Sari la conținutul principal

Privacy Policy

Last updated: 30 July 2026

This Privacy Policy explains how SeatPlanning ("we", "us") collects, uses and protects personal data when you use our seating-chart application and website, in accordance with the EU General Data Protection Regulation (GDPR). Our free seating-chart tool needs no account: what you create there is saved in your own browser's local storage so you do not lose it, and it is not sent to or stored on our servers. Clearing your browser data removes it.

1. Data Controller

The controller responsible for your personal data is MIVO STUDIO S.R.L., reachable at contact@seatplanning.com. Full company details (registered office, Trade Register number and CUI) are available in our Imprint. We act as a data controller for the account and website data we process for our own purposes (such as registration, billing and analytics), and as a data processor for the guest data you collect through the service, as described in our Data Processing Agreement. We are not required to appoint a Data Protection Officer and have not appointed one; privacy questions reach us directly at contact@seatplanning.com.

2. Information We Collect

We collect information that you provide directly to us. An email address is necessary to create an account and for us to enter into a contract with you; without it we cannot provide the service. Everything else is optional.

  • Name and email address when you create an account
  • Profile information you choose to provide
  • Billing details processed by our payment provider when you subscribe, including your country and any tax ID you enter
  • Event and guest data you add to your seating charts (including guest names, contact details and any RSVP fields you configure)
  • Special categories: dietary, allergy or accessibility details entered in an RSVP field can qualify as health data under Art. 9 GDPR. These fields are always optional, and we process their content only to make it available to the event organizer who asked for it.
  • Communications with us (support requests, live-chat messages, feedback)
  • Usage data, device/browser information and preferences
  • Your IP address, used transiently to apply rate limits and to protect the service against abuse

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our services
  • Process and complete transactions, issue invoices and manage subscriptions
  • Send you technical notices, security alerts and support messages
  • Respond to your comments and questions
  • With your consent, measure usage and send product updates
  • Detect, prevent and address fraud, abuse and security issues

4. Legal Bases for Processing

We process personal data on the following legal bases under Art. 6 GDPR:

  • Performance of a contract (Art. 6(1)(b)) — to provide the service you sign up for
  • Consent (Art. 6(1)(a)) — for non-essential analytics, session replay, live-chat and marketing emails; you may withdraw consent at any time
  • Legitimate interests (Art. 6(1)(f)) — to keep the service secure, to prevent fraud and abuse, and to keep our email deliverable by not re-sending to addresses that rejected our mail
  • Legal obligation (Art. 6(1)(c)) — to meet accounting, tax and other statutory requirements
  • Where an RSVP field contains health-related information such as an allergy, the event organizer is responsible for the explicit consent required under Art. 9(2)(a) GDPR; we process it only on their behalf

5. Automated Decision-Making

We do not make decisions about you solely by automated means that produce legal effects or similarly significantly affect you, and we do not carry out profiling of that kind. We do use an AI assistant to help answer support messages: when a reply is sent by the assistant without a person reviewing it first, it is labelled as AI-generated, and you can ask for a human at any point in the conversation.

6. Information Sharing

We do not sell your personal data. We share it only with the service providers (processors) that help us run SeatPlanning, and where required to comply with the law or protect our rights. All processors are bound by data-processing agreements.

  • With service providers (sub-processors) listed below who process data on our behalf
  • To comply with legal obligations or valid legal requests
  • To protect our rights, users and the security of the service
  • In connection with a merger, acquisition or asset sale, with appropriate safeguards

7. Sub-processors

We rely on the following providers to operate the service. Each is bound by a data-processing agreement and processes personal data only on our instructions:

  • Supabase — database, authentication and file storage
  • Vercel — application hosting, content delivery and cookieless website analytics
  • Stripe — payment and subscription processing (name, email, billing country, any tax ID)
  • Resend — transactional and lifecycle email delivery (recipient address, name, message content)
  • PostHog (EU-hosted) — product analytics and optional session replay
  • Upstash — rate limiting and abuse protection (processes IP addresses and email addresses as lookup keys)
  • Anthropic — AI-assisted support replies (your name, email address and the chat conversation)
  • Chatwoot — live-chat support (your account identifier, email, name and chat transcripts)
  • Google — sign-in with Google, and the address autocomplete offered when you set an event location
  • Oblio — invoicing and accounting. For Romanian customers, invoice data is submitted onward to the Romanian tax authority (ANAF) through the national e-invoicing system, as the law requires.
  • Telegram — internal operational alerts to our own team, which can include an account identifier

8. International Data Transfers

We keep data in the EU/EEA where we can: our product analytics (PostHog) is EU-hosted and our invoicing provider (Oblio) is established in Romania. Some providers are established in the United States or process data there, including Vercel, Stripe, Resend, Anthropic, Upstash, Google, Chatwoot and Telegram. Those transfers rely on appropriate safeguards under Chapter V GDPR: the EU Standard Contractual Clauses, and where applicable the provider's certification under the EU-U.S. Data Privacy Framework. Email us at contact@seatplanning.com for a copy of the safeguards that apply to a specific provider.

9. What Other People Can See

Charts stay private unless you decide otherwise. If you turn on public viewing or share an invite link, please be aware of what that link exposes:

  • Anyone holding the link can see the event name, date and location, the seating layout, and the first and last name of each guest together with their RSVP status and assigned seat.
  • Guest email addresses, phone numbers and free-text notes are never exposed through a public chart or an invite link.
  • An invite link is a single link shared with every guest, so any one guest who has it can see the rest of the guest list.
  • You can turn public viewing off, protect a public chart with a password, or stop sharing the link at any time.

10. Data Security

We implement appropriate technical and organizational measures to protect personal information against unauthorized access, alteration, disclosure or destruction. These include encryption in transit, row-level security on every database table, scoped access rules on stored files, rate limiting, and signature verification on the webhooks we receive.

11. Data Retention

How long we keep personal data depends on why we hold it:

  • Account data: kept while your account is active. Deleting your account deletes your profile, your charts, the guest data inside them, your support conversations, your email delivery history and anything you uploaded.
  • Guest data: kept for the life of the related chart, and deleted when you delete that chart or your account.
  • Operational logs, independent of account deletion: QR entry/check-in logs for 24 months, email delivery logs for 12 months, support conversations for 24 months after the last message, and bug/feedback reports (including any screenshot) for 18 months. A scheduled job removes these automatically once each period ends.
  • Invoices and payment records: kept for as long as accounting and tax law requires, which in Romania is ten years. These are held in our invoicing system rather than in your account.
  • Withdrawal-waiver records: the acknowledgment you give at checkout is kept as evidence for as long as a related claim could still be brought, including after you close your account. It is kept without your account identifier and linked only to the payment reference.
  • Email suppression list: if an address bounces or reports our mail as spam, that address stays on a suppression list after account deletion. Removing it would mean starting to email again someone who asked us to stop.
  • You can ask us to delete anything we are not legally required or entitled to keep by writing to contact@seatplanning.com.

12. Your Rights

Under the GDPR you have the right to:

  • Access your personal information
  • Correct inaccurate data
  • Request deletion of your data ('right to be forgotten')
  • Restrict or object to processing of your data
  • Data portability — export your data in a machine-readable format, which you can do yourself from your account settings
  • Withdraw consent at any time, without affecting prior processing
  • To exercise any of these, email contact@seatplanning.com. We respond within one month, and will tell you if we need longer.

13. U.S. State Privacy Rights

We do not sell your personal data. If you live in a U.S. state with a comprehensive privacy law (such as California under the CCPA/CPRA, or Colorado, Connecticut, Texas or Virginia), you have the right to know what personal data we hold, to access, correct or delete it, and to opt out of any "sale" or "sharing" of personal data. Because we do not sell or share personal data for cross-context behavioral advertising, no opt-out is required, but you may still exercise your rights by contacting us at contact@seatplanning.com.

14. Children's Privacy

SeatPlanning is intended for adults organizing events and is not directed to children. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data without the involvement of a parent or guardian, contact us at contact@seatplanning.com and we will delete it.

15. Right to Lodge a Complaint

If you believe we have not handled your personal data lawfully, please contact us first at contact@seatplanning.com so we can try to put it right. You also have the right to lodge a complaint with a data-protection supervisory authority. Our lead authority is the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 Bucharest, Romania, anspdcp@dataprotection.ro, www.dataprotection.ro. If you live or work in another EU/EEA country, you may complain to your local supervisory authority instead.

16. Cookies and Tracking

We use strictly necessary cookies to run the service and, only with your consent, non-essential cookies for product analytics, session replay and live-chat support. You can manage your choices at any time via the cookie settings. See our Cookie Policy for the full detail.

17. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the new version on this page and update the "Last updated" date. If a change materially affects how we use your data, we will tell you directly.

18. Contact Us

If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us at contact@seatplanning.com.