← Placement

Privacy

Last updated 23 August 2026

Who we are

Placement is operated by [Legal entity name], [registered address], the Netherlands. Chamber of Commerce (KvK) [number]. We are the controller for your account data, in the sense of the GDPR (in Dutch, the AVG).

For anything in this policy, or to exercise any of the rights below, write to [privacy@yourdomain]. [If you appoint a Data Protection Officer, name them here. Most operators of this size are not required to.]

What we store, and why

Two different kinds of data, held on two different legal bases.

Your account. Your email address and a hashed password. We need these to give you the service you asked for, so the basis is performance of a contract (Art. 6(1)(b) GDPR). If you try Placement without signing up we create an anonymous session with no email attached; it becomes a normal account only if you choose to save it.

What you build. Your events (name, date), your floor plans (the shapes, sizes and positions of tables and other objects), and your guest list, where an entry can hold a name, an email address, a party size, an RSVP status and free-text dietary notes. Same basis: it is the service.

Payments. When you pay for an event we keep the customer reference Stripe gives us, so we can show you your receipts, and we keep the record for as long as Dutch tax law requires. Card details go to Stripe directly and never reach our servers.

We run no third-party analytics, advertising or tracking scripts. The only cookies Placement sets are the session cookies that keep you signed in, which are strictly necessary and therefore need no consent banner under Article 11.7a of the Dutch Telecommunications Act.

Your guest list: you are the controller, we are the processor

The people on your guest list are not our users and have agreed to nothing with us. You decide what to enter about them; we store and display it on your instructions and make no other use of it. In GDPR terms you are the controller and we are your processor (Art. 28).

As your processor we will: only process guest data to run the service for you; keep it confidential; apply appropriate security; use only the sub-processors listed below; help you respond if a guest exercises their rights; tell you without undue delay if there is a breach; and delete the data when you delete the event or your account. [If you sell to organisations, expect them to ask for this as a signed data processing agreement, so have one ready.]

It is your responsibility to have a lawful basis for entering someone's details and to inform them if they ask, including that their details are stored in the United States, as set out below. Please note that dietary notes commonly record allergies, medical conditions or religious requirements, which are special-category data under Article 9 GDPR and need a stronger basis than ordinary contact details. Enter only what the event actually requires.

Who else processes it, and where

  • Supabase: database, authentication and storage. All account and event data lives here, on infrastructure in the United States (AWS, Northern Virginia).
  • Vercel: runs the application itself, in the United States (Washington, D.C.).
  • Stripe: payment processing.

Your data is stored in the United States, not in the EU. That is a transfer out of the European Economic Area, and it needs a legal basis under Chapter V of the GDPR: either the provider's certification under the EU–U.S. Data Privacy Framework, or the European Commission's Standard Contractual Clauses backed by a transfer impact assessment.

[Before publishing: check each provider's current Data Privacy Framework listing, accept or sign each one's data processing agreement, and record which basis you are relying on for which provider. If any is not certified, you need the SCCs and an assessment on file. Supabase also offers EU regions. Hosting there instead removes this section's problem rather than documenting it, which is worth costing out while the dataset is still small.]

Who can see it inside Placement

Placement has an internal dashboard that only named staff accounts can reach. It shows counts and totals — how many accounts, events and guests exist, how many events have been paid for — which are figures about usage, not about any one of your guests.

It can also open a single event read-only, showing its floor plan and guest list. That exists so we can see what you are seeing when you write to us about a problem. We open an event when there is a reason to, not to browse. Staff can also delete an account and everything attached to it.

[Decide and state your internal rule here: who holds a staff account, on what grounds an individual event may be opened, and whether that access is logged. GDPR data minimisation (Art. 5(1)(c)) expects the narrowest access that does the job, and saying so plainly here is what makes it a commitment rather than a capability.]

How long we keep it

Your events, guest lists and floor plans stay until you delete them. Deleting an event deletes its guests and its floor plan with it. Deleting your account deletes everything you have made, including events you have paid for, and cannot be undone.

Payment and invoice records are kept separately for seven years, the retention period Dutch tax law requires.

Your rights

Under the GDPR you can ask us for a copy of your data, correct it, delete it, restrict or object to its processing, and receive it in a portable form. Much of this you can do yourself: everything on your account is editable in the app, your guest list exports as a spreadsheet at any time, and deleting your account removes the lot. For anything else, write to [privacy@yourdomain]. We answer within one month.

If you think we have handled your data wrongly you can complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens, or to the authority where you live.

Changes

If this policy changes in a way that affects you, we will say so here and update the date at the top of this page.