Privacy Policy
Banded Mongooses, Inc.
Effective date: July 14, 2026
This Privacy Policy describes how Banded Mongooses, Inc. (“Company,” “we,” “our,” or “us”) collects, uses, stores, shares, and protects information in connection with Evie, an AI-powered event booking, guest communication, and lead management service for restaurants, bars, venues, and hospitality businesses (“Service”), available at withevie.ai.
This policy applies to venue customers (“Customers”), guests who interact with Evie-powered booking flows (“Guests”), and visitors to our website.
1. Information We Collect
Customer information. Account and business details Customers provide, such as venue name, contact information, pricing, availability, packages, and policies, along with billing information and account credentials.
Guest information. When Guests interact with Evie, we collect the information they provide, such as name, email address, phone number, event date, headcount, occasion, budget, and preferences, along with the content of their communications with the Service.
Google user data. If a Customer connects their Google Calendar to the Service, we access calendar availability and event data, and the email address of the connected Google account, through Google’s APIs as described in Section 3.
Usage information. Standard technical and usage data, such as device information, log data, and analytics about how the Service is used.
2. How We Use Information
We use the information we collect to provide and operate the Service, facilitate Guest inquiries and bookings, send notifications and summaries to Customers, provide customer support, analyze usage and performance, improve the Service, and comply with legal obligations.
3. Google User Data
This section applies to data we access from Google APIs when a Customer connects their Google Calendar, and it supersedes any other statement in this policy or in our Terms of Service with respect to Google user data.
What we access. With the Customer’s explicit consent through Google’s OAuth flow, we request the following scopes:
openid, email — we request these basic sign-in scopes to identify the Google account being connected. We read and store the connected account’s email address solely to show you which Google account is linked and to prevent the same account from being connected twice. We do not access your name, profile picture, or any other Google profile information.
calendar.readonly — we read events on the Customer’s connected calendar solely to determine whether requested dates and times are available, so the Service only offers and confirms open time slots and prevents double-bookings.
calendar.events — when a booking is confirmed through the Service, we create an event on the Customer’s connected calendar so the reservation appears alongside the Customer’s existing events, and when a booking is cancelled we delete the event we created. We only create and delete events that originate from bookings made through the Service; we never modify or delete events the Customer created.
How we use it. Google user data is used exclusively to provide the availability-checking, booking, and calendar-management features described above, and to identify the connected Google account. We do not use Google user data for advertising of any kind, we do not sell Google user data, we do not transfer it to data brokers or information resellers, we do not use it to determine credit-worthiness or for lending purposes, and we do not use it to develop, improve, or train generalized artificial intelligence or machine learning models. These restrictions apply equally to raw Google user data and to any aggregated, anonymized, or derived data created from it.
How we store and protect it. OAuth tokens and calendar data are stored encrypted at rest and transmitted only over encrypted connections (TLS). Access is restricted to systems and personnel that require it to operate the Service.
How we share it. We do not transfer or disclose Google user data to third parties except as necessary to provide the features described above (for example, our cloud hosting infrastructure). Google user data is not shared with, or processed by, any third-party AI/ML service, and is never used to develop, improve, or train AI/ML models. We may also disclose Google user data to comply with applicable law, or as part of a merger or acquisition with notice to affected users. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Revoking access. Customers may disconnect their Google Calendar at any time from their Service dashboard or by revoking access through their Google Account security settings. Upon disconnection, we immediately delete stored OAuth tokens and cease all access to the Customer’s calendar, and we delete any stored Google user data from our systems, including backups, within 30 days.
5. Data Security
We maintain administrative, technical, and physical safeguards designed to protect personal information, including encryption of data in transit and at rest, access controls, and security procedures to protect the confidentiality of your data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
6. Data Retention and Deletion
We retain personal information for as long as needed to fulfill the purposes described in this policy, to operate the Service, and to comply with legal obligations. When the applicable retention period expires, we delete or de-identify the data. Customers and Guests may request deletion of their personal information by contacting us at support@withevie.ai; we will respond within the timeframe required by applicable law. Google user data is deleted as described in Section 3 upon disconnection, and in any event upon account termination.
7. Your Rights
Depending on your location, you may have rights to access, correct, delete, or port your personal information, and to object to or restrict certain processing. To exercise these rights, contact us at support@withevie.ai.
8. Children’s Privacy
The Service is intended for business use and is not directed to children under 13. We do not knowingly collect personal information from children.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page with a revised effective date, and we will notify users of material changes to how we handle Google user data before they take effect.
10. Contact
Banded Mongooses, Inc.
