Skip to main content
Seat EveryoneStart your guest list

Privacy

Your guest list stays yours.

Effective August 24, 2026. Arquebus LLC doing business as Seat Everyone (“we,” “us”) provides a seating concierge for one wedding at a time. This page is how we collect, use, share, and keep personal information on this site. A seating chart holds things you would never post anywhere — who is not speaking to whom, who is bringing whom, which cousin needs the quiet end of the room. Here is exactly what happens to it.

If you live in a U.S. state with a consumer privacy law, the state privacy rights section is for you. Cookies and similar storage are summarized here and spelled out on the cookie notice.

Four places a list can live

  • A working draft. While you type, the guest list lives in this browser. Sign-in is not required to keep going, and the copy already open here is separate from anything saved to an account. Clearing this browser’s site data removes it.
  • A saved wedding. When you save under your sign-in, the plan is stored with your account on our host. Reads, saves, and deletes of that copy go through that account.
  • A public share. There is no link until you make one. Anyone with the link can open the public copy you chose to share. Turning it off stops it opening.
  • A backup copy. We keep a disaster-recovery copy of saved weddings for a limited time. It is not the live plan, and deleting the live plan does not instantly erase every backup.

Personal information we collect

You may give us:

  • Account and contact data — the email and identifiers Clerk holds when you sign in, and any address you write to us at gaurav@arquebus.dev.
  • Wedding and guest-list data — names, sides, groups, households, seating wishes, private notes, table layout, and the other facts you type so the room can be seated. This is often information about other people. Only put it here if you have a right to.
  • Transactional data — that a wedding pass was purchased or refunded, and the Stripe identifiers needed to grant or revoke the unlock. We do not receive your card number.
  • Communications — what you send to support.

We also collect, automatically:

  • Device class — phone, tablet, or desktop. Four buckets, nothing finer. We do not fingerprint your device.
  • First-party activity — which step of this site you reached, from a fixed list in the code. Guest names and notes are never in those lines.
  • Campaign tags — if you arrived from a tagged link, the tags on that link.
  • IP address — used temporarily for abuse prevention. Our application does not write it to the product database. Hosting and security providers may process ordinary network request metadata.

We do not collect government IDs, income, precise geolocation, or payment card numbers. We do not buy lists.

How we use it

  • To run the seating concierge, save a wedding, and show you a chart.
  • To sign you in (through Clerk) and keep a saved plan under that account.
  • To take payment and refunds (through Stripe) and unlock or re-lock the named chart.
  • To email a purchase note (through Postmark) when that sending is on.
  • To keep a disaster-recovery copy of saved weddings.
  • To count how the site is used, in the first-party log described below.
  • To answer you, to keep the service up, and to comply with law.

We do not use this information for interest-based advertising. We do not train a public AI model on your guest list.

A saved wedding opens under your sign-in

Sign-in is handled by Clerk. Your saved wedding is stored under that account. Every read, every save, and every delete of the saved copy goes through it, so a request that is not yours cannot reach that plan. The working draft in this browser is not that lock: it is already on this device.

Nothing is shared until you share it

There is no link to your chart until you make one. When you do, it opens a public copy rather than your working plan:

  • Your private notes stay behind. The note you wrote on a guest is removed from the shared copy.
  • The people map stays off. The view that shows how guests are connected is not included unless you turn it on.
  • You can turn the link off. Once you do, it stops opening for anyone who has it. We tell search engines not to index these pages, and we tell browsers and caches not to store them, so the next request after you turn a link off should not keep serving the chart. That is not a promise that a copy someone already downloaded disappears from their device.

Who holds a copy

We share personal information with the services that actually see something, and only in the role named. We do not sell it, and we do not share it for targeted advertising.

  • Clerk — sign-in and identity. When sign-in is switched on, their script loads in the browser. Clerk privacy.
  • Stripe — checkout and payment. Card details are entered on Stripe’s page, not here. Stripe privacy.
  • Fly.io — the application and saved weddings. Fly.io privacy.
  • GitHub — the off-host backup artifact, when that path is armed. GitHub privacy.
  • Postmark — the purchase email, only when we have turned that sending on. Postmark privacy.

We may also share information with professional advisors, with a buyer if this business is sold, or with authorities when we believe the law requires it. There is no Google Analytics here, and no advertising pixel. The counting described below is written by this site, into this site’s own database, and it is not sent to an analytics vendor.

Payment happens on Stripe

Checkout opens on Stripe’s own hosted page. Your card details are entered there, not here, so Seat Everyone never receives them.

Cookies and similar storage

See the cookie notice for the full list. In short: first-party browser storage holds the working draft and the visitor/session ids; Clerk sets sign-in cookies when accounts are on; we set no advertising cookies. We currently do not respond to “Do Not Track” signals.

Yours to delete

You can delete a saved wedding from your account page. It takes an explicit confirmation, and once it is done the wedding stops opening on every device you sign in from. The paid unlock goes with it. A wedding you start afterwards is a new one to unlock. The working copy already open in this browser is a separate thing.

Deleting removes the live plan from the running app. Copies may remain in Fly.io volume snapshots and in the off-host backup until those copies expire on their own schedule — today, the off-host artifact is kept for 30 days. We do not encrypt that backup in the application; access to it is limited to people who can operate the host and the backup store.

Open your account

How long we keep it

  • Working draft — until you clear this browser, or until the browser drops it.
  • Saved wedding — until you delete it, or we close the account as described in the terms.
  • Share link — until you turn it off.
  • Backup copies — until they expire (30 days for the off-host artifact today).
  • First-party counts — after 180 days the visitor id, account id, and plan id in those measurements are replaced with a scrambled stand-in, and campaign tags are deleted. We keep the key that does the scrambling, so this is not the same as erasing you.

We count what the site does, not who you are

We do measure how people move through this site, and we would rather tell you exactly how than leave you to guess.

A measurement is one line from a short fixed list — the landing page was opened, a step of the guest-list flow was reached, a chart finished solving, an export was downloaded, a share link was made. With it we keep the time, the step or section it refers to, and, where size matters, a bucket instead of a number: 50–99 guests, never 73.

No guest is ever in one. Not a name, not a note, not who cannot sit near whom, not the title you gave your wedding, not anything you typed. Those live in your plan and nowhere else, and the list of things we are allowed to count is fixed in the code — anything not on it is refused rather than quietly stored.

Three identifiers make the counting add up:

  • A visitor id. A random string this site puts in your browser’s own storage the first time you arrive. Not a cookie, not shared with anyone; clearing your browser data removes it.
  • A session id. Also random, and it expires after thirty minutes of no activity, or when you arrive again from a new campaign link.
  • Your account id, once you sign in, so one person who visited and then signed in is counted as one person.

Two more things come off the request itself: whether the browser is a phone, tablet or desktop — four buckets, nothing finer — and, if you arrived from a campaign link, the tracking tags that were in that link. We do not fingerprint your device. Our application uses the IP address temporarily for abuse prevention and does not write it to the product database. Hosting and security providers may process ordinary network request metadata.

After 180 days the visitor id, the account id and the plan id in those measurements are replaced with a scrambled stand-in, and the campaign tags are deleted outright. We keep the key that does the scrambling, so this is not the same as erasing you — it is a deliberate half-step that lets us still see “this was one returning person” years later without holding the id itself. The counts survive; the thread back to your account and your plan does not.

That rotation is not a promise we make and then forget. It runs on our server on a daily schedule, and every pass writes down what it changed, so “did it actually happen” is a question with an answer rather than an assurance.

Security

Saved weddings sit on our host under your sign-in. We do not claim encryption of the backup. Internet services can fail. If we learn of a breach that the law requires us to tell you about, we will.

Where it is processed

We operate in the United States. Clerk, Stripe, Fly.io, GitHub, and Postmark may process information in the United States or in other countries where they run. Privacy law there may not match the law where you live.

Children

This site is for people 18 and older. It is not directed at children. If you believe we have collected personal information from a child in a way the law forbids, write to us and we will delete what the law requires us to delete.

State privacy rights

If you are a resident of a U.S. state whose privacy law applies to us, you may have some of these rights: to know what we have collected, to receive a copy, to correct it, to delete it, to appeal a refusal, and to be free from discrimination for asking. These rights are not absolute. We may need enough information to confirm it is you.

We do not sell your personal information. We do not share it for targeted advertising. We do not use it for profiling that produces legal or similarly significant effects. We do not have actual knowledge that we collect, sell, or share the personal information of consumers under 16. Guest-list facts you type can include sensitive information about other people; we do not use that information to infer characteristics about you for advertising.

To make a request, email gaurav@arquebus.dev from the address on the account, and say what you want us to do. Authorized agents may write from that same thread; we may ask for proof they can act for you. California residents may also send a “Shine the Light Request” to that address with your name, mailing address, and a statement that you are a California resident. Nevada residents may use the same address to opt out of any future sale of covered information; we do not make those sales today.

Changes

We may update this page. The date at the top will change. Material changes will be posted here. Using the site after a change means this version applies to that use.

Anything else, ask

This page says what the product does and stops there. If you want to know something that is not written above, write to us and you will get a straight answer from a person.

gaurav@arquebus.dev

Written in plain words on purpose, on the skeleton of a U.S. privacy policy released by General Legal under CC0. If a line here is unclear, tell us and it gets rewritten. This is not a lawyer’s sign-off.