Privacy notice
This notice explains what tamrey collects, why, how long it is kept and who else touches it. The short version: we collect what you type into the planner, what the planner generates from it, your email and payment record if you buy something, and your message if you contact us. We do not collect, receive, process or store data about your attendees, and there is nowhere in the product to give it to us.
1. Who is responsible
Ookii Pup LLC, doing business as tamrey, is the controller of the personal data described here. Contact info@tamrey.com with any question or request.
2. What we collect
Event parameters you enter
Event name, city, country, venue type, dates, attendance figures, check in window, and the technical and structural answers the planner asks for. This is business information about an event. It normally contains no personal data, though an event name or city could identify a person indirectly if you choose to enter one.
Generated output
The packet produced from those parameters, so you can return to it.
Account information
Your email address, used to sign you in with a one time link and to send purchase receipts.
Purchase records
What you bought, when, the amount, the currency, and an identifier from our payment processor. We never see or store your full card number. Card details go directly to Stripe.
Technical information
Standard server and platform logs generated when you use the site, including IP address, browser type and request times, used for security, abuse prevention and fault diagnosis. Fonts and some scripts on the site load from Google Fonts, cdnjs (Cloudflare) and jsDelivr, which receive your IP address and browser details when they deliver those files.
Messages you send us
If you use the contact form, the name, email address and message you enter, sent to our inbox through FormSubmit.
Analytics, if you allow it
We use Google Analytics 4 and Contentsquare to understand how the site is used: which pages are visited, in what order, from which country and on what kind of device, whether a planner session reaches a packet, and where people stop. Analytics only runs if you accept it. If you decline, no analytics cookie is set and no analytics data is sent.
What analytics collects when you allow it:
- Pages viewed, in what order, and how long each was open
- Approximate location, at country and region level, derived from your IP address
- Device type, browser, operating system and screen size
- How you arrived, for example a search engine, a direct visit or a link
- Whether key steps happened, for example a planner reaching a preview or a checkout starting
- A randomly generated identifier stored in a cookie, so repeat visits from the same browser are recognized as the same visitor
- With Contentsquare, how each page is used, such as clicks, taps, scrolling and mouse movement, so a visit can be replayed to see where the site is hard to use
On IP addresses. Google Analytics 4 receives your IP address in order to work out roughly where you are, then discards it. It is not stored in our analytics data and we cannot see it there. IP addresses do appear briefly in hosting and sign in logs for security, as described above. We do not use IP addresses to identify individuals.
Session replay. Contentsquare records the page as you use it so we can replay the visit. Anything typed into a form field is masked in your browser before it is sent. Your account page and your packet are masked in full, so neither reaches Contentsquare. Contentsquare uses your IP address to work out roughly where you are and to filter out automated traffic, keeps it in short term logs for no more than 3 days, then deletes it.
What analytics is never joined to. Your analytics identifiers are not linked to your account, your email address, your purchases or your event parameters, and we do not send Contentsquare any identifier for your account. We have not enabled Google Signals, cross device tracking or advertising features, we do not import audiences or send data to advertising products, and we do not use analytics for advertising of any kind.
3. What we deliberately do not collect
- Attendee data. No names, no email addresses, no registration lists, no badge files, no scan data, no biometric data. The planner asks for counts and percentages. There is no upload field and no integration that could bring attendee records in.
- Payment card numbers. Handled entirely by Stripe.
- Special category data as defined by GDPR Article 9.
- Data about children. The service is not directed to anyone under 18.
- Analytics linked to your identity. Analytics is kept separate from your account, and neither we, Google nor Contentsquare can connect an analytics record to a named customer.
This is a design decision. The architecture has no place to put attendee data, which is why we can say it plainly to your security reviewer.
4. Why we process it, and on what legal basis
| Purpose | Data | Legal basis (UK and EU GDPR) |
|---|---|---|
| Generating and returning your packet | Event parameters, generated output | Performance of a contract |
| Signing you in and keeping your packets available | Email, saved packets | Performance of a contract |
| Taking payment and issuing receipts | Email, purchase record | Performance of a contract, and legal obligation for tax records |
| Security, abuse prevention and fault diagnosis | Technical logs | Legitimate interests in keeping the service available and unabused |
| Answering messages you send us | Name, email, message | Legitimate interests in responding to you |
| Understanding how the site is used, so it can be improved | Analytics events, session replays and identifiers | Consent, given through the cookie banner and withdrawable at any time |
| Improving the calculation model | Aggregated, non identifying usage patterns | Legitimate interests |
We do not use your data for advertising, we do not sell or share it for cross context behavioral advertising, and we do not profile you.
5. How long we keep it
- Paid packets and their inputs: 12 months from purchase, unless you delete them sooner. Export your packet when you unlock it, because we do not send a reminder before this date.
- Unpaid drafts: 90 days from last edit, unless you delete them sooner.
- Messages you send us: for as long as needed to respond and keep a record of the conversation.
- Account record: until you delete your account, then removed within 30 days.
- Purchase and tax records: seven years, as required for financial and tax purposes, in a minimized form.
- Technical logs: 90 days.
- Analytics data: 14 months in Google Analytics, after which event level records are deleted automatically. Aggregate reports may persist beyond that and cannot identify anyone.
- Contentsquare data: session replays for 1 month and analytics data for 13 months, after which both are deleted automatically.
6. Who else touches it
| Processor | What they do | Where |
|---|---|---|
| Netlify, Inc. | Hosts the site and runs the calculation function | United States, global edge network |
| Supabase, Inc. | Stores accounts, saved packets and purchase records, and issues sign in links | Oregon, United States |
| Stripe, Inc. | Processes payments and holds card data | United States and global |
| Google LLC (Google Analytics 4) | Measures site usage, only where you have accepted analytics cookies | United States, with EU and UK traffic routed through Google's regional collection |
| Content Square Inc. (Contentsquare) | Measures site usage and records session replays, only where you have accepted analytics cookies | United States |
| Namecheap, Inc. (Private Email) | Sends sign in emails from info@tamrey.com and holds our inbox | United States |
| FormSubmit | Forwards contact form messages to our inbox | Not published by the provider |
Deleting a packet or draft is permanent. We cannot restore it, so export anything you want to keep before you delete it.
Where the provider offers one, each is engaged under a data processing agreement, and each may process data only to provide its service to us. We do not sell your data to anyone. We may disclose data if legally required, or in connection with a sale of the business, in which case this notice continues to apply until you are told otherwise.
7. International transfers
We are based in the United States and our main processors are United States companies. If you are in the United Kingdom, the European Economic Area or Switzerland, your data will be transferred to the United States. Those transfers rely on the European Commission's Standard Contractual Clauses and the UK Addendum, together with the processors' own transfer frameworks, including certification under the EU US Data Privacy Framework where applicable.
Google Analytics data is transferred to Google LLC in the United States under the Standard Contractual Clauses and Google's Data Processing Terms, with EU and UK traffic passing through Google's regional collection so that IP addresses are handled inside the region before being discarded.
Contentsquare data is held in Contentsquare's United States data region.
8. Cookies and similar technology
There are two kinds of cookie and nothing else. There are no advertising cookies and no cross site tracking.
| Cookie | Purpose | Set by | Lifetime | Needs consent |
|---|---|---|---|---|
| Session and sign in | Keeps you signed in and protects the form against cross site request forgery | tamrey and Supabase | Session, or up to 30 days if you stay signed in | No, strictly necessary |
| Checkout and purchase state | Remembers which event you are paying for across the trip to Stripe, and which of your events are unlocked, so the page shows them correctly | tamrey | Until you clear it | No, strictly necessary |
| Cookie choice | Remembers whether you accepted or declined analytics, so you are not asked again | tamrey | Until you clear it | No, strictly necessary |
| _ga and _ga_[ID] | Google Analytics. Distinguishes visitors and sessions | Up to 2 years and 2 years | Yes | |
| _cs_id, _cs_s and other _cs_ cookies | Contentsquare. Distinguishes visitors and sessions and holds replay state. If you withdraw consent, _cs_optout records that choice | Contentsquare | Up to 13 months, session cookies 30 minutes | Yes |
Analytics cookies are not set unless you accept them. Until you make a choice, nothing analytics related loads. Decline and it never loads. Accept and you can change your mind at any time using Cookie settings in the footer, which stops further collection immediately.
Blocking cookies in your browser also works. Strictly necessary cookies cannot be turned off from the banner, because sign in and draft storage do not function without them.
9. Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to processing, receive it in a portable format, and withdraw consent where processing relies on consent. Residents of California and other United States states with comprehensive privacy laws may also have the right to know what is collected, to delete it, to correct it, and to be free from discrimination for exercising those rights. We do not sell personal information or share it for cross context behavioral advertising, so there is nothing to opt out of on that front.
To withdraw consent for analytics, use Cookie settings in the footer. Withdrawal stops future collection and does not affect anything collected while consent was in place.
To exercise any right, email info@tamrey.com. We respond within 30 days, or sooner where the law requires it, and we may need to verify your identity first. You can also export or delete your packets yourself from your account.
If you are in the UK or EU and are unhappy with our response, you may complain to your supervisory authority. In the UK that is the Information Commissioner's Office at ico.org.uk.
10. Security
Data is encrypted in transit. Database access is restricted by row level security, so one account cannot read another's records. The calculation model runs server side and is not exposed to the browser. Payment card data never reaches our systems. No system is perfectly secure, and we do not claim otherwise, but we will notify you and any regulator as required if a breach affects your data.
11. Your own obligations
If you are subject to GDPR or similar law for your event, that applies to the attendee data you hold, not to the parameters you enter here. Nothing in a tamrey packet is a compliance determination for your event. Where the output raises a privacy point, for example around biometric check in, it is naming a consideration rather than telling you what is lawful.
12. Changes
We may update this notice. Material changes will be noted with a new effective date at the top of this page. We do not send notification emails, so check the date here if it matters to you.
13. Contact
Ookii Pup LLC, doing business as tamrey. Privacy questions and requests: info@tamrey.com, or by mail to PO Box 29, Round Mountain, CA 96084, United States.
