Privacy Policy for Seatview
Effective Date: July 25, 2026
Seatview is a web application that helps you plan seating arrangements for events. In this policy, we lay out what data we collect and why, how it is handled, and the rights you have over it.
Our guiding principle is to collect only what we need to run the service. We never sell your data, we don't run ads, and we don't track you across other websites.
The data controller responsible for your personal information is Tatiana Doyle, doing business as Seatview, of 224 W 35th St Ste 500 #302, New York, NY 10001, contactable at support@seatview.us.
A note on guest data. This policy covers information about you — the person using Seatview. It does not cover information about your guests, which you (the organizer) enter into the Service. Much of what you enter is personal data about third parties (your guests), which may include health- or accessibility-related details treated as a special category of data under the GDPR. For guest data, you are the data controller and we process it on your behalf, only on your instructions and only to provide the service, as set out in our Data Processing Agreement. We never use guest data — including dietary or accessibility details — for our own purposes such as analytics or product improvement (see Section 1.4 and the DPA). You are responsible for having a lawful basis to provide guest data and for informing your guests as required by law. If you are a guest with questions about how your information got here, please contact the event organizer who entered it.
1. What We Collect and Why
1.1 Identity and access
If you sign in, we collect your email address. We use it to send you one-time numeric login codes (we never store passwords) and essential service messages. We won't sell it to third parties, and we won't use it for marketing you haven't asked for.
You can also use the free tier anonymously, with no email at all; your work is then tied to a temporary session on our servers.
1.2 Your events
To provide the service, we store what you enter: event names and dates, table and venue-layout details, guest names, guest groupings, keep-together pairs and do-not-seat conflicts, dietary restrictions, accessibility needs, and free-text notes.
1.3 Billing information
If you buy the paid tier, payment is handled by Stripe. Your card details go directly to Stripe and never touch our servers. We store your plan status and a record of the transaction so we can manage your access and support you with billing questions.
1.4 Website interactions
- IP address: used transiently to rate-limit authentication requests and protect the service against abuse. It is not used to build a profile of you.
- Operational logs: our servers generate logs for security, debugging, and reliability. In production these logs are stored with PostHog (EU-hosted), which processes them on our behalf as a subprocessor (see Section 2). This happens regardless of your analytics-banner choice: the logs are produced by our servers as part of operating the service (our legitimate interest), not by tracking your browser, and declining analytics does not stop them. They are not anonymized — they can include IP addresses, timestamps, and account email addresses (never login codes or session tokens) — and are kept only for a limited period (see Section 6). By default, logging never includes your event content (guest names, tables, notes, etc.). In exceptional cases — for example, debugging a specific reported bug — we may temporarily enable logging of the minimum event content needed to reproduce and fix the issue, for the duration of that investigation only. Where that content includes guest data, we do it as your processor and on your instructions under the Data Processing Agreement — as part of the service we provide to you, not on our own legitimate interest — and PostHog acts as our subprocessor for those logs. Even in those exceptional cases, we never log special-category guest data (dietary restrictions, accessibility needs, or anything else revealing health, disability, or similar sensitive characteristics) — those fields are always excluded from logs, with no exception.
- Usage analytics (opt-in only): with your consent, we use PostHog (hosted in the EU) to understand how the app is used — pages visited, product actions (such as creating an event or assigning a seat), referrer, approximate country, browser, and device type. Product-action events record only that an action happened (for example, "a guest was added"), never the content of what you entered — guest names, dietary restrictions, accessibility needs, and other guest content are never sent to analytics, regardless of consent. Non-identifying counts (for example, how many guests or tables are in an event) may be included, since they don't reveal anything about any individual guest — we treat these as usage data about your account. If you are signed in and have consented, this usage data is linked to your account (your numeric user ID and plan tier) so we can understand how the product is used across a session. None of this happens unless you accept the analytics banner: if you decline (or simply ignore it), no analytics identifiers are stored on your device and no usage data is sent. You can withdraw (or grant) consent at any time via Privacy choices — in the footer or in Account settings. Deleting your account also deletes your analytics profile and its events from PostHog.
1.5 What we don't collect
We do not use third-party advertising, cross-site tracking, or device-fingerprinting technologies. We do not collect personal information about you from third parties — everything comes directly from you and your use of the app. We have no mobile apps requesting device permissions.
2. When We Access or Disclose Your Information
To provide the service you've requested. We use a small number of third-party subprocessors to run the app (the same subprocessors, and their transfer mechanisms, are listed in our Data Processing Agreement):
- Payments — Stripe: processes payments for the paid tier and receives the information needed to take payment (such as your email address and the payment details you give Stripe directly). See Stripe's privacy policy.
- Email — Resend: delivers login codes and service emails, and therefore receives your email address and the message contents. See Resend's privacy policy.
- Hosting / infrastructure — Render: hosts our application and database, processing this data on our behalf. See Render's privacy policy.
- Analytics — PostHog (opt-in only): if you consent via the analytics banner, PostHog processes the usage data described in Section 1.4 on our behalf, on EU-hosted infrastructure. See PostHog's privacy policy.
- Operational logs — PostHog: PostHog also stores our server-side operational logs (Section 1.4), regardless of your analytics choice — these are generated by our servers to keep the service secure and reliable, not by tracking your browser, and are not anonymized (they can include IP addresses and account email addresses, and in exceptional debugging cases, non-special-category event content — see Section 1.4).
No human at Seatview looks at your event data except in limited circumstances: to help with a support request you make (with your express permission), or when an error stops an automated process and requires manual intervention to fix — in which case we access the minimum necessary.
To investigate abuse. We may review account or session metadata (not your event content, unless the report concerns it) when investigating violations of our Terms of Service or attacks on the service.
When required by law. We do not respond to government or law-enforcement requests for user data unless we are legally compelled to (for example, by a valid warrant, subpoena, or court order). Where the law allows, our policy is to notify affected users before disclosing their data. We may also disclose information where necessary to protect our rights, our users, or the public.
If we are ever acquired. If Seatview is acquired by or merges with another company, we will notify you before any of your personal information is transferred or becomes subject to a different privacy policy.
3. Legal Bases (GDPR)
Where the GDPR applies, we rely on: performance of our contract with you (to provide the service); our legitimate interests (to secure and improve the service); and consent or legal obligation where applicable.
4. Your Rights
You can exercise the main rights yourself, directly in the app, without contacting anyone:
- Access & portability: Account settings → Download my data exports everything we hold about you in a structured, machine-readable JSON format.
- Erasure: Account settings → Delete account permanently erases your account and all associated data.
- Rectification: all your data is editable in the app.
For anything else, contact us at support@seatview.us.
4.1 Rights under the GDPR (UK/EU users)
- Access — obtain a copy of the personal information we hold about you.
- Rectification — correct inaccurate or incomplete information.
- Erasure — request deletion of your personal information.
- Portability — receive your data in a structured, machine-readable format.
- Restriction / Objection — restrict or object to certain processing, including any processing based on legitimate interests.
- Withdraw consent — where processing is based on consent.
- No automated decision-making — we do not make decisions with legal or similarly significant effects about you based solely on automated processing.
- Complain — lodge a complaint with your local data protection authority (in the UK, the Information Commissioner's Office).
4.2 Rights under the CCPA/CPRA (California users)
- Know — the categories and specific pieces of personal information we collect, use, and disclose (see Sections 1–2).
- Delete — request deletion of your personal information.
- Correct — request correction of inaccurate personal information.
- Opt out of sale/sharing — we do not sell or share your personal information for cross-context behavioral advertising.
- Limit use of sensitive information — we use the sensitive information you provide (such as dietary or accessibility needs entered for guests) only to deliver the service, not for inferring characteristics.
- Non-discrimination — we will not discriminate against you for exercising these rights.
4.3 Authorized Agents
You may designate an authorized agent to submit a CCPA/CPRA request on your behalf. To do so, the agent must contact us at support@seatview.us with written proof of your authorization (for example, a signed permission statement or power of attorney). We will independently verify your identity directly — typically by requiring you to confirm the request from your own account or registered email — before completing it. We may deny a request if the agent cannot provide adequate proof of authorization.
5. How We Secure Your Data
All data is encrypted in transit (TLS). Login codes and session tokens are stored only as salted, one-way hashes — never in plaintext. Sessions use httpOnly, Secure, same-site cookies. Sensitive endpoints are protected by origin/CSRF checks and rate limiting, and our databases sit behind access controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
6. What Happens When You Delete Your Data
- Deleting your account (Account settings → Delete account) permanently deletes your account and all associated events, guests, tables, seating, and settings from our active databases immediately — there is no soft-delete grace period, and we cannot recover the data afterwards. Export first if you want a copy. Your Stripe customer record and, if you consented to analytics, your PostHog analytics profile and its events are deleted as part of the same request.
- Anonymous (not signed-in) sessions are session-scoped: their data is automatically swept approximately 30 days after the session expires.
- Backups and logs: copies of deleted data may persist in encrypted backups and operational logs for up to 14 days before being overwritten or deleted.
7. Data Retention
We keep your information only as long as needed for the purposes described in this policy: account data for as long as your account exists, session data until swept, and logs/backups for the limited periods above. We may retain minimal records where required to comply with legal obligations (for example, payment records for tax purposes) or to resolve disputes.
8. Location of Data and International Transfers
Our application and database are hosted on Render's US infrastructure. Our other service providers may also process data in the United States: Stripe (Stripe, LLC, US) and Resend (Plus Five Five, Inc., US). PostHog, our analytics and operational-log subprocessor, hosts in the EU (Frankfurt).
If you are located in the UK/EEA, your information may be transferred to and stored in the United States. Where that happens, we rely on the following safeguards, per provider:
- Stripe: certified under the EU-US Data Privacy Framework, its UK Extension, and the Swiss-US Data Privacy Framework; Standard Contractual Clauses apply as a fallback where DPF does not cover a transfer.
- Resend: Standard Contractual Clauses, incorporated into their Data Processing Addendum.
- Render: certified under the EU-US Data Privacy Framework, and maintains SOC 2 Type 2 and ISO 27001 certifications.
- PostHog: hosts in the EU by default; Standard Contractual Clauses apply to any EU/UK-to-US transfer that does occur (for example, cross-border support access).
9. Cookies
We use one strictly necessary cookie to keep you signed in and to operate the service securely. It is an httpOnly, Secure (in production), same-site session cookie and is not used for advertising or analytics. Because it is essential to providing the service, it cannot be disabled while using the app.
If you accept the analytics banner, PostHog stores an analytics identifier in a cookie and your browser's local storage so your visits can be counted consistently (see Section 1.4). Declining the banner means no analytics cookies or identifiers are set at all; we also store your banner choice itself locally so we don't ask again. We use no advertising or cross-site tracking cookies of any kind.
10. Children's Privacy
The app is not directed to children. You must be 18 or older to use it, and we do not knowingly collect personal information from any user under 18. If we learn that we have, we will delete it.
This age limit applies to you, the person using Seatview — not to your guests. A guest list may of course include children, and their information reaches us only because you entered it. For that data you are the controller and we are your processor, as set out in our Data Processing Agreement; you are responsible for having a lawful basis to provide it, which for a child may mean the consent of a parent or guardian.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will revise the "Effective Date" above and, for material changes, notify you in the app or by email.
12. Contact Us
Questions or requests regarding this Privacy Policy or your personal information:
- Email: support@seatview.us
- Address: 224 W 35th St Ste 500 #302, New York, NY 10001