Privacy
Privacy Policy
This policy explains what Venuvero currently collects, why it is used, when it is shared, and the controls available to workspace users and listed venues.
Effective September 8, 2026
Information collected
- Account information such as name, email, workspace, role, and authentication data.
- Email addresses and calendar data authorized through the provider permissions you choose. If you connect Apple Calendar, Venuvero also stores the Apple Account email and Apple-generated app-specific password needed for CalDAV access. Inbound email content is collected only when you forward it to Venuvero.
- Inquiry messages, event details, customer contact information, and sold services.
- Pricing, venue-profile information, files, URLs, and notes submitted by a workspace.
- Public venue facts, source URLs, observation dates, and generated comparisons.
- Claim, correction, and opt-out request details and verification evidence.
- Subscription status, billing contact details, invoice references, and payment-provider identifiers. Complete card numbers are collected by Stripe, not Venuvero.
- Security, diagnostic, usage, and error information needed to operate the service.
How information is used
Information is used to authenticate users; receive forwarded communications and sync authorized calendars; extract event details; generate user-reviewed drafts and estimates; display analytics; research sourced venue information; verify claims; prevent abuse; provide support; and maintain and improve reliability.
AI processing
Selected inquiry text, venue profiles, public source text, and pricing evidence may be sent to configured AI providers to perform extraction, summarization, matching, or drafting. When OpenAI processing is enabled, Venuvero sends only the content needed for the requested feature and disables provider-side response storage. Google or Microsoft user data is not used to train a generalized AI model, create advertising profiles, or improve an AI model unrelated to the user-facing Venuvero feature. Users should not submit unnecessary sensitive information.
Google API data
If you connect Google Calendar, Venuvero accesses your Google account email address, your calendar list, event timing and basic event details, and—only for a calendar you own—the ability to create or update confirmed Venuvero bookings. The current Gmail connection requests your Google account email address and permission to send only replies that a workspace user explicitly approves. It does not request permission to read, modify, delete, or label Gmail messages. To receive inquiries, you can enable automatic forwarding in Gmail. Google then sends selected messages to your unique Venuvero forwarding address. Venuvero stores and processes the forwarded sender, recipient, subject, message text, provider message ID, and thread references for inquiry classification and conversation threading. Attachments are not retained by the forwarding service.
Venuvero's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not sold, used for advertising, used to determine creditworthiness, or accessed by people except when the user asks for support, when needed to investigate abuse or a security incident, or when legally required.
Apple Calendar data
If you connect Apple Calendar, Venuvero uses your Apple Account email and an app-specific password generated by Apple to connect through CalDAV. Venuvero can list and read calendar events for availability and create, update, or remove confirmed Venuvero bookings in the calendar you select. The app-specific password is encrypted at rest, excluded from account exports, and erased when you disconnect Apple Calendar or delete the workspace. Venuvero never asks for or needs your primary Apple Account password.
Microsoft Graph data
If you connect Microsoft 365 Calendar, Venuvero accesses your basic signed-in profile and calendar event details for availability. For a calendar owned by the connected account and selected by the user, Venuvero may create or update confirmed Venuvero bookings. The current Outlook email connection requests your basic signed-in profile and Mail.Send. Mail.Send is used only after a workspace user approves a reply in Venuvero; the current connection does not request Mail.Read. Inbound Outlook inquiries can instead be forwarded to the workspace's unique Venuvero address. These are delegated permissions for the signed-in user; the service does not request application-wide access to an organization's mailboxes.
Cookies, local storage, and analytics
Venuvero uses a secure, HTTP-only session cookie that is necessary to keep a signed-in user authenticated. The product may use browser local storage for user-created interface preferences, such as saved reply templates. Venuvero does not currently use advertising cookies or cross-site tracking pixels. Cloudflare Web Analytics measures aggregate site performance and usage without placing cookies. Because the current site uses only necessary storage and cookie-free analytics, it does not display a non-essential cookie consent banner. If non-essential cookies are added, Venuvero will add consent controls where required. More detail appears in the Cookie Notice.
Service providers and sharing
Venuvero does not sell personal information. Information may be shared with Render for API hosting, Neon for encrypted PostgreSQL infrastructure, Cloudflare for website delivery, DNS, inbound email routing, and cookie-free web analytics, OpenAI for user-facing AI features, Stripe for billing, and a connected Google or Microsoft account as needed to provide the service, and a connected Apple account through CalDAV when selected by the user. These providers act under their own terms and appropriate service agreements. Information may also be disclosed when directed by the user, to protect rights and security, or when legally required. Stripe processes checkout, payment methods, invoices, and subscriptions; complete card numbers never reach Venuvero. Public market facts may be reused across workspaces, but private inquiries, internal pricing, and workspace notes are never placed into the shared market cache.
Retention and security
OAuth state expires after ten minutes, password-reset links after thirty minutes, and login sessions after thirty days. Provider tokens and Apple app-specific passwords remain encrypted until the connection or workspace is deleted. Imported inquiry records remain available to the workspace until the owner deletes the workspace or requests deletion, subject only to limited legal, billing, fraud-prevention, backup, and security retention. Venuvero uses access controls, tenant-scoped queries, hashed session tokens, AES-256-GCM encrypted connected-account credentials, request validation, transport encryption, and audit events. No system can guarantee absolute security. Additional control details appear on the Security page.
Your choices
A workspace owner can download a credential-free JSON export under Account → Privacy & data controls. Disconnecting erases the stored provider token or Apple app-specific password; Google disconnection also attempts provider-side revocation. The owner can permanently delete the workspace from the same panel after canceling any active paid subscription. Listed venues may request a correction, claim, or automated-collection opt-out through the listing request form. Venuvero may retain a minimal suppression record so an opted-out source is not collected again.
Children and sensitive information
Venuvero is a business service not directed to children under 13. Do not use it to collect children’s information or highly sensitive data unless legally authorized and necessary.
Changes and contact
Material changes will appear here with an updated effective date.
Contact Venuvero through the support channel inside your account or email hello@venuvero.com.