Privacy policy

Last updated 7 October 2026. This summary is written for clarity; have it reviewed for your jurisdiction (Malaysia PDPA, Singapore PDPA, Indonesia UU PDP) before launch.

What we collect

Organisers: name, email, password hash or Google account ID, billing records from Stripe (we never see full card numbers). Guests: only what the organiser enters or the guest submits — names, phone, email, reply, dietary notes and messages.

How it is used

To show invitations, record replies, send the messages the organiser asks us to send, and run the service. We do not sell personal data or show advertising.

Who controls guest data

The organiser decides who is invited and what is collected; we process guest data on their behalf. Guests can ask the organiser, or us at support@diagnostack.cloud, to correct or delete their details.

Retention

Event data stays until the organiser deletes the event or their account. Deleting an account removes all its events and guest lists immediately.

Security

Encrypted connections (HTTPS), hashed passwords, unguessable personal links, rate limiting and an audited admin console protected by two-factor authentication.

Third parties

Stripe (payments), Google (optional sign-in), our email delivery provider, and optionally Google Fonts for typefaces.