Privacy Policy
1. Who we are
This policy explains how Lobbi (“Lobbi”, “we”, “us”) handles personal data across our website at mylobbi.link and our app at in.mylobbi.link.
For privacy questions or requests, email [email protected].
2. What Lobbi is
Lobbi provides branded virtual waiting rooms for video calls. Hosts (typically professionals or teams) use the Lobbi app at in.mylobbi.link to design lobbies, set a call link, and admit guests. Guests open a public lobby link, check in, and wait until the host lets them into the underlying meeting (Zoom, Google Meet, Microsoft Teams, or another URL the host provides).
Lobbi is the doorway to your call — it does not replace your meeting provider.
3. Roles and responsibilities
Host account data. For information about people who sign up and use the Lobbi app, Lobbi is the data controller.
Guest check-in data. When a guest uses a lobby, the host decides who receives the link and why. The host is the data controller for guest personal data collected during check-in. Lobbi acts as a data processor, processing guest data on the host’s instructions to operate the waiting room (check-in, notifications, admit flow, and basic analytics for the host).
If you are a guest with questions about how your data is used, contact the host who invited you. You may also contact us at [email protected] and we will assist where we can.
4. Data we collect — hosts
When you create an account and use Lobbi, we may collect:
- Account: email address, full name, sign-in method (email one-time code or Google OAuth)
- Workspace: company or workspace name, logo, brand colours, and related settings
- Lobbies: lobby name, slug, design content, welcome messages, host name and photo, meeting URLs, activation status, and guest session status when you admit from Home or Monitor
- Media: images and files you upload to brand your lobbies (stored in our media storage)
- Usage and product analytics: actions in the app (for example creating a lobby, admitting a guest) via PostHog when enabled
- Technical data: IP address, browser type, and device information collected by our infrastructure and analytics providers
5. Data we collect — guests
When a guest opens a lobby link and checks in, we may collect:
- Name (required for check-in)
- Email (optional on many lobbies; if omitted we may assign an anonymous browser identifier prefixed with
anon:so the session can work without a real email) - Optional fields the host configures (for example phone or a custom question and answer)
- Session data: check-in time, wait status, delay messages, admit time, no-show status, and related event history
- Technical data: browser storage used to resume a wait after refresh, and product analytics events (for example check-in completed) when PostHog is enabled on the app
Guest lobbies are publicly reachable by anyone with the link. Do not enter sensitive information unless you trust the host who sent you the link.
6. How we use data
We use personal data to:
- Provide, maintain, and improve Lobbi
- Authenticate hosts and secure accounts
- Display branded waiting rooms and run the check-in / admit flow
- Show hosts who is waiting and provide lobby analytics
- Send transactional email (sign-in codes, account notices, and booking-related messages where configured)
- Understand product usage and fix errors
- Comply with law and protect against abuse
We do not sell personal data. We email hosts about their account and lobbies; we do not send marketing email to guests who only checked in to a lobby.
7. Legal bases (EEA / UK)
Where applicable, we rely on:
- Contract — to provide the service you sign up for
- Legitimate interests — to secure and improve Lobbi, and to process guest data on a host’s behalf
- Consent — where required (for example certain optional communications)
- Legal obligation — where we must retain or disclose data by law
8. Sharing and sub-processors
We use trusted providers to run Lobbi. They process data only on our instructions:
- Supabase — database, authentication, file storage, realtime updates, and edge functions
- Cloudflare — hosting, content delivery, and API infrastructure
- Resend — transactional email delivery
- PostHog — product analytics in the app, and web analytics on this marketing site (cookieless unless you accept analytics cookies) (see our Cookie Policy)
- Google — optional Google sign-in for hosts; Google Meet link creation for hosts who connect the Google Meet integration (see Google Meet integration); Google Fonts on this marketing site
- Slack — delivery of check-in notifications, for hosts who connect the Slack integration (see Slack integration)
We may disclose data if required by law, to protect rights and safety, or in connection with a merger or acquisition (with notice where appropriate).
9. Slack integration
Connecting Slack is optional and off unless a host turns it on. When a host connects it, Lobbi posts check-in notifications into one Slack channel chosen during installation, and teammates can admit, delay, or remove a guest from that message.
What Lobbi receives from Slack
- An incoming webhook URL that can post only to the chosen channel
- Workspace (team) ID and name, and channel ID and name — to label the connection in Lobbi and route notifications to the right place
- The Slack user ID of the person who connected the app — so actions taken from Slack are attributed to their Lobbi account
- Interaction details when someone presses a button — the Slack user, channel, and workspace IDs, and the Lobbi session the button refers to
Lobbi requests a single Slack permission, incoming-webhook. We cannot read
messages, files, channel lists, or member profiles in your workspace, and we cannot post
anywhere except the channel chosen at install. We do not use any Slack data to train
machine learning models.
What Lobbi sends to Slack
Each notification contains the guest’s name (or “A guest” if they gave none), the lobby name, and — once a teammate admits the guest — the meeting link. Guest email addresses, phone numbers, and answers to custom check-in questions are not sent to Slack.
How long we keep it, and how to delete it
The webhook URL and the workspace, channel, and user IDs are kept for as long as the integration stays connected. When a host disconnects Slack in Lobbi, or removes Lobbi from the Slack workspace, we delete the stored credentials and mark the connection revoked.
Notifications already delivered live in your own Slack workspace and follow your Slack retention settings rather than ours, so deleting those messages is done in Slack. To remove everything on our side, disconnect from Integrations in Lobbi, or email [email protected] and we will do it for you.
10. Google Meet integration
Connecting Google Meet is optional and off unless a host turns it on from Integrations in Lobbi. When connected, Lobbi can create a Google Meet link for a lobby, so admitted guests are sent straight into that meeting.
What Lobbi can access
Lobbi requests a single Google permission,
https://www.googleapis.com/auth/meetings.space.created. It lets Lobbi create
new Google Meet meeting spaces and manage only the meeting spaces Lobbi itself created.
Lobbi cannot read your Gmail, Google Calendar, contacts, Google Drive, or any meeting,
recording, or transcript that Lobbi did not create.
What Lobbi stores
- OAuth access and refresh tokens issued by Google, so Lobbi can create meeting links without asking you to reconnect each time
- The Google account email address, where Google provides it, to label the connection in Lobbi
- For each meeting Lobbi creates: the Google Meet link and meeting space identifier, linked to the lobby it was created for
How Lobbi uses and shares Google data
Google user data is used only to create and show Google Meet links for your lobbies. The meeting link is shown to guests you admit to that lobby, and teammates in your Lobbi workspace can use the connection to create meeting links for the workspace’s lobbies. Teammates and guests never see your Google tokens.
We do not sell Google user data, use it for advertising, or use it to develop, improve, or train generalised artificial intelligence or machine learning models. No person at Lobbi reads Google user data unless you ask us to (for example for support), it is needed for security reasons, or the law requires it.
Lobbi’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How long we keep it, and how to delete it
Tokens are kept only while Google Meet stays connected. When a host disconnects Google Meet in Lobbi, we revoke the tokens with Google and delete them from our systems. You can also remove Lobbi’s access at any time from your Google Account permissions page; the stored tokens stop working immediately, and we delete them on request. Meeting links stay with the lobby they were created for until the lobby is deleted or you ask us to remove them at [email protected].
11. How we protect your data
We use the following technical and organisational measures to protect personal data, including sensitive data such as Google OAuth tokens and other integration credentials:
- Encryption in transit: all traffic between your browser, our servers, and our providers (including Google APIs) is sent over HTTPS using TLS.
- Encryption at rest: our database, authentication records, and file storage are hosted on Supabase and encrypted at rest with AES-256, including backups.
- Isolated credential storage: OAuth access and refresh tokens and integration webhook URLs are kept in a separate table that only our server-side code can read. Row-level security is enabled on that table and all access from the Lobbi app, browsers, and the public API is revoked. Tokens are never sent to the browser, and we do not send them to analytics or error-tracking tools.
- Protected application secrets: OAuth client secrets and API keys are stored as encrypted secrets in our hosting environment and are never included in the app code delivered to browsers.
- Least-privilege access to third parties: we request only the narrowest permission each integration needs (for example, one Google scope and one Slack scope), and revoke tokens with the provider when you disconnect.
- Secure OAuth flow: every Google and Slack connection request carries a state value signed with HMAC-SHA256 that expires after 10 minutes, protecting against cross-site request forgery and tampering.
- Workspace isolation: database row-level security scopes workspace data so hosts can only access their own workspace’s lobbies, guests, and integrations.
- Passwordless authentication: hosts sign in with a one-time email code or Google, so we store no passwords. Sessions use signed, short-lived tokens that our server verifies on every protected request.
- Restricted internal access: access to production systems and data is limited to a small number of authorised team members who need it to operate and support Lobbi.
- Incident response: if a security incident affects your personal data, we will notify you and the relevant authorities as required by applicable law.
No method of transmission or storage is completely secure, but we work to protect your data and review these measures as Lobbi evolves. To report a security concern, email [email protected].
12. International transfers
Our infrastructure providers may process data in countries outside your own. Our Supabase
database, authentication, and file storage are hosted in the
United States (us-west-1). Cloudflare serves our site and API
from its global network, so requests are handled at the location nearest to the visitor.
Resend, PostHog, Google, and Slack each process data on their own infrastructure as
described in their privacy policies. Where required, we use appropriate safeguards such as
standard contractual clauses.
13. Retention
We keep account and lobby data while your account is active and as needed to provide the service. Session and check-in records are retained for host analytics and operational purposes. We delete or anonymise data when it is no longer needed, unless we must keep it for legal reasons.
There is no self-service account deletion in the app yet. To request deletion of your account or data, email [email protected].
14. Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or port your personal data, and to object to or withdraw consent for certain processing.
Hosts can update profile and workspace details in Settings. For other requests, contact [email protected]. We respond within the timeframes required by applicable law. You may also complain to your local data protection authority.
15. Children
Lobbi is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided data, contact us and we will delete it.
16. Beta and pricing
Lobbi is currently offered as a free beta. We may introduce paid plans later; we will email account holders before any change that affects billing. Beta features and data practices may evolve as the product develops.
17. Changes
We may update this policy. We will post the new effective date on this page and, for material changes, notify account holders by email where appropriate. Continued use after changes means you accept the updated policy.
18. Contact
Email: [email protected]
Website: mylobbi.link