Privacy policy
Last updated 7 October 2026. This summary is written for clarity; have it reviewed for your jurisdiction (Malaysia PDPA, Singapore PDPA, Indonesia UU PDP) before launch.
What we collect
Organisers: name, email, password hash or Google account ID, billing records from Stripe (we never see full card numbers). Guests: only what the organiser enters or the guest submits — names, phone, email, reply, dietary notes and messages.
How it is used
To show invitations, record replies, send the messages the organiser asks us to send, and run the service. We do not sell personal data or show advertising.
Who controls guest data
The organiser decides who is invited and what is collected; we process guest data on their behalf. Guests can ask the organiser, or us at support@diagnostack.cloud, to correct or delete their details.
Retention
Event data stays until the organiser deletes the event or their account. Deleting an account removes all its events and guest lists immediately.
Security
Encrypted connections (HTTPS), hashed passwords, unguessable personal links, rate limiting and an audited admin console protected by two-factor authentication.
Third parties
Stripe (payments), Google (optional sign-in), our email delivery provider, and optionally Google Fonts for typefaces.