Privacy & Data Protection

Privacy Policy

Last updated: 11 September 2026

Privacy Policy

This Privacy Policy explains how ZNZ Systems Ltd. ("we," "our," "us") collects, uses, and protects your personal data when you use SeatPlan.io - our web application (the "Service").

1. Information We Collect

If you do not sign up:

  • Your seating chart is stored only in your browser's local storage. It is automatically deleted at midnight and never transmitted to our servers.

If you sign up for an account:

  • We collect the following guest information you choose to enter:
  • • Name
  • • Email address
  • • Dietary requirements
  • • Comments
  • We also collect your account details through our authentication provider when you sign in.

If you use subscription features (templates, events, collaboration):

  • Templates and events you create, including event names, dates, and room configurations.
  • Guest seating data within your templates (names, dietary requirements, table assignments).
  • Collaboration invitations: email addresses of clients you invite to view or edit your seating charts.
  • Email engagement data: when collaboration invitation emails are opened or links are clicked.

2. How We Use Your Information

We use your information to:

  • Provide and save your seating charts.
  • Allow you to manage guest lists and event planning.
  • Authenticate and secure your account.

We do not sell or rent your personal information. If you accept optional analytics cookies, limited information may be shared with advertising partners we use for conversion measurement, as described in the Cookies and Analytics section below.

3. Cookies and Analytics

Cookies we use:

  • Essential cookies: Required for the site to function (authentication, session management). These cannot be disabled.
  • Analytics cookies (optional): When enabled, PostHog may set cookies for richer analytics and session replay, and we may load the Pinterest Tag and TikTok Pixel for ads measurement. Whether these are off or on by default depends on where you are located (see below); your explicit choice always takes precedence.

Where you are located:

  • EEA, United Kingdom, and Switzerland: optional analytics and advertising cookies are off until you accept them via the cookie banner, which we show on your first visit.
  • Everywhere else (for example the United States): optional analytics and advertising cookies are enabled by default under an opt-out model, and we do not show the banner unless you ask for it. You can opt out at any time via the Cookie Preferences link in the footer and choosing Essential Only.
  • If we cannot determine your location, we treat you as if prior consent were required.
  • We honor the Global Privacy Control (GPC) signal: when your browser sends it, optional cookies stay off until you explicitly accept them.

Cookieless analytics (PostHog):

Whether or not you accept analytics cookies, we use PostHog for privacy-focused audience measurement. If you choose Essential Only or dismiss the banner, PostHog runs in cookieless mode: it does not set analytics cookies and uses a daily rotating identifier instead of tracking you across sessions.

  • Cookieless mode collects high-level usage such as page views, referrers, browser, device type, and country-level location, plus a limited set of funnel events.
  • We respect your browser's Do Not Track setting.
  • We keep standard campaign parameters (UTM tags) for attribution and exclude other URL search parameters and hash fragments before tracking.
  • Personal data (guest names, emails, event names, and similar) is removed before any data is sent.

Advertising measurement (Pinterest and TikTok):

When analytics cookies are enabled (by your acceptance, or by regional default as described above), we may load the Pinterest Tag and the TikTok Pixel to measure ad effectiveness and conversions. Pinterest may process a hashed form of your account email when you are signed in (Enhanced Match) — this happens only after you explicitly accept cookies, never by regional default. Neither tag is loaded if you choose Essential Only.

Full analytics (PostHog with cookies):

When analytics cookies are enabled (by your acceptance, or by regional default as described above), PostHog (hosted in the US) may also set cookies to collect richer anonymised usage data such as features used and interaction patterns. This helps us improve SeatPlan.io.

  • We respect your browser's Do-Not-Track signal.
  • All personal data (names, emails, dietary information, guest details, table names, event names) is stripped before any data is sent to PostHog.
  • URL query parameters and fragments are removed before tracking.

Session recording:

Session replay is available only when analytics cookies are enabled (by your acceptance, or by regional default as described above). PostHog may record anonymised session replays to help us understand user experience issues. These recordings have the following safeguards:

  • All text on the page is masked — no guest names, emails, dietary information, or other personal data is visible in recordings.
  • All element attributes are masked — form values, input contents, and HTML attributes are hidden.
  • Recordings capture interaction patterns (clicks, scrolls, navigation) only, not your actual data.

Managing your preferences:

You can make or change your cookie choice at any time via the Cookie Preferences link in the footer, which re-opens the cookie banner. Your explicit choice is remembered and always overrides any regional default.

4. How Long We Keep Your Data

Basic account data:

  • Guest data is stored for 7 days after the expiry of your access.
  • If you do not extend your account, we delete your account and all associated guest data within 7 days.
  • If you have not signed up, your data is deleted automatically at midnight from your browser.

Subscription features (templates, events, collaboration):

  • Templates and events are stored while your subscription is active, plus 7 days after expiry.
  • Collaboration tokens expire after the duration you set (1-90 days).
  • Client email addresses from collaboration invitations are deleted immediately when the collaboration token expires.
  • Email engagement data (opens and clicks) is deleted along with the collaboration token.

Operational retention and cleanup:

  • We may delete design sessions that are not linked to a user account after they have been inactive for a period (for example 7 or 30 days), as part of routine maintenance.
  • We may remove historical layout snapshots when they no longer relate to an existing session, for example after a session has been deleted.
  • We may delete user accounts that have no remaining paid or trial access after an extended period following expiry (for example more than 7 days), subject to safeguards such as outstanding billing checks.
  • We may delete accounts that have never purchased persistence or subscription features when they show no meaningful activity for at least 7 days.

5. Legal Basis for Processing (GDPR)

We process personal data on the following bases:

  • Contract: to provide you with the Service when you sign up.
  • Consent: when you voluntarily enter guest details into the application.
  • Consent: for PostHog analytics cookies and session recording in the EEA, UK, and Switzerland, which there require your explicit opt-in via the cookie banner.
  • Legitimate interest: for analytics cookies and advertising measurement in regions that do not require prior consent, where they run under an opt-out model with the Cookie Preferences control always available.
  • Legitimate interest: for essential cookies required for the Service to function.
  • Legitimate interest: for limited, cookieless audience measurement through PostHog when analytics cookies are not accepted.

6. Your Rights

Under GDPR, you have the right to:

  • Access a copy of your personal data.
  • Request correction or deletion.
  • Restrict or object to processing.
  • Request portability of your data.

You may exercise these rights by contacting us at hi@seatplan.io. We respond within one month of receiving your request, as required by Article 12(3). We will first confirm your identity through your registered email address, so that we never hand your data to someone else.

What you receive

An access or portability request returns an archive containing everything we hold about your account: your account details, every seating design and guest list, billing records, collaboration invitations and their delivery history, notification records, AI import usage, and the connection metadata (IP address, browser) we captured. It is provided as JSON, which is structured and machine-readable as Article 20 requires, together with spreadsheet-readable copies of your guest lists. The archive includes a manifest listing every category of data we considered and, where a category is not included, why.

The archive contains your account and your own content, including the guest lists you created — for those you are the controller and we are your processor, so they are yours to receive. It never contains another customer's account data. It also does not include data held on our behalf by Clerk, Stripe, Resend, PostHog, or Sentry — ask us and we will obtain that for you.

What we keep after deletion

When you ask us to delete your account we remove it and everything associated with it, including designs you had previously deleted yourself. Two things are kept deliberately:

  • Invoices and payment records held by Stripe, which we are legally required to retain for accounting purposes (Article 17(3)(b)). Your Stripe customer record, including your saved payment methods, is deleted.
  • The internal record that your data was accessed or deleted, and by whom, kept for 24 months (Article 6(1)(c) and (f)).

Staff access to your data

Our staff can only access your data through an internal console restricted to SeatPlan.io administrators. Before looking up your account, generating a sign-in link for it, exporting your data, or deleting it, a staff member must record why they need it and how you contacted us.

That justification, and every internal action that reads or changes data identifying you, is written to an audit record that cannot be edited or deleted, and is kept for 24 months. Internal reports that contain only totals — for example how many customers are on each plan — are not recorded against you, because they do not identify you. You may ask us for the record of who has accessed your account.

7. Data Security

We apply technical and organizational measures to protect your data, including encryption at rest and in transit. Authentication is handled by our authentication provider, and application data for the Service is stored within AWS infrastructure in the Frankfurt region.

8. Third Parties

We only share data with essential service providers acting as data processors:

  • Authentication provider – user sign-in and account management.
  • AWS (Frankfurt) – hosting, compute, primary storage for application data (including guest information), and real-time collaboration infrastructure for live updates and presence indicators.
  • Resend – email delivery for collaboration invitations. Resend may track when emails are opened and when links are clicked.
  • PostHog (US) – product analytics. Runs in cookieless mode without analytics cookies by default; with your consent, may also set cookies for richer analytics and session recording. All personal data is stripped before transmission. Text and element attributes are masked in session recordings.
  • Stripe – payment processing for subscriptions. Stripe processes your payment information directly; we do not store card details.

All providers comply with GDPR and implement adequate safeguards. For US-based providers (for example PostHog and Stripe), and where our authentication provider processes data outside the EU/EEA, we rely on Standard Contractual Clauses (SCCs) or equivalent safeguards.

9. Collaboration Features

If you subscribe to our service, you may invite clients to collaborate on your seating charts:

  • You invite clients by entering their email address. We send them a unique, time-limited link to access your seating chart.
  • Clients can access your seating chart without creating an account.
  • You can revoke a client's access at any time.
  • Some elements of the seating chart may be restricted by you as the organiser.
  • We log when clients access the collaboration link for security purposes.

10. International Transfers

We aim to keep your data within the EU/EEA. If data is transferred outside the EU/UK, we use Standard Contractual Clauses (SCCs) or other legally required safeguards.

11. Contact Us

For questions or to exercise your GDPR rights, contact us at: