Legal

Privacy Policy

Last updated: July 18, 2026

This policy explains how GuestSight — the event-feedback service available at guestsight.ai, app.guestsight.ai, guestsight.link, and survey.guestsight.ai (together, the “Service”) — handles personal data under the EU General Data Protection Regulation (GDPR). It is written to describe what the Service actually does: we collect what the product needs to work, we don't run third-party analytics, and we don't sell data.

1. Who we are (controller & contact)

IN SHORT

GuestSight is run by Giovannini Tech Solutions, a German sole proprietorship. For privacy questions, write to privacy@guestsight.ai.

The controller responsible for the processing described in this policy (except where Section 2 says otherwise) is:

Giovannini Tech Solutions – Inh. Fabio Giovannini
Einzelunternehmen (registered German sole proprietorship)
VAT ID (USt-IdNr.): DE460918801

[STREET ADDRESS — TO BE INSERTED BEFORE LAUNCH]

The operator's postal address will be published in the Imprint before launch.

Privacy contact: privacy@guestsight.ai (general questions: hello@guestsight.ai). We have not appointed a data protection officer; at our current size we are not required to.

2. Who this policy covers

IN SHORT

Three groups of people interact with GuestSight: visitors to this website, organizers with accounts, and event attendees. For attendee feedback and survey data, the organizer is the controller and we process it on their behalf.

  • Website visitors — anyone browsing guestsight.ai. We are the controller. See Section 4.
  • Organizers — companies and professionals with a GuestSight account. We are the controller for account, workspace, and billing data. See Sections 5–7.
  • Attendees — guests at an organizer's event who scan a QR code or fill out a survey. For this data, the organizer is the controller and GuestSight is a processor under Art. 28 GDPR, acting on the organizer's instructions. Sections 8–10 describe that processing transparently on the organizer's behalf; attendees with questions about how their feedback is used should contact the event organizer first (we help organizers respond — see Section 15).

3. Processing at a glance

IN SHORT

One table: what we process, why, on what legal basis, and for how long.

DATAPURPOSELEGAL BASISRETENTION
Server & access logs (IP address, request data)Delivering the website and APIs, security, abuse preventionLegitimate interest (Art. 6(1)(f))Short-term, deleted automatically
Organizer account data (name, email, Google ID, avatar)Providing your account and signing you inContract (Art. 6(1)(b))Life of the account; anonymized on deletion
Workspace data (events, QR codes, reports, settings)Providing the core serviceContract (Art. 6(1)(b))Life of the account
Session data & auth cookiesKeeping you signed in, securing your sessionContract & legitimate interest (Art. 6(1)(b), (f))Up to 30 days
Billing references (Stripe customer & subscription IDs, plan, status)Managing your subscription — card data goes to Stripe directly, never to usContract (Art. 6(1)(b)); statutory duties (Art. 6(1)(c))Contract term plus statutory retention
Email delivery log (recipient, subject, delivery status)Making sure service emails arrive; troubleshootingLegitimate interest (Art. 6(1)(f))12 months, deleted automatically
Attendee QR feedback (star rating, optional comment)Collecting event feedback on the organizer's behalfProcessed for the organizer (Art. 28) under the organizer's legal basisUntil the organizer deletes it
Attendee survey responses (answers, technical metadata, duplicate-check cookie)Running post-event surveys on the organizer's behalfProcessed for the organizer (Art. 28) under the organizer's legal basisUntil the organizer deletes it
Feedback & survey text sent to AI providersGenerating analysis reports and follow-up surveysProcessed for the organizer (Art. 28)Transient — used to generate the output

4. Website visitors

IN SHORT

The website runs no analytics, sets no cookies, and loads nothing from third-party servers. The only data that arises is standard server logs.

guestsight.ai is a static website served from our hosting provider AWS (Amazon CloudFront/S3). It contains no analytics or tracking scripts, no tracking pixels, and no third-party embeds. Fonts are self-hosted, so your browser makes no requests to font CDNs or other third parties. The website sets no cookies.

Like virtually every website, our infrastructure records technical server logs when pages are requested: IP address, date and time, requested URL, browser type (user agent), and referrer. We use these logs solely to deliver the site, keep it secure, and diagnose problems. The legal basis is our legitimate interest in operating a secure website (Art. 6(1)(f) GDPR). Logs are kept short-term and deleted automatically; we do not use them to identify visitors.

5. Organizer accounts & workspace data

IN SHORT

You sign in with Google — no passwords. We store the basic profile Google provides, your workspace content, and server-side sessions that expire after 30 days.

Sign-in via Google. GuestSight accounts use Google sign-in exclusively; we never see or store a password. When you sign in, we receive and store from your Google account: your name, email address, Google account identifier, and profile picture URL. Google processes the sign-in itself as an independent controller under the Google Privacy Policy. The legal basis for our processing is the performance of our contract with you (Art. 6(1)(b) GDPR).

Profile & workspace. You can additionally set a display name, a job title, and upload an avatar image (stored on AWS in the EU). Your workspace holds the content you create to use the product: company and team details, events, QR codes, collected feedback, surveys, and generated reports.

Sessions. When you sign in we create a server-side session record so we can keep you signed in and let you sign out everywhere. Sessions expire and are deleted automatically after 30 days. The associated cookies are listed in Section 13.

6. Payments & billing (Stripe)

IN SHORT

Paid plans are bought through Stripe as merchant of record. Your card details go directly to Stripe and never touch our servers — we only store subscription references and status.

Paid plans are sold through Stripe as merchant of record (Stripe Managed Payments). When you subscribe, you enter your payment details directly with Stripe at checkout; Stripe collects and processes your payment data (card number, billing address) as described in Stripe's Privacy Policy. We never receive or store card numbers.

What we store on our side is limited to references and state: your Stripe customer and subscription identifiers, the product/price of your plan, the billing interval, the subscription status, and the current billing-period end date. We use this to grant your plan's features and to show your billing status in the dashboard. Legal bases: performance of the contract (Art. 6(1)(b) GDPR) and compliance with statutory (e.g. tax) obligations (Art. 6(1)(c) GDPR).

7. Emails we send

IN SHORT

We currently send transactional emails only (account and service messages). Delivery metadata — not the message content — is logged and auto-deleted after 12 months. Marketing email would only ever be sent with your opt-in.

We send transactional emails tied to your account and use of the Service — for example a welcome email, event lifecycle notifications (such as an event-ended recap), and plan/billing confirmations. These are sent via a specialised transactional email delivery provider using an EU datacenter. Legal basis: performance of the contract (Art. 6(1)(b) GDPR).

To make sure emails actually arrive and to troubleshoot delivery problems, we keep a delivery log storing the recipient address, subject line, email type, delivery status, timestamps, and any delivery error. The message content itself is not stored in this log. Log entries are deleted automatically after 12 months. Legal basis: our legitimate interest in reliable email delivery (Art. 6(1)(f) GDPR).

No marketing without opt-in. We currently send no newsletters or marketing email. The dashboard's “Product emails” settings include a newsletter toggle that is off by default; non-transactional email would only be sent to organizers who opt in there (legal basis: consent, Art. 6(1)(a) GDPR, withdrawable at any time).

8. Attendee feedback via QR codes

IN SHORT

Scanning a QR code and leaving feedback is anonymous: we store the star rating, the optional comment, and a timestamp — no name, no email, no IP address, no cookies.

When an attendee scans a GuestSight QR code, their browser opens a feedback page at guestsight.link. That page sets no cookies and runs no analytics. Submitting the form sends exactly three things: the feedback link token, a star rating (1–5), and an optional free-text comment (up to 1,000 characters).

What we store with a submission: the rating, the comment, the submission time, and which event and QR location it belongs to. We store no IP address, no device or browser information, and no identifier of the attendee. A feedback entry cannot be traced back to a person by us or by the organizer — unless the attendee writes personal details into the comment text itself, which we recommend against.

Two transient technical mechanisms exist to protect the Service: the IP address is used briefly for rate limiting (stored only in short-lived counters that delete themselves automatically), and a duplicate check based on a one-way hash of the submission prevents identical re-submissions for 24 hours. Neither stores the IP address with the feedback or creates a profile of the attendee.

For this data, the event organizer is the controller and GuestSight is their processor (see Section 2).

9. Attendee surveys

IN SHORT

Survey answers are stored without your name or contact details. For duplicate prevention and abuse protection we store one functional cookie, a hashed (not raw) IP, and your browser type.

Organizers can invite attendees to a post-event survey at survey.guestsight.ai. A survey response stores: the answers (including an optional NPS score and optional comments), how far the survey was completed, and submission timestamps. In addition, two pieces of technical metadata are stored for abuse protection and quality control: the browser's user-agent string and a one-way hash (SHA-256) of the IP address — the raw IP address is never stored and cannot be recovered from the hash.

Duplicate-detection cookie. When you submit a survey, the survey page sets one functional cookie (named ep_survey_{survey-id}) containing a random response identifier. Its only purpose is to prevent the same browser from filling out the same survey twice. It is HttpOnly and Secure, expires after 90 days, is scoped to the survey domain, and is not used for tracking of any kind. Longer surveys also auto-save your in-progress answers to our servers so they aren't lost; nothing is stored in your browser's local storage.

We store no name, email address, or attendee identifier with a response. Note that the organizer distributes the survey link themselves (e.g. by email to their attendee list); whether the organizer can connect responses to individuals depends on how they distribute the link — that is under the organizer's control, with the organizer as controller and GuestSight as processor (see Section 2).

10. AI analysis of feedback & surveys

IN SHORT

To generate reports and follow-up surveys, feedback and survey text — which contains no attendee identities — is processed by third-party AI (large-language-model) providers. It is used to generate the analysis, not to identify anyone.

GuestSight's core feature is turning raw feedback into analysis for the organizer. To generate a report or follow-up survey, we send the collected feedback content — ratings, comment text, QR location labels, survey answers, and event context (such as the event name) — to large language models for analysis. Organizer account data is not included, and because we collect no attendee identities (Sections 8–9), none are sent.

These AI requests are processed by US-based providers of large language models and AI infrastructure acting on our behalf. The providers process the text solely to generate the requested output; see Section 12 on international transfers. Processing happens on the organizer's behalf as part of the service they configured (Art. 28 GDPR; for organizer-side data, Art. 6(1)(b)).

11. Recipients & processors

IN SHORT

A short list: AWS (EU) for hosting, Stripe for payments, Google for sign-in, an EU email delivery provider, and US-based AI providers for analysis. We don't sell data and use no ad networks.

The Service uses the following recipients and categories of recipients (Art. 13(1)(e) GDPR):

  • Amazon Web Services (AWS) — hosting and storage for the entire Service, in the AWS Frankfurt region (eu-central-1, Germany).
  • Stripe — payments, as merchant of record (an independent controller for the purchase and payment data; see Section 6).
  • Google — sign-in (independent controller for the Google-account side of sign-in; see Section 5).
  • A transactional email delivery provider — sends our service emails from an EU datacenter (see Section 7).
  • AI (large-language-model) and AI infrastructure providers — process feedback and survey text to generate analysis, as processors bound by contract (see Sections 10 and 12).

We do not sell personal data, we do not share it with advertising networks, and no third-party analytics providers receive data about you.

12. International transfers

IN SHORT

Your data lives in the EU (Frankfurt). US transfers happen for payments (Stripe), sign-in (Google), and AI analysis, protected by the EU–US Data Privacy Framework and/or standard contractual clauses.

The Service and its databases are hosted in the EU (AWS Frankfurt, Germany), and transactional email is sent from an EU datacenter. Some providers process data in the United States: Stripe (payment processing), Google (sign-in), and the AI providers described in Section 10.

Where personal data is transferred outside the EU/EEA, we rely on the safeguards provided for in the GDPR — in particular an adequacy decision such as the EU–US Data Privacy Framework where the provider is certified, and/or the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) in the provider's data processing terms. Note that the content sent for AI analysis is the anonymous feedback and survey text described in Sections 8–10.

13. Cookies

IN SHORT

Only strictly necessary cookies: three sign-in cookies for organizers and one duplicate-check cookie for surveys. No analytics or marketing cookies — which is why you don't see a cookie banner.

For signed-in organizers (app.guestsight.ai / api.guestsight.ai), signing in sets three cookies, all HttpOnly, Secure, and SameSite=Lax, shared across guestsight.ai subdomains:

  • access_token — keeps you signed in; expires after 1 hour.
  • refresh_token — renews your sign-in without asking you to log in again; expires after 30 days.
  • session_id — identifies your session so you can sign out; expires after 30 days.
  • oauth_state — a short-lived (5-minute) security cookie used only during the Google sign-in redirect to prevent cross-site request forgery.

For survey participants (survey.guestsight.ai), one functional cookie, ep_survey_{survey-id}, prevents duplicate submissions (90 days; see Section 9).

guestsight.ai and guestsight.link set no cookies at all. All cookies above are strictly necessary for the functions you actively use — there are no analytics, preference, or marketing cookies anywhere on the Service, and no consent banner is shown because none is required for strictly necessary cookies.

14. Data retention & deletion

IN SHORT

Account data lives as long as your account; deleting your account anonymizes it immediately. Attendee data belongs to the organizer's workspace and is deleted with it.

  • Account data — kept for the life of your account. When you delete your account, your profile is immediately anonymized: name, email address, and Google identifier are overwritten, and your picture, avatar, and job title are removed. Non-personal workspace records may remain for the workspace's other members.
  • Sessions — deleted automatically after 30 days, or immediately when you sign out.
  • Email delivery log — deleted automatically after 12 months.
  • Attendee feedback and survey responses — retained as part of the organizer's workspace for as long as the organizer keeps the event data; deleted when the organizer deletes it or their workspace is removed.
  • Rate-limiting counters — expire and delete themselves automatically within hours.
  • Billing records — references and records connected to paid plans are kept for the duration of the contract and thereafter as long as statutory (e.g. tax-law) retention duties require.

Where no fixed period is stated above, we keep personal data only as long as necessary for the purpose it was collected for, and then delete or anonymize it.

15. Your rights

IN SHORT

You have the full set of GDPR rights — access, correction, deletion, restriction, portability, objection — via privacy@guestsight.ai. Attendees should contact their event organizer first.

Under the GDPR you have the right to access the personal data we hold about you (Art. 15), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18), to data portability (Art. 20), and to object to processing based on legitimate interests (Art. 21). Where processing is based on consent, you may withdraw it at any time with effect for the future.

To exercise these rights, email privacy@guestsight.ai. Organizers can also delete their account directly in the dashboard.

If you are an event attendee, the event organizer is the controller for your feedback and survey data — please direct requests to the organizer who invited you; we support organizers in fulfilling them (Art. 28 GDPR). Note that because feedback is stored without identifiers (Section 8), we are typically unable to find or attribute a specific submission to a person (Art. 11 GDPR).

You also have the right to lodge a complaint with a data protection supervisory authority — in particular in the EU member state of your habitual residence, your place of work, or the place of the alleged infringement. The supervisory authority competent for us is the data protection authority of the German federal state in which we are established.

16. Security, minors & automated decisions

IN SHORT

Data is encrypted in transit and at rest, hosted in the EU. The Service is a business tool, not directed at children. No automated decision-making in the legal sense.

Security. All connections to the Service use TLS (HTTPS). Data is stored on AWS infrastructure in the EU with encryption at rest, access restricted on a least-privilege basis, and session cookies protected against script access (HttpOnly). No system is perfectly secure, but we design the Service to collect little and protect what it holds.

Minors. GuestSight is a business tool and is not directed at children. We do not knowingly collect personal data from children under 16.

No automated decision-making. We do not carry out automated decision-making or profiling with legal or similarly significant effects on individuals within the meaning of Art. 22 GDPR. The AI-generated reports (Section 10) are analytical summaries for the organizer about events — not decisions about individual people.

17. Changes to this policy

IN SHORT

When the Service changes, this policy changes with it — the date at the top always tells you the current version.

We will update this policy when the Service or legal requirements change, and the “Last updated” date at the top reflects the current version. If a change materially affects how we process organizers' personal data, we will notify account holders (e.g. by email or in the dashboard) before it takes effect. Questions about this policy: privacy@guestsight.ai.