The Grand Moment LLC operates a marketplace at thegrandmoment.events that connects engaged couples and event hosts with event-services vendors. This Privacy Policy explains what personal data we collect, how we use it, and the rights you have over it.
Who We Are
The Grand Moment LLC ("TGM," "we," "our," "us") operates The Grand Moment marketplace at thegrandmoment.events. We are based in Georgia, United States.
Personal Data We Collect
In shortAccount info, profile content, event details, payment metadata (never full card numbers), and standard usage signals — plus a few items from third parties like Stripe and OAuth providers.
2.1Information you provide.
Account information (name, email, password hashed, phone, business name for vendors); profile information (photos, bio, services, pricing, license/permit copies for vendors); event details (date, location, vision, budget, guest count, style preferences); payment information (handled by Stripe — we receive only metadata such as charge IDs and the last four digits of cards, never full card numbers); communications (messages, inquiries, contracts, reviews); identification documents (Stripe-required KYC for vendors, where Stripe is the controller).
2.2Information collected automatically.
Device, browser, and operating-system identifiers; IP address (used in part for fraud prevention and ESIGN/UETA audit trails); usage events (page views, feature use, click patterns); cookies and similar technologies — see our Cookie Policy.
2.3Information from third parties.
Stripe Connect onboarding data (returned to TGM as charges-enabled / payouts-enabled status); OAuth login providers (Google, etc.) where used; public business directories for vendor profile enrichment, with vendor consent.
2.4Sensitive personal information.
We do not knowingly collect health data, biometric data, precise geolocation (beyond city-level for matching), data of minors under 13, or other categories the CPRA classifies as sensitive — except as vendors voluntarily upload (e.g., dietary restrictions in a catering inquiry).
How We Use Personal Data
In shortTo run the marketplace, match couples with vendors, process payments, send transactional and (opt-in) marketing messages, prevent fraud, and meet legal obligations.
We use personal data to:
- 3.1. Operate, maintain, and improve the Service.
- 3.2. Match Customers with relevant Vendors via our AI matching engine.
- 3.3. Facilitate communication, contracts, and payments between Customers and Vendors.
- 3.4. Provide analytics, fraud prevention, security, and trust-and-safety enforcement.
- 3.5. Send transactional messages (account, billing, payments, dispute updates).
- 3.6. Send marketing messages, subject to your opt-out preferences.
- 3.7. Comply with legal obligations and respond to lawful requests.
- 3.8. Defend our legal rights and enforce our Terms.
We do notsell personal data to third parties for monetary consideration as the term "sale" is used in the CCPA/CPRA. We may "share" personal data for cross-context behavioral advertising as defined by the CPRA — we currently do not do this, but if we begin we will provide notice and an opt-out per CPRA § 1798.135.
Your Rights
In shortAccess, correct, delete, port, and opt out — exercise any of these by emailing privacy@thegrandmoment.events. California, EU/UK, and other state-law residents get the additional rights their jurisdictions provide.
5.1Universal rights.
You may (a) access and request a copy of personal data we hold about you; (b) correct inaccurate personal data; (c) delete personal data, subject to retention requirements (see § 7); (d) restrict or object to certain processing; (e) request data portability where applicable; (f) opt out of marketing communications. To exercise these rights, email privacy@thegrandmoment.events.
5.2California rights (CCPA/CPRA).
California residents have additional rights including the right to know, delete, correct, opt out of sale or sharing, and limit sensitive personal information. We do not "sell" or "share" personal data as those terms are used in the CCPA/CPRA, but if we begin we will provide a "Do Not Sell or Share My Personal Information" link on the Service.
5.3EU/EEA/UK rights (GDPR/UK GDPR).
EU/EEA/UK residents have additional rights under the GDPR, including the right to lodge a complaint with a supervisory authority. Our legal bases for processing are typically (a) performance of a contract, (b) compliance with a legal obligation, (c) our legitimate interests in operating the Service, and (d) your consent where applicable.
5.4Other state laws.
Residents of Virginia, Colorado, Connecticut, Utah, Texas, and any other state with comprehensive privacy law have rights similar to those under the CPRA — including access, deletion, correction, and opt-out of targeted advertising. We honor these rights on the same basis as California rights above.
Security
We use reasonable technical and organizational measures to protect personal data, including encryption in transit, encryption at rest where supported, access controls, and audit logging. No system is completely secure, and we cannot guarantee absolute security.
Retention
We retain personal data:
- 7.1. For as long as your account is active.
- 7.2. For a period after account closure as required by law, accounting standards, dispute resolution, or our reasonable business operations (typically 7 years for financial records, 2 years for general account data).
- 7.3. For the 12-month archival tail described in our Vendor Terms § 5.2 for Vendor Content.
We delete or anonymize personal data when retention is no longer necessary.
International Data Transfers
We are based in the United States. If you are outside the U.S., personal data we collect may be processed in the U.S., where data-protection laws may differ from those in your jurisdiction. We use Standard Contractual Clauses or other lawful transfer mechanisms where applicable.
Affiliate Sharing & Corporate Restructuring
In connection with any corporate restructuring (including the planned consolidation of TGM and TRD Media Group LLC under Jerido Enterprise LLC, or any future migration of the operating entity to Delaware), we may transfer personal data to the successor entity. We will notify users of any change in the controller of their personal data.
Children
The Service is not directed to children under 13, and we do not knowingly collect personal data from children under 13. If you believe we have collected such data, contact us at privacy@thegrandmoment.events and we will delete it.
Changes to This Policy
We may update this Privacy Policy. Material changes will be notified at least 30 daysin advance through the Service or email. The "Effective" date at the top reflects the most recent revision.
Contact
Questions or to exercise your rights: