Legal

Privacy policy

This policy describes what we collect when you use Samia Venue, why we collect it, and the control you keep over it. The short version: we collect what the service needs, we keep your details private — even from the venue — and we never sell them.

On this page

  1. 1.What we collect
  2. 2.How we use it, and our lawful basis
  3. 3.The managed no-contact rule
  4. 4.Who we share it with
  5. 5.How long we keep it, and deletion
  6. 6.How we keep it safe
  7. 7.Your rights
  8. 8.Changes and contact

What we collect

We collect what we need to run a managed venue marketplace — nothing more. We don’t use third-party analytics or advertising trackers.

  • Your name and phone number, from your profile.
  • Your email address, used to sign you in.
  • Booking details: the date, guest count, and the event message you send.
  • Payment metadata: the amount, the status, and a transaction id. We never store card numbers.
  • A device push token, if you turn on notifications, so we can send booking updates.
  • Venue location, for the venues shown on the platform.
  • Error logs, to find and fix problems and keep the service secure.

How we use it, and our lawful basis

Your information is used to:

  • Coordinate your booking and carry messages between you and the venue.
  • Hold, capture, refund, and pay out payments.
  • Send booking updates and notifications you’ve asked for.
  • Verify venues and keep both sides of the marketplace safe.
  • Diagnose errors and keep the platform running.

We rely on the lawful bases that fit each use: performing the booking you asked for, our legitimate interest in running a safe and working platform, meeting legal and accounting duties, and your consent where it applies (such as notifications).

The managed no-contact rule

Samia is a managed marketplace, so you and the venue don’t swap personal contact details. Everyone communicates through Samia.

Your details stay with us

Your contact details are not shared with the venue, and the venue’s contact details are not shared with you. A venue’s view of a booking leaves out your identity. This keeps the booking coordinated through us — and keeps your personal information private.

Who we share it with

We share data only with the services that make the platform run, and only what each one needs:

  • WaafiPay, to process payments.
  • Supabase, which provides our hosting and infrastructure.
  • A web-push delivery service, to send the notifications you’ve turned on.

We never sell your personal data. Not to anyone, not for anything.

How long we keep it, and deletion

We keep your data while your account is active. You can ask us to delete it: we scrub your personal data, but we keep transaction records that the law and accounting rules require us to hold. Where you have bookings, we anonymise the account rather than hard-delete it — so the booking and payment record stays intact, but it’s no longer tied to you.

How we keep it safe

Your data is stored on secured infrastructure with access limited to the people who need it to run the service and help you. Payments are handled by WaafiPay, and card details never reach or rest on our systems.

Your rights

  • Access: ask for a copy of the personal data we hold about you.
  • Correction: update your details in account settings, or ask us to fix them.
  • Deletion: ask us to delete your data — we scrub personal data and keep only the transaction records the law requires, anonymising accounts that have bookings.

To make any of these requests, contact us and a person will handle it.

Changes and contact

If we change this policy in a way that matters, we’ll tell you by email before the change takes effect. For any privacy question or request, contact us — a person, not a queue, reads it.

Questions about this document? Contact us.

See also the terms of service and the payment terms.

Version 1.1 · Effective 4 August 2026