Skip to content

Privacy Policy

Last updated: [EFFECTIVE DATE]

1. About this policy

This policy explains how PreSeated handles personal data. PreSeated is operated by [COMPANY NAME] (SSM registration no. [SSM REGISTRATION NO.]), a company incorporated in Malaysia with its registered address at [REGISTERED ADDRESS]. In this policy, "PreSeated", "we", "us" and "our" mean [COMPANY NAME].

It covers our website, our web console for organizers and administrators, our mobile app, the public RSVP page we host for each event, and the WhatsApp messages we send on an organizer's behalf.

We handle personal data in accordance with Malaysia's Personal Data Protection Act 2010 and the amendments that took effect in 2025.

2. The two roles we play

PreSeated handles two different kinds of personal data, and our responsibility is different for each. This distinction runs through the whole policy, so it is worth being clear about it first.

Data we control. Account details of the organizers, co-organizers, helpers and administrators who sign in to PreSeated, and the details of people who contact us about buying PreSeated. We decide why and how this data is used, so we are the data controller for it. This policy is your notice for that data.

Data we process for an organizer. Everything about the guests of an event: the guest list, seating, RSVP answers and messages. The organizer decides what is collected and why. We only hold and handle it to run the service for them, so the organizer is the data controller and we are their data processor.

If you are a guest at an event, the organizer of that event — the host, or the planner acting for them — is responsible for your data. We describe in this policy what happens to it inside PreSeated, but a request to see, correct or delete it should go to the organizer. If you do not know who that is, contact us and we will pass your request on.

3. Personal data we collect

If you hold a PreSeated account

  • Your full name, email address and mobile number.
  • Your role: organizer, co-organizer, helper or administrator, and which events you are attached to.
  • Your password, which is stored only as a cryptographic hash and is never visible to us.
  • Sign-in records kept by our authentication provider, and whether your account is suspended.
  • Records of invitations issued to you, and whether they were used.

If you are a guest at an event

The organizer decides which of these to collect. A guest may provide them through the RSVP link, or the organizer may enter or import them:

  • Name and mobile number.
  • The number of people in the party.
  • Dietary preferences chosen from a list, such as vegetarian, halal, no seafood or no pork.
  • Free text dietary notes, which often mention allergies.
  • Seating needs chosen from a list, such as a baby chair, a wheelchair space or an aisle seat.
  • A free text message of blessings or wishes, if the organizer's RSVP page asks for one.
  • The table assigned, whether the guest checked in at the door, and when.
  • The date and time of the RSVP.
  • A record of each WhatsApp message sent to the guest, including the number it went to and the message text.

Technical data

  • A session cookie so you stay signed in to the web console. It is strictly necessary and we do not use cookies for advertising, analytics or tracking.
  • The language you choose in the mobile app, stored on the device itself.
  • For the public RSVP page, an anti-spam check that sends the visitor's IP address to Cloudflare so it can distinguish a person from a bot. We do not store the IP address ourselves.
  • When someone redeems an invitation link, a one-way hash of their IP address, kept for fifteen minutes to limit repeated guessing. The IP address itself is not stored.
  • Ordinary server logs kept by our hosting providers, and error messages we record to diagnose faults.

Data from your device, in the mobile app

  • If you choose to add guests from your phone's contacts, the app asks for permission to read your address book. Only the contacts you tick are saved to the event. We do not upload your address book, and we do not keep a copy of contacts you did not pick.
  • If you choose an event cover photo, the app asks for permission to your photo library so you can select one. Only the photo you select is uploaded.

You can withdraw either permission in your phone's settings at any time. The rest of the app continues to work.

4. Sensitive personal data

Some of what an event records counts as sensitive personal data under the Personal Data Protection Act, which means it needs a guest's express consent before it is collected:

  • A dietary preference such as halal or no pork may reveal a religious belief.
  • A note about an allergy or a medical diet, or a seating need such as a wheelchair space, reveals information about health or disability.

Organizers are responsible for obtaining that consent from their guests. Organizers should collect these details only where the event genuinely needs them, and should not use them for any other purpose.

5. How we use personal data

For account holders, we use your data to:

  • create and secure your account and sign you in;
  • give you the access your role allows;
  • provide support when you contact us;
  • send you service messages about your events, billing and changes to the service; and
  • keep the records we need for invoicing, tax and accounting.

For guest data, we act only on the organizer's instructions, which in practice means:

  • storing the guest list and the seating plan for the event;
  • showing each guest their own table on the private link we send them;
  • sending the event's WhatsApp messages to the numbers on the list;
  • recording check-in at the door; and
  • producing the organizer's reports and exports for their own event.

We do not sell personal data. We do not use guest data for our own marketing, and we do not use it to train machine learning models.

6. Where guest data comes from

An organizer can add guests in three ways, and we want to be clear about what that means for a guest:

  • The guest fills in the RSVP link themselves. The guest provides the data directly.
  • The organizer types the guest in, or picks them from the contacts on their phone.
  • The organizer imports a list from a spreadsheet.

In the second and third cases the guest may never have interacted with PreSeated before receiving a WhatsApp message about the event. The organizer is responsible for having a lawful basis for that, and for having given the guest the notice the law requires. Our terms require organizers to confirm this.

If you received a message from PreSeated about an event and do not want further messages, reply to the sender, or contact us at [PRIVACY EMAIL] and we will pass your request to the organizer.

7. Who we share personal data with

We share personal data only with the providers we need to run the service, and only as far as each one needs it. We do not sell personal data to anyone.

  • Supabase — our database, authentication and file storage provider. Holds all account and guest data. Hosted in Singapore.
  • Vercel — hosts the PreSeated website, the RSVP pages and the web console, and runs the scheduled job that sends messages.
  • Meta Platforms — operates the WhatsApp Business Platform. When a message is sent, Meta receives the guest's mobile number and the details the message shows: the guest's name, the event name, date, time and venue, the table number, and the link to the guest's own page. Meta also fetches the event cover photo where the message includes one. Meta handles that data under its own terms and privacy policy.
  • Cloudflare — provides the anti-spam check on the public RSVP page, and receives the visitor's IP address for that purpose.
  • Apple and Google — distribute the mobile app through their app stores. They do not receive event or guest data from us.
  • Our professional advisers, such as accountants and lawyers, where they need access and are bound by confidentiality.

We may also disclose personal data where the law requires it, where a court or regulator orders it, or where it is needed to establish or defend a legal claim. If our business is sold or reorganised, data may transfer to the buyer, who would remain bound by this policy.

8. Transfers outside Malaysia

Our database and file storage are hosted in Singapore, and our website hosting and WhatsApp messaging providers operate from data centres in several countries, including the United States. Personal data held in PreSeated is therefore transferred outside Malaysia.

We only use providers that offer a level of protection comparable to the Personal Data Protection Act, under written contracts that require them to protect the data, to use it only on our instructions, and to help us respond to requests from individuals. We assess each transfer before we rely on it and review those assessments periodically.

9. How long we keep personal data

  • Guest data for an event — for as long as the organizer's account is active and for twelve months after the event date, then deleted. An organizer can remove a guest sooner, which hides them from the event immediately.
  • Records of WhatsApp messages sent — the phone number and message text are deleted twelve months after the event. We keep the counts and dates for a further seven years, because they are the basis of the invoice and we are required to keep accounting records for that long.
  • Event details, including the cover photo — deleted with the guest data, twelve months after the event.
  • Account holder data — while the account is open, and for twelve months after it is closed.
  • Invoices and accounting records — seven years, as Malaysian tax law requires.
  • Support correspondence — twenty-four months.
  • Invitation links — seven days, after which they expire and are no longer usable.
  • Anti-abuse records for invitation links — fifteen minutes.

Where we are required to keep something longer, for example because of a legal claim, we keep only what is necessary for that purpose.

10. How we protect personal data

  • All traffic to and from PreSeated is encrypted in transit, and data is encrypted at rest by our database provider.
  • Passwords are stored only as cryptographic hashes.
  • Access to an event's guest list is enforced in the database itself, so an organizer can only reach their own events and a helper only sees the events they were added to.
  • Helpers can check guests in but cannot delete guests or change seating.
  • Access by our own staff is limited to the administrators who need it to operate and support the service, and is logged.
  • Links we send to guests contain a long random token, are excluded from search engines, and show only that guest's own name, party size and table — never another guest's details or anyone's phone number.
  • Invitation links are single use, expire after seven days, and lock after repeated failed attempts.

No system is completely secure. We review our arrangements regularly and improve them where we find a weakness.

11. Data breaches

If a breach of personal data occurs, we will notify the Personal Data Protection Commissioner as soon as practicable, as the Personal Data Protection Act requires. Where the breach is likely to cause significant harm, we will also notify the people affected without unnecessary delay, and we will tell the organizer whose event is involved so they can notify their guests.

12. Your rights

Under the Personal Data Protection Act 2010 you may:

  • ask for a copy of the personal data we hold about you;
  • ask us to correct it if it is wrong or out of date;
  • withdraw your consent to our using it, where we rely on consent;
  • ask us to stop using it for direct marketing; and
  • ask us to transmit it to another provider, where that is technically feasible.

To make a request, write to [PRIVACY EMAIL]. We may ask you to confirm your identity before we act, and we will respond within the time the law allows.

If you are a guest at an event, please send your request to the organizer of that event, because the data is theirs. If you send it to us, we will pass it on and tell you we have done so.

You may also complain to the Personal Data Protection Department of Malaysia (Jabatan Perlindungan Data Peribadi) if you are not satisfied with how we have handled your data. We would rather you came to us first so we can put it right.

13. Cookies

The web console uses a single cookie to keep you signed in. It is strictly necessary for the service to work and cannot be switched off while you are using the console. Blocking it will sign you out.

We do not use advertising cookies, analytics cookies or third-party tracking, on our website or anywhere else in the service.

14. Children

PreSeated is a tool for organizers running events and is not intended for children. We do not knowingly collect data about anyone under 18 as an account holder.

An organizer's guest list may include children who are attending an event with their family, for example where a baby chair is requested. That data is the organizer's responsibility, and they should collect only what the event needs.

15. Data protection officer

We have appointed a data protection officer, who can be reached at [PRIVACY EMAIL] or by writing to the address in section 17.

16. Changes to this policy

We may update this policy. The "last updated" date at the top of the page shows when it last changed. If a change materially affects how we handle your data, we will tell account holders by email or in the app before it takes effect.

17. Contact us

[COMPANY NAME]

[REGISTERED ADDRESS]

Privacy enquiries: [PRIVACY EMAIL]

General support: [SUPPORT EMAIL]

WhatsApp: [SUPPORT WHATSAPP NUMBER]

Back to PreSeated