RiteBinder Privacy Policy
Effective date: upon publication · Last updated: upon publication
RiteBinder ("RiteBinder," "we," "us") is operated by ARDEO LABS LLC, a Florida limited liability company. This policy explains what we collect, why, and what your rights are. It covers the RiteBinder mobile and web apps, the RiteBinder website, the login-free client surfaces (public booking pages, agreement portals, questionnaire portals, script-approval portals, and rehearsal-agenda pages), and support channels. It applies both to officiants (the celebrants and practices who hold RiteBinder accounts) and to the people they serve — couples, families, and honorees — whose details an officiant enters or who interact with an officiant's links.
The short version: your data is yours. We don't sell it, we don't run ads, we don't use your content to train AI models, we never market to your couples or families, and you can export or delete everything at any time.
1. What we collect
Account information. Email address, name, and authentication credentials (managed by our authentication provider).
Your practice content. What you enter to run your officiant practice: packages and prices, ceremonies and their dates, venues, agreements, questionnaires, scripts and script versions, your ceremony library, license-return tasks, payment records, notes, and your business branding and payment-link URLs.
The people you serve. You may enter — or they may submit through your links — names, pronouns, phonetic pronunciations, email addresses, phone numbers, ceremony and venue addresses, and notes about your clients: couples, partners, family members, and, for funerals and memorials, the person being honored and their surviving family. You are responsible for having the right to collect and share that information with us; we use it only to provide the service to you and never for our own marketing. Email we send on your behalf goes out in your name and your brand — never ours.
Your phone's contacts, only when you pick one. On iOS and Android you can add a client by picking one contact from your address book. We read only that one contact's name and the phone number and email address you choose from their card — nothing else on it, and nothing else in your address book. RiteBinder never uploads, browses, syncs, or stores your address book, and picking a contact does not send us anything on its own: what you keep is whatever you save onto the client record, exactly as if you had typed it. On the web this feature only appears in browsers that offer their own contact picker; it is absent everywhere else.
Ceremony content, which is often personal. Questionnaire answers (how a couple met, family history, anecdotes), vows, eulogy material, and style preferences including a free-text note about religious or spiritual tradition. We treat all of it as your confidential content: it is never sold, never used for advertising, and never used to train AI models.
E-signature records. When a client signs an agreement through the portal, we record the typed signature name, the signer's email address, the server-side date and time, and the IP address the signing request arrived from, so you have evidence the agreement was signed.
Portal activity. Timestamps for when a link was opened, a questionnaire submitted, or a script approved, plus the name and text of any comment a client leaves on a script.
Payment information. Subscription payments are processed by Stripe. We receive your subscription status only — we never receive or store card numbers, card brands, or billing card details of any kind (billing happens on Stripe's own pages). What your clients pay you reaches you by one of two rails, and they collect different things. On your own payment rails — your link, your invoice, cash or a check — the payment happens entirely outside RiteBinder, and we record only the amount, method label, date, and note you enter. When you turn on collecting through RiteBinder, we ask Stripe to open a checkout page as a direct charge on the Stripe account you connected: you are the merchant of record, and the money settles to you — never into a RiteBinder balance. To open that page we send Stripe the amount, what the payment is for, your practice name, a reference of our own so the payment lands on the right ceremony, and your client's email address, so Stripe can fill the form in for them and send them a receipt. Your client enters their card — or their bank details, where you collect by bank transfer — on Stripe's own page, and those details are never delivered to us. What comes back to us is the amount, the method, the timestamps, Stripe's own identifiers for the charge, and the platform fee that applied — never card data.
Usage and device data. Product analytics events (screens used, features triggered), device type, OS version, and approximate region, collected via PostHog. Crash and error diagnostics collected via Sentry.
On-device copies. Podium mode caches the rendered script and your branding locally on your device so it works with no network. That cache lives on your device and is cleared when you delete the app or the ceremony.
Support communications. Emails you send to our support address.
2. How we use it
- Provide, maintain, and improve the service (including the offline podium cache and backups).
- AI ceremony drafting: the interview answers, your pins, partner names/pronouns/phonetics, your style settings (including the religion note), and any library excerpts you select are sent to Anthropic's API to draft ceremony blocks. The draft lands in your review queue — it is never visible to a couple or family until you share it, and nothing becomes part of a script without your acceptance. Under Anthropic's commercial API terms, your inputs and outputs are not used to train their models.
- AI inquiry intake: inquiry text you paste is sent to the same provider to suggest a client and ceremony. Suggestions land in a review queue; possible duplicates are surfaced, never merged automatically; a suggestion becomes part of your records only when you accept it. (Inquiries submitted through your public booking page are recorded directly as a new inquiry for you to review. Where you have turned instant booking on for an offering, a booking made there is recorded directly as a booked ceremony: the agreement you configured goes out for signature, and the date is held for the window you set.)
- Instant booking, when you have turned it on, acts on your instruction: the booking, the client record, and the agreement are created from the visitor's submission under the settings you chose.
- Send the email you initiate to your clients — questionnaire invites and nudges, script shares, approval confirmations, agreement sends and signed receipts, payment reminders and receipts, booking-inquiry acknowledgments — via Resend, in your brand with your reply-to — and, where you have turned the features on, review requests after a ceremony and instant-booking mail (receipts, signature confirmations, and a notice if a held date releases), which RiteBinder sends in your name at the moment the feature calls for.
- Send product email the service requires (sign-in codes, billing receipts, security notices), a short onboarding sequence, and the optional weekly pipeline digest. You can unsubscribe from anything non-transactional.
- Send push notifications you enable (questionnaire completed, script approved or commented, agreement signed, rehearsal and podium reminders), delivered through Expo.
- Measure aggregate product usage, diagnose crashes, prevent fraud and abuse, and comply with law.
We do not sell or rent personal information, and we do not share it with third parties for their own advertising.
3. Client links, share scopes, and vow privacy
Your clients reach RiteBinder through links, not accounts. Each link carries a long random token and is unguessable. Every client link can be turned off: share links — scripts, questionnaires, rehearsal agendas — can be revoked from the app, and an agreement's link stops resolving when you void the agreement. A revoked link shows nothing, not an error page that confirms what used to be there. Anyone who has a live link can see what that link renders — treat links like the documents themselves.
- Booking pages are public by design: they show your active packages and prices.
- Agreement portals show the agreement snapshot and collect the signature record above.
- Questionnaire portals show the questions you sent and accept answers, saving partial progress as it is typed.
- Script portals render a snapshot at a scope. A partner-scoped link deliberately omits the other partner's vows and anything you marked officiant-only; a full-scope link shows everything you left couple-visible. Scope filtering happens on our server, so excluded text is never delivered to the browser.
- Rehearsal-agenda pages show a derived timeline for planners and coordinators and contain no script text at all.
4. If you're a couple, a family member, or a guest
The officiant you hired uses RiteBinder to run your ceremony. They are responsible for the relationship with you; we process your details on their behalf to provide the service. What you write into a questionnaire goes to your officiant. To access, correct, or delete information about you, contact your officiant — or email us and we'll help route the request.
5. Where your data lives
Data is stored with Supabase (PostgreSQL) in the United States, encrypted in transit (TLS) and at rest. Access in our systems is enforced by row-level security scoped to your practice; the client-facing pages are rendered by server functions that read only the specific data that link is entitled to. The website and those pages are served from our hosting (Fly.io, US region).
6. How long we keep it
- While your account is active: we keep your content so the service works.
- If you delete your account (Settings → Delete account): if you own the practice, it enters a 7-day grace window — sign back in before it ends to restore everything. Your clients' portals, questionnaire links, and agreement pages stop resolving immediately. After the window, your content is permanently deleted, except minimal records we must keep for legal, tax, or security purposes (e.g., invoices).
- What those minimal records are. Beyond invoices, four kinds of record outlive a purge, and none of them is your practice content: the record that an email address hard-bounced or filed a spam complaint on our shared sending domain, because discarding it would resume sending to a mailbox that refused us; a waitlist sign-up and the date its consent was given, which belongs to no practice and is our evidence that a mailing was asked for; the identifiers of the payment notifications Stripe delivered to us, kept so a redelivered notification is not counted twice; and any payment notification we could not match to a ceremony, kept open so money that arrived is investigated rather than lost. The last two hold Stripe identifiers, amounts, and timestamps — no card data and no ceremony content.
- If you were invited to someone else's practice, deleting your account removes your access immediately; the practice and its records stay with the owner.
- Backups age out on a rolling schedule of no more than 30 additional days.
7. Your rights and choices
- Access & portability: export your ceremony documents from the app at any time, on any plan — script PDF, large-type podium PDF, cue cards, rehearsal agenda, booking confirmation, and Word (.docx). You can also download a complete copy of your account data — clients, ceremonies, scripts and their versions, questionnaires, agreements, your library, license tasks, and money records — as JSON, self-serve from the app. Prefer we assemble it? Email us and we'll provide one.
- Correction: edit your content in the app.
- Deletion: Settings → Delete account, or email us and we'll run the same deletion for you.
- Marketing opt-out: unsubscribe links in every non-transactional email; the weekly digest has its own toggle.
- State privacy rights: depending on where you live (e.g., California, Colorado, Virginia, Florida), you may have statutory rights to access, delete, correct, or obtain a copy of your personal information, and to non-discrimination for exercising them. We honor these requests for everyone, resident or not. We do not "sell" or "share" personal information as those terms are defined in the CCPA/CPRA.
To exercise any right: [email protected]. We verify requests via your account email and respond within the time required by applicable law (generally 45 days).
8. Service providers (subprocessors)
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, server functions | US |
| Stripe | Subscription billing | US |
| Anthropic | AI drafting of ceremony scripts and parsing of inquiry text you submit | US |
| Resend | Transactional and lifecycle email delivery | US |
| PostHog | Product analytics | US |
| Sentry | Error and crash diagnostics | US |
| Fly.io | Hosting for the website, booking pages, and client portals | US |
| Expo (EAS) | App builds and push-notification delivery | US |
| Cloudflare | DNS, email routing, and bot protection on public booking pages (Turnstile, which processes the visitor's IP address) | US |
Each provider processes data only as needed to provide its service to us, under its own contractual data-protection commitments.
9. Children
RiteBinder is a business tool for adults; accounts require you to be 18+. Ceremonies often involve children — a baby naming, children in a wedding party, a grandchild reading at a memorial — but we do not collect information from children directly and the service is not directed at them. Any child's name that appears in a ceremony is content you entered, under your responsibility. If you believe a child has provided us information, contact us and we will delete it.
10. Security
Row-level security on every table, TLS everywhere, encryption at rest, scoped credentials, revocable client links with constant-time misses, server-side scope filtering for shared scripts, and no card data in our systems. No method of transmission or storage is 100% secure; if we learn of a breach affecting your personal information, we will notify you as required by law.
11. Changes
We'll post changes here and update the date above. For material changes, we'll notify you in the app or by email before they take effect.
12. Contact
Questions about your data, or a request to export or delete it? Email [email protected].
Ardeo Labs LLC5944 Coral Ridge Dr # 1017
Coral Springs, FL 33076
United States