Privacy Policy
Last Updated: May 18, 2026
1. Introduction
BAP ("we," "our," or "us") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our marketplace platform connecting event hosts with venues.
2. Information We Collect
2.1 Information You Provide
- Account Information: Name, email address, profile photo
- Payment Information: Processed and stored entirely by Stripe — BAP does not store payment card data
- Event Information: Event details, guest count, date, event type, and budget
- Venue Information: Business name, EIN, location, room details, photos, and menu packages
- Messages: Communications sent between hosts and venues through the in-platform messaging system
- Reviews: Feedback submitted by hosts and venues following completed events
2.2 Automatically Collected Information
- Usage Data: Pages visited, features used, actions taken on the platform
- Device Information: IP address, browser type, device type, operating system
- Session Data: Recorded by Sentry for error tracking and reliability purposes, with sensitive fields excluded
- Cookies and Similar Technologies: Used for session management and platform preferences
2.3 Information from Third Parties
- Google OAuth: If you sign in with Google, we receive your name, email address, and profile photo from Google
- Stripe: We receive payment processing status and Stripe Connect verification information for venues
3. How We Use Your Information
We use collected information to:
- Operate the Platform: Create and manage accounts, display event listings and venue profiles, facilitate the offer and booking process
- Process Payments: Coordinate payment flows through Stripe Connect between hosts and venues
- Enable Communication: Deliver in-platform messages and transactional email notifications
- Enforce Platform Rules: Monitor messaging for circumvention attempts, enforce Terms of Service, prevent fraud and abuse
- Improve the Platform: Analyze usage patterns and technical errors to improve reliability and features
- Future Platform Intelligence: Platform usage and booking data may be used in the future to power assisted event creation and venue matching features designed to help hosts and venues get better results
- Legal Compliance: Comply with legal obligations and respond to lawful requests
4. Information Sharing
4.1 Between Platform Users
When you post an event or submit an offer, relevant information is shared between hosts and venues to facilitate the booking:
- Hosts can see venue profiles, room details, menu packages, and offer terms
- Venues can see event listings including event type, date, guest count, and budget
- Both parties can see reviews submitted about them following completed events
4.2 Service Providers
We share information with the following trusted third-party providers:
- Stripe: Payment processing and venue identity verification via Stripe Connect
- Resend: Transactional email delivery
- Sanity: Content management and data storage
- Vercel: Hosting and infrastructure
- Vercel Analytics: Platform usage and performance analytics
- Sentry: Error tracking and session replay for platform reliability
- Google: Authentication services (if you sign in with Google)
4.3 Legal Requirements
We may disclose information when required by law or to:
- Comply with legal processes such as subpoenas or court orders
- Enforce our Terms of Service
- Protect the rights, property, or safety of BAP, our users, or the public
- Investigate fraud, circumvention, or security issues
4.4 Business Transfers
If BAP is acquired or merged with another company, user information may be transferred as part of that transaction. We will provide notice before such a transfer occurs.
5. Data Security
We implement appropriate technical and organizational measures to protect your information, including:
- Encryption of data in transit (HTTPS/TLS)
- Secure authentication via NextAuth with Google OAuth and email
- Session replay configured to exclude sensitive fields such as payment details
- Regular security monitoring and updates
- Limited internal access to personal information
No method of transmission over the internet is 100% secure. We cannot guarantee absolute security of your information.
6. Data Retention
We retain your information for as long as necessary to:
- Provide our services and maintain your account
- Comply with legal obligations including tax records and transaction history
- Resolve disputes and enforce agreements
- Prevent fraud and abuse
When you delete your account, we will delete or anonymize your information except where we are required to retain it for legal purposes.
7. Your Privacy Rights
Depending on your location, you may have the following rights:
7.1 Access and Portability
Request a copy of the personal information we hold about you.
7.2 Correction
Update or correct inaccurate information in your account settings.
7.3 Deletion
Request deletion of your personal information, subject to legal retention requirements.
7.4 Opt-Out
Unsubscribe from non-essential emails using the unsubscribe link in any message.
7.5 Restriction and Objection
Object to or restrict certain processing of your information.
To exercise any of these rights, contact us at support@bapapp.org.
8. Cookies and Tracking
We use cookies and similar technologies for:
- Essential Cookies: Required for platform functionality including authentication and session management
- Functional Cookies: Remember your settings and preferences
- Error and Reliability Tracking: Sentry uses session data to help us identify and fix technical issues
- Analytics: Vercel Analytics collects aggregated usage data to help us understand how the platform is being used and improve the experience
You can control cookies through your browser settings, but disabling essential cookies will affect platform functionality. See our Cookie Policy for full details.
9. Children's Privacy
BAP is not intended for users under 18 years of age. We do not knowingly collect information from children. If we learn we have collected information from a child, we will delete it promptly. If you believe a child has provided us with information, contact us at support@bapapp.org.
10. International Data Transfers
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place to protect your information in accordance with this Privacy Policy.
11. Third-Party Links
Our platform may contain links to third-party websites. We are not responsible for the privacy practices of those sites and encourage you to read their privacy policies.
12. California Privacy Rights
California residents have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information is collected, used, and shared
- Right to delete personal information
- Right to opt-out of the sale of personal information — we do not sell personal information
- Right to non-discrimination for exercising CCPA rights
To exercise these rights, contact us at support@bapapp.org.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or prominent notice on the platform. Your continued use after changes constitutes acceptance of the updated policy.
14. Contact Us
For questions or concerns about this Privacy Policy or our data practices, contact us at:
BAP Support
Email: support@bapapp.org
By using BAP, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.