Last updated: October 6, 2026
Sumerzé is operated by Creamery Technologies LLC, a Colorado limited liability company ("Sumerzé," "we," "us," or "our"), which is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and share information when you use the Sumerzé mobile application and website ("App").
Account information. When you register, we collect your name, email address, and the role you select (customer, provider, or both).
Profile information. Providers may optionally provide a business name, bio, city and state, phone number, service listings, portfolio photos, and before/after transformation images.
Payment information. All payment data (card numbers, bank account details) is collected and stored directly by Stripe. Sumerzé does not store full payment card information on our servers. We store Stripe payment intent IDs and payout account identifiers to manage bookings and payouts.
Booking and messaging data. We store booking requests, booking status, scheduled dates, service names, amounts paid, and messages exchanged between Customers and Providers through the App. Message monitoring: Sumerzé monitors in-app conversations to detect fraud, harassment, and policy violations. By using the messaging feature, you acknowledge that messages may be reviewed by our team or automated systems. Messages are not end-to-end encrypted and should not be treated as private communications outside the scope of coordinating services.
Location data. We use the city and state in your profile to match you with nearby services. If you allow it, the App uses your device's location while you are using it to show providers near you; we never track your location in the background. Providers give their address and ZIP code: the address and phone number are shown only to a Customer with a confirmed booking, the ZIP code is used to calculate sales tax, and maps and search show only an approximate location (about 1 km), never the exact address.
Contacts (Invite your clients). If a Provider uses Invite your clients, the App opens the iOS contact picker. The App has no access to the contact list: it only receives the name and number of the people the Provider picks, and uses them only on the device to prepare a text message the Provider sends from their own phone. Sumerzé does not upload, store or share those contacts, and does not message them.
Device and usage data. We collect push notification device tokens to send you booking and message alerts. We may collect basic usage analytics (feature interactions, error logs) to improve the App. We record when a Provider's profile or photos are viewed; the Provider only sees view totals, never who viewed them.
What Providers see about Customers. When you request a booking or send a message, the Provider sees your name, profile photo, and your Sumerzé trust history (customer rating, completed bookings, and no-shows). Providers may keep private notes about their clients that only they can see. Your email and phone number are never shown to other users.
User-submitted feedback. If you submit feedback through the App, we store the message and its category (suggestion, bug report, or other).
We do not sell your personal information. We share information only in the following circumstances:
Stripe
Payment processing, identity verification (KYC), and provider payouts via Stripe Connect Express.
stripe.com/privacySupabase
Database hosting, authentication, and file storage (profile photos, portfolio images).
supabase.com/privacyAnalytics & error monitoring providers
We use analytics and error-monitoring tools (currently Sentry) to understand App usage and diagnose technical issues. These providers process usage data and crash reports on our behalf and are contractually prohibited from using that data for their own purposes. We may change or add analytics providers over time; this section will be updated accordingly.
Resend
Transactional email delivery (e.g., account confirmation, support responses).
resend.com/privacyWe may also disclose information if required by law, to enforce our Terms of Service, or to protect the rights, property, or safety of Sumerzé, our users, or the public.
Payment disputes. If a payment made in the App is disputed with a bank or card issuer (a chargeback), we share with Stripe — and, through Stripe, with the bank and card network — the information about that booking needed to respond: the customer's name and email, the service, booking dates and status, payment amounts and receipts, the customer's review, the messages exchanged between customer and provider about that booking, and photos or documents the provider supplies. Only information about the disputed booking is shared.
Publicly accessible Provider content. Provider profile information — including business name, bio, city, services, reviews, and portfolio photos. Is publicly accessible and not protected by the App's private data handling. Specifically:
We retain your account information and booking history for as long as your account is active. If you delete your account through the App, your photos are removed right away and your profile and personal data are deleted after 30 days. Bookings and messages you shared with another person stay in their history, shown as “Deleted user”, because they are part of their record too. Specific retention periods by data category:
You may access, correct, or delete your personal information at any time through the App's profile settings. To delete your account and all associated data, use the "Delete My Account" option in the Profile screen. For additional requests or questions, contact us at legal@sumerze.com.
California residents (CCPA/CPRA). Under the California Consumer Privacy Act, California residents have the following rights:
Categories of personal information collected include: identifiers (name, email, phone), commercial information (booking history, payment amounts), professional information (provider bio, services, portfolio), internet/network activity (usage analytics, push tokens), and message content (text messages exchanged between customers and providers through the in-app chat, which may be reviewed by Sumerzé as described in Section 1). We do not collect sensitive personal information beyond what is described in Section 1. To submit a verifiable consumer request, email legal@sumerze.com with the subject line "California Privacy Request."
European Economic Area & UK residents (GDPR/UK GDPR). If you are located in the EEA or UK, you have the following rights under applicable data protection law:
Our legal bases for processing personal data are: (a) contract performance. To create your account, process bookings, and facilitate payments; (b) legitimate interests. Specifically, improving platform safety, preventing fraud, detecting and investigating policy violations, and sending service-related notifications that users would reasonably expect; and (c) consent. Where you have explicitly provided it, such as agreeing to identity verification. To exercise any of these rights, contact legal@sumerze.com.
International data transfers. Sumerzé's infrastructure is hosted in the United States. If you are located in the European Economic Area (EEA) or United Kingdom, your personal data is transferred to and processed in the United States. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission with our data processors (including Supabase and Stripe) as the lawful transfer mechanism for these transfers. By using the App, you acknowledge that your data will be processed in the United States in accordance with this Privacy Policy.
We send push notifications for booking requests, booking status updates, new messages, and payment requests. You can disable push notifications at any time in your device's system settings. Disabling notifications does not affect your ability to use the App, but you may miss time-sensitive alerts.
Sumerzé is not intended for users under the age of 18. We do not knowingly collect personal information from minors. If we learn that we have collected information from a minor, we will delete it promptly.
We use industry-standard security measures including encrypted connections (HTTPS/TLS), row-level security policies on our database, and Stripe's PCI-compliant infrastructure for payment data. No method of transmission or storage is 100% secure; use the App at your own risk.
Providers may optionally participate in the Sumerzé Verified program, which confirms their real identity through a government ID check. This section explains how identity data is handled.
What we collect. When a provider initiates identity verification, Stripe Identity (a service operated by Stripe, Inc.) collects a photo of a government-issued ID document and a selfie photograph directly from the provider. Sumerzé does not receive, view, or store the ID document or selfie.
Who processes it. Identity documents and biometric data (facial geometry derived from the selfie) are processed solely by Stripe Identity. Stripe's privacy policy at stripe.com/privacy governs how this data is collected, retained, and deleted. Sumerzé receives only the verification result (approved or not approved).
What Sumerzé stores. Sumerzé stores a record of the verification outcome (verified or not), the Stripe verification session ID for audit purposes, and the date the verification was completed. We do not store any biometric data.
Purpose. Identity verification data is used only to confirm that a provider is a real person. It is not used for credit checks, background checks, advertising, or any other purpose.
Biometric data. Facial recognition and biometric comparison is performed exclusively by Stripe. Sumerzé does not use, access, or retain biometric identifiers or biometric information. Providers in states with biometric privacy laws (such as Illinois, Texas, and Washington) should review Stripe's biometric data practices at stripe.com/privacy.
Consent. Identity verification is entirely optional. Providers must explicitly consent to the collection and processing of their identity data by agreeing to the Sumerzé Verified terms before initiating the process.
Deletion. To request deletion of your Sumerzé Verified record, contact legal@sumerze.com. For deletion of identity documents processed by Stripe, contact Stripe directly per their privacy policy.
In the event of a data breach that affects your personal information, we will notify affected users as required by applicable law. Under GDPR, we will notify the relevant supervisory authority within 72 hours of becoming aware of a breach where feasible, and notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. Under applicable US state laws, we will provide notice within the timeframes required by the laws of each affected user's state. Breach notifications will be sent to the email address associated with your account.
This section applies to the Sumerzé website at sumerze.com in addition to the App.
Essential cookies. We use cookies that are strictly necessary for the website to function. For example, remembering your language preference (English or Spanish) and your cookie consent choice. These cookies do not require your consent as they are required for the site to operate.
Analytics cookies. We may use analytics tools on the website to understand how visitors navigate and use the site. These tools may set cookies or use similar tracking technologies. We ask for your consent before loading non-essential cookies, via the cookie banner displayed on your first visit.
Managing cookies. You can withdraw cookie consent at any time by clearing your browser cookies and revisiting the site, at which point the consent banner will reappear. You can also disable cookies in your browser settings, though this may affect website functionality.
In addition to the transactional and service-related messages described elsewhere in this Policy, Sumerzé may occasionally send you promotional emails about new features, referral incentives, or other marketing communications. You may opt out of marketing emails at any time by clicking the "unsubscribe" link included at the bottom of every marketing email, or by emailing support@sumerze.com with the subject line "Unsubscribe." Opting out of marketing communications does not unsubscribe you from transactional messages (such as booking confirmations, payment receipts, or security notices), which we will continue to send as needed to operate your account. In accordance with the CAN-SPAM Act, all marketing emails from Sumerzé clearly identify Sumerzé as the sender and provide a working opt-out method.
The App and our website may contain links to third-party websites or services that are not owned or controlled by Sumerzé, including payment processors, social media platforms, or external links supplied by Providers. This Privacy Policy applies only to information collected by Sumerzé. We are not responsible for the privacy practices of any third-party site, and we encourage you to review the privacy policy of any third-party website before providing it with information.
We may update this Privacy Policy from time to time. We will notify you of material changes via the App or email. Continued use of the App after changes are posted constitutes your acceptance of the updated policy.
Privacy or legal questions? legal@sumerze.com.
General support? support@sumerze.com.
Billing questions? billing@sumerze.com.