Privacy Policy
Last updated: July 25, 2026
1. About This Policy
I am Coming ("IAC", "we", "us", or "our") provides event planning, invitation, RSVP, guest management, messaging, payment, and related services. This Privacy Policy explains how we collect, hold, use, disclose, retain, and protect personal information when you use our websites, applications, communications, or services.
This policy applies to event hosts, organisation members, guests, invitees, public registrants, partners, and visitors. If you provide us with information about another person, you must be authorised to do so and should make them aware of this policy where appropriate.
2. Information We Collect
- Account and profile information: name, email address, phone number, profile image, authentication provider, language preferences, organisation, role, and account identifiers.
- Event and guest information: event details, dates, locations, media, invitations, guest names and contact details, RSVP responses, attendance numbers, messages, accessibility or dietary details that users choose to provide, and activity relating to an event.
- Payment and transaction information: plan, currency, amount, transaction or checkout identifiers, payment status, invoice or receipt information, and limited payment metadata. Payment card details are handled by the relevant payment processor rather than stored directly by IAC.
- Communications: support requests, feedback, emails, messages, notification preferences, and records showing whether service communications were delivered, opened, or acted upon.
- Device, usage, and diagnostic information: IP address, browser or device type, operating system, page and route information, referral or campaign information, session identifiers, feature interactions, logs, crash reports, and performance information.
- Advertising and attribution information: advertising referral context, conversion events, source-page context, timestamps, and technical identifiers used to understand whether an advertisement resulted in an account registration or event purchase.
3. How We Collect Information
We collect information:
- directly from you when you create an account, create or manage an event, register, RSVP, make a purchase, contact us, or otherwise use the service;
- from event hosts, organisation administrators, guests, invitees, and other users who provide information necessary to organise an event;
- automatically through cookies, local storage, pixels, analytics tools, logs, and similar technologies; and
- from service providers such as authentication providers, payment processors, application stores, communications providers, and advertising or analytics providers.
4. How We Use Information
We use personal information to:
- provide, operate, maintain, and improve IAC;
- create accounts, authenticate users, manage organisations, and enforce access permissions;
- create and manage events, invitations, registrations, guest lists, RSVPs, check-ins, messages, reminders, and notifications;
- process purchases, activate plans, issue receipts, manage refunds or disputes, and maintain financial records;
- provide customer support and communicate about accounts, events, service changes, security, and administrative matters;
- personalise the service, understand feature usage, diagnose faults, measure performance, and develop new features;
- measure advertising effectiveness, including whether an advertisement resulted in a completed registration or event purchase;
- protect users and IAC, prevent fraud or abuse, enforce our terms, and maintain security; and
- comply with legal obligations and respond to lawful requests.
Where applicable law requires a legal basis, our basis will depend on the context and may include performing a contract, complying with law, our legitimate interests, or your consent. You may withdraw consent where processing is based on consent, but this does not affect processing that occurred before withdrawal.
5. Analytics, Advertising, and Similar Technologies
We use analytics and measurement services to understand use of IAC and assess whether our advertising is effective. These services include Google Analytics, Google Tag Manager, New Relic, and the OpenAI Ads Measurement Pixel.
The OpenAI Ads Measurement Pixel loads a browser SDK from OpenAI and records selected conversion events. Our current implementation measures when an email-and-password registration is completed and when a Stripe payment has completed and the associated event has been updated to a paid plan. These measurement calls do not intentionally include a raw name, email address, or phone number.
The OpenAI Ads SDK may capture advertising referral context, store it in a first-party__oppref cookie, add source-page context and timestamps, and batch nearby measurement events. IAC also stores a checkout-session-based key in browser local storage to reduce duplicate purchase measurements. That key remains until it is cleared by the user or the browser.
Cookies, pixels, and browser storage can usually be blocked or cleared using browser settings, although doing so may affect functionality or measurement. Depending on your location, you may also have rights to object to or withdraw consent for certain analytics or advertising processing. See our Cookie Policy or contact us to exercise an applicable right.
6. How We Disclose Information
We may disclose personal information to:
- Event participants: hosts, organisation members, managers, guests, or invitees where necessary to provide event functionality.
- Cloud, storage, authentication, and infrastructure providers: including providers such as Google and Firebase.
- Payment and application-store providers: including Stripe, Apple, and Google, where relevant to a purchase.
- Communications and support providers: including email, messaging, notification, customer-support, and monitoring services.
- Analytics and advertising providers: including Google, New Relic, and OpenAI, for analytics, diagnostics, attribution, and conversion measurement.
- Professional advisers and authorities: where reasonably necessary for legal, accounting, security, fraud-prevention, or regulatory purposes.
- Business transaction participants: in connection with a proposed or completed financing, merger, acquisition, reorganisation, or sale of assets, subject to appropriate safeguards.
- other parties when you direct us to disclose information, give consent, or where disclosure is otherwise permitted or required by law.
We do not disclose guest lists publicly unless an event feature or the event host expressly makes particular information available to the intended participants.
7. International Data Handling
Some providers that support IAC operate in, or process information from, countries outside Australia, including the United States and other locations in which those providers or their subprocessors operate. Privacy and data-protection laws in those locations may differ from those in your location. Where required, we take reasonable steps to use providers and arrangements that protect personal information in accordance with applicable law.
8. Data Security
We use reasonable technical and organisational safeguards designed to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. These safeguards may include access controls, authentication, encryption in transit, monitoring, backups, and incident-response practices. No transmission or storage system is completely secure, and we cannot guarantee absolute security.
9. Data Retention and Deletion
Retention depends on the type of information, why we hold it, and applicable legal requirements:
- Account and profile information: generally retained while an account is active and then deleted or de-identified when no longer required, subject to legal, security, dispute, and backup requirements.
- Event and invitation records: primary event and invite records are generally retained while an event is active and for approximately 90 days after the event date. Eligible events may then be placed in a downloadable archive and removed from the active event and invite collections.
- Event archives: archive download links are intended to remain available for approximately 14 days. Expired archive files and records are scheduled for deletion. Related billing, analytics, activity, message, security, or backup records may follow different retention periods.
- Payment and transaction records: retained as needed for accounting, tax, fraud prevention, refunds, chargebacks, disputes, and other legal or operational requirements.
- Analytics, advertising, and diagnostic records: retained according to our operational needs and provider settings, then deleted or de-identified when no longer reasonably required. Browser cookies and local-storage records may remain until they expire or are cleared.
- Backups and logs: residual copies may remain temporarily in protected backups or logs until they are overwritten through ordinary retention cycles.
The current self-service profile deletion function removes the account's authentication access and primary user-profile record. It does not automatically remove every event, guest, transaction, analytics, operational, legal, or backup record associated with the account. To request broader deletion or de-identification, contact us using the privacy-request process below.
10. Your Privacy Rights and Choices
Depending on your location and subject to legal exceptions, you may have rights to:
- request access to personal information we hold about you;
- request correction of inaccurate or incomplete information;
- request deletion or de-identification of information;
- object to or request restriction of certain processing;
- withdraw consent where processing relies on consent;
- request a portable copy of certain information; and
- complain about how we handle personal information.
To make a request, email privacy@iamcoming.io with the subject "Privacy Request" and describe the account, event, information, and right involved. We may ask for information reasonably necessary to verify your identity and authority. We will respond within the period required by applicable law and explain any lawful reason that prevents us from fully completing a request.
11. Privacy Complaints
To make a privacy complaint, email privacy@iamcoming.io with the subject "Privacy Complaint" and provide enough detail for us to investigate. We will review the complaint, may request further information, and will respond within the period required by applicable law.
If you are in Australia and are not satisfied with our response, you may be able to contact the Office of the Australian Information Commissioner.
12. Children's and Minors' Information
IAC accounts and purchasing services are not directed to children under 16. Event hosts may nevertheless provide limited guest information relating to a minor—for example, a child's name, attendance, or dietary information—when organising an event. The person providing that information must have appropriate authority and should limit it to what is reasonably necessary. Contact us if you believe information about a minor has been provided without appropriate authority.
13. Third-Party Services and Links
IAC may link to or integrate with third-party services. Their handling of information is governed by their own terms and privacy policies where they act independently of IAC. We encourage you to review those policies.
14. Changes to This Policy
We may update this policy when our services, providers, or legal obligations change. We will post the updated policy on this page, change the "Last updated" date, and provide additional notice where required.
15. Contact Us
For privacy questions, requests, or complaints, contact the IAC privacy contact at privacy@iamcoming.io.