Privacy Policy

Last updated: May 1, 2026

1. Introduction

HAFLAH ("the Service"), operated by Sykari LLC ("we", "us", or "our"), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our web application.

By using the Service, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

Account Information: When you create an account, we collect your email address and password. If you sign in via Google, we receive your name and email from Google.

Profile Information: You may optionally provide your first name, last name, date of birth, phone number, city, country, and a short bio.

Event Data: When you create or participate in events, we collect event details (name, date, venue, capacity), guest lists, member names, ticket allocations, and check-in records.

Usage Data: We automatically collect information about how you access and use the Service, including your browser type, device type, IP address, pages visited, and timestamps.

Cookies and Local Storage: We use browser cookies and local storage to maintain your session, remember your language preference, and store your cookie consent choice.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service
  • Authenticate your identity and manage your account
  • Process event creation, guest registration, RSVP responses, dish coordination, and QR code check-ins
  • Send transactional communications (e.g., ticket request approvals)
  • Improve, personalize, and expand the Service
  • Monitor and analyze usage trends and preferences
  • Detect, prevent, and address technical issues or fraud

Gathering data (RSVPs, dishes, history)

Beyond the core ticketed-event data, the Service collects data specific to potlucks and RSVP events. We treat all of it as the host's data — they decide what to do with it, we just store and serve it.

RSVP responses (yes / no / pending) are stored at both the household level (one invite) and the named-member level when the host or guest provides member names. Per-member RSVPs are visible to the host of the event and to the inviter on the household's own invite page. Aggregate counts (e.g. "3 of 5 going") are visible to other guests on potluck events; on RSVP events, other guests see counts only, never names.

Potluck dish data — dish name, dietary tags, the category it's in, and which guest brought it — is visible to everyone on the event's invite. We do not share it outside that event. Hosts can soft-remove dishes; removed dishes are hidden from guests but retained in the host's history (see below).

Hosts have access to a per-event history view that captures dish board changes (added, renamed, recategorized, dietary changes, removed, restored) with timestamps and the actor's name or email. This audit log exists so hosts can answer "who changed what." It is visible only to the host (and admins for support). Entries are kept for the lifetime of the event row; deleting the event removes them.

When a host deletes a potluck or RSVP event, all related rows — guests, members, dishes, dish categories, RSVP statuses, and the dish history — are deleted with it via cascading foreign keys. Backups follow the same retention schedule as the rest of our data (see Data Retention).

4. How We Share Your Information

We do not sell, rent, or trade your personal information to third parties. We may share information in the following circumstances:

  • With Event Hosts: When you register as a guest for an event, the host and their coordinators can see your name, ticket status, and check-in status.
  • With Service Providers: We use third-party services to operate the platform, including Supabase (database and authentication), Vercel (hosting), Google (OAuth authentication), Resend (transactional email), and Stripe (payment processing). These providers have access to your information only to perform services on our behalf and are contractually obligated to protect it.
  • Legal Requirements: We may disclose your information if required by law, regulation, legal process, or governmental request.

5. Data Storage and Security

Your data is stored securely using Supabase, which uses PostgreSQL databases with encryption at rest and in transit. We implement Row Level Security (RLS) policies to ensure users can only access data they are authorized to view.

While we strive to use commercially acceptable means to protect your personal information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.

In the event of a security incident affecting your personal data, we will notify you and any applicable regulators without undue delay and in accordance with applicable law.

6. Cookies and Tracking

Essential Cookies: We use essential cookies to maintain your authentication session. These are necessary for the Service to function.

Preference Storage: We use browser local storage to remember your language preference, cookie consent choice, and cached profile data for faster page loads.

Analytics: We may use analytics tools to understand how users interact with the Service. This data is anonymized and used solely to improve the user experience.

You can manage your cookie preferences at any time using the "Cookie Preferences" link in the footer of every page.

7. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate personal data
  • Request deletion of your personal data
  • Object to or restrict the processing of your personal data
  • Request portability of your personal data
  • Withdraw consent at any time where processing is based on consent

To exercise any of these rights, please contact us at the email address below. We will respond within the timeframe required by applicable law.

8. California Residents

If you are a California resident, the California Consumer Privacy Act (CCPA) gives you the rights described in Section 7 above (access, deletion, correction, and portability), as well as the right to know what categories of personal information we collect, why, and to whom we disclose it.

We do not sell or share your personal information for cross-context behavioral advertising, and we have not done so in the preceding twelve (12) months. We will not retaliate against you for exercising any CCPA right.

To submit a CCPA request, email legal@myhaflah.com from the email associated with your account or include sufficient information to verify your identity.

Supplemental Regional Notices

The following supplemental notices apply to users resident in the listed countries, in addition to the rights described in Section 7 above.

United Kingdom (UK GDPR)

If you are in the United Kingdom, our processing of your personal data is governed by the UK General Data Protection Regulation and the Data Protection Act 2018. Our lawful basis is (a) contract — to provide the Service to you; (b) legitimate interests — to operate, secure, and improve the Service; and (c) consent — for any optional marketing communications.

You have the right to access, rectify, erase, restrict processing of, port, and object to processing of your personal data, and to withdraw consent at any time without affecting the lawfulness of prior processing. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at https://ico.org.uk.

Canada (PIPEDA)

If you are in Canada, our handling of your personal information is governed by the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation. We collect, use, and disclose your personal information only with your knowledge and consent, except where authorized or required by law.

You have the right to request access to and correction of your personal information, and to challenge our compliance with PIPEDA. If you are not satisfied with our response, you may file a complaint with the Office of the Privacy Commissioner of Canada at https://www.priv.gc.ca.

Australia (Privacy Act 1988)

If you are in Australia, our handling of your personal information is governed by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We collect personal information only by lawful and fair means, use it only for the purposes for which it was collected (and related purposes you would reasonably expect), and disclose it only as described in this Policy.

You have the right to access and correct your personal information and to make a complaint about our handling of it. Complaints should first be directed to legal@myhaflah.com; if not resolved, you may complain to the Office of the Australian Information Commissioner at https://www.oaic.gov.au.

United Arab Emirates (PDPL)

If you are in the United Arab Emirates, our processing of your personal data is subject to Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL). We process personal data only for legitimate purposes disclosed in this Policy and apply appropriate technical and organizational safeguards.

You have the right to request access to, correction or deletion of, and restriction of processing of your personal data. Personal data is transferred to and stored on servers in the United States as described in our "International Data Transfers" section below; you consent to that transfer when you use the Service. To exercise your PDPL rights, email legal@myhaflah.com.

9. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Service. Event data (guest lists, check-in records) is retained for the duration of the event and a reasonable period afterward for the host's records. Payment records are retained as required by tax and accounting laws (typically seven years). You may request deletion of your account and associated data at any time, subject to retention obligations described above.

10. Children's Privacy

The Service is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected such information, we will take steps to delete it promptly.

11. International Data Transfers

Your information may be transferred to and maintained on servers located outside of your country of residence, including in the United States where Sykari LLC operates. By using the Service, you consent to the transfer of your information to countries that may have different data protection laws than your jurisdiction.

12. Spotify and YouTube Integrations

If a host opts in to song requests for an event, we offer optional integrations with two third-party music services: Spotify (via the Spotify Web API) and YouTube (via the YouTube Data API v3). The information below applies only when a host has explicitly connected their account.

Spotify Web API. When a host clicks "Connect Spotify," they're redirected to Spotify to authorize HAFLAH. After authorization, we receive their Spotify user ID, display name, and OAuth access + refresh tokens. We never see Spotify passwords. The OAuth tokens are encrypted at rest using AES-256-GCM and stored in our database; they are used solely to create and maintain a public Spotify playlist on the host's behalf and to add or remove tracks the host or their guests have selected. The host can revoke this access at any time from event settings, which deletes our stored tokens; they may also revoke at https://www.spotify.com/account/apps. Use of the Spotify integration is also governed by Spotify's terms and policies.

YouTube Data API. When a host clicks "Connect YouTube," they're redirected to Google to authorize HAFLAH. After authorization, we receive their YouTube channel ID, display name, and OAuth access + refresh tokens (with the youtube and youtube.readonly scopes). The OAuth tokens are encrypted at rest using AES-256-GCM and stored in our database; they are used solely to create and maintain a public YouTube playlist on the host's behalf and to add or remove videos the host or their guests have selected. The host can revoke this access at any time from event settings, which deletes our stored tokens; they may also revoke at https://myaccount.google.com/permissions. By using the YouTube integration, you agree to the YouTube Terms of Service at https://www.youtube.com/t/terms, and your use of Google services through this integration is subject to the Google Privacy Policy at https://policies.google.com/privacy.

Guest searches. When a guest searches for a track or video to add to a playlist, the search query is sent from our servers to Spotify or YouTube using application-level credentials. The search query is not associated with the guest's identity in our analytics, and Spotify/YouTube do not receive any personal information about the guest from HAFLAH.

We retain song-request records (track or video name, artist or channel, and the platform identifier) for the lifetime of the event, plus any retention period stated elsewhere in this Policy. OAuth tokens are deleted immediately when a host disconnects, when an account is deleted, or when the host's authorization expires and is not renewed.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated "Last updated" date and, where appropriate, communicated by email or in-app notice. Continued use of the Service after changes constitutes acceptance of the revised policy.

14. Contact Us

If you have any questions about this Privacy Policy or our data practices, or to submit a privacy or CCPA request, please contact us at:

Sykari LLC
Email: legal@myhaflah.com