Privacy Policy
Effective 2026-07-30
Family-Friendly Events LLC 760 Warrior Dr., Suite 2-512, Stephens City, VA 22655 Email: [email protected]
Family-Friendly Events LLC ("Family-Friendly Events," "we," "our," or "us") operates the website at familyfriendlyevents.com (the "Site" — part of the "Service" defined in our Terms of Service). This Privacy Policy describes what personal information we collect, how we use it, and your rights with respect to that information.
By using the Site you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Site.
This Privacy Policy is part of, and incorporated into, our Terms of Service. Any dispute arising from our data practices is governed by the dispute-resolution terms of the Terms of Service — including binding arbitration and the class-action waiver, with a 30-day opt-out.
1. Information We Collect
1.1 Information you provide directly
-
Account registration. When you create an account — as a family or event planner ("Client") or as a vendor — we collect your name, email address, and a password (stored as a one-way hash; we never store your plaintext password).
-
Vendor profiles. Vendors provide business name, business address, service area, phone number, website URL, social media links, vendor category, a description of their services, and optionally photos and videos. This information is displayed publicly on your vendor profile.
-
Client preferences. Clients may provide event type preferences, location preferences, and saved vendor lists. This information is stored in your account and is not publicly displayed.
-
Messages. When you use our on-site messaging system to communicate with a vendor or client, we store the content of those messages.
-
Reviews. If you submit a review of a vendor, we collect the review text, rating, and the event date (optional). Published reviews are displayed publicly attached to your username.
-
Support communications. If you contact us for support, we collect the content of your message and any information you provide to help us resolve your issue.
-
Non-profit and school discount verification. If you claim a non-profit or K–12 school discount on a paid subscription, we collect: (a) your organization's Employer Identification Number (EIN) for 501(c)(3) non-profits, or its NCES School ID / accreditation reference for K–12 schools; (b) the email address used for fast-path domain-match verification, when applicable; and (c) any supporting documentation you upload (e.g., IRS determination letter, accreditation letter, letter of authorization on organizational letterhead). This information is used solely to determine and re-verify discount eligibility and is retained while the affiliation is active. Rejected or expired verification documents are deleted 90 days after the affiliation lapses or is revoked.
-
Email sign-ups. If you sign up for our mailing list (including via the splash page before creating a full account), we collect your email address. This list is managed via Kit (ConvertKit).
-
Vendor quote and inquiry requests. If you send a quote or inquiry request to a vendor through the Site, we collect your name, email address, phone number, event date, budget, and any details you include in your message. You can submit an inquiry without creating an account.
-
"Notify me" requests. If you ask us to notify you when a vendor, category, or feature becomes available, we collect your email address.
1.2 Information collected automatically
-
Log data. When you visit the Site, our servers and our CDN provider (Cloudflare) automatically record your IP address, browser type and version, operating system, referring URL, pages visited, and the date and time of each request.
-
Cookies and similar technologies. We use cookies and similar technologies to keep you logged in, remember your preferences (including your timezone setting), and understand how visitors use the Site. See Section 6 (Cookies) for details.
-
Usage data. We collect information about how you interact with the Site — searches performed, vendor profiles viewed, and features used — to improve our service.
1.3 Information from third parties
-
Stripe. When you purchase a vendor subscription or make any payment on the Site, payment processing is handled by Stripe. We receive a tokenized confirmation of your payment and your billing address; we do not store your card number, CVV, or full payment card data on our servers.
-
Mapbox. We use Mapbox to geocode vendor addresses (convert a street address to latitude/longitude coordinates) for the purpose of geographic search. Vendor addresses submitted during registration are transmitted to Mapbox for this purpose.
2. How We Use Your Information
We use the information we collect to:
-
Provide the Service. Create and maintain your account, display vendor profiles, facilitate search and discovery, process payments, and enable messaging and reviews.
-
Communicate with you. Send transactional email (account verification, password resets, payment confirmations, and booking-related messages) via Postmark. Send marketing email if you have opted in; you may opt out at any time. Our marketing emails (sent via Kit) may include technology that tells us whether you opened the message or clicked a link, which we use to measure engagement and improve our communications.
-
Improve the Site. Analyze usage patterns to improve features, fix bugs, and understand which content is most valuable to users.
-
Personalize your experience. Based on your activity on our Site (for example, the event type you are planning, or whether you register as a vendor), we may show you relevant on-site recommendations and content — such as suggested vendor categories — and occasional affiliate links to third-party products or services (for example, business insurance for vendors). These recommendations use only your activity on our own Site; we do not track you across other companies' websites to select them. Where we include an affiliate link from which we may earn a commission, we disclose that relationship.
-
Ensure safety and integrity. Detect and prevent spam, fraud, abusive content, and violations of our Terms of Service. Apply our content moderation policies to vendor profiles, reviews, and community content.
-
Comply with legal obligations. Respond to lawful requests from law enforcement, courts, or regulators; enforce our Terms; and exercise or defend legal claims.
We do not sell your personal information, and we do not engage in "cross-context" targeted advertising — that is, advertising selected by tracking you across other, unaffiliated websites or apps. The on-site personalization described above uses only first-party data from your activity on our own Site. We also do not engage in profiling that produces legal or similarly significant effects about you. If any of these practices change, we will update this policy and provide the opt-out choices required by applicable law.
3. How We Share Your Information
We do not sell or rent personal information. We share information only as described below.
3.1 Publicly displayed information
Vendor profile information — including business name, address, phone number, website, social media links, service area, photos, and reviews — is publicly visible on the Site and may be indexed by search engines.
Client usernames and review content are publicly visible when a review is published. Client email addresses, event details, and saved preferences are not publicly displayed.
3.2 Service providers
We share information with third-party service providers who process it on our behalf under confidentiality obligations:
| Provider | Purpose | Data shared |
|---|---|---|
| Stripe | Payment processing | Billing name, billing address, payment amount |
| Postmark | Transactional email delivery | Email address, name, email content |
| Kit (ConvertKit) | Marketing email | Email address, name, opt-in status |
| Cloudflare | CDN, DDoS protection, DNS | IP address, log data |
| Mapbox | Geocoding vendor addresses | Vendor street address |
| Meilisearch Cloud | Full-text search index | Vendor profile data (public fields only) |
| Google Analytics (Google LLC) | Site analytics; loads only if you consent | Usage data, device and browser information |
| YouTube, Vimeo, Spotify | Embedded media on vendor profiles; an embed loads only if you consent | IP address and device information, collected by the provider when an embed loads |
| Support channel | Customer support communications | Name, email, support message content. Support is currently handled by direct email; if we adopt a third-party ticketing system, we will name it in this table. |
3.3 Legal and safety disclosures
We may disclose your information if we believe in good faith that disclosure is necessary to: (a) comply with a law, regulation, or legal process; (b) protect the rights, property, or safety of Family-Friendly Events, our users, or the public; or (c) detect and prevent fraud or security incidents.
3.4 Business transfers
If Family-Friendly Events LLC is involved in a merger, acquisition, or sale of all or substantially all of its assets, user information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on the Site before your information is transferred and becomes subject to a different privacy policy.
4. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the service. When you delete your account:
- Your public profile (vendor) or username (client reviews) is removed from public display within 30 days of account deletion.
- Some information may be retained longer as required by law or for legitimate business purposes such as fraud prevention, tax records, or resolving disputes.
- Aggregated, anonymized analytics data that cannot identify you individually may be retained indefinitely.
5. Your Rights and Choices
5.1 Access and correction
You may view and update most account information by logging in and visiting your account settings. To correct information that you cannot update yourself, contact us at [email protected].
5.2 Deletion
You may request deletion of your account and associated personal information by contacting [email protected]. On receipt of a verifiable request, we will delete your personal information from our records and direct our service providers to delete it from theirs, within 45 days.
We may be unable to delete some information where retaining it is necessary to: complete a transaction or provide a service you requested, or otherwise perform a contract with you; detect security incidents and protect against fraudulent, malicious, deceptive, or illegal activity; debug and repair errors that impair intended functionality; comply with a legal obligation (for example, tax or accounting records); or otherwise use the information internally in a lawful manner compatible with the context in which you provided it.
5.3 Marketing email opt-out
You may unsubscribe from marketing emails at any time by clicking the unsubscribe link in any marketing message or by contacting us. We will continue to send transactional messages necessary to maintain your account.
5.4 California residents — CCPA rights
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), to the extent those laws apply to us:
- Right to know. You may request disclosure of the categories of personal information we collect, the purposes for which we use it, and the categories of third parties with whom we share it.
- Right to delete. You may request deletion of personal information we have collected about you, subject to certain exceptions.
- Right to correct. You may request that we correct inaccurate personal information we maintain about you.
- Right to portability. You may request a copy of the personal information you provided to us in a portable and readily usable format.
- Right to non-discrimination. We will not discriminate against you for exercising your CCPA rights.
- Do Not Sell. We do not sell personal information. If this practice changes, we will update this policy and provide an opt-out mechanism.
To exercise your CCPA rights, contact us at [email protected]. To protect your information, we verify your request before acting on it — generally by asking you to confirm details we already hold (such as the email address associated with your account) and matching them against our records; we may request additional information where necessary to verify your identity to the degree of certainty the law requires.
California "Shine the Light." California Civil Code § 1798.83 permits California residents to request information about personal information we disclose to third parties for those third parties' own direct-marketing purposes. We do not disclose personal information to third parties for their direct marketing.
5.5 Virginia residents — VCDPA rights
If you are a Virginia resident, you have rights under the Virginia Consumer Data Protection Act (VCDPA), including the right to: confirm whether we process your personal data and access it; correct inaccuracies; delete personal data; obtain a portable copy; and opt out of the processing of your personal data for (i) targeted advertising, (ii) the sale of personal data, or (iii) profiling in furtherance of decisions that produce legal or similarly significant effects.
We do not sell personal data, conduct cross-context targeted advertising, or engage in profiling that produces legal or similarly significant effects, so these opt-outs are not currently applicable. On-site personalization based solely on your activity on our own Site (see "Personalize your experience" in Section 2) is not "targeted advertising" as defined by the VCDPA. We state these rights here for transparency and will provide an opt-out mechanism if our practices change. The personal data of a known child is treated as "sensitive data" under the VCDPA. We process such data only with the consent required by law, only as reasonably necessary to provide the service requested, and only for purposes we disclosed when the data was collected.
To exercise your VCDPA rights, contact us at [email protected]. You may appeal a denied request by replying to our response; we will respond within the timeframes the VCDPA requires. If we deny your appeal, we will provide you with a way to contact the Virginia Attorney General to submit a complaint about the result.
6. Cookies
We use the following types of cookies:
| Type | Examples | Purpose | Consent required? | Duration |
|---|---|---|---|---|
| Strictly necessary | laravel_session, XSRF-TOKEN, Cloudflare Turnstile, cookie-choice value (browser local storage) |
Keep you logged in; CSRF protection; bot protection on forms; remembering your cookie choice | No — functional requirement | Session |
| Functional | ffe_timezone, language preference |
Remember your preferences | No — functional requirement | Up to 1 year / Session |
| Analytics | _ga, _ga_XXXXXXXX (Google Analytics 4) |
Understand Site usage patterns to improve the service | Yes — consent required | Up to 2 years |
| Embedded media | YouTube, Vimeo, Spotify cookies | Play embedded video, audio, and virtual tours on vendor profiles | Yes — consent required | Set by the provider |
Cookie consent: On your first visit, a banner will appear asking for your consent to analytics and embedded-media cookies. You may accept or reject non-essential cookies. Your preference is stored in your browser's local storage and can be changed at any time via the "Cookie preferences" link in the site footer. If you reject analytics cookies, Google Analytics will not be loaded and no analytics data will be collected about your visit. Third-party media embeds will also not load; we display an outbound link instead. Strictly necessary and functional cookies are set regardless of your consent choice.
Do Not Track and Global Privacy Control. Some browsers can send a "Do Not Track" signal or a Global Privacy Control (GPC) opt-out preference signal. Because we do not sell personal data and do not process it for cross-context targeted advertising, there is no sale or sharing for these signals to opt out of, and we do not currently respond to them; the cookie banner described above controls our optional cookies. If our practices change, we will honor opt-out preference signals as required by applicable law.
Most browsers also allow you to control cookies directly through browser settings. Disabling all cookies may prevent certain Site features from working correctly, including login.
7. Geographic Scope and International Users
The Site is operated from the United States and is directed to users located in the United States. We design our privacy practices to comply with applicable United States federal law, the law of the Commonwealth of Virginia (where our entity is established), and the privacy laws of US states that apply to our users — including the California Consumer Privacy Act and the Virginia Consumer Data Protection Act.
We do not target, market, or direct the Site to users in the European Union, the European Economic Area, the United Kingdom, Canada, or any other jurisdiction outside the United States, and we have not designed the Site to comply with the data-protection laws of those jurisdictions. In particular, Family-Friendly Events LLC does not hold itself out as a "data controller" or "data processor" within the meaning of the EU General Data Protection Regulation, the UK Data Protection Act 2018, Canada's Personal Information Protection and Electronic Documents Act, Quebec Law 25, or comparable foreign privacy regimes; we have not designated a representative under Article 27 of the GDPR; and we do not maintain a Data Protection Officer for purposes of those laws.
If you choose to use the Site from outside the United States, you do so on your own initiative. Any personal information you submit will be transferred to, processed in, and stored in the United States, which may have data-protection laws that differ from the laws of your country. By using the Site you consent to that transfer and processing.
If you are an individual outside the United States and you do not wish your information to be processed under United States law, please do not create an account or submit personal information to the Site. If you have already done so and you wish to have your data removed, you may close your account from your account settings or contact us at [email protected]; we will delete your personal information subject to the retention exceptions described in Section 4.
8. Children's Privacy
The Site is intended for adults (18 and older) and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected information from a child under 13, please contact us at [email protected] and we will delete it promptly.
Account registration and the pre-launch email sign-up form each require you to affirm that you are 18 years of age or older. We do not collect date of birth or other age information from any visitor.
Analytics cookies and other persistent identifiers load only after a visitor consents through our cookie banner, and we do not use persistent identifiers to profile users or to serve targeted advertising. If we obtain actual knowledge that we have collected personal information from a child under 13 through any part of the Site, including forms that can be submitted without an account, we will delete it promptly and will not use or disclose it.
The Site is family-friendly in its content and vendor standards; this does not mean we provide services to or collect information from minor users. The Site does not allow users under 18 to create accounts. The Site's "family-friendly" brand positioning describes the content and vendor standards, not the intended audience — the site is operated for adults making event planning decisions, not for children.
9. Security
We implement commercially reasonable technical and organizational measures to protect your personal information against unauthorized access, disclosure, alteration, or destruction. These include HTTPS/TLS encryption for all data in transit, hashed password storage, encryption at rest for sensitive fields, multi-factor authentication on staff accounts, and role-based access controls restricting who on our team can access user data.
Breach notification. In the event of a security incident involving your personal information, we will promptly investigate and, where required, notify affected individuals and the applicable regulatory authorities in the manner and within the timeframes required by applicable law.
No method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
10. Third-Party Links
Vendor profiles may include links to third-party websites (vendor websites, social media profiles). We are not responsible for the privacy practices of those websites. This Privacy Policy applies only to familyfriendlyevents.com.
11. Changes to This Policy
We may update this Privacy Policy periodically. When we make material changes, we will update the "Effective date" at the top of this page and, where required by law or where changes materially affect your rights, notify you by email or by a prominent notice on the Site. If a material change expands the personal information we collect, the purposes for which we use it, or the parties with whom we share it, or affects your dispute-resolution rights, we will ask account holders to affirmatively accept the updated policy before it applies to them.
Continued use of the Site after a policy change constitutes acceptance of the updated policy.
12. Contact Us
For privacy questions, access requests, deletion requests, or CCPA inquiries:
Family-Friendly Events LLC Email: [email protected] Phone: 540-569-1555 760 Warrior Dr., Suite 2-512, Stephens City, VA 22655
We aim to respond to all privacy inquiries within 30 days.