Skip to main content

Privacy Policy

Last updated: 4 September 2026

This Privacy Policy explains how SeatPlanning ("we", "us") collects, uses and protects personal data when you use our seating-chart application and website, in accordance with the EU General Data Protection Regulation (GDPR). Our free seating-chart tool needs no account: what you create there is saved in your own browser's local storage so you do not lose it, and it is not sent to or stored on our servers. Clearing your browser data removes it.

1. Data Controller

The controller responsible for your personal data is MIVO STUDIO S.R.L., reachable at contact@seatplanning.com. Full company details (registered office, Trade Register number and CUI) are available in our Imprint. We act as a data controller for the account and website data we process for our own purposes (such as registration, billing and analytics), and as a data processor for the guest data you collect through the service, as described in our Data Processing Agreement. We are not required to appoint a Data Protection Officer and have not appointed one; privacy questions reach us directly at contact@seatplanning.com.

2. Information We Collect

We collect information that you provide directly to us. An email address is necessary to create an account and for us to enter into a contract with you; without it we cannot provide the service. Everything else is optional.

  • Name and email address when you create an account
  • Profile information you choose to provide
  • Billing details processed by our payment provider when you subscribe, including your country and any tax ID you enter
  • Event and guest data you add to your seating charts (including guest names, contact details and any RSVP fields you configure)
  • Special categories: dietary, allergy or accessibility details entered in an RSVP field can qualify as health data under Art. 9 GDPR. These fields are always optional, and we process their content only to make it available to the event organizer who asked for it.
  • Communications with us (support requests, live-chat messages and any screenshot you attach to them, feedback)
  • Usage data, device/browser information and preferences
  • Your IP address, used transiently to apply rate limits and to protect the service against abuse
  • How you found us: the campaign, referring website and landing page of your first visit, recorded in a first-party cookie and attached to your account when you register

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our services
  • Process and complete transactions, issue invoices and manage subscriptions
  • Send you technical notices, security alerts and support messages
  • Respond to your comments and questions
  • With your consent, measure usage and send product updates
  • Detect, prevent and address fraud, abuse and security issues
  • Understand which marketing channels bring people to SeatPlanning, and — only with your consent — report to the advertising platform that a click became a signup or a purchase

4. Legal Bases for Processing

We process personal data on the following legal bases under Art. 6 GDPR:

  • Performance of a contract (Art. 6(1)(b)) — to provide the service you sign up for
  • Consent (Art. 6(1)(a)) — for non-essential analytics, session replay, live-chat, advertising measurement and marketing emails; you may withdraw consent at any time
  • Legitimate interests (Art. 6(1)(f)) — to keep the service secure, to prevent fraud and abuse, to keep our email deliverable by not re-sending to addresses that rejected our mail, and to record which marketing channel brought you to us (a first-party record only, never shared)
  • Legal obligation (Art. 6(1)(c)) — to meet accounting, tax and other statutory requirements
  • Where an RSVP field contains health-related information such as an allergy, the event organizer is responsible for the explicit consent required under Art. 9(2)(a) GDPR; we process it only on their behalf

5. Automated Decision-Making

We do not make decisions about you solely by automated means that produce legal effects or similarly significantly affect you, and we do not carry out profiling of that kind. We do use an AI assistant to help answer support messages: when a reply is sent by the assistant without a person reviewing it first, it is labelled as AI-generated, and you can ask for a human at any point in the conversation.

6. Information Sharing

We do not sell your personal data. We share it only with the service providers (processors) that help us run SeatPlanning, and where required to comply with the law or protect our rights. All processors are bound by data-processing agreements.

  • With service providers (sub-processors) listed below who process data on our behalf
  • With advertising platforms, only where you accepted analytics cookies, and only to confirm that an ad click led to a signup or purchase — your email address is hashed before it is sent and is never disclosed in the clear
  • To comply with legal obligations or valid legal requests
  • To protect our rights, users and the security of the service
  • In connection with a merger, acquisition or asset sale, with appropriate safeguards

7. Sub-processors

We rely on the following providers to operate the service. Each is bound by a data-processing agreement and processes personal data only on our instructions:

  • Supabase — database, authentication and file storage
  • Vercel — application hosting, content delivery and cookieless website analytics
  • Stripe — payment and subscription processing (name, email, billing country, any tax ID)
  • Resend — transactional and lifecycle email delivery (recipient address, name, message content)
  • PostHog (EU-hosted) — product analytics and optional session replay
  • Upstash — rate limiting and abuse protection (processes IP addresses and email addresses as lookup keys)
  • Anthropic — AI-assisted support replies (your name, email address and the chat conversation)
  • Live chat — the messages you send us and any name or email you give. Conversations are stored on our own infrastructure (Supabase, EU) and replies are drafted by Anthropic
  • Google — sign-in with Google, and the address autocomplete offered when you set an event location
  • Oblio — invoicing and accounting. For Romanian customers, invoice data is submitted onward to the Romanian tax authority (ANAF) through the national e-invoicing system, as the law requires.
  • Telegram — internal operational alerts to our own team, and support conversations: your messages, our assistant's replies and an anonymous conversation reference (never your name or email). Screenshots you attach are not sent there — they stay on our own infrastructure and our team opens them from our admin tools.
  • OpenAI — ChatGPT Ads measurement, only if you accepted analytics cookies. Receives your IP address, browser information, the address of our site and the ad click identifier, plus a hashed (irreversible) form of your email address when you sign up or buy. Its pixel sets its own __oppref and __obref cookies and can detect supported customer information present on the page, hashing it in your browser before sending; this cannot be switched off separately, so declining analytics cookies is what stops it.
  • Meta — the same advertising measurement for Facebook and Instagram ads, on the same consent condition and with the same hashed data, when we run those campaigns.

8. International Data Transfers

We keep data in the EU/EEA where we can: our product analytics (PostHog) is EU-hosted and our invoicing provider (Oblio) is established in Romania. Some providers are established in the United States or process data there, including Vercel, Stripe, Resend, Anthropic, Upstash, Google, Telegram and — where you consented to advertising measurement — OpenAI and Meta. Those transfers rely on appropriate safeguards under Chapter V GDPR: the EU Standard Contractual Clauses, and where applicable the provider's certification under the EU-U.S. Data Privacy Framework. Email us at contact@seatplanning.com for a copy of the safeguards that apply to a specific provider.

9. What Other People Can See

Charts stay private unless you decide otherwise. If you turn on public viewing or share an invite link, please be aware of what that link exposes:

  • Anyone holding the link can see the event name, date and location, the seating layout, and the first and last name of each guest together with their RSVP status and assigned seat.
  • Guest email addresses, phone numbers and free-text notes are never exposed through a public chart or an invite link.
  • An invite link is a single link shared with every guest, so any one guest who has it can see the rest of the guest list.
  • You can turn public viewing off, protect a public chart with a password, or stop sharing the link at any time.

10. Data Security

We implement appropriate technical and organizational measures to protect personal information against unauthorized access, alteration, disclosure or destruction. These include encryption in transit, row-level security on every database table, scoped access rules on stored files, rate limiting, and signature verification on the webhooks we receive.

11. Data Retention

How long we keep personal data depends on why we hold it:

  • Account data: kept while your account is active. Deleting your account deletes your profile, your charts, the guest data inside them, your support conversations, your email delivery history and anything you uploaded.
  • Guest data: kept for the life of the related chart, and deleted when you delete that chart or your account.
  • How you found us: kept for as long as your account exists, and deleted with it.
  • Operational logs, independent of account deletion: QR entry/check-in logs for 24 months, email delivery logs for 12 months, support conversations for 90 days after the last message, and bug/feedback reports (including any screenshot) for 18 months. A scheduled job removes these automatically once each period ends.
  • Invoices and payment records: kept for as long as accounting and tax law requires, which in Romania is ten years. These are held in our invoicing system rather than in your account.
  • Withdrawal-waiver records: the acknowledgment you give at checkout is kept as evidence for as long as a related claim could still be brought, including after you close your account. It is kept without your account identifier and linked only to the payment reference.
  • Email suppression list: if an address bounces or reports our mail as spam, that address stays on a suppression list after account deletion. Removing it would mean starting to email again someone who asked us to stop.
  • You can ask us to delete anything we are not legally required or entitled to keep by writing to contact@seatplanning.com.

12. Your Rights

Under the GDPR you have the right to:

  • Access your personal information
  • Correct inaccurate data
  • Request deletion of your data ('right to be forgotten')
  • Restrict or object to processing of your data
  • Data portability — export your data in a machine-readable format, which you can do yourself from your account settings
  • Withdraw consent at any time, without affecting prior processing
  • To exercise any of these, email contact@seatplanning.com. We respond within one month, and will tell you if we need longer.

13. U.S. State Privacy Rights

We do not sell your personal data. If you live in a U.S. state with a comprehensive privacy law (such as California under the CCPA/CPRA, or Colorado, Connecticut, Texas or Virginia), you have the right to know what personal data we hold, to access, correct or delete it, and to opt out of any "sale" or "sharing" of personal data. We never sell personal data. The only processing that may count as "sharing" for cross-context behavioral advertising is the advertising measurement described in section 6, which happens only if you accept analytics cookies — so declining them, or withdrawing at any time in the cookie settings, is your opt-out. You may also exercise any of these rights by contacting us at contact@seatplanning.com.

14. Children's Privacy

SeatPlanning is intended for adults organizing events and is not directed to children. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data without the involvement of a parent or guardian, contact us at contact@seatplanning.com and we will delete it.

15. Right to Lodge a Complaint

If you believe we have not handled your personal data lawfully, please contact us first at contact@seatplanning.com so we can try to put it right. You also have the right to lodge a complaint with a data-protection supervisory authority. Our lead authority is the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 Bucharest, Romania, anspdcp@dataprotection.ro, www.dataprotection.ro. If you live or work in another EU/EEA country, you may complain to your local supervisory authority instead.

16. Cookies and Tracking

We use strictly necessary cookies to run the service, one first-party cookie recording how you found us, and — only with your consent — non-essential cookies for product analytics, session replay, advertising measurement and live-chat support. You can manage your choices at any time via the cookie settings. See our Cookie Policy for the full detail.

17. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the new version on this page and update the "Last updated" date. If a change materially affects how we use your data, we will tell you directly.

18. Contact Us

If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us at contact@seatplanning.com.