1. Who We Are
SAMAIO (“we,” “us,” or “our”) provides an offline-first event planning and coordination operating system for couples, hosts, and professional wedding coordinators.
Legal Entity: [LEGAL BUSINESS NAME] • Registered Address: [FULL LEGAL ADDRESS]
2. Scope of This Policy
This Privacy Policy applies to personal information collected when you access or use the SAMAIO web application, host workspace, guest RSVP portals, and related legal or support communication channels.
3. Data Controller and Processor Roles
For account creation, billing, and direct support communications, SAMAIO acts as a Data Controller.
For guest list entries, RSVP details, seating assignments, vendor contacts, and event logistics uploaded by hosts or coordinators into a workspace, the Customer acts as the Data Controller, and SAMAIO acts as a Data Processor processing information on the Customer’s instructions. Hosts and coordinators are responsible for providing appropriate notice and obtaining any required consent from guests before entering guest information into SAMAIO.
4. Information We Collect
We collect information directly from you, automatically when you interact with our Services, and from third-party payment or authentication integrations.
5. Account and Identity Information
When registering an account or accessing a host workspace, we may collect your email address, full name, profile image URL, password hashes (handled via secure authentication providers), workspace role (Couple or Coordinator), and licensing keys.
6. Event Workspace Information
SAMAIO processes event names, event dates, venues, budget allocations, itemized vendor expenses, vendor contacts, timelines, floorplan CAD dimensions, design preferences, and custom event notes entered into your event workspace.
7. Guest and RSVP Information
To facilitate guest registry management and digital RSVP portals, SAMAIO processes guest names, email addresses, phone numbers, guest group classifications (e.g., Bride Family, Groom Family), RSVP attendance statuses, dietary preferences or restrictions, accessibility requirements, plus-one designations, seating assignments, and personal notes left for the couple.
8. Payment and Transaction Information
Paid Plan transactions are processed through Lemon Squeezy, which acts as the merchant of record for purchases made through its checkout. Lemon Squeezy may process payments, applicable taxes, payment verification, refunds, chargebacks, and transaction communications under its own terms and policies. SAMAIO may receive transaction identifiers, customer email address, subscription status, license entitlements, billing country or region, currency, and payment status necessary to provide and manage the Services.
SAMAIO does not store full payment-card numbers or card security codes on its own servers unless expressly stated in the Privacy Policy. The price, currency, billing interval, first-charge date, trial-conversion terms, and renewal terms will be displayed before the user completes checkout.
9. Device, Usage, and Technical Information
We log technical details necessary for platform security and debugging, including IP address, browser user-agent, operating system version, access timestamps, rate-limit counters, and server error tracebacks.
10. Local-First and Offline Data
SAMAIO utilizes a local-first application architecture designed for event-day reliability:
- Workspace information and offline edits are saved locally on your device’s browser storage (`localStorage` / IndexedDB).
- Pending changes automatically synchronize to SAMAIO cloud infrastructure when connectivity is restored.
- Offline availability does not guarantee that external integrations (such as email delivery via Resend or payment webhooks) operate without internet access.
- Users and coordinators are responsible for securing their physical devices and shared browser environments.
- In rare cases of simultaneous multi-device editing, synchronization conflicts or delays may occur.
11. Support Communications
When you contact SAMAIO Concierge or technical support, we collect the content of your message, email address, diagnostic logs, and related ticket information to resolve your inquiry.
12. How We Use Information
We use collected information to provide, maintain, format, and synchronize event workspaces; transmit RSVP invitation links and emails; verify subscription entitlements; prevent fraud or abuse; and deliver concierge support.
13. Cookies, Local Storage, and Service Workers
SAMAIO uses essential session cookies, local storage tokens, and Progressive Web App (PWA) service workers strictly required for authentication, offline caching, and workspace state persistence.
Inventory: [ANALYTICS AND COOKIE INVENTORY]
14. AI-Assisted Features
If you utilize AI-assisted seating recommendations or event drafting tools:
- Relevant event logistics metadata is transmitted to accredited AI infrastructure providers to generate suggestions.
- Customer event inputs are not used by SAMAIO to train public foundation models.
- AI outputs are suggestions only and must be reviewed by the user. AI does not replace human judgment regarding guest relationships, dietary safety, or venue accessibility.
15. How We Share Information
We do not sell, rent, or trade personal information or guest lists to advertisers. We share data only with infrastructure subprocessors necessary to deliver the Services or when legally mandated.
16. Subprocessors and Service Providers
SAMAIO engages trusted third-party subprocessors for cloud hosting (Cloudflare), database persistence (Supabase / PostgreSQL), email delivery (Resend), and billing (LemonSqueezy).
Full List: [SUBPROCESSOR LIST URL]
17. International Data Transfers
SAMAIO operates globally. Data may be stored or processed in servers located outside your home jurisdiction. We enforce appropriate safeguards for international data transfers.
Safeguards: [INTERNATIONAL TRANSFER SAFEGUARDS]
18. Data Retention
After a verified deletion request, SAMAIO will delete or anonymize personal information from active databases within 30 days, subject to legal, security, audit, backup, and billing record requirements.
Schedule: [RETENTION PERIODS]
19. Security
We implement administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, destruction, loss, or alteration.
20. User Privacy Rights
Depending on your jurisdiction, you have rights to access, correct, port, export, or delete your personal information stored on SAMAIO.
21. GDPR/UK GDPR Rights
European Union and UK residents have rights under the General Data Protection Regulation, including rights to object to processing, lodge complaints with supervisory authorities, and request data portability.
22. California Privacy Rights
California residents have rights under the CCPA/CPRA to request categories of data collected, request deletion, and opt out of any future data sales. SAMAIO does not sell personal information.
23. Marketing Communications
You can opt out of non-essential promotional newsletters at any time by following the unsubscribe link in our emails or contacting support.
24. Children’s Privacy
SAMAIO is not directed toward children under 16 years of age. We do not knowingly collect personal information from children.
25. Third-Party Links and Services
Our Services may contain links to third-party vendor sites or payment portals. We are not responsible for the privacy practices of external websites.
26. Data Breach and Security Incident Communications
In the event of a confirmed security incident affecting Customer Data, SAMAIO will notify affected account holders in accordance with applicable legal requirements.
27. Changes to This Policy
We may update this Privacy Policy from time to time. The effective date at the top of this document indicates when changes take effect.
28. Contact Information
For privacy inquiries, GDPR/CCPA requests, or data deletion requests, contact our privacy response team at: