Last updated July 28, 2026
This page describes the data MahjPlay currently receives, stores, and uses for event registration, table assignment, and check-in.
When you buy a seat or reserve a table, we collect the buyer name and email, ticket type, quantity, payment status, order amount, and the event associated with the purchase.
When you complete a player profile, we collect your name, badge name, email, optional phone number, mahjong experience, usual and event-specific playing speed, table vibe, comfort with mixed-experience tables, special requests, whether you volunteer to bring mahjong equipment, event-policy acknowledgements, and communication preferences.
When you join a waitlist, we collect your name, email, and optional phone number.
When a buyer purchases multiple seats, we store the tickets under that purchase. Assigning additional tickets to attendees is not yet available.
Accounts use passwordless email sign-in. We store account identifiers, login email details, verified email state, admin membership, delegated group or event access grants, and reusable player profile details tied to the signed-in account.
For organizer workflows, we store event contacts, internal event notes, admin notes, check-in status, table assignments, and audit records for privileged changes. Organizers can generate exports from event records. Notes may include personal information if an organizer enters it.
Payments are handled by Stripe Checkout. We do not build or store card entry fields in MahjPlay. We store Stripe checkout session IDs, payment intent IDs when available, processed Stripe event IDs, and payment status so orders can be fulfilled and reconciled.
Checkout records store site terms and event code-of-conduct acceptance, acceptance time, the current site terms version, a snapshot of the accepted event code of conduct, and the browser IP address seen by the server for that acceptance.
Signed profile and order links are stored as token hashes. We use account session cookies through AWS Amplify so signed-in users can access protected pages.
MahjPlay uses Google Analytics with first-party analytics cookies to understand event-page visits, campaign attribution, registration and account funnels, event-admin feature usage, and aggregate commerce performance. Analytics is routed through a MahjPlay server-side Google Tag Manager service running on AWS before approved measurements are sent to Google.
Analytics may include a public event identifier and slug, organizer-group identifier, sanitized page category, workflow step and outcome, registration state, campaign parameters such as source, medium, and campaign, and checked-in catalog names, prices, quantities, currency, and aggregate value.
MahjPlay does not send Google Analytics names, email addresses, phone numbers, account identifiers, order or ticket identifiers, Stripe identifiers, secure-link tokens, profile answers, admin actor identifiers, notes, free-form form values, search terms, or raw error messages. URLs are sanitized before measurement, and visitor IP forwarding headers are removed by the analytics proxy.
Advertising signals, personalized advertising, Google Signals, user-provided data, and cross-device user IDs are disabled. Analytics is directional and does not replace MahjPlay or Stripe registration and financial records.
The HttpOnly mahjplay_analytics cookie stores granted or denied for one year. The HttpOnly mahjplay_attribution cookie stores sanitized first- and last-qualified campaign touches for up to 90 days from the latest qualified touch. A qualified touch requires valid source and medium campaign parameters or an external referring site; direct and internal navigation do not overwrite it. The attribution cookie never stores a visitor ID, full URL, advertising click ID, or arbitrary query value.
MahjPlay honors the Global Privacy Control signal and an explicit analytics denial before loading Google Tag Manager. Turning analytics off removes MahjPlay attribution and the Google Analytics cookies visible to the application. Turning it back on reloads collection on the resulting page load. The default US experience does not show a consent banner.
We use this information to process registrations, send transactional messages, manage tickets and table groups, help hosts seat compatible players, run check-in, support attendees, enforce event policies, maintain security, and keep operational records.
Optional communication preferences are used to understand whether you want future event updates, game-finder features, or vendor and merchandise offers.
Aggregate analytics helps MahjPlay and authorized event organizers understand outreach, registration completion, account workflows, and which event-admin features are working. It is not used to profile individual attendees or staff.
The app uses AWS services for hosting, account sign-in, database storage, server functions, and email delivery when configured. The app uses Stripe for checkout and payment processing. Transactional email may be sent through AWS SES or an SMTP provider, depending on the deployment.
These providers receive the information needed to perform their services, such as login email addresses, payment checkout details, transactional email content, and infrastructure logs.
Event organizers and authorized staff can view the event registration, profile, waitlist, seating, check-in, contact, note, and export data needed to operate their event.
Site administrators can access account, organizer, event, access, audit, and support data for operations, troubleshooting, and permission management. Public users cannot browse other registrations.
Authorized event organizers can view aggregate analytics only for events they are permitted to administer. Site administrators can view aggregate analytics across MahjPlay events.
After signing in, attendees can view registrations linked to their account, and buyers can view purchases linked to their account. Only the buyer can see purchase totals.
We keep registration, payment, profile, access, audit, and event operation records as long as needed to run events, support attendees and organizers, satisfy financial or security needs, and improve future event operations.
You can view your events and purchases from the My events page and update your reusable player profile and login email from your profile page after signing in. To ask about your information or request a correction, contact us.
Use Analytics choices below to turn optional analytics collection off or back on for this browser without creating an account.
Analytics is currently on for this browser. You can change this choice without signing in.
Questions about this privacy page can be sent to hello@mahjplay.events.