Privacy Policy

Last updated: September 17, 2026

Draft. This document is a draft pending legal review and may change before the final version is published.

This Privacy Policy explains how SEATORY ("SEATORY", "we", "us") collects, uses and protects personal data when you use seatory.app (the "Service"). We wrote it to be read, not skimmed past — if anything is unclear, email us at privacy@seatory.app.

1. Who we are

The Service is operated by Individual Entrepreneur Elena Kolodyazhnaya (Taxpayer ID 231100682963, OGRNIP 326237500410673), the data controller for account data described below. Contact: privacy@seatory.app.

2. Data we collect

  • Account data — your email address, name and password (stored as a secure hash);
  • Event data — event names, dates, venues, guest lists, seating charts, schedules and menus you create;
  • Guest page usage — when a guest searches for their seat, the name they type is used to find them and is not stored separately;
  • Support messages and feedback you send us;
  • Technical data — IP address, device and browser type, pages visited and essential cookies (see section 8);
  • Payment data — payments are processed by Stripe. We receive confirmation of the payment and its amount, but never see or store your full card details.

3. How we use your data and our legal bases

  • To provide the Service — seating charts, guest pages, exports and collaboration (performance of a contract, GDPR Art. 6(1)(b));
  • To secure your account and prevent abuse (legitimate interests, Art. 6(1)(f));
  • To process payments and keep records required by law (contract and legal obligation, Art. 6(1)(b) and (c));
  • To send service emails — sign-in codes, password resets and purchase confirmations (contract);
  • To improve the Service using aggregated, non-identifying statistics (legitimate interests).

We do not sell your personal data, and we do not use it for targeted advertising.

4. Your guests' data

Guest lists and seating charts are information you add about other people. For that data, you act as the controller and SEATORY acts as your processor: we store and display it only so the Service works for your event, and we never use it for our own purposes, share it for marketing or contact your guests.

You are responsible for having a lawful basis to add your guests' information and for letting them know how it is used. When you delete an event, its guest data is deleted with it.

5. Who we share data with

We share data only with service providers that help us run SEATORY:

  • Stripe, Inc. — payment processing;
  • Hosting provider — servers that store the Service's data;
  • Email delivery provider — to send sign-in codes and service emails.

We may also disclose data when required by law or to protect the rights and safety of our users and the Service.

6. International data transfers

Our servers are located in the Russian Federation, which means your data is transferred to and stored outside the European Economic Area, the United Kingdom and the United States. We protect it with encryption in transit, access controls and the safeguards required by applicable law.

7. How long we keep data

We keep your data for as long as your account exists. When you delete your account, your events, seating charts and guest lists are deleted. Payment records are kept for as long as tax and accounting laws require.

8. Cookies

seatory.app uses only essential cookies and local storage — to keep you signed in and remember basic preferences. We do not use advertising or cross-site tracking cookies, and we do not load third-party analytics on seatory.app.

9. Your rights

Depending on where you live, you have the right to:

  • access the personal data we hold about you and get a copy of it;
  • correct inaccurate data;
  • delete your data ("right to be forgotten");
  • restrict or object to certain processing;
  • receive your data in a portable format;
  • withdraw consent at any time, where processing is based on consent;
  • lodge a complaint with your local data protection authority.

California residents: you have the right to know, delete and correct your personal information and to not be discriminated against for exercising these rights. We do not sell or "share" personal information as defined by the CCPA/CPRA.

To exercise any of these rights, email privacy@seatory.app. We respond within 30 days. Guests who appear on an event's guest list can contact the event host or us directly.

10. Security

We use HTTPS encryption, hashed passwords, access controls and regular backups. No system is perfectly secure, but we work hard to protect your data and will notify you and the relevant authorities of a data breach as required by law.

11. Children

SEATORY is intended for adults planning events. We do not knowingly collect personal data from children under 16 as account holders.

12. Changes to this policy

We may update this Privacy Policy from time to time. We will post the new version at seatory.app/privacy and, for significant changes, notify you by email.