Niche Society

Privacy Policy

Niche Society

Product: Niche Frontdesk

Effective date: 21 September 2026

Niche Society (“we”, “us”, “our”) operates Niche Frontdesk, a mobile application for authorised front-desk and event staff. This policy explains how we collect, use, store, and share personal data when you use the app.

If you do not agree with this policy, please do not use Niche Frontdesk.

1. Who this policy covers

This policy applies to:

  • Operators — staff who create an account, wait for approval, and use the app to manage assigned events and guest check-in.
  • People whose data appears in the app in the course of an event — for example guests on an assigned guest list. We process that data to provide the service to the event organiser.

This policy does not replace any privacy notice the event organiser gives to their guests.

2. Who we are

Controller (operator accounts and app operations): Niche Society

Contact: support@niche-society.com

Website: www.niche-society.com

For guest names, seating, invitation codes, and check-in status, we typically act as a processor on behalf of the event organiser (the controller of that guest data). We use that data only to run check-in and related event operations.

3. Data we collect

3.1 Account and profile

When you register or complete your account, we collect:

  • Full name
  • Email address
  • Phone number and country code
  • Gender (if you choose to provide it)
  • Password, or sign-in through Google or Apple
  • Profile photo, if you add one
  • Account status (for example pending approval or active)

3.2 Authentication and security

  • Sign-in credentials and one-time verification codes (email or SMS)
  • Authentication identifiers from Firebase, Google, or Apple
  • Session tokens needed to keep you signed in

We do not store your Google or Apple password.

3.3 Device and notifications

  • A device notification token, so we can send operational alerts
  • Language preference (English or Arabic) stored on the device
  • Basic technical logs (for example failed requests) used to keep the service working

3.4 Camera (QR scanning)

If you use Scan QR Code, the camera is used on the device to read invitation codes. We do not keep a camera stream or photo of the QR code. We send the scanned or typed code to our servers only to verify the guest and record check-in.

The camera is not used for past (completed) events.

3.5 Event and guest operations

Depending on events you are assigned to, the app may show and update:

  • Event name, date, time, venue, and status (live, upcoming, completed)
  • Guest name, invitation code, table, seat, companion details, and arrival status
  • Check-in counts and related event statistics

This information is provided by the event organiser’s systems. You should use it only for your assigned duties.

3.6 Support

If you contact us, we collect whatever you send (for example name, email, and the content of the message) so we can respond.

We do not sell personal data.

4. How we use data

We use personal data to:

  • Create and manage operator accounts, including admin approval
  • Sign you in and protect accounts (verification codes, session security)
  • Show assigned events and guest lists
  • Record guest check-in when you scan or enter an invitation code
  • Send service notifications (for example operational alerts)
  • Remember language and similar app settings
  • Improve reliability, diagnose errors, and secure the service
  • Meet legal and regulatory obligations

We do not use operator or guest data for third-party advertising.

6. Who we share data with

We share data only as needed:

RecipientWhy
Event organisers / venue operatorsSo they can run the event and see check-in results
Cloud and infrastructure providersHosting, database, and API delivery
Firebase (Google)Authentication, and push notifications if enabled
Google / AppleOnly if you choose that sign-in method
SMS / email providersTo send verification codes
Professional advisers and authoritiesIf required by law, dispute, or safety

These parties may process data only for the purposes above, under appropriate contracts where required.

We do not share your data with unrelated marketers.

7. Retention

We keep data only as long as needed for the purposes above:

  • Operator account — while the account is active, then for a limited period after deletion or deactivation unless the law requires longer
  • Check-in and event records — for the life of the event operations and any period the organiser or the law requires
  • Security and technical logs — for a short operational period
  • Support messages — as long as needed to resolve the request and keep a reasonable record

When data is no longer needed, we delete or irreversibly anonymise it where practicable.

8. Security

We use reasonable technical and organisational measures, including:

  • Encrypted transport (HTTPS) between the app and our servers
  • Authenticated API access
  • Role-based access so operators see only assigned events
  • Admin approval before a new operator can use the service

No method of transmission or storage is completely secure. Please keep your device and sign-in details confidential.

9. International transfers

Our infrastructure and vendors (including Firebase / Google) may process data outside Saudi Arabia. Where we transfer personal data abroad, we take steps required by applicable law, such as contractual safeguards.

10. Your rights

Subject to the PDPL and other applicable law, you may request to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Request deletion of your account and related personal data
  • Withdraw consent where processing is based on consent
  • Object to or restrict certain processing
  • Lodge a complaint with the competent Saudi authority (SDAIA)

You can update much of your profile in Account Settings, and you can request account deletion from the app.

We may need to verify your identity before fulfilling a request. We may refuse or limit a request where the law allows (for example, data we must keep, or data that belongs to an event organiser).

For guest-list data, the event organiser is usually the right first contact. We will help where we are required to.

Contact for privacy requests: support@niche-society.com

11. Children

Niche Frontdesk is for authorised adult staff. It is not directed at children. We do not knowingly create operator accounts for anyone under 18.

Guest lists may include minors if the event organiser collected that information. We process it only to provide the service to that organiser.

12. Local storage on your device

The app stores on the device items such as:

  • Sign-in session
  • Cached profile
  • Language preference

Clearing app data or uninstalling the app removes local copies. It does not by itself delete your account on our servers. Use account deletion or contact us for that.

13. Changes to this policy

We may update this policy from time to time. The “Effective date” at the top will change when we do. Material changes may also be communicated in the app or by email. Continued use after an update means you accept the revised policy.

14. Contact

Niche Society

Email: support@niche-society.com

Website: www.niche-society.com

If you have questions about this policy or how we handle personal data, write to us at the email above.