1. Introduction
Listori (“we,” “our” or the “Platform”) respects your privacy and is committed to protecting the personal data you share with us. This Policy describes what information we collect, how we use it, with whom we share it and the rights you have over it, in compliance with the General Data Protection Regulation (GDPR) and applicable equivalent laws.
By using listori.io, you accept the practices described in this Policy. If you do not agree, please do not use the Platform.
2. Information We Collect
We collect the following categories of information:
- Account data: name, email address and encrypted password when you sign up.
- Event data: information about the weddings or events you create (dates, venues, descriptions).
- Guest data: names, phone numbers, email addresses and custom fields that you upload about your guests.
- WhatsApp integration data: when you connect your WhatsApp Business account through Meta’s Embedded Signup, we store, in encrypted form, your WhatsApp Business Account ID, Phone Number ID and access tokens. We do not access your personal WhatsApp conversations.
- Usage data: technical logs, IP address, browser, pages visited and Platform events, for security purposes and to improve the service. When you browse our commercial website, we measure those visits and the main actions (creating an account, starting a payment, completing it) by default, in accordance with this notice; you may object at any time in section 12. Session recordings are different and are only enabled if you expressly authorize them. We never measure the invitations your guests open, nor the confirmation, pass, checkout or administration screens.
- Apple Wallet pass: if a guest adds their entry pass to the Wallet app on their iPhone, we store a device identifier that iOS generates for us and a token so that we can notify them when their pass changes (for example, if the host assigns them a different table). We do not store any data from the phone or from the content of the pass, and that identifier cannot be used to recognize the guest outside Listori. It is deleted as soon as the guest removes the pass from their Wallet or the host deletes the guest.
- Attribution: for a limited period, we retain UTM parameters and click identifiers (for example, from an advertising campaign) to know which ad brought in a sign-up or a purchase. We do not use them to identify guests, and they stop being collected if you object.
- Cookies: we use essential cookies to keep your session active, and analytics and marketing cookies to measure use of the website and the effectiveness of our ads. We do not display an interruptive notice: the information is here, and you can turn off measurement whenever you wish in section 12.
3. How We Use Your Information
- To provide, maintain and improve the features of the Platform.
- To process the sending of WhatsApp broadcasts on your behalf, using your own WhatsApp Business Account.
- To send transactional emails related to your account (sign-up, password recovery, operational notifications).
- To send lifecycle communications about the use of your account where appropriate; you can unsubscribe by topic. Unsubscribes, bounces and complaints are honored before any non-transactional sending.
- To detect, prevent and respond to fraud, abuse or security issues.
- To comply with legal and regulatory obligations.
We do not sell your personal information or that of your guests to third parties.
4. Integration with Meta / WhatsApp Business Platform
Listori acts as an authorized Meta Tech Provider. When you connect your WhatsApp Business Account through Embedded Signup:
- You, not Listori, control the WhatsApp Business Account and bear the messaging costs with Meta.
- Your access token is stored encrypted at rest (Supabase Vault) and is never exposed in the frontend or in logs.
- We only use the strictly necessary permissions:
whatsapp_business_management,whatsapp_business_messagingandbusiness_management. - You can disconnect your Meta account at any time from your account settings or from Meta’s Business Manager.
5. Legal Bases for Processing
We process your data on the following legal bases:
- Performance of a contract: to provide you with the service you signed up for.
- Legitimate interest: for security, fraud prevention and product improvement.
- Consent: for marketing communications (which you may withdraw at any time).
- Legal obligation: when the law requires us to retain or disclose information.
6. Sharing with Third Parties
We share data only with providers that render essential services to us:
- Supabase: database and authentication.
- Vercel: application hosting.
- Meta Platforms, Inc.: for sending messages through the WhatsApp Business Platform.
- PostHog: product analytics, autocapture and session recordings on authorized surfaces, only after consent and with masking.
- Apple Inc.: solely to deliver the silent notification that updates a pass already saved in the Wallet app. That notification travels empty: Apple does not receive the guest’s name, their event, or any of the content of the pass.
- Resend: delivery and measurement of account/lifecycle emails; it receives only the data necessary to deliver the message.
All providers are subject to contractual confidentiality and security obligations equivalent to those described in this Policy.
7. Data Retention
We retain your data for as long as your account is active or as long as necessary to provide you with the service. If you delete your account, we will delete or anonymize your personal data within a maximum of 30 days, unless the law requires us to retain it for longer (for example, tax or audit records).
8. Your Rights
You have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Request the deletion of your data (the “right to be forgotten”).
- Object to or restrict certain processing.
- Port your data in a structured format.
- Withdraw your consent at any time.
- File a complaint with the data protection authority of your country.
To exercise any of these rights, write to us at jjjimlo@gmail.com.
9. Security
We implement technical and organizational measures to protect your data: encryption in transit (TLS 1.3), encryption at rest of sensitive tokens (Supabase Vault), Row Level Security in the database, multi-tenant authentication and continuous auditing. Even so, no system is 100% impenetrable; we recommend that you use strong, unique passwords.
10. Minors
Listori is not directed at children under 16 years of age. If you discover that a minor has provided us with personal information without parental consent, contact us so that we can delete it.
11. Changes to this Policy
We may update this Policy from time to time. We will notify you by email or through a prominent notice on the Platform before the changes take effect. The “last updated” date at the top of this document indicates the version in force.
13. Contact
If you have questions about this Policy or about the processing of your data, write to us at: