Legal
Attorney note — notice at collection placement
This summary is placed at the top to serve as the CPRA notice at collection. Please confirm a link to it also appears at the actual points of collection (signup form, quiz, SMS opt-in), and that the categories map cleanly onto the statutory buckets in Civ. Code §1798.140(v).
This Privacy Policy applies to CurateVIP LLC, a Wyoming limited liability company and a wholly-owned subsidiary of RMK GROUP LLC, doing business as CURATEvip ("we," "us," or "our"). We operate the websites and applications at curatevip.app, curatevip.ai, and book.curatevip.ai (together, the "Service").
For privacy questions or requests, contact us at members@curatevip.app, or write to us at CurateVIP LLC, c/o RMK GROUP LLC, 254 Chapman Rd, Ste 208 #23854, Newark, DE 19702.
Attorney note — confirm CPRA request methods
The mailing address is supplied and now doubles as a second method for submitting privacy requests alongside email. Confirm that is sufficient — a postal address generally counts, but a web form or the in-app Profile page may work better in practice, since postal requests to a forwarding suite are slow against the 45-day response clock.
Information you give us directly:
Text message (SMS) information:
Information collected automatically:
Payment information:
Attorney note — sensitive data classification
Two classification calls to confirm. Net worth band: a self-reported band is likely outside CPRA's enumerated "sensitive personal information" list, but it is high-sensitivity in practice; consider treating it as SPI voluntarily. Inbound SMS content: the contents of text messages are enumerated SPI unless the business is the intended recipient. CurateVIP is the intended recipient of replies to its own number, which is the exemption relied on below — but that should be confirmed for any message that gets forwarded to or processed by a third party for a purpose other than replying to the member.
We do not use your quiz answers, taste profile, or net worth information to target advertising, and we do not sell or license that data.
We use automated systems, including third-party AI models, to help generate recommendations and written content for you. Information such as your preferences, cities, and quiz-derived profile may be sent to an AI provider for processing so it can produce those recommendations. These systems inform curation; they do not make decisions that produce legal or similarly significant effects about you.
Attorney note — AI processing and ADMT
Travel curation should sit outside California's automated decision-making technology rules, which attach to "significant decisions" in lending, housing, education, employment and healthcare. Worth a second look, though: if the self-reported net worth band is used to accept or reject membership applicants, counsel should consider whether that is automated decision-making and whether any fair-access theory attaches. Also please confirm the AI vendor's contract actually prohibits training on CurateVIP customer data before this paragraph is published as written.
We do not sell your personal information. We share it with service providers who process it on our behalf, under contract, and who are not permitted to use it for their own purposes:
We may also disclose information:
We do not share your phone number with third parties for their own marketing, and we do not sell it.
Attorney note — vendor contracts and the Google Analytics question
Confirm a signed DPA with CPRA service-provider terms is in place with every vendor named above. Without those terms a disclosure can be recharacterized as a "sale" or "sharing," which would contradict the no-sale statement in Section 11. Google Analytics specifically: if advertising features or signals are enabled, plaintiffs treat that as sharing for cross-context behavioral advertising. Please confirm those features are off, or the policy needs to disclose sharing and the site needs a working opt-out mechanism.
Your Speed profile is the taste fingerprint we derive from your quiz answers, your stated cities, and how you use the Service. We use it to power your recommendations. We do not sell it, and we do not share it with venues or advertisers for their own use.
We may use aggregated or de-identified data, which cannot reasonably be used to identify you, to improve our curation and the Service. Where we hold data in de-identified form, we maintain it in that form and do not attempt to re-identify it.
Federal law regulating automated text messages requires businesses to be able to prove that a person agreed to be texted. To meet that obligation, when you opt in we record:
We keep this consent record as legal evidence. Please note: we retain the SMS consent record even after you close your account or ask us to delete your data. We do this because the record is what protects both of us if there is ever a dispute about whether you agreed to receive messages, and because the law permits a business to retain information needed to establish or defend a legal claim and to comply with legal obligations. If you delete your account, we stop texting you, and the consent record is retained separately for that limited legal purpose only — it is not used for marketing or profiling.
To stop receiving texts at any time, reply STOP to any message, or email members@curatevip.app.
Attorney note — corrected an inaccurate deletion promise
The previous policy promised that on an account deletion request all personal data would be "deleted or anonymized within 30 days." That was not accurate as built — the SMS consent record and the full inbound message log are retained indefinitely. A deletion promise the system does not keep is itself an exposure, so it has been removed and replaced with the accurate statement above.
Counsel to confirm: (a) that the legal-claims exemption is the right basis for retaining consent records after deletion; (b) whether retention should be bounded — CPRA requires disclosing a retention period or the criteria for setting one, and "indefinite" is disfavored; a period tied to the TCPA limitations period plus a margin is the usual approach; and (c) whether the full body of every inbound reply genuinely needs indefinite retention, which is a weaker justification than the consent record itself. Recommend the client set a defined retention period and implement an automated purge.
Attorney note — retention periods need to be set
CPRA requires a retention period for each category, or the criteria used to determine it. The bullets above are accurate but several are open-ended. The client should adopt a written retention schedule with concrete periods — particularly for billing records, booking records, and inbound SMS content — and this section should then be updated to state them.
We take reasonable technical and organizational measures to protect your personal information. Traffic between you and the Service is encrypted in transit, access to member data is restricted, and our database and payment providers apply their own security controls.
No method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security.
Attorney note — softened unsubstantiated security claims
The prior policy claimed "industry-standard" measures including encryption at rest and "regular security reviews." Those are specific, auditable claims and overstated security representations are a standard FTC Section 5 theory after a breach, so they have been narrowed to what is readily substantiated. If the client can document encryption at rest and a review cadence, the stronger language can be restored. Please also confirm no certification (SOC 2, ISO, PCI) is claimed anywhere on the site, since none is held.
If you are a California resident, you have the following rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act.
Right to know. You can ask us to tell you the categories and specific pieces of personal information we have collected about you, where we got it, why we collected it, and the categories of third parties we disclosed it to.
Right to delete. You can ask us to delete the personal information we collected from you. We must honor that request unless an exception applies — for example, where we need the information to complete a transaction, detect security incidents, comply with a legal obligation, or establish, exercise, or defend a legal claim. As explained in Section 7, we retain SMS consent records after deletion on that last basis, and we retain billing records as required for tax and accounting.
Right to correct. You can ask us to correct inaccurate personal information we hold about you. Much of it you can correct yourself in your Profile.
Right to opt out of sale or sharing. You can direct us not to sell your personal information and not to share it for cross-context behavioral advertising. We do not sell or share your personal information, so there is nothing to opt out of — but the right exists and you may exercise it. See Section 11.
Right to limit use of sensitive personal information. You can direct a business to limit its use of sensitive personal information to what is necessary to provide the service. We only use any sensitive personal information we hold for those permitted purposes — to run your membership, respond to you, secure the Service, and meet legal obligations — so no additional limitation is required. You may still submit a request.
Right to non-discrimination. We will not deny you service, charge you a different price, or give you a lower quality of service because you exercised a privacy right. We do not offer financial incentives in exchange for personal information.
Right to data portability. You can ask for the personal information you gave us in a portable, readily usable format.
How to submit a request. Email members@curatevip.app with the subject line "Privacy Request," from the email address on your account, and tell us which right you are exercising. We will confirm receipt within 10 business days and respond within 45 calendar days, and we may extend by another 45 days if we tell you why. We will ask you to verify your identity before we act on a request to know, delete, or correct — usually by confirming information already associated with your account. We do not charge a fee unless a request is manifestly unfounded or excessive.
Authorized agents. You may use an authorized agent to submit a request on your behalf. We will ask the agent for written permission signed by you, and we may ask you to verify your own identity directly with us and to confirm that you gave the agent permission. An agent registered with the California Secretary of State may submit proof of that registration instead.
Appeals and complaints. If we deny your request, you may ask us to reconsider by replying to our response. You may also file a complaint with the California Privacy Protection Agency or the California Attorney General.
Attorney note — does CCPA actually apply yet?
Confirm whether CurateVIP LLC currently meets a CCPA "business" threshold. An invite-only startup at $299/yr very likely does not meet the revenue or 100,000-consumer thresholds, so the statute may not yet apply. The client can either comply voluntarily and keep this section as drafted — good practice and good optics, but it creates real commitments including the 45-day clock and a verification workflow — or state that it is not a covered business and offer the rights as a matter of policy without statutory deadlines. Recommend the former only if the client can actually meet the deadlines. Separately, counsel should decide whether to add a multi-state rights section (Colorado, Connecticut, Virginia, Texas, Oregon) now or on growth.
Attorney note — verify before publishing an absolute no-sale statement
This statement holds only if every vendor is under a valid service-provider contract and no advertising or analytics tag transmits identifiers to an ad network. Please verify the actual tags loading on curatevip.app and curatevip.ai (Google Analytics advertising features, any Meta pixel, any remarketing tag). If any ad tech is present, CPRA requires a working "Do Not Sell or Share My Personal Information" link in the site footer and honoring of Global Privacy Control signals — neither exists today, and this is among the most commonly pled CPRA violations.
We use cookies and similar technologies to keep you signed in, remember your preferences, and understand how the Service is used. Some are necessary for the Service to work; others support analytics.
You can control cookies through your browser settings. Blocking some cookies may break parts of the Service.
We do not currently respond to browser "Do Not Track" signals, because no common standard for them has been adopted.
Attorney note — Global Privacy Control vs. Do Not Track
The Do Not Track sentence is accurate and permitted, but DNT is not the same as Global Privacy Control. California requires businesses that sell or share to honor GPC. If the no-sale statement in Section 11 is confirmed, GPC handling is not strictly required; if any ad tech is found, GPC support must be implemented and this paragraph rewritten.
The Service is for adults. It is not directed to anyone under 18, and we do not knowingly collect personal information from anyone under 18. If we learn we have collected information from someone under 18, we will delete it promptly. If you believe we have, contact members@curatevip.app.
CURATEvip is operated from the United States and is intended for United States residents. Your information is stored and processed in the United States, and our service providers may process it in other countries where they operate. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States, where privacy laws may differ from those in your country.
Attorney note — US-only assumption
This is drafted on the assumption that the product is sold only to US consumers, so no GDPR transfer mechanism is claimed. If the client ever markets to or accepts EU/UK members, this section plus a lawful-basis section and a standard contractual clauses analysis all become necessary.
The Service links to third-party websites and services, including hotel and venue sites. This Policy does not apply to them. Please review their privacy policies before giving them information.
We may update this Privacy Policy. When we make material changes, we will update the effective date above and give notice through the Service or by email. Your continued use of the Service after an update constitutes acceptance of the revised Policy.
For questions about this Policy, or to submit a privacy request:
CurateVIP LLC
A Wyoming Limited Liability Company · A wholly-owned subsidiary of RMK GROUP LLC
Email: members@curatevip.app
Mailing address: c/o RMK GROUP LLC, 254 Chapman Rd, Ste 208 #23854, Newark, DE 19702
See also our Terms & Conditions.