1. Executive Overview
Host + Gather, LLC (“Host + Gather,” “we,” “our,” or “us”) is committed to safeguarding the confidentiality, integrity, and availability of the information entrusted to us. This Privacy Policy delineates the governance framework we employ to collect, process, and protect personal data in compliance with applicable data‑protection statutes, including but not limited to the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and relevant U.S. federal and state privacy laws.
2. Scope of Coverage
This Policy applies to all visitors, prospects, and clientele (collectively, “Users”) who access our website, digital assets, and associated event‑planning services (collectively, the “Services”). By engaging with the Services, you acknowledge that you have read and understood this Policy.
3. Data Acquisition Matrix
We collect data through the following operational channels:
Voluntary Disclosures – Information you intentionally submit via inquiry forms, consultation bookings, email communications, or contractual agreements (e.g., name, email address, telephone number, event particulars).
Automated Interactions – Log files, cookies, pixel tags, and analytic tools that capture device identifiers, IP addresses, browser metadata, referring URLs, and on‑site behavior metrics.
Third‑Party Interfaces – Payment gateways, calendar integrations, social‑media plug‑ins, and other external systems used to facilitate or augment the Services.
4. Purpose‑Driven Processing
We process personal data strictly on a lawful‑basis model, including but not limited to the execution of contracts, legitimate business interests, compliance with legal obligations, and, where required, explicit consent. Key processing objectives include:
Event ideation, planning, execution, and post‑event wrap‑up.
Client relationship management, marketing automation, and service personalization.
Cybersecurity, fraud mitigation, and platform optimization.
Regulatory reporting and fiscal record‑keeping.
5. Data Retention & Minimization
Personal data is retained for the duration necessary to fulfill the aforementioned purposes or as mandated by statutory retention schedules. We apply data‑minimization principles to ensure only pertinent data is archived in secure repositories.
6. Data Sharing & International Transfer Protocols
We do not monetize personal data. We may, however, disclose data to vetted third‑party processors (e.g., payment processors, CRM vendors, analytics providers) under binding data‑processing agreements. Cross‑border transfers are executed pursuant to GDPR‑compliant mechanisms such as Standard Contractual Clauses (SCCs) or an adequacy decision.
7. User Rights Arsenal
Subject to applicable law, Users may exercise the following rights: access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. CCPA‑covered consumers may also opt out of “sale” or “sharing” of personal information (as defined under CCPA).
8. Security Governance
We maintain a multi‑layered security architecture encompassing administrative, technical, and physical controls—such as role‑based access control (RBAC), encryption at rest/in transit, intrusion detection systems, and periodic penetration testing. No transmission method is 100% secure; therefore, absolute security cannot be guaranteed.
9. Children’s Data Policy
Our Services are not directed to children under 13. We do not knowingly collect personal data from minors. If we become aware of such data, we will delete it promptly.
10. Policy Maintenance & Revision Cadence
We reserve the unilateral right to amend this Policy to reflect evolving legal, technical, or operational requirements. Material changes will be communicated via conspicuous site banners or direct email notifications, with the “Effective Date” updated accordingly.