer.

12.Data Retention

We retain personal information only as long as necessary for the purposes described in this policy, or as required by applicable law. Our general retention standards:

  • Active accounts: Retained for the life of the account.
  • Deleted accounts: Personal identifiers are deleted or anonymized within 30 days of a verified deletion request, except where retention is required by law (e.g., tax records, fraud prevention).
  • Booking records: Retained for 7 years for financial, tax, and legal compliance purposes, but personal identifiers are removed after 2 years where possible.
  • Identity verification documents: Deleted within 30 days of the completion of the verification review, regardless of outcome.
  • Messages: Retained while the relevant booking or conversation is active. You may request deletion of messages that do not relate to an open dispute.
  • Server/access logs: Retained for up to 90 days for security and debugging purposes, then deleted.

13.Your Rights

Regardless of where you live, Vynue honors the following rights for all users:

  • Right to Access: Request a copy of the personal information we hold about you.
  • Right to Correction: Request that we correct inaccurate or incomplete personal information. Most profile information can be corrected directly in your account settings.
  • Right to Deletion: Request deletion of your personal data. We will comply within 30 days, subject to retention obligations required by law (tax records, fraud prevention, active dispute resolution).
  • Right to Data Portability: Request an export of your personal data in a machine-readable format (JSON or CSV).
  • Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
  • Right to Opt Out of Marketing: Unsubscribe from promotional emails at any time via the unsubscribe link in any email, or by updating your notification preferences in your account settings. Transactional emails (booking confirmations, receipts, security alerts) cannot be disabled.
  • Right to Non-Discrimination: We will never deny you service, charge you different rates, or provide a degraded experience because you exercised any of your privacy rights.

To exercise any of these rights, email us at privacy@vynue.com with “Privacy Request” in the subject line. We will verify your identity and respond within 30 days. If we need more time, we will inform you within the initial 30-day period.

14.Children Under 18

Vynue is an adult platform. Our Services are not directed at, and we do not knowingly collect personal information from, anyone under 18 years of age. We take age verification seriously and enforce age attestation during onboarding.

If you are a parent or guardian and believe your child under 18 has created an account, contact us immediately at privacy@vynue.com. We will investigate and, if confirmed, delete the account and all associated personal data promptly.

15.User-Generated Content

Content you post publicly on Vynue — including profile descriptions, photos, videos, and reviews — may be visible to other users. You are responsible for what you choose to share publicly. Do not include sensitive personal information (financial details, government ID numbers, precise home address) in public profile fields.

Private messages sent through our platform are encrypted in transit and not displayed to third parties except as described in Section 8.4 (legal compliance) or when content is reported and reviewed by our moderation team for safety purposes.

Once a review is posted and made public (after the applicable hold period), it may remain visible even if a user requests account deletion, as it forms part of the booking record and other user's experience. Reviewed names may be anonymized upon a deletion request.

17.International Users

Vynue is based in the United States, and our servers are located in the US. If you access our Services from outside the United States, your personal information will be transferred to and processed in the US, which may have different data protection laws than your home country.

By using our Services, you consent to this transfer. We apply the protections described in this policy regardless of where you are located. If you are located in the EU/EEA or UK and have concerns about cross-border transfers, please contact us at privacy@vynue.com.

18.California Residents (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you additional rights regarding your personal information.

Categories of Personal Information Collected

As described in Section 4, we collect identifiers, commercial information, internet or electronic network activity, and audio/visual information (photos/videos you upload). We do not collect Social Security Numbers.

Selling & Sharing

We do not sell your personal information as defined under the CCPA. We do not share your personal information with third parties for cross-context behavioral advertising.

California Consumer Rights

  • Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected about you over the past 12 months.
  • Right to Delete: Request deletion of your personal information, subject to certain legal exceptions.
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Opt Out of Sale/Sharing: We do not sell or share for advertising — this right is already honored by default.
  • Right to Limit Sensitive Personal Information: We do not use sensitive personal information beyond what is necessary to provide the Services.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.

To exercise California rights, email privacy@vynue.com or use the contact form on our website. We will respond within 45 days. We may need to verify your identity before processing your request. You may designate an authorized agent to make requests on your behalf with written authorization.

Retention

See Section 12 for our data retention schedule.

19.Other State Privacy Rights

Residents of Colorado, Connecticut, Virginia, Texas, and other states with comprehensive privacy laws may have rights similar to those described in Section 13 and Section 18, including rights to access, correct, delete, and port their personal data, and to opt out of targeted advertising and profiling.

As stated in Section 7, we do not sell personal data or engage in targeted advertising, so opt-out rights related to those activities are honored by default for all users. To exercise any other state-specific rights, contact us at privacy@vynue.com. We will respond within the timeframe required by your jurisdiction's applicable law.

Right to Appeal: If we decline your privacy request, you may appeal by replying to our decision email with “Privacy Appeal” in the subject line. We will respond within 60 days. If your appeal is denied, you may contact your state's Attorney General.

20.Changes to This Policy

We may update this Privacy Policy from time to time. When we do:

  • We will update the “Last revised” date at the top of this page.
  • For material changes — changes that expand how we collect, use, or share data — we will email you at least 30 days before the changes take effect, and we will provide the option to delete your account before they apply.
  • For non-material changes (clarifications, typo corrections, formatting), the updated policy will take effect upon posting.

Your continued use of the Services after material changes take effect constitutes acceptance of the updated policy.

21.Contact Us

For questions, concerns, or requests related to this Privacy Policy or your personal data, please contact us:

Vynue Privacy Team

Email: privacy@vynue.com

General Support: support@vynue.com

We aim to respond to all privacy inquiries within 5 business days.

This Privacy Policy was last revised on March 6, 2026. Previous versions are available upon request.