Privacy
Privacy Policy
Last updated: 2026-08-01
SeatMaply is an independently operated seating-chart tool. We follow a local-first approach: when you use the editor anonymously, projects stay in your browser and are not uploaded merely because you open the site.
1. Scope
This policy covers the SeatMaply public website and editor, optional account and cloud-save features, and in-product feedback or support messages you choose to send us.
You can use the local editor without creating an account. Your browser and hosting providers may still process technical data needed to deliver and secure the service.
2. Information we process
- Browser-local projects: floors, spaces, rooms, tables, seats, text, background images, project settings, and people information you enter or import.
- Local preferences: language, onboarding progress, and sign-in reminder state.
- Account and verification data: email address, one-time-code delivery records, authentication session, and account identifier when you sign in.
- Cloud projects: the complete project file, title, size, revision, and timestamps only after you explicitly save a project to the cloud.
- Security and infrastructure data: IP address, User-Agent, requested URL, time, Turnstile signals, and high-level failure categories.
- Basic public-site analytics: page URLs, views, clicks, scrolling, and browser or device information on marketing and legal pages. Analytics does not run inside the editor.
- Support messages: the address, message, and attachments you voluntarily send.
- In-product feedback: the category, message, and optional contact email you provide, plus the language, editor path, User-Agent, IP, Origin, and Turnstile data needed to submit it. We do not read or upload project contents with feedback.
- Feedback abuse counters: the server uses a secret key to turn the IP address and signed-in user ID into keyed HMAC pseudonymous identifiers. It stores only UTC windows, request counts, and expiry times—not the raw IP, user ID, or feedback message.
3. Why we use this information
- To provide anonymous editing, local storage, import, export, and project backups.
- To provide sign-in, cloud save, project deletion, and account deletion when you choose those features.
- To understand basic use of marketing and legal pages and improve public content and navigation.
- To prevent abuse, protect accounts and the service, and diagnose technical failures without placing project contents in analytics.
- To answer support, privacy, and legal requests.
4. Local projects, cloud save, imports, and exports
Local projects are stored in IndexedDB in your current browser. Language and onboarding preferences use localStorage. Clearing site data removes this local information; deleting an account does not silently remove browser-local copies.
CSV, Excel, SeatMaply project backups, and background images are read in the browser first. They are not uploaded unless you later choose cloud save. PNG exports and project backups download directly to your device.
Cloud save is optional. The default limit is five cloud projects per account and 2 MiB per project. Project contents are excluded from analytics events.
5. Service providers
Clarity does not run on `/zh/app/`, `/en/app/`, account, or cloud-project interfaces. We send denied values for both advertising and analytics storage and require Strict masking for the Clarity project. Clarity therefore does not set its cookies or build continuous cross-page visits. We do not send Clarity project contents, people names, account email addresses, background images, imported rows, user identifiers, or custom tags.
These providers process data needed to supply their services under their own terms and privacy notices. SeatMaply does not use advertising pixels or grant Clarity advertising storage.
- Supabase: optional email authentication, sessions, cloud-project storage, and account deletion.
- Cloudflare: Turnstile abuse protection and forwarding messages sent to hello@seatmaply.com.
- Resend: delivering in-product feedback to hello@seatmaply.com as transactional email.
- Vercel: static hosting for the public site and editor, including necessary infrastructure logs.
- Microsoft Clarity: cookieless page-view and basic interaction analytics on marketing and legal pages only.
- Google Gmail: receiving support, privacy, and legal messages forwarded by Cloudflare.
6. Retention and deletion
- You control browser-local data, which remains until you clear site data or reset the project.
- Authentication sessions remain until sign-out, expiration, or account deletion.
- Cloud projects remain until you delete the project or account; limited infrastructure backups may take additional time to expire.
- Support messages are kept only as needed to handle the request, maintain necessary records, and meet legal obligations.
- In-product feedback is not written to a SeatMaply database. Resend currently retains Free-plan email data for 30 days; the resulting email copy is managed in the receiving Gmail account as needed to handle the request and maintain necessary records.
- Feedback abuse counters are retained for no more than 48 hours and are removed opportunistically by later feedback requests.
- Security logs are retained for provider-defined operational periods and should be limited to the shortest period needed for security.
- Microsoft currently documents these Clarity retention periods: click and heatmap aggregate data for nine months, playback data for 30 days, and labeled or favorited sessions for nine months. SeatMaply does not plan to label or favorite sessions; continuous journeys and full playback are limited in cookieless mode.
7. Your choices and rights
You may continue using local editing without signing in, download a project backup, permanently delete individual cloud projects, or delete your account. You may also contact us to request access, correction, or deletion of personal information connected with your account or support request.
If a project contains information about other people, you are responsible for having a lawful and necessary reason to process it and for avoiding unrelated sensitive information.
8. Children
SeatMaply is intended for users with legal capacity to use the service and is not directed to children as account holders. Teachers and organizers entering information about minors must follow applicable law and institutional rules and collect only what is necessary.
9. Changes
We will update this policy and its date when our processing, providers, or public features materially change. Material changes will be highlighted on the site or in the product when reasonably possible.
Contact us
To exercise a privacy right, report a concern, or ask about this policy, email:
hello@seatmaply.com