Agape & Co.

Privacy Policy

Last updated September 26, 2026

Agape & Co. (“we”, “us”) provides inquiry-to-booking software for wedding professionals at agapeand.co. This policy explains what we collect, how we use it and the choices you have. It covers two groups of people: vendors who use our dashboard, and couples (or anyone) who send an inquiry to a vendor through a form we host.

What we collect

  • Vendor accounts: your name, business name, category, email, a hashed password (if you don't sign in with Google), and the business details you add in Settings, such as pricing notes, FAQs and links.
  • Inquiries: what a couple enters on a vendor's inquiry form or sends by email: names, contact details, event date, venue, guest count, budget and their message. Vendors can also add leads themselves or forward lead emails to us.
  • Messages: the emails we send and receive on a vendor's behalf, and the drafts we prepare for them.
  • Payments: subscription and retainer payments are handled by Stripe. We receive the status and amount; we never see or store full card numbers.
  • Technical data: basic logs (such as IP address and browser) to keep the service secure and working, and a bot check on our forms.

How we use it

  • To run the service: show vendors their leads, send replies and follow-ups they've set up, and check their availability.
  • To draft replies: inquiry details and the vendor's business information are sent to our AI provider to write a reply the vendor can send or review.
  • To bill vendors, prevent abuse and keep the service secure.
  • To contact vendors about their account. We don't send marketing to couples, and we don't sell personal information.

Google sign-in and Google Calendar

If you choose “Continue with Google”, we receive your name, email address and whether Google has verified that address. We use them only to create and sign in to your account.

If you connect Google Calendar, we request two limited permissions. Free/busyaccess lets us see when you're busy on the date a couple asks about, so replies don't promise dates you may not have. We can't read event titles, guests or details. We also create one calendar of our own in your account, named after your business (“… bookings”), and add, update or remove your booked events on it. We can't see or change your other calendars. The access token is stored encrypted. You can disconnect at any time in Settings or from your Google account; the bookings calendar then stays in your account for you to keep or delete.

Agape & Co.'s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We don't use Google user data for advertising, don't sell it, don't use it to train AI models, and don't let people read it except where you ask us to, for security, or where the law requires.

Who helps us run the service

We share data only with providers that process it for us, under their own privacy and security terms:

  • Render hosts the app and database (United States).
  • Resend sends and receives email.
  • Stripe processes payments and vendor payouts.
  • Anthropic provides the AI that drafts replies. It doesn't train its models on data we send through its API.
  • Cloudflare provides DNS, security and the Turnstile bot check on our forms.
  • Google, only if a vendor signs in with Google or connects Google Calendar.

We may also disclose information if the law requires it, or as part of a merger or sale of the business, with notice to you.

Vendors and couples

When a couple sends an inquiry, it goes to the vendor they contacted. That vendor decides how to use it and may have their own privacy policy. We process the inquiry on the vendor's behalf. Couples can ask the vendor, or us, to see or delete their information.

Keeping and deleting data

We keep account and lead data while the vendor's account is open. When a vendor closes their account, we delete their data within 30 days, except what we must keep for tax, legal or security reasons. You can ask us to access, correct or delete your information at any time. California residents have these rights under the CCPA, and we'll never treat you differently for using them.

Security

Connections use HTTPS, passwords are hashed, and calendar tokens are encrypted. No system is perfectly secure, but we work to protect your information and will notify affected users of a breach as the law requires.

Children

The service is for businesses and adults planning events. It isn't directed to children under 16, and we don't knowingly collect their information.

Changes and contact

If we make significant changes, we'll update this page and let vendors know by email. Questions or requests: hello@agapeand.co.