Legal
What we collect, who it goes to, and what we never do with it. Written to be read, not to be survived.
Last updated: 13 August 2026
This distinction runs through everything below, so it comes first.
For vendors' own account data — your email, business name, subscription — Celestial Collective is the controller. We decide what to collect and we answer for it.
For everything a vendor enters about their clients — the couples, the guest lists, the contracts, the photographs — the vendor is the controller and we are the processor. We hold and process that information on their instruction. If you are a couple or a guest and want your information corrected or removed, the fastest route is the vendor you are working with. You can also contact us and we will help.
Your name and email address (needed to have an account at all), your business name, phone, business address and public profile, your trades and service area, and your subscription status. If you connect Stripe to take payment, we store the connection — not your bank details, which stay with Stripe.
Names, email addresses and phone numbers; event dates, venues and addresses; budgets, quotes, contracts and invoices; questionnaire answers, notes and messages; running orders; and, where relevant to the job, guest lists — names, party size, RSVP status and meal choices — plus song requests, shot lists and photographs.
Some of those people never signed up for anything. A wedding guest whose name is on a seating chart has no account here and did not choose us. We treat that information as belonging to the couple and their vendor, we do not build profiles from it, we do not market to it, and we do not use it to train anything.
Your names and email address, your wedding date, your venue and town, and your budget. Everything you build in the planner: your checklist and tasks, your guest list and their replies, the suppliers you are considering and the ones you have booked, what you have paid them, your running order, your seating chart, your music list and your wedding website. Messages you write to a supplier reach that business, because that is what a message is for.
Your guest list is other people's information, and the same rule applies to it as to a vendor's client records above: we treat it as belonging to you, we do not build profiles from it, we do not market to it, and we do not use it to train anything.
If you allow notifications, we store a push token — an identifier for that one installation of the app, issued by Expo, which is what lets a notification reach that device and no other. It is removed when you sign out. Inside the app you can switch off any individual kind of notification, and anything switched off still appears in the app's own list, so turning them off costs you the interruption and never the information.
The app also sends your device's time zone — the name of it, such as America/Chicago, and not your location. It is used for one thing: so that we do not send you a notification in the middle of your night. The apps ask for no location permission and read no location.
Contracts, invoices and questionnaires open at a private link with no account. We record what you submitted and, for signatures, that the signature happened — because a contract nobody can prove was signed is not a contract.
Ordinary server logs, and error reports when something breaks. We use cookies and local storage only to keep you signed in and to remember interface preferences. There are no advertising or analytics cookies, because there is no advertising or analytics.
Polaris, our assistant, answers questions about your own work. To do that it sends a bounded snapshot of your data to Anthropic, which runs the model. That is a real disclosure and it deserves specifics rather than a shrug.
What goes: your business name and trade; your upcoming events; running orders; open tasks; contract numbers, statuses and totals; your price list; and open enquiries. When you ask about one specific event, it also sends that event's song requests, do-not-play list, shot list and the contacts for that job.
Guests are counted, not listed. Polaris receives head counts and meal tallies — not five hundred names. That was a deliberate decision, not an accident of implementation.
What never goes: another vendor's anything. Polaris reads using your own credentials, so the database refuses it exactly what it refuses you. No instruction typed into it can widen that.
Anthropic processes this to return an answer. Under our arrangement with them, your content is not used to train their models. If you would rather no data went to a model at all, do not use Polaris — every other part of the product works without it.
Only the companies that make the product run. Each gets the minimum needed to do its job, and none of them may use it for their own purposes.
The database, sign-in, file storage and server functions. Effectively all stored data lives here.
Hosts this website and the web app.
Payments and subscriptions. Checkout is hosted by Stripe — card numbers never reach our servers.
Runs Polaris. See the section above for precisely what it receives.
Sends transactional email — the contract to sign, the invoice, the reminder.
Only if you connect it. We request permission to send mail as you and to read and write calendar events, so bookings appear in your calendar and your real availability is respected. We do not read your inbox.
Separately, and without connecting anything: when you look up an address, or search for a supplier who is not on Celestial, that search term and the town you are searching in go to Google Places. Nothing identifying you goes with it.
The weather forecast a vendor sees against a booking. What is sent is the venue's town, and the coordinates that town centre resolves to rounded to about a kilometre — never a device location, and with no account, token or identifier attached. For a date more than about a fortnight away, nothing is sent at all.
Only if you connect it, and only for DJs building playlists.
Builds and distributes the Polaris mobile apps, and relays their push notifications. A notification passes through Expo to Apple or Google and then to your device, carrying the same sentence you would read in the app.
We will also disclose information if the law requires it. If that ever happens and we are permitted to tell you, we will.
We do not sell personal information, and we do not share it for cross-context behavioural advertising — under the CCPA's definitions or anyone else's.
Connecting a Google account is optional. If you do, Celestial Collective requests only the four permissions below, and uses each one only as described.
gmail.send
Sends the contracts, invoices, reminders and client messages you compose or approve, from your own address. This permission is send-only: we cannot read, search, list or modify anything in your mailbox, and we do not request a permission that would let us.
calendar.readonly
Reads the events already on your calendar so the app can show your true availability and warn you before you accept a date that conflicts with something booked elsewhere.
calendar.events
Creates a calendar event when you confirm a booking, and updates or removes it when the booking is rescheduled or cancelled — so you are not keeping two systems in step by hand.
calendar.app.created
Creates and manages a dedicated Celestial calendar for your bookings, so they stay out of your personal one. We ask for this because it is narrower: it confines what the app creates to a calendar you can hide, share or delete on its own.
We store the resulting access and refresh tokens encrypted, solely to keep these integrations running. We do not sell Google user data, use it for advertising, or use it to train AI models. Human access is limited to what is necessary for support you have asked for, a security investigation, or compliance with the law.
You can disconnect at any time inside the app, or revoke access directly at myaccount.google.com/permissions. Revoking deletes the tokens we hold.
Celestial Collective's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
A vendor CRM operated by a company that also books weddings has an obvious question hanging over it, so here is the plain answer.
Every query the application makes runs as the signed-in vendor, and the isolation is enforced in the database one layer beneath the application. There is no code path — and no assistant prompt — that reaches another vendor's rows. Celestial Celebrations cannot see another vendor's book of business through this platform.
The couples' planning app runs on a separate database entirely. Data crosses between them only where a couple has explicitly linked their planning to a vendor's event.
Account and client records are kept while the account is open, because a vendor needs last year's contracts.
Client-facing links expire: portal logins end 30 days after the event.
You can delete your account yourself, from inside the Polaris app: Account → Delete my account. It happens immediately — there is no waiting period, nothing to approve at our end, and no archived copy we can restore for you afterwards.
Your login, profile, leads, tasks, contracts, messages, designs and uploads go with it. What stays is the record of events you worked — the running order and any notes — with your name removed, because that belongs to the couple who booked the day rather than to you. A couple should not lose the timeline of their own wedding because a supplier closed an account.
The full steps, and exactly what is deleted and what is kept. If you cannot get into the app, email andrew@celestial-celebrations.com from the address on the account and we will do it for you.
Wherever you live, you can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, or object to how we use it. If you are in the UK, EU, California or another place with specific privacy law, those rights are yours by statute and we will honour them without making it difficult.
If the request concerns information a vendor entered about you, we will pass it to that vendor and help them act on it — they are the controller of that record.
This is a tool for businesses and is not directed at children. We do not knowingly collect information from anyone under 13. Where a vendor records a guest who happens to be a child — a name on a seating chart — that information belongs to the couple and their vendor and is treated as above.
We are based in Missouri, United States, and our providers store data in the United States. If you are outside the US, using Celestial means your information is transferred there.
If we change anything that matters, we will update the date at the top and tell account holders directly. We will not quietly widen what we do with your data and hope you do not notice.
Questions, requests or complaints:
andrew@celestial-celebrations.com
Celestial Celebrations LLC, trading as Celestial Collective · St. Louis,
Missouri, United States