Skip to content
HELM

Legal

Privacy Policy

Last updated: September 9, 2026

Contents

  • 1. Information we collect
  • 2. How we use information
  • 3. How we share information
  • 4. Consent records
  • 5. Your privacy rights
  • 6. Data retention
  • 7. Security
  • 8. Children
  • 9. Changes
  • 10. Contact

HELM, Inc., a Delaware corporation (“HELM,” “we,” “us,” “our”) respects your privacy. This Privacy Policy explains what personal information we collect, how we use and share it, and the choices and rights you have. It applies to the HELM website, apps, and services (the “Platform”). HELM currently operates only in the United States.

1. Information we collect

  • Account & profile: name, email, phone number, role, and (for Chefs) profile content such as bio, photos, specialties, and service details.
  • Bookings & transactions: event details, guests, location, allergies/notes, pricing, and payment status. Card details are collected and processed by Stripe; HELM does not store full card numbers.
  • Receipts & expense review: receipt images or PDFs, merchant and purchase details, line items, totals, approval decisions, and dispute notes. Receipts can include names, loyalty identifiers, or partial payment-card information.
  • Content you submit: messages between hosts and Chefs, reviews, and support requests.
  • Consent records: your acceptance of our terms and your SMS/marketing consent, with version, timestamp, and technical metadata (see “Consent records”).
  • Technical data: device, log, and usage data, and information from cookies and similar technologies (see our Cookie Policy).
  • Analytics (only if you choose “Accept all”): pages viewed, searches run (role, state, guest range, whether a date was chosen), results counts, and the steps you complete in a booking or provider application. These records use a random device identifier and, if you are signed in, a one-way hashed version of your account ID — never your name, email address, phone number, or street address. Analytics is off until you opt in, and Global Privacy Control or a browser “Do Not Track” setting keeps it off even if you previously opted in.

2. How we use information

We use personal information to operate the Platform: to create and secure your account, match hosts with Chefs, process bookings and payments, enable messaging, send transactional communications, provide support, prevent fraud and abuse, comply with law, and improve our services. Where you have opted in, we may send marketing communications.

3. How we share information

  • Between hosts and Chefs: to coordinate a booking, we share the information each party needs (e.g., name, contact, event details).
  • Service providers (subprocessors): Stripe (payments/payouts), Supabase (database, authentication, storage/hosting), Anthropic (AI-assisted receipt parsing, and AI-assisted drafting of Chef profile and service descriptions), GoHighLevel (SMS/email delivery and CRM), Google LLC (Google Analytics 4 — website traffic and campaign measurement, only with your “Accept all” consent), PostHog Inc. (product analytics, United States region, only with your “Accept all” consent), and our application hosting provider. AI outputs are always suggestions that a person reviews: receipt fields are checked by our team before any decision, and profile or service drafting runs only when a Chef requests it, uses only information that Chef has provided to HELM (such as their profile details, work history, and notes they type), and publishes nothing until the Chef reviews, edits, and saves the result. Per our agreement with Anthropic, this information is not used to train Anthropic's models.
  • Legal & safety: where required by law or to protect rights, safety, and the integrity of the Platform.
  • Business transfers: in connection with a merger, acquisition, or sale of assets.

We do not sell your personal information for money, and HELM does not disclose personal information for cross-context behavioral advertising. Our analytics is configured for measurement only: Google Signals, advertising personalization, and Google Ads linkage are disabled; PostHog session recording and autocapture are off; and PostHog events reach us through a HELM-owned first-party path that does not forward your IP address. HELM recognizes the Global Privacy Control (GPC), which overrides both optional attribution consent and analytics consent.

4. Consent records

We keep an auditable record of the policies you accept (Terms, Privacy) and your SMS/marketing consent — including the policy version, the time, and technical metadata — so we can honor and evidence your choices.

5. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, or export your personal information, and to opt out of certain sharing. Signed-in customers can download a portable JSON export or submit and track a verified deletion request from Account > Profile > Your data. We verify those requests through the authenticated account session. You may also contact us at hello@itshelm.com; we will respond within the time required by law. Global Privacy Control overrides optional attribution and analytics consent. You can withdraw analytics consent at any time through “Cookie preferences” in the site footer; withdrawing stops collection immediately and deletes the analytics cookies from your browser. HELM installs no advertising or session-replay SDK.

6. Data retention

We retain personal information for as long as your account is active and as needed to provide the Platform, and thereafter as required for legal, tax, accounting, fraud-prevention, chargeback, and dispute purposes. When a verified deletion request is fulfilled, HELM removes or pseudonymizes account identifiers, saved preferences, messages/review free text, CRM contact data, reusable payment-customer data, and booking address/health/free-text details. We retain the minimum pseudonymized booking and transaction ledger, consent history, privacy-request record, and any legal-hold evidence required for those purposes. Our current operational default is to delete receipt files and parsed line-item detail 24 months after the later of settlement or refund/dispute closure, unless a legal hold or accounting obligation requires longer retention.

Analytics retention — PLACEHOLDER — counsel to confirm. Our proposed configuration is Google Analytics 4 user-and-event data retention set to 2 months, and PostHog event retention per that project's settings. These values are a proposal, not a commitment, until counsel confirms them; this paragraph is replaced with the confirmed language before analytics is enabled in production.

7. Security

We use administrative, technical, and organizational safeguards designed to protect personal information, including access controls and encryption in transit. No system is perfectly secure; we cannot guarantee absolute security.

8. Children

The Platform is not directed to individuals under 18, and we do not knowingly collect personal information from them.

9. Changes

We may update this Policy. Material changes will be communicated through the Platform. The “last updated” date reflects the latest revision.

10. Contact

Privacy questions or requests: hello@itshelm.com.

HELM

Hospitality Exchange | Luxury Marketplace

© 2026 HELM

Company

About HELMOur TeamWork with HELM

Services

Private ChefsEvent ServersBartenders & Mixologists

Resources

How HELM WorksFAQsGuidesPerspectivesContact Us

Legal

TermsPrivacyCookies
Legal·