Privacy Policy
Niche Society
Product: Niche Frontdesk
Effective date: 21 September 2026
Niche Society (“we”, “us”, “our”) operates Niche Frontdesk, a mobile application for authorised front-desk and event staff. This policy explains how we collect, use, store, and share personal data when you use the app.
If you do not agree with this policy, please do not use Niche Frontdesk.
1. Who this policy covers
This policy applies to:
- Operators — staff who create an account, wait for approval, and use the app to manage assigned events and guest check-in.
- People whose data appears in the app in the course of an event — for example guests on an assigned guest list. We process that data to provide the service to the event organiser.
This policy does not replace any privacy notice the event organiser gives to their guests.
2. Who we are
Controller (operator accounts and app operations): Niche Society
Contact: support@niche-society.com
Website: www.niche-society.com
For guest names, seating, invitation codes, and check-in status, we typically act as a processor on behalf of the event organiser (the controller of that guest data). We use that data only to run check-in and related event operations.
3. Data we collect
3.1 Account and profile
When you register or complete your account, we collect:
- Full name
- Email address
- Phone number and country code
- Gender (if you choose to provide it)
- Password, or sign-in through Google or Apple
- Profile photo, if you add one
- Account status (for example pending approval or active)
3.2 Authentication and security
- Sign-in credentials and one-time verification codes (email or SMS)
- Authentication identifiers from Firebase, Google, or Apple
- Session tokens needed to keep you signed in
We do not store your Google or Apple password.
3.3 Device and notifications
- A device notification token, so we can send operational alerts
- Language preference (English or Arabic) stored on the device
- Basic technical logs (for example failed requests) used to keep the service working
3.4 Camera (QR scanning)
If you use Scan QR Code, the camera is used on the device to read invitation codes. We do not keep a camera stream or photo of the QR code. We send the scanned or typed code to our servers only to verify the guest and record check-in.
The camera is not used for past (completed) events.
3.5 Event and guest operations
Depending on events you are assigned to, the app may show and update:
- Event name, date, time, venue, and status (live, upcoming, completed)
- Guest name, invitation code, table, seat, companion details, and arrival status
- Check-in counts and related event statistics
This information is provided by the event organiser’s systems. You should use it only for your assigned duties.
3.6 Support
If you contact us, we collect whatever you send (for example name, email, and the content of the message) so we can respond.
We do not sell personal data.
4. How we use data
We use personal data to:
- Create and manage operator accounts, including admin approval
- Sign you in and protect accounts (verification codes, session security)
- Show assigned events and guest lists
- Record guest check-in when you scan or enter an invitation code
- Send service notifications (for example operational alerts)
- Remember language and similar app settings
- Improve reliability, diagnose errors, and secure the service
- Meet legal and regulatory obligations
We do not use operator or guest data for third-party advertising.
5. Legal basis (Saudi PDPL)
Where the Saudi Personal Data Protection Law applies, we process data because:
- Contract — we need it to provide Frontdesk (account, assigned events, check-in)
- Legitimate interest / operational necessity — security, fraud prevention, service logs, product reliability, in a way that does not override your rights
- Consent — where required (for example optional profile fields, or notifications where consent is legally needed)
- Legal obligation — if the law requires us to keep or disclose information
You may withdraw consent where processing is based on consent. That does not affect processing we already carried out, or processing we still need for the contract or the law.
7. Retention
We keep data only as long as needed for the purposes above:
- Operator account — while the account is active, then for a limited period after deletion or deactivation unless the law requires longer
- Check-in and event records — for the life of the event operations and any period the organiser or the law requires
- Security and technical logs — for a short operational period
- Support messages — as long as needed to resolve the request and keep a reasonable record
When data is no longer needed, we delete or irreversibly anonymise it where practicable.
8. Security
We use reasonable technical and organisational measures, including:
- Encrypted transport (HTTPS) between the app and our servers
- Authenticated API access
- Role-based access so operators see only assigned events
- Admin approval before a new operator can use the service
No method of transmission or storage is completely secure. Please keep your device and sign-in details confidential.
9. International transfers
Our infrastructure and vendors (including Firebase / Google) may process data outside Saudi Arabia. Where we transfer personal data abroad, we take steps required by applicable law, such as contractual safeguards.
10. Your rights
Subject to the PDPL and other applicable law, you may request to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Request deletion of your account and related personal data
- Withdraw consent where processing is based on consent
- Object to or restrict certain processing
- Lodge a complaint with the competent Saudi authority (SDAIA)
You can update much of your profile in Account Settings, and you can request account deletion from the app.
We may need to verify your identity before fulfilling a request. We may refuse or limit a request where the law allows (for example, data we must keep, or data that belongs to an event organiser).
For guest-list data, the event organiser is usually the right first contact. We will help where we are required to.
Contact for privacy requests: support@niche-society.com
11. Children
Niche Frontdesk is for authorised adult staff. It is not directed at children. We do not knowingly create operator accounts for anyone under 18.
Guest lists may include minors if the event organiser collected that information. We process it only to provide the service to that organiser.
12. Local storage on your device
The app stores on the device items such as:
- Sign-in session
- Cached profile
- Language preference
Clearing app data or uninstalling the app removes local copies. It does not by itself delete your account on our servers. Use account deletion or contact us for that.
13. Changes to this policy
We may update this policy from time to time. The “Effective date” at the top will change when we do. Material changes may also be communicated in the app or by email. Continued use after an update means you accept the revised policy.
14. Contact
Niche Society
Email: support@niche-society.com
Website: www.niche-society.com
If you have questions about this policy or how we handle personal data, write to us at the email above.
