Placecard Privacy Policy
Effective date: July 14, 2026
Last updated: July 14, 2026
This Privacy Policy explains how Placecard (we, us, or our) collects, uses, discloses, and protects information when people use our websites, applications, event pages, guest lookup tools, checkout flows, emails, and related services (collectively, the Service).
Operator: Silver Sage Software LLC
Contact: support@placecard.app
Website: https://placecard.app
If you are a host or event organizer, you are responsible for making sure that you have the right to upload, import, publish, and otherwise process guest information through the Service.
1. Scope
This Privacy Policy applies to:
- hosts, organizers, venue operators, planners, and other account holders who use Placecard to create and manage events;
- guests and visitors who access a published event page, QR code, guest lookup flow, or public guest list;
- people who receive emails or complimentary access invitations from Placecard; and
- people who contact us for support, billing, privacy, or other requests.
This Privacy Policy does not apply to websites, services, or applications that we do not operate, including third-party services that may be linked from the Service.
2. Information we collect
We collect information in the following categories.
Account information
When a host creates or uses an account, we may collect:
- name;
- email address;
- authentication identifiers;
- account creation date;
- administrator status, where applicable; and
- related account records needed to operate the Service.
Authentication is handled through our authentication provider, currently WorkOS AuthKit.
Event information
Hosts may create and manage events. Event information may include:
- event title;
- subtitle or description;
- event date text;
- venue or location text;
- public event slug or URL;
- publication status;
- whether the host has enabled a public guest list;
- guest count;
- uploaded floor-plan images; and
- event creation and update timestamps.
Guest information
Hosts may upload, import, or manually enter guest information. Guest information may include:
- guest full name;
- table number or seating assignment;
- meal preference;
- import identifiers from a spreadsheet or CSV file; and
- related event assignment records.
Meal preferences or similar event details may reveal dietary restrictions, allergies, religious practices, accessibility needs, or other sensitive information depending on what a host enters. Placecard is not designed for medical records or highly sensitive personal data. Hosts should not upload sensitive guest information unless it is necessary for the event and they have the right to do so.
Uploaded content
Hosts may upload floor-plan images or similar event-related files. We validate supported file types and file sizes, but hosts remain responsible for the content they upload.
Billing information
If a host purchases a paid plan, we may collect and store billing-related records, such as:
- selected plan;
- billing provider;
- billing status;
- provider customer ID;
- checkout ID;
- order ID;
- subscription ID;
- current billing period end;
- payment failure status; and
- related entitlement records.
Payments are processed by our billing provider, currently Polar. We do not intentionally store full payment card numbers on our own systems.
Email and notification information
We may collect and process email information needed to send and track service-related or access-related emails, including:
- recipient email address;
- email delivery ID;
- delivery status, such as pending, sent, delivered, bounced, complained, delayed, or failed;
- complimentary grant reason or related access record; and
- timestamps related to email delivery.
Our email delivery provider is currently Resend.
Device, session, cookie, and security information
When someone uses the Service, we may collect or process:
- IP address or derived network information;
- browser, device, and request metadata;
- session identifiers;
- authentication/session storage information;
- guest lookup session cookie information;
- rate-limit and abuse-prevention records;
- logs and diagnostic information; and
- information needed to maintain security, prevent abuse, and operate the Service.
For published guest pages, we use a guest session cookie to support rate limiting, abuse prevention, and the guest lookup experience. See our Cookie Policy for more detail.
Support and communications
If you contact us, we may collect your name, email address, message contents, attachments, and other information needed to respond.
3. Sources of information
We collect information from:
- you, when you create an account, contact us, pay for a plan, or use the Service;
- hosts, when they upload guest lists or event information;
- guests, when they use a published event page or guest lookup flow;
- service providers, such as authentication, billing, email, hosting, and database providers;
- automated technologies, such as cookies, logs, and security systems; and
- publicly accessible or linked information only when reasonably needed to operate or secure the Service.
4. How we use information
We use information to:
- provide, operate, and improve the Service;
- authenticate hosts and manage accounts;
- create, edit, and publish events;
- import and manage guest lists;
- enable guests to find table assignments through a published event link or QR code;
- show optional public guest lists when enabled by a host;
- process billing, checkout, subscription, entitlement, and customer portal flows;
- send transactional, service, support, billing, and access-related emails;
- prevent fraud, abuse, scraping, unauthorized access, and misuse;
- rate-limit guest-facing endpoints;
- debug, monitor, and maintain the Service;
- comply with legal obligations;
- enforce our Terms of Service; and
- respond to support, legal, privacy, or safety requests.
5. Published event pages and guest visibility
Hosts can publish an event page and share it through a link or QR code. When an event is published, anyone with the event link or QR code may be able to access guest-facing event features.
Depending on the event settings and guest lookup flow, guest-facing information may include:
- event title, date, and location text;
- guest names matching a search query;
- table assignments;
- the selected guest’s meal preference;
- tablemates at the same table; and
- an optional public guest list grouped by table, if the host enables that feature.
Hosts are responsible for deciding whether to publish an event, whether to enable the public guest list, and whether the event information and guest information they upload is appropriate to make available through the Service.
6. How we disclose information
We may disclose information in the following circumstances.
Service providers
We use service providers to operate the Service. These may include:
- Convex for backend, database, file storage, and server functions;
- WorkOS AuthKit for authentication and user management;
- Polar for billing, checkout, subscription, entitlements, and customer portal functionality;
- Resend for email delivery;
- Vercel or similar hosting/infrastructure providers for deployment, hosting, serverless execution, and request handling;
- other vendors we use to operate, secure, debug, or improve the Service.
Hosts and guests
Information may be displayed to hosts inside their own event dashboard. Guest-facing event information may be shown to guests and other visitors through a published event page, guest lookup flow, QR code, or public guest list.
Legal, safety, and compliance
We may disclose information if we believe it is reasonably necessary to:
- comply with law, legal process, or government requests;
- protect the rights, privacy, safety, or property of Placecard, users, guests, or others;
- investigate or prevent fraud, abuse, security incidents, or misuse;
- enforce our Terms of Service; or
- respond to disputes, chargebacks, or billing issues.
Business transfers
If we are involved in a merger, acquisition, financing, reorganization, sale of assets, or similar transaction, information may be transferred as part of that transaction, subject to appropriate protections.
With your direction or consent
We may disclose information when you direct us to do so or when you give consent.
7. Selling or sharing personal information
We do not sell personal information for money. We do not currently use cross-context behavioral advertising or marketing pixels in the Service. If we later add advertising, retargeting, or similar marketing technologies, we will update this Privacy Policy and our Cookie Policy and provide any choices required by applicable law.
8. Legal bases for processing, where applicable
Where laws such as the GDPR or UK GDPR apply, our legal bases may include:
- contract: to provide the Service, account, checkout, and event-management features;
- legitimate interests: to secure, maintain, improve, and prevent abuse of the Service;
- consent: where required for optional cookies, marketing communications, or optional processing;
- legal obligation: to maintain billing, tax, compliance, or legal records; and
- vital or public interests: where required in rare safety or legal circumstances.
For guest information uploaded by hosts, the host generally determines what guest information is uploaded and why. Placecard processes that information to provide the Service.
9. Retention
We keep information for as long as reasonably necessary to provide the Service, comply with legal obligations, resolve disputes, prevent abuse, enforce agreements, and maintain business records.
General retention principles:
- account records are kept while the account is active and for a reasonable period afterward;
- billing records may be retained as required for tax, accounting, fraud-prevention, and legal purposes;
- event and guest records are kept while needed to operate the event and account;
- floor-plan images may remain in storage while associated with an event and may remain in backups for a limited time after deletion;
- email delivery metadata may be retained to diagnose delivery, compliance, and abuse issues;
- security, rate-limit, and diagnostic logs may be retained for a reasonable period; and
- published event information remains available until unpublished, removed, or otherwise restricted.
Hosts may request deletion of account, event, or guest information by contacting support@placecard.app. Some records may need to be retained where required for billing, security, legal, tax, accounting, or dispute purposes.
10. Security
We use administrative, technical, and organizational safeguards designed to protect information. These include authentication controls, access controls, file validation, rate limiting, webhook validation, and security monitoring appropriate for the current stage of the Service.
No internet service can guarantee perfect security. You are responsible for using a secure device, keeping your login credentials safe, and limiting the information you upload to what is appropriate for your event.
11. Your choices and rights
Depending on where you live, you may have rights to:
- access personal information;
- correct personal information;
- delete personal information;
- receive a copy of personal information;
- object to or restrict certain processing;
- withdraw consent, where processing is based on consent;
- opt out of certain sales, sharing, or targeted advertising if applicable; and
- appeal or complain to a privacy regulator where applicable.
To make a request, contact support@placecard.app. We may need to verify your identity and account relationship before responding.
Guests whose information was uploaded by a host may also need to contact the host directly, because the host controls the event content and guest list.
12. California and other U.S. state privacy rights
Some U.S. state privacy laws give residents additional rights over personal information. If those laws apply to us or to your information, we will honor applicable rights and provide required disclosures.
We do not currently sell personal information for money or use cross-context behavioral advertising. If this changes, we will update this policy and provide any required opt-out methods.
13. International users and transfers
We operate the Service using providers that may process information in the United States and other countries. If you access the Service from outside the United States, your information may be transferred to, stored in, or processed in a country that may not provide the same level of data protection as your home jurisdiction.
Where required, we rely on appropriate safeguards for international transfers.
14. Children’s privacy
The Service is not intended for children under 13, and we do not knowingly collect personal information directly from children under 13. Hosts should not upload information about children unless they have the legal right and appropriate consent or authority to do so.
For paid host accounts, you must be at least 18 years old or have authority to bind the organization you represent.
15. Third-party links and services
The Service may link to third-party websites or services. We are not responsible for the privacy practices of third parties. Review their policies before providing information to them.
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The updated version will be posted on this page with a new effective date or last updated date. If changes are material, we may provide additional notice where required.
17. Contact
Questions, requests, or concerns about this Privacy Policy can be sent to:
Placecard Privacy
Email: support@placecard.app
Operator: Silver Sage Software LLC
Appendix: Notice at collection summary
This table summarizes the categories of personal information we collect and the purposes for which we use them. Section 2 has the complete details.
| Category | Examples | Purposes |
|---|---|---|
| Account information | Name, email address, authentication identifiers, account status | Create accounts, authenticate users, provide host features, support users, secure the Service |
| Event information | Event title, date text, location text, public slug, publication status, guest count | Create and manage events, publish event pages, generate guest-facing event experiences |
| Guest information | Guest names, table assignments, meal preferences, CSV import identifiers | Import guest lists, manage seating, let guests find their table, show optional public guest lists |
| Uploaded content | Floor-plan images and related file metadata | Store and display event floor plans, support host event management |
| Billing information | Plan, billing status, customer ID, checkout ID, order ID, subscription ID, payment failure status | Process checkout, manage subscriptions, provide paid access, maintain accounting and fraud-prevention records |
| Email information | Recipient email, delivery ID, delivery status, complimentary access reason | Send service-related emails, track delivery, manage complimentary access, prevent abuse |
| Device, session, and security information | IP-derived information, browser/request metadata, guest session cookie, rate-limit records, logs | Operate, secure, debug, rate-limit, and prevent abuse of the Service |
| Support communications | Message contents, contact details, attachments | Respond to requests, provide support, resolve disputes, improve the Service |
We do not sell personal information for money, and we do not currently use cross-context behavioral advertising or marketing pixels.