Privacy Policy
Last updated: 14 June 2026
VenuePitch (“VenuePitch”, “we”, “us”) is a UK-based software service that helps event planners, venues, and hospitality professionals generate AI-powered visualisations and client proposals. This policy explains what personal data we collect, how we use it, who we share it with, and what rights you have under the UK GDPR and Data Protection Act 2018.
Data controller: Kyle Daylan, trading as VenuePitch. Contact: hello@venuepitch.com.
1. What we collect
- Account data: email address, password (hashed), your role and plan.
- Uploaded content: photos of venues, product images, and any files you upload to generate visualisations. You own these files.
- Generated outputs: AI-generated visualisations and proposal documents you create.
- Payment data: we do not store card numbers. Payments are handled by Stripe; we receive only your Stripe customer ID and subscription status.
- Usage data: anonymous product analytics (page views, feature usage) via PostHog. Error diagnostics via Sentry (may include your user ID).
- Cookies: essential authentication cookies and, with your consent, analytics cookies. See our Cookie Policy.
2. Why we collect it (lawful basis)
- Contract — to provide you the service you subscribed to (rendering visualisations, storing your saved venues, generating proposals).
- Legitimate interest — to secure the service, prevent abuse, and improve product quality through anonymised analytics.
- Legal obligation — to comply with tax, accounting, and law enforcement requirements.
- Consent — for non-essential analytics cookies (you can withdraw at any time via the cookie banner).
3. Who we share it with (data processors)
We share your data with a small set of trusted processors, all covered by data processing agreements:
- Supabase (database + auth + file storage) — hosted in the EU.
- Vercel (application hosting) — global CDN, primary region EU.
- Stripe (payments + subscriptions) — global; PCI-DSS compliant.
- Google Gemini API (AI image generation) — your uploaded photos are transmitted to Google for processing. Google does not train models on your inputs per their enterprise API terms.
- Resend (transactional email delivery).
- PostHog (product analytics) — EU-hosted.
- Sentry (error monitoring).
We do not sell your data. We do not share it for advertising.
4. How long we keep it
- Account data: until you delete your account (see Section 6).
- Uploaded images + generated outputs: until you delete them, or 90 days after account closure (whichever comes first).
- Billing records: retained for 6 years per HMRC requirements.
- Anonymised analytics: retained indefinitely in aggregate.
5. Where we store it
Primary storage is in the European Union (Supabase EU region, Vercel EU edge). Some processors (Stripe, Google) transfer data to the US under Standard Contractual Clauses and the EU-US Data Privacy Framework.
6. Your rights
Under UK GDPR you have the right to:
- Access the data we hold about you
- Correct inaccurate data
- Delete your data (“right to erasure”)
- Export your data in a portable format
- Restrict or object to certain processing
- Withdraw consent for optional processing (analytics)
- Complain to the Information Commissioner's Office (ico.org.uk)
To exercise any of these, email hello@venuepitch.com with the subject “Data request”. We will respond within 30 days.
7. Security
All data is encrypted in transit (TLS 1.2+) and at rest. Passwords are hashed via bcrypt. File access uses signed URLs with short expiry. Access to production data is limited to the data controller. If we discover a breach affecting your personal data we will notify you and the ICO within 72 hours.
8. Children
VenuePitch is a professional tool intended for business users aged 18 or over. We do not knowingly collect data from anyone under 18.
9. Changes to this policy
We may update this policy from time to time. Material changes will be announced by email at least 30 days before taking effect. The “Last updated” date at the top of this page always reflects the current version.