Skip to content
PricingPlan freeVendor sign up
Legal & privacy

Privacy Policy

Last updated August 27, 2026.

This Privacy Policy explains how Trunnion AI LLC ("Trunnion AI," "Zennvue," "we," "us," or "our"), a Duskbridge company, handles personal information when you use the Zennvue website, marketplace, vendor workspace, planning tools, and related services (the "Services").

Our roles

For the public website, the marketplace, and couple accounts, Zennvue acts as the business (or "controller") that decides how personal information is processed. For client records that a vendor stores in their workspace, such as their clients' names, contact details, contracts, and event records, Zennvue acts as the vendor's service provider (or "processor") and processes that information only on the vendor's instructions under our Data Processing Addendum. A list of the providers that process personal information on our behalf is published at Subprocessors.

Information we collect

  • Account and profile information. Name, email, phone, business details, role, account credentials, preferences, vendor listing details, portfolio content, and wedding or event details.
  • Service content. Inquiries, messages, proposals, contracts, invoices, files, timelines, guest or attendee information, reviews, support requests, and other content you choose to provide.
  • Transaction information. Subscription, booking, payout, refund, and transaction records. Stripe handles payment-card and bank-account data under its own terms; Zennvue does not store full card numbers.
  • Device and usage information. IP address, browser, device, pages or features used, approximate location derived from IP, referral data, logs, and security events.
  • Information from others. Details shared by another authorized participant in a wedding, event, team, or booking, and information received from service providers or integration partners.

Sensitive personal information

Some of the information handled by the Services can be sensitive personal information as state privacy laws define it. Specifically: the contents of messages between couples and vendors where Zennvue is not the intended recipient of the message; guest and attendee records; and event details across categories such as officiant, catering, and venue that can reveal religious practice, dietary needs, health accommodations, or relationship information.

We collect this information only because you or another authorized participant submits it to run a requested wedding or event workflow. We use and disclose it only for the purposes permitted by law for that collection: providing the Services you request, security and fraud prevention, and legal compliance. We do not use or disclose sensitive personal information to infer characteristics about you, we do not use it for advertising, and we do not sell it. It is retained on the same schedule as the service content it belongs to (see Retention below). Because our use stays within these permitted purposes, state law does not currently require a separate "Limit the Use of My Sensitive Personal Information" control; if our practices ever change, we will offer that control before the change takes effect.

How we use information

  • Provide accounts, marketplace discovery, matching, CRM workflows, planning tools, communications, bookings, payments, payouts, support, and requested integrations.
  • Personalize and improve the Services, maintain records, diagnose errors, secure accounts, prevent abuse and fraud, enforce agreements, and comply with law.
  • Send service notices and, where permitted, product or marketing communications. You can opt out of marketing email without losing transactional messages.
  • Measure website and campaign performance only when optional analytics or advertising has been accepted where consent is required.
  • Operate AI-assisted features described in the product and at AI disclosures. Users remain responsible for reviewing outputs before relying on or sending them.

AI features and model training

Zennvue may process prompts, workflow context, and selected service content to provide drafting, matching, summarization, review, and recommendation features. We do not represent customer content, including couple-to-vendor messages, contracts, guest information, or event details, as training material for a shared cross-customer model. Tenant-scoped adaptation, where enabled by agreement, must remain within that tenant; a generally available self-service disablement control is not currently claimed. If we ever propose cross-customer model improvement, we will describe the change per feature and obtain consent that defaults to off for consumer content before doing so. The current model-provider register is not yet public, so do not submit regulated, highly sensitive, or third-party confidential information to an AI feature unless your signed agreement identifies the approved processing boundary. AI output may be incomplete or incorrect and does not replace professional advice.

How we disclose information

We disclose information as needed between couples, clients, vendors, team members, and other participants in a requested marketplace or workflow interaction. We also use providers for hosting, database, identity, payment, email, analytics, advertising, security, support, and infrastructure services; the current providers, their functions, and their processing locations are listed at Subprocessors. A reporting copy of a submitted public contact request or newsletter signup is sent to our private Trunnion lead registry as operational form processing independent of optional analytics consent. We may disclose information to comply with law, protect rights and safety, investigate abuse, complete a corporate transaction, or with your direction.

Sale, sharing, and targeted advertising

We do not sell personal information in exchange for money. However, if you accept the optional advertising category on this website, we share identifiers (such as cookie IDs), device information, and browsing activity on this site with Meta for cross-context behavioral advertising. State privacy laws treat that disclosure as a "sale" or "sharing" of personal information and as "targeted advertising." You can opt out at any time:

  • Use the Do Not Sell or Share My Personal Information link in the footer, or the Manage privacy control, to reject or withdraw the advertising category. Withdrawal takes effect immediately: we signal revocation to the vendor, delete the cookies that category set, and reload the page so tracking stops for the current visit.
  • Send an opt-out preference signal. We process Global Privacy Control in a frictionless manner and honor it as a valid opt-out of sale, sharing, and targeted advertising; we treat the legacy Do Not Track signal the same way. When either signal is present, optional analytics and advertising stay off and any inconsistent saved choice is replaced.
  • When you reject or withdraw, we also apply the vendor-side restriction signals available to us: Google tags run under Consent Mode with storage denied by default, and the Meta pixel, when it runs at all, runs under Meta's Limited Data Use flag.

Cookies and similar technologies

Necessary storage supports security, sessions, preferences, and requested product functions. On the public website, optional Google Analytics, Trunnion visit measurement, and Meta Pixel remain off until the matching optional category is accepted. Accepting the analytics category also enables a periodic newsletter signup prompt. An email you explicitly submit through the footer signup is processed as the requested first-party action independent of that optional choice. You can change any choice through Manage privacy. See the Cookie Notice.

Retention

We keep personal information only as long as reasonably necessary for the purposes described in this policy. The schedule below states the period or the criteria used to set it for each category:

  • Account and profile information. Kept while the account is active. After closure, deleted or de-identified once it is no longer needed for the record-keeping, dispute, fraud-prevention, and legal obligations below.
  • Service content, including messages, contracts, guest and attendee records, and event details. Kept for the life of the related account and event workflow. Deleted on a verified deletion request or account closure, subject to legal holds and the record-keeping obligations below. Minor guests' information follows the stricter rule in the Children section.
  • Transaction records. Kept as required for tax, accounting, audit, and payment-dispute obligations, typically seven years.
  • Device, usage, and security logs. Kept on a short rolling window sized to security investigation and diagnostics needs, then deleted or aggregated.
  • Marketing signup records. Kept until you unsubscribe or object, plus the suppression record needed to honor that choice.
  • Backups. Deleted content ages out of backups on the backup system's limited rolling window; deletion is complete when that window lapses. Logs and replicas are covered by the same deletion process or carry the retention stated above.

Security

We use administrative, technical, and physical safeguards appropriate to the nature of the information, and we describe them, including the boundary of what has and has not been independently audited, at Security. Keep credentials confidential and report suspected compromise promptly.

Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, obtain a portable copy of, restrict, or object to certain processing, withdraw consent, opt out of targeted advertising, sale, or sharing, and appeal a denied request. To exercise a right, email hello@zennvue.com with the subject "Zennvue privacy request" or use Privacy Choices.

  • Response time. We respond to verifiable requests within 45 days. Where the law allows, we may extend once by a further 45 days and will tell you why before the original deadline passes.
  • Verification. We may verify identity, account authority, and request scope using the information already associated with the account. We only ask for what verification requires.
  • Authorized agents. An authorized agent may submit a request for you. The agent should email the same address, identify you and themselves, and include your signed permission or proof of power of attorney; we may also confirm the request with you directly and verify the agent's identity.
  • Appeals. If we deny a request, the response will explain why and how to appeal. Appeal by replying to the denial or emailing hello@zennvue.com with the subject "Zennvue privacy appeal." We decide appeals within 45 days and, if the appeal is denied, we include a way to contact your state attorney general or privacy regulator.
  • Non-discrimination. We do not discriminate against you for exercising a privacy right. We will not deny the Services, charge a different price, or provide a different level of quality because you exercised one.

State-specific disclosures

Residents of states with comprehensive privacy laws in effect, including California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia, have some or all of the rights described above under their state's law. Where a state recognizes universal opt-out mechanisms, including California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, and Texas, we honor Global Privacy Control as described above. For California residents: the categories of personal information we collect, the purposes, the categories of recipients, and the retention criteria are described in the sections above; the categories shared for cross-context behavioral advertising when you accept the advertising category are identifiers, device information, and internet activity; and we have not knowingly sold or shared the personal information of consumers under 16. For workspace client records, Zennvue acts as a service provider or processor to the vendor, and rights requests for those records are routed to the vendor as the responsible business.

Children

The Services are intended for adults and are not directed to children under 13. Do not create an account or submit a child's personal information unless you are legally authorized and the information is necessary for a permitted event workflow. Where a guest list or event record includes a minor's information, that information is used only inside the event workflow it was submitted for: it is excluded from advertising and analytics, it is not used for AI model training, and it is deleted on the same schedule as the event record it belongs to.

International use

Zennvue is operated from the United States. If you use the Services from another country, information may be processed in the United States and other locations where our providers operate, subject to applicable safeguards and law.

Policy changes

We may update this policy as the Services or law change. We will post the revised date and provide additional notice when required. Material changes apply prospectively unless law permits otherwise.

Contact

Trunnion AI LLC, a Duskbridge company, 8100 Wyoming Blvd NE, Ste M4-301, Albuquerque, NM 87113. Email hello@zennvue.com.