Privacy Policy
Last updated:
Best Guests measures live events. A customer uploads a guest list, we find and organize what those guests posted publicly about the event, we measure what the event produced, and we build a picture of the audience that showed up. This policy explains what data that takes, why we handle it, who we share it with, and what you can ask us to do.
1.Who we are and what this covers
Best Guests is a product of Mundial Partners. In this policy, "Best Guests", "we" and "us" mean that company. "You" means whoever is reading, which might be a customer, someone evaluating us, or a guest on a list a customer uploaded.
This policy covers bestguests.ai, the application at app.bestguests.ai, the emails we send, and any other Best Guests product that links here. It does not cover the events themselves, the ticketing platforms our customers use, or the social networks where guests post. Those services have their own policies and we do not control them.
2.Our two roles
This is the part worth reading even if you skip the rest, because it decides who you talk to about your data.
If you are a customer, or you visited our site. We decide how your data is handled, so we are the controller of it. Everything in this policy is our commitment to you directly.
If you are a guest on a list one of our customers uploaded. That customer decides what happens to your data. They are the controller and we are their processor. We handle your data on their instructions, for their event, under a contract with them. We do not sell it, we do not use it to market to you, and we do not use it for our own purposes.
So if you are a guest and you want your data corrected or deleted, the fastest route is the company that invited you to the event. They can do it themselves inside the product. If you come to us instead, we will pass your request to them, tell you who they are where we are allowed to, and help them act on it.
3.What we collect
From customers
- Account data. Your name, work email address, and a password we store only as a salted hash, never in readable form. If you sign in with Google or Microsoft instead, we receive your name, email address, and profile picture from them. We do not receive your password.
- Workspace data. Your company or workspace name, your logo if you upload one, your teammates' names and email addresses when you invite them, and each person's role.
- Project data. Event names, dates, locations, goals, budgets, and cover images. Whatever you type into a project, we store.
- Billing data. Your plan, your usage against it, and your invoice history. Card numbers go to our payment processor and never reach our systems.
- Things you send us. Support emails, demo bookings, and anything you write to us.
From the guest lists customers upload
- What the customer provides. Usually a name and an email address, often a social handle, and sometimes a phone number, employer, job title, or ticket type. The customer chooses which columns to send.
- What we add. We enrich guest records using data providers and public sources: social profiles and handles, follower counts, job title, employer, and general location. This is how the product can tell a customer who actually attended and what reach they have.
- Public content about the event. Posts, stories, reels, and mentions that guests published publicly, plus the public engagement numbers attached to them.
We only ever look at public content. We do not access private accounts, private messages, direct messages, or anything that would require a guest's login. Where a platform offers an API, we use it within that platform's terms. If a guest makes a post private or deletes it, it stops being available to us, and we remove it from a customer's workspace on the next sync.
From anyone who uses the site
- Waitlist submissions. Your email address, if you give it to us, plus the time you submitted it.
- Usage and device data. Pages you viewed, the page that referred you, your browser and operating system, an approximate location derived from your IP address, and timestamps.
- Cookies. Described in section 8.
We do not knowingly collect government identifiers, health data, financial account data, or any other special category of data. Please do not put it in a guest list.
4.How we use it
- To run the product. Import lists, match public content to the right guests, calculate earned media value and the other metrics, produce reports, and build the guest network a customer can invite back.
- To keep accounts secure. Authenticate you, verify email changes, detect abuse, and keep one workspace's data out of another's.
- To send transactional email. Verification, password resets, invitations, and the notifications you have switched on. You cannot opt out of these while you have an account, because they are how the product works.
- To bill you and to count usage against your plan.
- To support you. Answer questions, investigate problems, and follow up.
- To improve the product. We look at aggregated, de-identified usage to find what is slow, broken, or unused.
- To send marketing, if you asked for it or you are already a customer. Every marketing email has a working unsubscribe link, and using it does not affect your account.
- To meet legal obligations and to enforce our terms.
Three things we do not do. We do not sell personal data. We do not use one customer's guest lists, enrichment data, or event content to build features or models for another customer. We do not market to the guests on a customer's list.
5.Legal bases
If you are in the European Economic Area, the United Kingdom, or Switzerland, we need a legal basis for handling your data. Ours are:
- Contract. Running the product for a customer who has signed up for it, including billing and support.
- Legitimate interests. Securing our systems, preventing abuse, understanding aggregate product usage, and marketing to existing customers. We have weighed these against your interests and we will explain the assessment if you ask.
- Consent. Non-essential cookies, and marketing email where consent is required. You can withdraw it at any time.
- Legal obligation. Tax records, and responding to lawful requests.
Where we act as a processor on a customer's instructions, the legal basis for handling guest data is the customer's to establish, not ours. Our contract with them requires them to have one.
7.How long we keep it
- Workspace data, including guest lists, enrichment, and reports: for as long as the workspace is active. Delete a project or a list and we remove it from the product immediately and purge it from backups within 30 days.
- Closed accounts: deleted within 30 days of the account closing, except where we have to keep something longer for tax or legal reasons.
- Billing records: seven years, because tax law requires it.
- Waitlist emails: until we launch and contact you, or until you ask us to remove you.
- Server logs: up to 90 days.
A customer can ask us to delete their workspace at any time, and we will confirm when it is done.
9.Security
- Everything travels over TLS, and data at rest is encrypted.
- Passwords are stored as salted hashes. Nobody at Best Guests can read your password.
- Access to production data is limited to the people who need it, and it is logged.
- Workspaces are separated at the query level, so one customer cannot reach another's data.
- Uploaded files are given unguessable names and served from storage that is not publicly listable.
No system is perfectly secure, and we will not pretend otherwise. If a breach affects your data we will tell you and any regulator we are required to notify, within the deadlines that apply, and we will say what happened rather than what sounds best. Report a vulnerability to operations@bestguests.ai and we will respond.
10.International transfers
We are based in the United States and our infrastructure runs there, so data you send us is processed in the US. If you are in the EEA, the UK, or Switzerland, that is a transfer out of your region. We rely on the European Commission's Standard Contractual Clauses, and the UK Addendum where it applies, and we put the same terms in place with our subprocessors. Ask us and we will send you the mechanism that covers your data.
11.Your rights
Depending on where you live, you can ask us to:
- Tell you what data we hold about you and give you a copy
- Correct it if it is wrong
- Delete it
- Restrict or object to how we use it
- Send it to you, or to someone else, in a portable format
- Stop sending you marketing
- Withdraw a consent you gave earlier
Email operations@bestguests.ai and we will respond within 30 days. We may need to verify who you are first, which protects you more than it protects us. Exercising these rights costs nothing and we will not treat you differently for it.
If you are a guest rather than a customer, see section 2: the request usually has to go to the company that invited you, and we will help route it.
In the EEA or UK you can also complain to your data protection authority. In California you have the rights described above, we do not sell personal information or share it for cross-context behavioral advertising, and we do not use sensitive personal information for inferring characteristics.
12.Children
Best Guests is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a guest list contains a child's data, tell us and we will work with the customer who uploaded it to remove it.
13.Changes and contact
When we change this policy we update the effective date at the top. If a change materially affects how we handle your data, we will email customers at least 30 days before it takes effect, so there is time to object or leave. We will not apply a materially different practice to data we already hold without telling you first.
Getting in touch
Reach out by email with any questions, comments, or concerns.
- operations@bestguests.ai
- Operated by
- Best Guests, a product of Mundial Partners.