Legal
Privacy Policy
Last updated: May 2026 · v1.0 (beta)
What we collect
- Host accounts: name, email, password hash (or OAuth identity), basic platform preferences.
- Guest records: imported from your spreadsheets / Punchbowl exports — name, email, phone, age group, dietary restrictions, allergies, plus-one allowances, RSVPs.
- Communications: every email and SMS we send on your behalf is logged with delivery status.
- Operational metadata: audit trail of admin actions, IP addresses for rate-limiting, page-view bumps for invitation engagement signals.
What we don't do
- We don't sell or rent guest data.
- We don't share data with third-party advertisers.
- We don't use guest data for purposes outside running the event.
- We don't email guests automatically — sends require an explicit host action AND must pass our outbound safety gate (off by default).
Sub-processors
- Vercel — application hosting (USA).
- Neon — Postgres database (USA).
- Resend — outbound email (USA).
- Twilio — outbound SMS, when enabled per tenant.
- Sentry — application error monitoring.
Your rights
Hosts can export all tenant data to CSV from the admin at any time. Email hello@listorun.com for deletion requests or any privacy question.
This is a placeholder beta privacy policy. A full GDPR / CCPA-compliant policy will replace it before public launch.