Privacy Policy
Last updated: August 2026
My Guest Work Pty Ltd (ABN 38 698 315 187) trading as MyGuestWork
1. Introduction
1.1 This Privacy Policy explains how My Guest Work Pty Ltd (ABN 38 698 315 187), trading as MyGuestWork (we, us or our), collects, uses, holds, discloses and protects personal information. We handle personal information in accordance with the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs), and, where they apply to you, other privacy laws.
1.2 This Privacy Policy applies to our website at myguestwork.com, our app at app.myguestwork.com (together, the Platform), the event pages, QR code pages and guest seat-finder pages created through the Platform, and your communications with us.
1.3 If you do not agree with how we handle personal information as described in this Privacy Policy, you should not use the Platform.
2. Definitions
2.1 In this Privacy Policy:
3. About the Platform
3.1 MyGuestWork is an event guest management platform. It helps Organisers manage guest lists, online RSVPs and digital invitations, seating plans, QR code guest lookup pages, event pages, menus, floor plans, logos and related event materials.
3.2 Some features may only be available on certain plans, and some features may be introduced, changed or removed over time.
4. Personal Information We Collect
4.1 The personal information we collect depends on how you interact with the Platform.
4.2 Account users and Organisers. When you create an account or use the app, we may collect:
4.3 We do not collect or store your full card number, CVC or bank account details. Payments are handled by Stripe (see clause 11).
4.4 Guest information entered by Organisers. Organisers may upload or enter personal information about Guests, which may include:
4.5 RSVP information provided by Guests. Where an Organiser uses our RSVP feature and a Guest completes an RSVP, we collect:
4.6 Dietary information and notes are optional and may be left blank. Some dietary options can reveal health information or religious beliefs, which are sensitive information. See clause 16 for how we handle this.
4.7 RSVP delivery records. When RSVP invitations, reminders or confirmations are sent, we record the delivery status of each invitation, the number of send and reminder attempts and when they occurred, a sanitised reason where a message fails or bounces, and log entries recording that a message was sent, which may include the recipient email address. We also store information our email provider reports back to us about failed delivery, which may include the recipient email address and the provider's reason.
4.8 Our seat-finder feature is designed to use minimal guest information. A Guest can be added and seated using a first name alone, and the seat-finder itself does not require guest email addresses, phone numbers, dietary requirements or health information. That information is collected only where an Organiser records it or uses the RSVP feature.
4.9 Some features may collect additional guest information if we introduce them in the future. For example, if WhatsApp or SMS invitation features are enabled, guest phone numbers may be used to deliver messages where those features are available and used. We will only use information in this way once the relevant feature is available and used.
4.10 Guests using public event pages and RSVP pages. If you are a Guest and you access an event page, seat-finder page or RSVP page using a QR code or link, we may process the page you visit, your search interactions, technical information about your device and browser, and a shortened irreversible hash of your IP address used to apply rate limits. We do not run analytics or advertising on guest-facing pages, and we do not send anything to an advertising platform about a Guest's use of them (see clause 8 and clause 9). If you use a public photo upload feature where available, we may process the uploaded content and an optional uploader display name. A seat-finder page may display guest first names, last names (where provided) and seating or table assignments, but never guest email addresses, phone numbers or payment details. An RSVP page displays the names of the people covered by that invitation and any answers already saved for them. We do not display payment details on any guest-facing page. See clause 6.
4.11 Website visitors and support requests. When you visit myguestwork.com, we may collect information you submit through the contact form (name, email address, event type and message), analytics information (only if you accept analytics cookies), and, only if you accept marketing, information shared with Meta as described in clause 8.4, and general usage information including your IP address, which we collect as part of normal server logs. If you contact support, we may also collect your message, user ID (if logged in), the relevant event, the page URL, and technical details such as your user agent, viewport size, platform, browser language and timezone.
4.12 Signing up and completing a purchase. If you have accepted marketing, then at the moment you complete a signup or a purchase in the app we also collect advertising identifiers for the purpose of sending them to Meta. These are the "_fbp" and "_fbc" cookie values, your IP address in full, your browser user agent string in full, and, for a purchase, the address of the page the checkout began from. We use them together with a hashed form of your email address and user ID, and with the amount, currency and plan name. This collection happens at app.myguestwork.com rather than on our website, and it does not happen at all where marketing consent is absent. Clause 9 sets out what is sent, to whom, and on what conditions.
5. How and Why We Use Personal Information
5.1 We generally collect personal information directly from you. Where guest information is uploaded by an Organiser, we collect it from the Organiser rather than the Guest. We may also receive information from the service providers that help us operate the Platform (see clause 12).
5.2 We use personal information to provide and operate the Platform; create and manage accounts; authenticate users and maintain sessions; create, manage and display events and public guest pages; store and display uploaded files; send RSVP invitations, reminders and confirmations at an Organiser's direction; record RSVP responses, dietary requirements and delivery status, and make them available to the Organiser; process payments and manage plan access; provide support; send transactional and service-related emails; apply rate limits and protect public guest pages from automated abuse; monitor, secure, maintain and improve the Platform; diagnose errors; understand usage where analytics consent is given; measure and improve our advertising and build audiences for it, where marketing consent is given; prevent misuse, fraud and security incidents; comply with our legal obligations; and enforce our Terms of Service.
5.3 We do not sell your personal information for money. When you accept marketing, we share information with Meta for advertising by two routes: information about your visit to this website, collected by the Meta Pixel and described in clause 8.4, and, if you sign up or buy a plan, a record of that signup or purchase sent from our servers and described in clause 9. A purchase record includes the amount, the currency, the plan name and a hashed form of your email address and user ID. See also clause 21.4. We will only use or disclose it for a purpose set out in this Privacy Policy, for a related purpose you would reasonably expect, or as otherwise permitted or required by law.
6. Guest Links, QR Codes and Public Guest Pages
6.1 Organisers may create QR codes or links that let Guests access event pages, seat-finder pages or RSVP pages without an account. Two kinds of link are used and they work differently.
6.2 Shared event and seat-finder links. Anyone who has the QR code or URL can access these pages. Access is controlled by who holds the link, not by individual guest logins. A seat-finder page may display a guest's first name, last name (where provided) and seating or table assignment. It does not display guest email addresses, phone numbers or payment details.
6.3 Personal RSVP Links. Where an Organiser uses the RSVP feature, each invitation is issued its own RSVP Link containing a long, randomly generated secret. An RSVP Link should be treated as private, because:
6.4 Public RSVP lookup. An Organiser may optionally switch on a page that lets a Guest find their own invitation by entering their name, or their name and email address, for example after scanning a printed QR code. This option is off unless the Organiser turns it on. Where it is on, the page never returns a guest list or a list of possible matches, requires an exact match on the details the Organiser entered, and gives the same response for every unsuccessful attempt regardless of the reason. A successful match takes that person to the RSVP Link described in clause 6.3, which means someone who knows a Guest's name exactly as the Organiser recorded it may be able to reach that invitation and view or change its answers. We apply rate limits to this page to make repeated guessing impractical. Organisers should weigh this before enabling the option.
6.5 Organisers decide what guest information they upload and are responsible for sharing QR codes and links only with intended Guests. We configure app routes and public guest pages to discourage search-engine indexing (for example, using "noindex" and "nofollow" controls, a robots file and related headers), but we cannot guarantee how every search engine, browser or third party will treat a page, and anyone given the link may be able to open it.
6.6 If you are a Guest with concerns about your information appearing on an event page or RSVP page, please contact the Organiser first, as they control the content and can revoke an RSVP Link. You may also contact us using the details in clause 24.
7. Organiser Responsibility for Guest Data
7.1 If you upload guest information to the Platform, you are responsible for having the right to collect, use and upload it. This includes:
7.2 For guest information an Organiser uploads, the Organiser decides what is collected and how it is used, and we generally handle that information on the Organiser's behalf by storing and displaying it as directed. To the extent concepts such as controller and processor apply to you under laws such as the GDPR or UK GDPR, the Organiser will usually be the controller and we will usually act as a processor or service provider. This is a general description and not legal advice; your role depends on the facts and the laws that apply to you.
8. Cookies, Local Storage and Analytics
8.1 We use cookies, local storage and similar technologies to operate the Platform. This clause is about those technologies and what they do in your browser. It does not cover the information we send to Meta directly from our servers, which is not a cookie or a similar technology and is described separately in clause 9.
8.2 Strictly necessary cookies and storage. We use these to authenticate users, keep them logged in, maintain sessions, secure the app and operate core functionality. This includes Supabase authentication and session cookies (using an "sb-*" naming pattern). They are essential, are not used for analytics, and cannot be switched off through our cookie preferences while you use the app. We also use browser local storage for interface preferences, and a cookie named "mgw_cookie_consent" to remember your cookie choice.
8.3 Analytics. We load Google Analytics 4 and Microsoft Clarity only after you accept analytics in our cookie banner or . If you decline, those scripts are not loaded. Where accepted, they may collect information such as pages visited, time on pages, device and browser information, approximate location, clicks, scrolling and interactions, referral information and session activity. Advertising is a separate choice, described in clause 8.4 and clause 9.
8.4 Advertising. We use the Meta Pixel, a tracking script provided by Meta Platforms, Inc., to measure the results of our advertising on Facebook and Instagram and to build audiences for future advertising. It is off by default. We load it only after you accept marketing cookies in our cookie banner or , and that is a separate choice from analytics. Accepting marketing also turns on a second advertising channel, which sends information to Meta directly from our servers rather than from your browser. The rest of this clause describes the pixel only. That second channel is described in clause 9.
When it is loaded, the Meta Pixel records the pages you view on this website and clicks on links through to the MyGuestWork app, and sends that activity to Meta along with your IP address, browser and device information, and the address of the page you were on. It sets cookies in your browser, including "_fbp", a randomly generated identifier for your browser, and "_fbc", which records that you arrived from a Meta advertisement. Meta may combine this with information it already holds about you if you have a Facebook or Instagram account.
The pixel does not send Meta your name, email address, phone number, or anything you type into this website. We have turned off Meta's automatic advanced matching, which would otherwise collect information from form fields. Both of those statements are about the pixel and about this website. Neither is true of the channel in clause 9, which does send Meta your email address, in hashed form, when you complete a signup or a purchase in the app.
You can withdraw consent at any time through in the footer. Withdrawing it stops both the pixel and the channel in clause 9 from sending anything further, subject to the single exception in clause 9.8. It does not delete information Meta has already received through either of them.
8.5 We do not run advertising or session recording scripts on our free tools. Neither the Meta Pixel nor Microsoft Clarity is loaded on:
These tools do their work inside your browser. Nothing you upload to them is sent to us or to anyone else. Google Analytics 4 does run on these pages and records page views and anonymous counts, such as how many rows were in a list that was checked. It never receives the contents of your file, and no name, email address or other detail from your guest list is sent anywhere.
The heading above is about the scripts we load. The server-side channel in clause 9 does not reach these pages either. It sends an event only when a signup or a purchase is completed, and neither of those happens on a free tool page.
8.6 We do not use analytics on guest-facing pages. Neither Google Analytics nor Microsoft Clarity is loaded on:
The pages listed above are guest-facing pages in the MyGuestWork app. The Meta Pixel is not used on any of them, and is not used anywhere on app.myguestwork.com.
That statement is about the pixel. It does not mean that nothing about activity in the app reaches Meta. We send events to Meta from our servers when an account user completes a signup or a purchase, as described in clause 9. Those two moments involve an account user rather than a Guest, and no event is sent from any of the guest-facing pages listed above.
8.7 No analytics cookies (for example "_ga", "_ga_*", "_clck" or "_clsk") are set on those pages, and no session recording takes place on them. If Clarity is already running and you navigate to one of those pages, we stop it for that page. No advertising cookies (for example "_fbp" or "_fbc") are set on those pages either. Those two cookies can be set during a visit to myguestwork.com, and this clause is about where they are set rather than where they are read. Where they exist, their values are read and sent to Meta at the two moments described in clause 9. That does not happen on a guest-facing page.
8.8 Because nothing on a guest-facing page depends on analytics consent, we do not show the cookie banner on those pages and no consent cookie is written there. A consent cookie set during an earlier visit to our main website or app in the same browser may still be present. An authentication cookie may also be present on an RSVP page if you happen to be signed in to the app as an account user in the same browser. A Guest who is not signed in is not issued one. The app reads that carried-over consent cookie to decide whether the channel in clause 9 may send anything. See clause 9.7.
8.9 You can change your analytics and marketing preferences at any time using . They are separate choices and you can accept one without the other. The marketing choice controls both the Meta Pixel and the server-side channel in clause 9. Because the consent cookie is shared with app.myguestwork.com, a change you make here also applies in the app, and it takes effect for the next signup or checkout that begins after you make it.
9. Information Sent to Meta from Our Servers
9.1 This clause describes a second advertising channel, which is separate from the Meta Pixel described in clause 8.4. The pixel is a script that runs in your browser. This channel is a direct transmission from our servers to Meta, using a Meta service called the Conversions API. We use it for the same purpose as the pixel, to measure the results of our advertising on Facebook and Instagram and to build audiences for future advertising, but it reaches Meta by a different route. At the moment we send it there is no script running, no access to anything stored on your device and no page involved, which is why it is described in its own clause rather than as a cookie or a similar technology.
9.2 When we send an event. We send an event to Meta at two moments only: when a purchase is completed, sent from our payment system once the payment has settled, and when a signup is completed, sent when a new account is created. Nothing is sent while you browse the app, and nothing is sent at any other point.
9.3 What a completed purchase sends. The event contains:
9.4 What a completed signup sends. The event contains the same information as clause 9.3, other than the amount, the currency and the plan name, none of which exists at that point.
9.5 Hashing does not make this anonymous. Hashing your email address and user ID with SHA-256 turns each of them into a fixed-length value that does not read as an email address or an ID. This is not the same thing as the shortened, irreversible hash of an IP address described in clause 4.10 and clause 12.3. The hashed value is complete, stable and unique to you, and we send it for the express purpose of allowing Meta to match you by calculating the same value from information it already holds. It remains personal information, we treat it as personal information, and we do not describe it as anonymous, anonymised or de-identified.
9.6 Consent gate. None of the information in clause 9.3 is collected or sent unless a stored marketing consent choice of accepted is present for you. Where it is not present, no advertising identifier is collected at that moment at all, so there is nothing to send. We also collect and send nothing where your browser sends a Global Privacy Control signal with the request, whether or not marketing consent is present.
9.7 How consent reaches the app. Marketing consent can only be given through the cookie banner or on myguestwork.com. The consent cookie is set for myguestwork.com and its subdomains, which is how the app at app.myguestwork.com is able to read it (see clause 8.8). There is no cookie banner in the app and no way to give marketing consent there. If you reach the app without having visited myguestwork.com in the same browser, no marketing consent is stored for you, and no event is sent when you sign up or purchase.
9.8 Withdrawing consent. You can withdraw marketing consent at any time through in the footer of every page on myguestwork.com. Withdrawing it stops this channel, because we read your consent choice and the advertising identifiers at the moment a checkout or signup begins. There is one exception. If you begin a checkout while marketing consent is in place and withdraw it before the payment settles, the purchase event for that checkout is still sent.
9.9 What we keep. We do not keep a record of the events we send or of the information contained in them. We record only whether an attempt succeeded or failed, a trace identifier for that attempt, and an error code where it failed.
9.10 Transfer to the United States. Meta Platforms, Inc. is based in the United States, and we send these events from our servers to Meta's servers there. That is a disclosure of your personal information outside Australia, and it is separate from the transfer of pixel-collected information described in clause 12.6. The steps we take in relation to overseas disclosures are described in clause 12.6.
9.11 We cannot recall an event once it has been sent. Withdrawing consent, closing your account and asking us to delete information we hold all stop future events and act on our own records, but none of them reaches an event Meta has already received. We cannot delete or retrieve it. You would need to deal with Meta directly about information Meta holds about you.
10. Contact Forms, Emails and Marketing
10.1 If you submit a contact form, we collect your name, email address, event type and message, delivered using Brevo, and use it to respond. We may also use Brevo (or another provider) to send service-related emails, support messages, account notifications, workspace invitations and, where permitted, product updates to account users.
10.2 RSVP invitations and reminders. Where an Organiser uses the RSVP feature, we send invitations, reminders and confirmations to the guest email addresses that Organiser has entered. These messages are delivered using Resend and are sent at the Organiser's direction rather than ours. Reminders go out only when an Organiser chooses to send them, only to Guests who have not yet replied, and no more than once a day for each invitation.
10.3 An invitation or reminder contains the Guest's first name, the invitation label, the event name, any artwork or message the Organiser has set, and the RSVP Link. Seating and table assignments are not included in these messages.
10.4 Confirmation emails. After an RSVP is submitted, we send a confirmation containing the answers saved for that invitation, including each named person's dietary requirements, any free text dietary information and any note to the Organiser. Where more than one person on an invitation has an email address, each of them receives that confirmation. This means RSVP answers, including dietary requirements, may be visible to the other people named on the same invitation.
10.5 RSVP messages are sent from a MyGuestWork address using a display name the Organiser sets. Replies are directed to the Organiser's account email address, so a Guest who replies will see and reach that address.
10.6 We do not include open tracking or click tracking in RSVP messages, and we configure our sending domains so that this tracking is off. Organisers cannot see whether a Guest has opened a message. Organisers can see whether a message was sent, whether sending failed and whether a Guest has replied.
10.7 Stopping RSVP messages. RSVP invitations, reminders and confirmations are transactional messages about an event you have been invited to. They are not marketing, they do not carry an unsubscribe link, and we do not add guest email addresses to any mailing list or contact list. If you do not want to receive them, contact the Organiser, who controls the guest list and can remove you or revoke your invitation. You may also contact us using the details in clause 24.
10.8 We do not send marketing emails to Guests. You can unsubscribe from marketing emails where required by law. Service-related emails (such as security, billing, account or event-functionality messages) may still be sent because they are necessary to provide the Platform.
11. Billing and Payments
11.1 Payments are processed by Stripe, which may collect card, billing and payment method information directly. We do not collect or store your full card number, CVC or bank account details. Stripe's own privacy policy applies to information it processes.
11.2 To manage your purchases, plan access, subscriptions, renewals and event credits, we collect and store the following billing information through Stripe:
11.3 We use this information to process payments, manage your plan, subscription and event credits, issue and reconcile invoices, maintain an accurate record of credit and subscription changes, prevent and investigate payment issues or misuse, and comply with our tax, accounting and other legal obligations. Separately, and only where you have accepted marketing, we use the amount, the currency and the plan name from a completed purchase to measure our advertising, by sending them to Meta as described in clause 9. No other billing information listed in clause 11.2 is used for advertising, and none of it is sent to Meta.
12. Service Providers and International Transfers
12.1 We use third-party service providers to operate the Platform:
12.2 Our email providers receive the content of the messages we send, including the recipient's email address and, for RSVP confirmations, the answers described in clause 10.4. We send these as individual transactional messages and do not build or store mailing lists or contact lists with these providers.
12.3 We use Upstash to apply rate limits to public pages, including RSVP pages and the public RSVP lookup. It receives a shortened, irreversible hash of your IP address and, for the lookup, an irreversible fingerprint of the name searched. We do not send your IP address or the name itself to Upstash in a readable form.
12.4 We use Sentry to monitor and diagnose software errors, including on guest-facing RSVP pages. Error reports may include technical information such as error messages, stack traces, page URL, browser version, operating system and technical context. We configure Sentry to avoid sending cookies, request headers, request bodies and user identity where reasonably practical. Because the report includes the page URL, an error captured on an RSVP page will include that page's RSVP Link.
12.5 We disclose information to Meta Platforms, Inc. by two routes, and only where you have accepted marketing. The Meta Pixel sends the browsing activity described in clause 8.4, together with your IP address and your browser and device information. From our servers we send the signup and purchase events described in clause 9, which contain your "_fbp" and "_fbc" cookie values, your IP address in full, your browser user agent string in full, your email address and user ID hashed using SHA-256, and, for a purchase, the amount, the currency, the plan name and the address the checkout began from. The hashed values are not comparable to the shortened hash we send to Upstash under clause 12.3. A hashed email address is complete and stable, Meta can match it against its own records, and it remains personal information.
12.6 Our primary application database and file storage are hosted with Supabase in an Australian region. However, these providers operate in Australia and overseas, so your personal information may be processed, stored or accessed in countries outside your country of residence, including the United States and Europe. Where required by applicable law, we take reasonable steps to ensure overseas disclosures are subject to appropriate protections, such as contractual protections or standard contractual clauses. Meta Platforms, Inc. is based in the United States. Information collected by the Meta Pixel is transferred there, and so are the signup and purchase events we send from our servers under clause 9. Both are disclosures of your personal information outside Australia.
13. Data Retention
13.1 We retain personal information for as long as reasonably necessary to provide the Platform, maintain event records, provide support, comply with legal obligations, resolve disputes, enforce agreements and maintain security.
13.2 Event data, guest lists, seating assignments, RSVP responses and uploaded files may be retained while the relevant account or event remains active, unless deleted earlier by the Organiser or by us. Billing, subscription and transaction records may be retained longer where required for tax, accounting, legal or compliance purposes.
13.3 Deleting a Guest also deletes that Guest's RSVP response and any plus-ones they added. Deleting an event deletes its guest list, RSVP invitations, RSVP responses and RSVP settings.
13.4 Some operational records are kept after that deletion. These include our sending and delivery logs, and the delivery reports our email provider returns to us, either of which may contain a recipient email address. We keep them to investigate delivery problems, security incidents and disputes. Revoked RSVP Links are also retained in a disabled state so the same link cannot be reissued or reused.
13.5 We do not currently run these operational records through a fixed automatic deletion schedule. We delete them on request, and where we no longer need personal information and are not required or permitted by law to keep it, we take reasonable steps to delete, destroy or de-identify it. To ask us to delete records that relate to you, contact us using the details in clause 24. Deletion, destruction and de-identification are all things we do to records we hold. None of them reaches information already disclosed to a third party, including an event already sent to Meta under clause 9.
14. Accessing, Correcting or Deleting Information
14.1 You may be able to access, edit or delete certain information directly through the app, including your events, guest lists and RSVP data, and you may request access to or correction of the personal information we hold about you. To close your account and have your account information deleted, contact us using the details in clause 24. Deleting information we hold does not delete information a third party has already received, including an event already sent to Meta under clause 9. See clause 9.11.
14.2 Organisers are responsible for maintaining the guest information they upload, including RSVP responses. If you are a Guest and want your information corrected or removed, contact the Organiser first, as they control the relevant data. A Guest can also change their own RSVP answers at any time using their RSVP Link, unless the Organiser has revoked it or locked the invitation after the RSVP deadline.
14.3 You may also contact us using the details in clause 24. We may need to verify your identity, and we may refer your request to the relevant Organiser where they control the data. We will respond within a reasonable time and, where the Privacy Act applies, within the time it requires. If we decline access or correction, we will explain why where required to do so.
15. Children and Minors
15.1 The Platform is not directed at children, and you must be at least 18 to create an account or purchase a paid plan.
15.2 Children may nonetheless appear in guest lists, photos or videos uploaded by Organisers or Guests, and a Guest completing an RSVP may add a child as a plus-one. Organisers are responsible for ensuring they have appropriate permission to upload or share information or media involving minors. If you believe information about a child has been uploaded without appropriate permission, please contact the Organiser or contact us using the details in clause 24.
16. Sensitive Information
16.1 Dietary requirements. Where an Organiser collects dietary requirements through the RSVP feature, some of the information a Guest provides may be sensitive information. A dietary requirement can reveal health information (for example a nut allergy or coeliac disease) or a religious belief (for example halal or kosher). Free text dietary information and notes to the Organiser may also contain sensitive information where a Guest chooses to enter it.
16.2 Providing dietary information is optional. A Guest can leave it blank or record that they have no dietary requirements, and an Organiser who does not want to collect it at all can switch that part of the RSVP form off.
16.3 Notice at the point of collection. Before an RSVP is submitted, we display a short notice on the RSVP form explaining that the response, dietary requirements and any note are shared with the Organiser, together with a link to this Privacy Policy. On the public RSVP lookup page we display a notice explaining that the name entered is used only to find that invitation. These are notices only. There is no separate tick box, submitting an RSVP is not conditional on acknowledging the notice, and we do not create or store a record of any consent decision.
16.4 We collect dietary information only to help the Organiser cater for the event. We make it available to the Organiser, who decides what is collected and how it is used, and who may share it with a venue, caterer or other event supplier. It is also included in the confirmation email described in clause 10.4, which is sent to every person named on the invitation who has an email address. Dietary information a Guest provides may therefore be visible to the other people on their invitation as well as to the Organiser.
16.5 Where a Guest enters dietary information for a plus-one, that information describes another person and is provided by the Guest completing the form rather than by the person it is about. The Guest completing the form is responsible for having that person's agreement before entering it.
16.6 We do not ask for sensitive information for any other feature of the Platform, and we do not ask Guests for health or religious information beyond the dietary options described above. Depending on how the Platform is used, sensitive information could nonetheless be included in uploaded files, event names, guest notes, photos, videos or messages.
16.7 Organisers and users should avoid uploading sensitive information unless it is necessary, they have the right to do so, and (where required) they have the individual's consent. Where we become aware that we hold sensitive information, we handle it in accordance with applicable law and this Privacy Policy.
17. Security
17.1 We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification and disclosure. These steps may include HTTPS for data in transit; authentication and session controls; access controls and internal restrictions; database and storage security measures provided by our infrastructure providers; rate limiting on public pages; error monitoring; and security reviews and updates.
17.2 Each RSVP Link contains a long secret generated with a cryptographically secure random number generator, which makes an RSVP Link impractical to guess. Because access to an invitation depends on holding that link rather than on a login, the security of an invitation depends on how the link is sent, stored and forwarded.
17.3 No online service can be completely secure. You are responsible for keeping your account secure and for managing access to event links, RSVP Links, QR codes and public guest pages.
18. Your Privacy Rights
18.1 Depending on where you live and the laws that apply to you, you may have rights in relation to the personal information we hold about you. This clause gives a general overview. Clauses 19 to 21 set out additional information for users in Australia, the United Kingdom and the European Economic Area, and the United States (including California).
18.2 Subject to the conditions and exceptions in the laws that apply to you, these rights may include the right to:
18.3 Not all of these rights apply in every location, and some are subject to conditions and exceptions. To exercise a right, contact us using the details in clause 24. We may need to verify your identity before responding, and some requests may be limited where we need to retain information for legal, security, billing or other legitimate reasons. We will not discriminate against you for exercising a privacy right.
19. Australian Users
19.1 If you are in Australia, we handle your personal information in accordance with the Privacy Act and the APPs.
19.2 You may request access to, or correction of, the personal information we hold about you. If we decline a request, we will explain why where we are required to do so, and tell you how to complain. You may complain to us first using the details in clause 24, and if you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
20. UK and European Users
20.1 If you are in the United Kingdom or the European Economic Area, the UK GDPR or EU GDPR may apply to our handling of your personal information. This clause applies to the extent those laws apply to you.
20.2 Our role. For most personal information we handle about account users, we act as a controller. For guest information that an Organiser uploads, the Organiser is usually the controller and we usually act as a processor (see clause 7).
20.3 Legal bases. Where the GDPR or UK GDPR applies, we rely on one or more of the following legal bases: performance of a contract with you (to provide the Platform); our legitimate interests (such as securing, maintaining and improving the Platform, and delivering event messages on an Organiser's behalf), balanced against your rights; your consent (for example, for analytics and marketing cookies, which you can withdraw at any time); and compliance with our legal obligations. We rely on your consent, and not on legitimate interests, for the advertising disclosures described in clause 8.4 and clause 9. That includes disclosing your hashed email address, your IP address and a record of your signup or purchase to Meta. Because we rely on consent for those disclosures rather than legitimate interests, the right to object in clause 20.6(e) does not apply to them. You can withdraw your consent instead, at any time, under clause 20.6(g).
20.4 Special category data. Dietary requirements provided through an RSVP may reveal health information or religious beliefs, which are special category data under Article 9. For guest information, the Organiser is the controller and we act as a processor (see clause 20.2 and clause 7.2). It is therefore the Organiser who must establish a lawful basis and an Article 9 condition for collecting dietary information from their Guests, and who must give those Guests the information their local law requires. We display a notice at the point of collection and a link to this Privacy Policy, as described in clause 16.3, but that notice is not a consent step and we do not record a consent decision.
20.5 Providing dietary information is always optional. If you would prefer not to provide it, you can leave it blank. You can change or clear information you have already provided using your RSVP Link, unless the Organiser has revoked it or locked the invitation, and you can ask the Organiser to remove it or contact us using the details in clause 24.
20.6 Subject to the conditions and exceptions in those laws, you may have the right to:
20.7 To exercise any of these rights, contact us using the details in clause 24. If you are in the UK, you may complain to the Information Commissioner's Office (ICO) at ico.org.uk. If you are in the EEA, you may complain to your local data protection authority. Information about international transfers of your personal information is set out in clause 12.
21. United States and California Users
21.1 If you are in the United States, this clause applies in addition to the rest of this Privacy Policy. If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the CCPA), may give you the rights described below to the extent it applies to you.
21.2 Subject to the conditions and exceptions in the CCPA, you may have the right to:
21.3 We do not sell your personal information for money. When you accept marketing in our cookie banner or , we do engage in cross-context behavioural advertising, which is described in clause 21.4. We do not do so in any other circumstances, and we do not do so at all if your browser sends a Global Privacy Control signal.
21.4 We use analytics tools (Google Analytics 4 and Microsoft Clarity) and two advertising channels, being the Meta Pixel in your browser and the events we send to Meta from our servers as described in clause 9. We use each of them only after you accept the matching category in our cookie banner or .
When you accept marketing, we share information with Meta Platforms, Inc. so we can measure our advertising and reach people who may be interested in MyGuestWork. That is information about your visit to this website, and, if you sign up or buy a plan, a record of that signup or purchase, which includes your email address in hashed form and, for a purchase, the amount, the currency and the plan name. Under Californian law this counts as sharing personal information for cross-context behavioural advertising, and may also be treated as a sale. We do not receive payment for it.
You can stop this at any time through in the footer of every page. If your browser sends a Global Privacy Control signal, we treat that as an instruction not to sell or share your personal information for cross-context behavioural advertising. We honour it whether or not you have accepted marketing, and it stops both channels: the Meta Pixel is not loaded, and no event is sent from our servers.
Apart from the analytics and advertising you have consented to above, we do not sell or share your personal information.
21.5 We will not discriminate against you for exercising any privacy right. To make a request, contact us using the details in clause 24. We may need to verify your identity, and you may use an authorised agent where the law allows.
22. Complaints
22.1 If you have a privacy complaint, please contact us first using the details in clause 24. We will review it and respond within a reasonable time.
22.2 If you are not satisfied with our response, you may be able to contact your local privacy regulator. Details of the relevant regulators for Australia, the UK and the EEA are set out in clauses 19 and 20.
23. Changes to this Privacy Policy
23.1 We may update this Privacy Policy from time to time. If we make material changes, we may notify users by updating this page, sending an email or displaying a notice in the app. The updated Privacy Policy applies from the date it is published unless stated otherwise.
24. How to Contact Us
24.1 For privacy questions or requests, contact:
My Guest Work Pty Ltd (trading as MyGuestWork)
Email: privacy@myguestwork.com