Privacy Policy
Last updated: 2026
This notice explains how The Guest Office (“we”) handles personal data when you use The Guest Office, and how guests who receive an invitation through the service can exercise their rights under the UK and EU General Data Protection Regulation.
1. Who is responsible for your data
For our own customers (the people who create an account) we are the data controller. For guest data that a customer uploads and sends invitations to, the customer is the controller and we act as their processor — we only handle guest data on their instructions.
The Guest Office
[Registered address line 1]
[City, Postcode]
[Country]
privacy@theguestoffice.com
2. What we collect
- Account data — name, email address, optional company name and country, sign-in times.
- Guest data entered by our customers — name, company, email address, phone number, relationship notes, seat allocations, attendance answers, dietary requirements and any message a guest writes.
- Files — tickets, agendas, venue photos and documents uploaded by the host.
- Email delivery data — whether an email was delivered, bounced or was marked as spam.
- Technical logs — actions taken in the workspace (who did what and when) and error records, kept for security and support.
We do not use advertising or analytics trackers, and we set no cookies other than the one that keeps you signed in.
3. Why we use it, and our legal basis
- To provide the service — deliver invitations, tickets and reminders, record RSVPs and collect feedback. Legal basis: performance of a contract (customers) and the legitimate interests of the host in organising their hospitality (guests).
- To keep the service secure and diagnose problems. Legal basis: legitimate interests.
- To meet legal and accounting obligations. Legal basis: legal obligation.
Dietary requirements can reveal health or religious information. They are optional, and a guest provides them voluntarily so the host can cater for them; a guest can always leave the field blank or contact the host directly.
4. Who we share it with
We only share personal data with the service providers listed on our subprocessors page, and with the host who invited the guest. We never sell personal data.
- Lovable Cloud (Supabase infrastructure) — Application hosting, database, file storage and authentication.
- Lovable Email — Sending invitation, ticket, reminder and feedback emails.
- HNeeds sports data feed — Fixture, team and venue information.
5. Where data is stored
Personal data is stored in the European Union. Where a provider processes data outside that region, it does so under the European Commission’s standard contractual clauses.
6. How long we keep it
- Account data: while the account is open, then deleted.
- Guest records and uploaded ticket files: kept while the host’s workspace is active. Hosts can set an automatic clean-up (for example 12 months after the event), after which guest contact details and ticket files are erased.
- Activity and security logs: up to 24 months, or shorter if the host sets it.
- Email delivery records: up to 12 months.
Deleting a workspace removes its guests, invitations, files and logs.
7. Your rights
You have the right to access a copy of your data, to have it corrected or erased, to restrict or object to processing, and to data portability. Where we act as a processor, we pass a request on to the host who invited you and help them answer it.
To make a request, email privacy@theguestoffice.com. We answer within one month. If you are not satisfied you can complain to your national data protection authority.
8. Security
Data is separated per workspace and enforced at database level, tickets and documents are kept in private storage and only ever shared through short-lived personal links, and guest pages are excluded from search engines. Access to production data is limited to the people who need it.
9. Changes
We will post any change to this notice on this page and, for material changes, notify account holders by email.