Data stored for an event
ArriveList stores the event title, optional date, source language, expected display names, arrival state, server timestamps, bounded change history, optimistic versions, and hashed capability credentials.
Data we deliberately avoid
ArriveList does not ask for email, phone, address, birth date, ticket ID, photographs, location, membership, notes, device fingerprint, or user accounts.
Private-link access
Raw manager and staff secrets remain in URL fragments, are captured only by the browser, removed from the address bar, stored for this tab in session storage, and sent only in dedicated capability headers. The server stores hashes rather than raw secrets.
Analytics and observability
Optional analytics may run after consent on localized public pages only. Manager and staff routes emit no analytics. Event titles, guest names, locators, capabilities, counts, and search text must not enter analytics or observability payloads.
Retention
Manager deletion is immediate. Closed events are automatically deleted after 30 days, and all events no later than 90 days after creation. Operational records needed to provide and protect the service are bounded.
Your choices
Use the manager link to delete the complete event. You may reject optional analytics and reopen cookie settings at any time without losing core product access.
Questions about these terms or your data: sympify.info@gmail.com