Privacy Policy
Version 1.0 · Effective June 6, 2026
This Privacy Policy is part of, and incorporated into, the Zennvue Terms of Service.
It explains how Viceroy, LLC d/b/a Viceroy NM collects, uses, shares, and protects personal information in connection with the Zennvue platform. Capitalized terms not defined here have the meanings given in the Terms of Service.
Contents
- Introduction and Scope
- Our Role: Controller and Processor
- Information We Collect and Sources
- How We Use Information
- AI and Automated Processing
- How We Share Information; Subprocessors
- Cookies, Tracking, and Your Choices
- Your Privacy Rights
- Marketing Communications
- Data Retention
- Security
- International Users and Transfers
- Children's Privacy
- Third-Party Links
- Changes to This Policy
- Contact and Rights Requests
1. Introduction and Scope
This Privacy Policy explains how Viceroy, LLC d/b/a Viceroy NM, a New Mexico limited liability company, operator of the Zennvue platform and marketplace for the event industry (a Trunnion AI product) ("Zennvue," "we," "us," or "our"), collects, uses, shares, and protects personal information in connection with the Zennvue platform, website, marketplace, mobile applications, and related features (the "Service"). The defined terms used here (including "Vendor," "Client" or "Couple," "Content," and "Stripe") have the meanings given in our Terms of Service. This Policy applies to vendors, clients (couples), and visitors, and it is part of, and incorporated into, our Terms of Service.
2. Our Role: Controller and Processor
Our own user data. For account, billing, and usage data we collect to operate the Service, Zennvue is a controller (a "business" under the California Consumer Privacy Act and comparable state privacy laws) and decides how that data is handled.
Client data uploaded by vendors. When a vendor enters personal information about its own clients (for example client names, emails, and event details), the vendor controls that data and Zennvue acts as a processor (a "service provider" under the California Consumer Privacy Act and comparable state privacy laws) on the vendor's behalf and under the Vendor Agreement. Clients should direct requests about that data to the vendor, and we will support the vendor in responding.
Guest data entered by couples. When a couple enters personal information about wedding guests (for example guest names, contact details, and meal preferences), the couple controls that data and Zennvue processes it on the couple's behalf to provide planning features such as guest lists, RSVPs, and seating charts.
3. Information We Collect and Sources
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email, password, business name, role. | You |
| Vendor business data | Listings, services, pricing, contracts, proposals, invoices, CRM and calendar entries. | Vendor |
| Client and guest data | Client names, emails, and event details a vendor adds; guest details a couple adds. | Vendor / Couple |
| Payment metadata | Plan, billing status, transaction metadata. Card data is held by Stripe, not Zennvue. | You, Stripe |
| Usage data | Device, log, and analytics data about Service use. | Automatic |
| Communications | Messages and support requests. | You |
4. How We Use Information
We use personal information to:
- Provide, operate, secure, and improve the Service, including the marketplace and AI features.
- Create and manage accounts, process Subscriptions, and bill for plans and add-ons.
- Facilitate vendor-client connections and display vendor listings and any reviews.
- Communicate about the Service, including service, billing, and security notices.
- Detect, prevent, and address fraud, abuse, and security issues, and enforce our agreements.
- Comply with legal obligations and exercise or defend legal claims.
Legal bases. Where required by law, we rely on the legal bases of performance of a contract, our legitimate interests in operating and securing the Service, your consent (which you may withdraw in writing and serve said notice upon us pursuant to the terms of this Contract), and compliance with legal obligations.
5. AI and Automated Processing
The Service uses AI-assisted features that process user-entered data to provide parsing, recommendations, drafts, lead scoring, and marketplace matching. These features operate on the data you and your vendors enter to deliver the requested output, and are delivered using third-party model providers (currently Anthropic, with OpenAI and Google (Gemini) as fallback providers) under terms intended to prevent training on data submitted through the Service.
Model training. Zennvue does not use client personal data uploaded by vendors to train or improve AI models. Where we improve our features, we use aggregated or de-identified data that does not identify an individual. We do not use your personal information to make decisions producing legal or similarly significant effects without human involvement.
6. How We Share Information; Subprocessors
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We share personal information only as described here:
- Service providers and subprocessors, who process data on our behalf under contract.
- Between users, as needed to facilitate a vendor-client engagement (for example displaying a vendor listing or sharing booking details with a client).
- Legal and safety, when required by law or to protect the rights, property, or safety of Zennvue, our users, or others.
- Business transfers, in a merger, acquisition, financing, or sale of assets, subject to this Policy.
| Subprocessor | Purpose | Location |
|---|---|---|
| Stripe, Inc. | Payment processing (Stripe Connect). | United States |
| Render | Application hosting and storage. | United States |
| Anthropic | AI-assisted features (primary model provider). | United States |
| OpenAI | AI-assisted features (fallback model provider). | United States |
| Google (Gemini) | AI-assisted features (fallback model provider). | United States |
We may engage additional service providers (for example for transactional email and product analytics) to operate the Service. We maintain a current list of subprocessors and will provide it on request to the contact in Section 16.
7. Cookies, Tracking, and Your Choices
We use cookies and similar technologies for essential, functional, and analytics purposes, described in our Cookie Policy. You can manage cookies through your browser and any consent tool we provide. We honor recognized opt-out preference signals, including Global Privacy Control, where required by law. Because there is no common standard, we do not currently respond to browser Do Not Track signals.
8. Your Privacy Rights
8.1 Rights Available to You
Depending on where you live, you may have the rights to know or access, to correct, to delete, to data portability, to opt out of the sale or sharing of personal information and of targeted advertising and certain profiling, to limit use of sensitive personal information, and to not be discriminated or retaliated against for exercising these rights. California residents have these rights under the CCPA as amended by the CPRA, and residents of other states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, and others as they take effect) have comparable rights, which may include a right to appeal a denied request.
8.2 How to Exercise Your Rights
Submit requests using the contact details in Section 16. We will verify your identity before responding and will respond within the time required by law (for example, 45 days under the CCPA, extendable as permitted). You may use an authorized agent where allowed. If we deny a request, you may appeal where your state provides an appeal right, and we will respond to the appeal as required. For client or guest data a vendor or couple uploaded, please contact that vendor or couple; we will assist as their service provider.
8.3 California Disclosures (CCPA / CPRA)
In the preceding 12 months, we have collected the categories of personal information described in Section 3 (identifiers, customer records, commercial information, internet activity, and inferences), from the sources listed there, for the business purposes in Section 4, and have disclosed those categories to the service providers and parties in Section 6. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.
Sensitive personal information. We do not use or disclose sensitive personal information for purposes that would require offering a right to limit beyond those allowed as a service provider. Shine the Light. California residents may request information about disclosures to third parties for their direct marketing; we do not share personal information for third-party direct marketing. Financial incentives. We do not offer financial incentives for personal information.
9. Marketing Communications
We may send you service and transactional messages, which are not promotional and which you cannot opt out of while you have an account. For promotional emails, you can opt out using the unsubscribe link or by contacting us; we comply with CAN-SPAM and applicable law. Any marketing texts or calls, if offered, are sent only with the consent required by the TCPA and applicable law.
10. Data Retention
We retain personal information for as long as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements, after which we delete or de-identify it. Vendors and couples control the retention of client and guest data within their accounts, subject to the Terms of Service and Vendor Agreement.
11. Security
We use administrative, technical, and organizational measures designed to protect personal information, and we host the Service in the United States. These measures include encryption in transit (TLS) and at rest (AES-256), access controls and role-based permissions, multi-factor authentication options, logging and monitoring, and encrypted backups. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach affects your personal information, we will notify you and the appropriate authorities as required by law.
12. International Users and Transfers
The Service is operated from and hosted in the United States, and we store customer data in the United States. If you access the Service from outside the United States, your information will be processed in the United States, where data-protection laws may differ from those in your location, and you consent to that processing.
13. Children's Privacy
The Service is intended for users 18 and older. We do not knowingly collect personal information from children under 13 (or the minimum age in your jurisdiction). If we learn we have, we will delete it.
14. Third-Party Links
The Service may link to third-party sites and services we do not control. This Policy does not apply to them, and we are not responsible for their privacy practices.
15. Changes to This Policy
We may update this Policy. We will post the updated version with a new version number and effective date, and for material changes we will require re-acceptance on next login. Each acceptance is logged against the specific document version.
16. Contact and Rights Requests
Zennvue is operated by Viceroy, LLC d/b/a Viceroy NM.
8100 Wyoming Blvd NE, Ste M4-301, Albuquerque, NM 87113
- General inquiries: hello@zennvue.com
- Privacy and rights requests: privacy@zennvue.com
We will provide this Policy in an accessible format on request.