Privacy
Last updated 23 August 2026
Who we are
SeatsAssigner is operated by Menifays, Sigmaplantsoen 315, 2321 KK Leiden, the Netherlands. Chamber of Commerce (KvK) 42160283. We are the controller for your account data, in the sense of the GDPR (in Dutch, the AVG).
For anything in this policy, or to exercise any of the rights below, write to support@seatsassigner.com.
What we store, and why
Two different kinds of data, held on two different legal bases.
Your account. Your email address and a hashed password. We need these to give you the service you asked for, so the basis is performance of a contract (Art. 6(1)(b) GDPR). If you try SeatsAssigner without signing up we create an anonymous session with no email attached; it becomes a normal account only if you choose to save it.
What you build. Your events (name, date), your floor plans (the shapes, sizes and positions of tables and other objects), and your guest list, where an entry can hold a name, an email address, a party size, an RSVP status and free-text dietary notes. Same basis: it is the service.
Payments. When you pay for an event we keep the customer reference Stripe gives us, so we can show you your receipts, and we keep the record for as long as Dutch tax law requires. Card details go to Stripe directly and never reach our servers.
We run no third-party analytics, advertising or tracking scripts. The only cookies SeatsAssigner sets are the session cookies that keep you signed in, which are strictly necessary and therefore need no consent banner under Article 11.7a of the Dutch Telecommunications Act.
We do count page views ourselves. When you open a page we record the path you visited, the day, and the website that sent you here if it was not this one. We do not store your IP address. Instead your IP address and browser are combined into a one-way code that changes every day, which lets us count one browser once rather than five times, and makes it impossible for us to recognise you tomorrow or to work backwards to you at all. No cookie is set, nothing leaves our servers, and the raw records are deleted after 30 days, leaving only daily totals. If you browse with JavaScript off you are not counted.
Your guest list: you are the controller, we are the processor
The people on your guest list are not our users and have agreed to nothing with us. You decide what to enter about them; we store and display it on your instructions and make no other use of it. In GDPR terms you are the controller and we are your processor (Art. 28).
As your processor we will: only process guest data to run the service for you; keep it confidential; apply appropriate security; use only the sub-processors listed below; help you respond if a guest exercises their rights; tell you without undue delay if there is a breach; and delete the data when you delete the event or your account. If you need this as a signed data processing agreement, for instance because you are an organisation with its own obligations, write to us and we will provide one.
It is your responsibility to have a lawful basis for entering someone's details and to inform them if they ask, including that their details are stored in the United States, as set out below. Please note that dietary notes commonly record allergies, medical conditions or religious requirements, which are special-category data under Article 9 GDPR and need a stronger basis than ordinary contact details. Enter only what the event actually requires.
Who else processes it, and where
- Supabase: database, authentication and storage. All account and event data lives here, on infrastructure in the United States (AWS, Northern Virginia).
- Vercel: runs the application itself, in the United States (Washington, D.C.).
- Stripe: payment processing.
Your data is stored in the United States, not in the EU. That is a transfer out of the European Economic Area, which Chapter V of the GDPR allows on one of two bases, and each provider is bound by one. Supabase processes it under a data processing addendum that incorporates the European Commission's Standard Contractual Clauses. Vercel and Stripe are certified under the EU–U.S. Data Privacy Framework, and their data processing agreements carry the same clauses as a fallback.
Who can see it inside SeatsAssigner
SeatsAssigner has an internal dashboard that only named staff accounts can reach. It shows counts and totals — how many accounts, events and guests exist, how many events have been paid for — which are figures about usage, not about any one of your guests.
It can also open a single event read-only, showing its floor plan and guest list. That exists so we can see what you are seeing when you write to us about a problem. Staff can also delete an account and everything attached to it.
One person holds a staff account: the founder. We do not open your event. If you write to us about a problem and ask us to look, we open that one event, read-only, for that conversation and nothing else.
How long we keep it
Your events, guest lists and floor plans stay until you delete them. Deleting an event deletes its guests and its floor plan with it. Deleting your account deletes everything you have made, including events you have paid for, and cannot be undone.
Payment and invoice records are kept separately for seven years, the retention period Dutch tax law requires.
Your rights
Under the GDPR you can ask us for a copy of your data, correct it, delete it, restrict or object to its processing, and receive it in a portable form. Much of this you can do yourself: everything on your account is editable in the app, your guest list exports as a spreadsheet at any time, and deleting your account removes the lot. For anything else, write to support@seatsassigner.com. We answer within one month.
If you think we have handled your data wrongly you can complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens, or to the authority where you live.
Changes
If this policy changes in a way that affects you, we will say so here and update the date at the top of this page.