How we handle your information
Privacy.
A plain-language account of what we collect, what we do with it, and what we will never do with it. We hold information the way an atelier holds a measured fitting — with care, and only what is needed.
On this page
What we collect
We collect only the information needed to operate the atelier on your behalf. In practice:
- What you give us at the studio account: the name and email of each person on your studio, your billing details (held by our payment processor, not by us), and your studio's brand inputs (color palette, wordmark, optional logo file).
- What you put inside the dashboard: wedding records, couple contacts, vendor research, dossiers, notes, and any other content you create or upload. This is your work product and is held under your studio's name.
- What your couples enter: intake questionnaire answers, dates, guest counts, budgets, vendor preferences, and any photographs or files they choose to attach to their portal.
- Routine server logs: IP address, timestamp, page or endpoint accessed, browser user-agent. Logs are written by our hosting infrastructure and used for operational diagnostics and security.
We do not collect special-category information (health, genetic, biometric, religion, political views). If a couple voluntarily places such information in a portal field — for instance, a dietary or accessibility note — it is held under your studio's account and never used by us for any secondary purpose.
How we use it
We use the information you give us to operate the atelier, to communicate with you, and to keep the service safe. Specifically:
- To run the service: render your dashboard, send your couples their portals, generate dossiers when you request them, accept payment.
- To communicate: answer your application, send the occasional product update, send transactional messages (magic-link sign-ins, receipts, account notices). You may opt out of product updates at any time; transactional messages are required for the account to function.
- To keep the service safe: detect abuse, rate-limit suspicious traffic, investigate incidents.
We do not sell or rent your information. We do not run advertising on this site. We do not use your dashboard content, your couples' portal content, or any data you place in the service to train any machine-learning model. When we use AI to generate a dossier on your behalf, your search inputs are passed to the underlying provider only for that request and are not retained by us beyond the dossier itself.
Cookies & tracking
We use only the cookies the service requires to function. At present that is:
- A session cookie set after you sign in, used to keep you signed in across pages. Expires when you sign out.
- A CSRF token cookie used to verify that form submissions come from you. Expires with the session.
- Edge cookies set by our delivery provider (Cloudflare) for security and performance.
This marketing site (peonyandlace.com) runs no analytics, no behavioral cookies, no advertising trackers, and no fingerprinting. The application (app.peonyandlace.com) runs the operational cookies above. If we later add product analytics inside the app, we will document the tool, document what is collected, and update this page in advance.
Your couples' data
This is the part we take most seriously. When a couple completes their intake inside a portal, the information they provide is yours. It is held under your studio's tenant in our database. We process it on your behalf, under your direction, in service of the wedding you are planning for them.
Specifically, your couples' data:
- is never sold or shared with anyone outside your studio without your direction;
- is never used to train any model, ours or anyone else's;
- is never aggregated across studios to produce market reports, lead lists, or any other commercial product;
- is exportable on request — yours, the couple's, or both — without friction.
If a couple writes to us directly asking for their data or its deletion, we will route the request to you (the studio responsible for them) within seven days. You are the data controller for your couples' information; we are the data processor.
How long we keep it
- Active studio accounts: we retain your dashboard content for as long as the account is active, plus archival snapshots for disaster recovery.
- Cancelled studio accounts: 90-day grace window during which your data is still retrievable on request. After the grace window, the account and its tenant data are deleted within thirty days, except where retention is required by law (for example, tax records of payments made).
- Couples' portal data: retained for the life of the studio account that hosts it. Couples may request deletion of their portal at any time by writing to [email protected]; we will route the request to the responsible studio.
- Server logs: 30 days, then deleted.
- Billing records: 7 years, as required by U.S. tax practice.
Who else touches it
We use a small number of third-party providers to operate the atelier. Each one is bound by its own privacy commitments and processes data only on our instructions. As of the date of this page, the list is:
- Stripe — payment processing (US). We never see or store your full card number; Stripe handles that. stripe.com/privacy
- Resend — transactional email delivery (US). Used for magic-link sign-ins, receipts, and product notices. resend.com/legal/privacy-policy
- Cloudflare — delivery, TLS termination, edge security (US). cloudflare.com/privacypolicy
- Anthropic — AI inference for dossier generation (US). Your search inputs are passed for the request only and are not retained for training under our terms with Anthropic. anthropic.com/legal/privacy
If we add, remove, or replace a subprocessor, we will update this list and email subscribers at least fourteen days before the change takes effect.
If you are outside the United States
Peony & Lace is operated from Colorado by a single U.S. limited liability company. Our infrastructure is hosted in the United States. If you access the service from outside the United States, your information will be transferred to and processed in the United States.
If you are in the European Economic Area, the United Kingdom, or Switzerland, we will treat your information as if the General Data Protection Regulation applied to it — that is, we will honor your rights of access, correction, deletion, restriction, portability, and objection on the same terms described below, and we will respond to data-subject requests within thirty days.
Your rights
You may at any time:
- request a copy of the information we hold about you;
- request correction of anything that is wrong;
- request deletion (subject to legal retention windows above);
- export your dashboard data in machine-readable form;
- withdraw consent for product update emails (transactional email cannot be withdrawn while you have an account);
- ask any other question about your information.
Write to [email protected]. We respond by hand, within seven days. There is no fee.
How we keep it safe
We hold your information using engineering practices appropriate to a small atelier handling sensitive client data: encrypted-in-transit connections (TLS), per-tenant isolation in the database with row-level enforcement, short-lived magic-link authentication, signed session cookies, and routine offsite backups. We do not promise that any system is unbreakable; we do promise to operate ours carefully and to tell you, by email, of any incident that meaningfully affects your studio within seventy-two hours of discovery.
Contact & changes
Privacy questions, requests, and complaints go to [email protected]. The responsible party is Ellis Intelligence LLC, a single-member Colorado limited liability company doing business as Peony & Lace.
We may update this page. If we do, we will email subscribers at least fourteen days before any change takes effect. The current version and effective date are recorded at the bottom of the page.