Home

Privacy Policy

Last updated: August 18, 2026

Here's what data we collect, how we use it, and who can access it — in the simplest terms possible.

1. Data we collect

From organizers: name, phone number or email (for sign-in), and the event data they create. From guests: name and phone number (when responding to an invitation), and their answers to any custom questions the organizer added.

2. How we use your data

We use your data only to run the service: displaying the invitation, recording guest responses, sending confirmations and reminders (via WhatsApp or email once enabled), and showing response stats to the organizer. We never sell your data or use it for advertising.

3. Who can access your data

A given event's guest data is visible only to that specific event's organizer — enforced at the database level itself (Row Level Security), not just in the interface. No other organizer can see events or guests that aren't theirs.

4. Sharing data with third parties

When an organizer enables WhatsApp or email sending, the confirmation message is sent through the relevant provider (Meta WhatsApp Cloud API, or Resend for email) — only the data needed to deliver that message (the phone number or email, and the message text) is shared with them. We never share your data with anyone else.

5. Data security

Data is stored in Supabase (a secure PostgreSQL-based infrastructure), protected by row-level access policies. No full-privilege admin key is ever used from inside the browser.

6. Your rights

Any guest can edit or delete their response via their own private link at any time before the deadline. To request full deletion of your data from any event, reach us at support@mahalli.app.