Privacy Policy
Last updated: August 8, 2026. asemble is a service and trademark of Smashed Studios LLC. Privacy contact: hello@asemble.app.
1. Information We Collect
We collect information you provide to use asemble:
- Account information: the phone number, email address, Google identity, and optional display name used for sign-in. You may use a single supported identifier and can later link another sign-in method.
- Measurements: body measurements you save or submit for outfit coordination.
- Event data: event details, guest lists, groups, coordination settings, contact channel, deadlines, responses, and payment status.
- External payment references: handles or instructions a host chooses to display. We do not store bank account or card numbers.
- Payment summaries: if an on-platform Stripe payment feature is made available and used, Stripe processes payment credentials. asemble receives transaction details such as amount, status, mode, and time, not the full card number.
- Communication records: invitations, reminders, delivery status, consent timestamps, opt-out preferences, and compliance records. Consent records may include a hashed IP address and user agent.
- Guest identifiers: a phone number or email provided through an event link, even if the guest does not create an account.
- Post-event feedback: ratings, optional review text, private improvement suggestions, publication consent, attribution choice, contact permission, and delivery or dismissal timestamps.
Separately, and not connected to any user account, we keep a small record of businesses we approach about a referral partnership, typically wedding coordinators and event planners. This is the only information described here that is not given to us by the person it describes:
- Business contact details: the business or coordinator name, and exactly one way to reach them, either a business email address or an Instagram handle, never both. Optionally a two-letter country code, used only to check which contact rules apply before we write.
- Our own notes: internal free-text notes, such as how we came across the business. These are never shown to the recipient.
- Who introduced us: if someone suggested we get in touch, we store that person's name so the message can say so honestly. It is a display name only. We keep no contact details for that person and use it solely to write one sentence of one message.
- The conversation: the messages we send and any reply sent back through the private link included in them. Replying requires no account.
- Partnership records: if a coordinator accepts and sets up a referral code, we record which asemble account claimed the partnership and when.
These contacts are entered one at a time by hand. We do not buy, scrape, or bulk-import contact lists, and the tool we use to send this outreach has no import function, deliberately. We do not track whether a message was opened or a link clicked, and we do not record the IP address or device of anyone who replies.
2. How We Use Information
- Provide event coordination, measurement reuse, guest matching, status tracking, exports, and purpose-specific sharing.
- Authenticate users through phone OTP, email magic link, or Google OAuth.
- Send sign-in, invitation, reminder, confirmation, and optional post-event feedback messages through Twilio and Resend.
- Attach an unauthenticated guest submission to a new account when the guest completes the normal sign-in flow through the secure post-submission handoff.
- Analyze aggregate usage and performance to improve the service. We do not sell personal data.
- Publish a host’s rating and approved review text only after explicit permission. Public reviews never include event names, identifiers, contact details, private improvement feedback, or profile photos.
Automated phone and SMS support currently uses +1 numbers. Reply STOP for a platform-wide event SMS opt-out, STOP followed by the host first name for host-specific reminders, and START to resubscribe. Requested authentication messages cannot be delivered if the related channel is blocked.
3. Data Sharing
- Event hosts: a host can view information a guest submits for that event and can export the fields needed for coordination.
- Tailor sharing: a host can create a purpose-specific link from an event export. The link expires and can be revoked. Anyone with a valid link can view the included fields until expiry or revocation.
- Service providers: Supabase for database and authentication, Twilio for SMS, Resend for transactional email, Stripe for any enabled payment processing, and Google Cloud for selected AI and Google sign-in functions.
- Legal and safety: information may be disclosed when required by law or necessary to protect rights and safety.
4. Storage and Security
Data is stored in Supabase-managed PostgreSQL databases and protected by application authorization and row-level security. Data is transmitted over HTTPS. Measurement data is structured and is not shared for third-party advertising.
5. Your Choices and Rights
- View and edit your profile, measurements, and event history.
- Export supported event or measurement data.
- Opt out of event SMS by replying STOP, or opt out of a specific host’s reminders with STOP followed by the host first name.
- Use the unsubscribe link in an event email or contact us for broader suppression, except for authentication emails you request.
- Stop post-event feedback emails without disabling event or sign-in email.
- Edit feedback, withdraw review publication, or permanently delete a review from your account.
- Revoke active tailor links created from events you host.
- Delete your account from the Profile page.
- If we contacted you about a referral partnership: every message includes a private link carrying a No thanks and a Don't contact me again option. Either closes the conversation immediately and stops any follow-up; the second also adds your address to our global do-not-email list. Neither requires an account. Emails additionally carry a one-click unsubscribe link. To have the record removed entirely instead, email hello@asemble.app.
6. Measurement Data
Saved profile measurements may be reused as a starting point across events. When you submit measurements for an event, the event keeps a copy accessible to the host. Internal admin tools show whether measurements exist, not their values. Staff cannot sign in as you. Ask hosts and tailors to collect only the fields needed for the garment.
7. Retention and Deletion
We retain personal data while an account is active or as needed to provide the service. Post-event request delivery records are deleted after 365 days. Review responses are deleted after 730 days unless the host deletes them sooner; expired reviews leave public display. Deleting your account removes your profile, saved measurements, authentication credentials, hosted-event reviews, and data for events you host. Minimized participation records may remain in another host’s event so that host can preserve an accurate event record; your account identity is removed from those records. Communication opt-out and compliance logs may be retained so preferences and legal obligations continue to be respected. Partnership outreach records follow their own schedule: the messages themselves are deleted after 24 months, and the contact record for a business that never engaged is deleted after 18 months. Where someone asked not to be contacted again, we deliberately keep the minimum needed to honour that, being the name, the channel, and the request itself, because deleting it is how a person ends up being contacted again. Contact hello@asemble.app to request deletion of data associated with a specific event or identifier when you do not have an account.
8. Cookies and Similar Storage
- Essential: authentication sessions, security, consent preferences, and basic service functions.
- Analytics: optional usage and performance measurement that can be declined through the cookie banner.
- Marketing: optional measurement that would require consent. We do not currently use third-party advertising cookies.
Clear the asemble cookie preference in your browser if you want the consent banner to appear again.
9. Children’s Privacy
asemble is not intended for children under 13, and we do not knowingly collect their personal information. Contact us if you believe a child has provided information.
10. Changes
We may update this policy. Material changes will be communicated through the app or email. Continued use after changes constitutes acceptance of the updated policy.
11. Contact
Questions or privacy requests can be sent to hello@asemble.app.