Privacy Policy
Last updated June 2026
This Policy explains how [Company Name] ("we") handles personal data in ConciergeGuest (the "Service"). We act as a data controller for your account data, and as a data processor for the guest data you upload.
1. Data we collect
Account data: your name, email, hashed password, phone number (for verification), organization details, and billing identifiers held by our payment processor.
Guest data you upload: guest names, emails, phone numbers, companies, and attendance/RSVP status, processed on your behalf.
Usage data: logs, IP addresses, and audit records used for security and to operate the Service.
2. How we use it
To provide the Service (events, invitations, check-in, follow-ups), to process payments, to secure the platform and prevent abuse (including phone verification and rate limiting), and to communicate with you about your account.
3. Legal bases
We rely on performance of our contract with you, our legitimate interests in operating and securing the Service, and consent where required. For guest data, you are responsible for the lawful basis to contact your guests.
4. Sharing and sub-processors
We share data with sub-processors who help run the Service, including our hosting provider (DigitalOcean), email provider (Resend), SMS verification provider (Twilio), and payment processor (Stripe). Each processes data under their own terms and only as needed to provide their function.
5. Retention
We keep account data while your account is active and for a reasonable period afterwards. Guest data is retained until you delete it or close your account, after which it is deleted or anonymised within a reasonable period, subject to legal retention requirements.
6. Security
We use encryption in transit, hashed passwords and reset tokens, per-tenant data isolation (application and database row-level security), audit logging, and access controls. No system is perfectly secure, but we take reasonable measures to protect your data.
7. Your rights
Subject to applicable law you may access, correct, delete, or export your personal data, and object to or restrict certain processing. Guests should direct such requests to the organization that invited them (the controller); we will assist that organization as processor.
8. International transfers
Where data is transferred outside your region, we rely on appropriate safeguards such as standard contractual clauses.
9. Contact
Privacy questions or requests: [[email protected]].
This is a starter template and not legal advice. Have it reviewed by a qualified solicitor or data-protection adviser before relying on it.