The short version
The free planner saves names, layouts and manual seat assignments in your browser. That local chart is not uploaded to us. If you deliberately buy and use an Event Pass, the event you choose, including its guest rules, is also stored in our cloud database so it can use paid planning features, sync across devices and be shared. We do not sell personal information or use chart contents for advertising.
Information you enter into the tools
- Where it is stored: in your browser's local storage, on your device only.
- Who can see it: anyone with access to that browser profile on that device. We cannot see it.
- How to delete it: use the Reset button in the tool, or clear site data for this domain in your browser settings.
- Retention: the local copy stays until you delete it. We do not control that copy and cannot delete it for you.
Event Pass accounts and cloud charts
Event Pass users sign in by email. Our authentication and database provider processes the account email, sign-in records, cloud chart document and version history. The owner can delete a cloud event from the account. Private view links use a random secret token; only a one-way hash of that token is stored.
Cloud editing lasts for 90 days after payment. The event is then kept read-only for a 30-day export period and deleted after day 120, together with its versions and private share link. Deleting a cloud event does not remove a separate copy already saved in your browser.
Payments and service providers
Waffo Pancake acts as the Merchant of Record for Event Pass purchases. It processes checkout, payments, applicable taxes, refunds and chargebacks; we do not receive your full card number. We receive the email, order and payment identifiers, amount, currency, status, tax and timing needed to activate and support the pass. Supabase provides authentication, database and server functions and sends account and collaboration messages. Resend sends service reminders before an Event Pass cloud copy is deleted; it processes the recipient address and delivery metadata for those messages. Cloudflare provides hosting, security, cookie-free aggregate Web Analytics, and Zaraz consent and tag management. If you consent to Analytics, Google Analytics 4 processes the analytics events described below. Each provider handles information under its own privacy terms.
Information collected automatically
Like most websites, our hosting provider records standard server request data such as IP address, browser type, referring page and time of request. This is used for security and aggregate traffic measurement.
Cloudflare Web Analytics provides aggregate page and performance measurements without using cookies. Separately, Google Analytics 4 is loaded through Cloudflare Zaraz only after you accept the Analytics purpose. It may set first-party analytics cookies and receive page paths, referrer and general device information, plus anonymous product actions and counts such as starting a plan, adding guests, adding a rule, auto-arranging or exporting.
We configure Zaraz not to send your originating IP address to Google Analytics. Neither analytics service receives guest or student names, notes, relationship details, seating rules, meal or accessibility information, or chart contents. Rejecting Analytics prevents Google Analytics 4 from loading; the planner still works normally.
Children, your rights, and changes to this policy
This site is intended for adults, including teachers who may enter student names into the classroom tool. Keep student charts local unless your organisation has decided it has an appropriate legal basis and safeguards for cloud processing. Do not create public links containing sensitive personal information.
Depending on where you live, you may have rights to access, correct or delete personal data held about you. Local chart data can be deleted from your browser. Event Pass owners can delete their cloud event or contact us about account and payment records. If this policy changes, the updated version will be posted here with a new last-updated date.