Privacy policy
Last updated July 13, 2026
Seat Layer lets event organizers design a seating chart, publish it, and sell seats. This page says what information the service handles, why, and what happens to it. It is written to be read, not skimmed past.
What we collect
- Organizer accounts. Your name, email address, and password. The password is never stored; we keep only a one-way scrypt hash of it. Signing in with Google or Apple stores the name and email those providers share.
- Bookings. When a guest reserves seats we store the name and email they enter, the seats, the amount, and a booking reference, so the order can be confirmed, looked up, and shown to the event's organizer.
- Payments. Card and bank details never touch Seat Layer. Guests pay on the payment provider's own hosted checkout (Stripe, PayPal, or Square), and organizers enter payout bank details on Stripe's hosted onboarding. We store only the provider's reference for the payment. A sale an organizer records manually (paid by cash or a transfer app) stores no payment details at all.
- Nothing else. No advertising, no analytics, no trackers. The only cookie is the session cookie that keeps you signed in. Chart drafts you design live in your own browser's storage until you publish them.
How it is used
To run the service you asked for: publishing charts, reserving seats, taking payments through the provider you chose, emailing the verification link and booking confirmations, and showing organizers the orders for their own events. We do not send marketing email and we do not sell or rent anyone's information.
Who sees it
- Your event's organizer. They see the orders for their own charts: guest name, email, seats, amount, and status. That is how they run the door.
- Payment providers. What you enter on their checkout pages is governed by their policies: Stripe, PayPal, Square.
- Nobody else, unless the law requires it.
How long we keep it
Accounts and orders are kept while the account and its events are active, since organizers need their sales records. Email the address below to delete your account or your booking details, and we will remove what the organizer's legitimate sales records do not require.
Security
Traffic runs over HTTPS, passwords and tokens are stored only as one-way hashes, and payment webhooks are accepted only with a verified signature. No online service can promise perfection; if you find a problem, please report it to the address below.
Children
Seat Layer is not directed at children under 13 and does not knowingly collect their information.
Changes and contact
Changes to this policy are posted on this page with a new date at the top. Questions, deletion requests, or security reports: [email protected].