Privacy Policy

Last updated: September 6, 2026

1. Information We Collect

We collect the following information when you use Gevent:

Information you provide

  • Account data: name, email, password (hashed), venue name, phone
  • Event data: guest names, table numbers, dietary restrictions, confirmation statuses
  • Business data: inquiry information, budgets, billing data
  • Team data: names and emails of the people on your team
  • Gallery photos: images uploaded to the event wall (EXIF data is removed during processing)

Automatically collected information

  • Usage data: pages visited, features used, access times
  • Technical data: IP address, browser type, operating system, device type
  • Technical cookies: only the essential ones for authentication and session preferences. We do not use analytics or advertising cookies.

2. Legal Basis for Processing

We process your data under the following legal bases:

  • Consent: granted when creating your account and accepting these terms
  • Contractual fulfillment: necessary to provide you with the contracted service
  • Legitimate interest: to improve the service, prevent fraud and ensure security
  • Legal obligation: when the law requires us to retain or share data

3. How We Use Your Information

We use your data to:

  • Provide and maintain the Gevent service
  • Process RSVP confirmations and send event-related notifications
  • Send transactional emails (confirmations, alerts, account changes)
  • Send push notifications (only with your explicit consent)
  • Improve the platform based on aggregated usage patterns
  • Prevent fraud and ensure service security
  • Comply with legal obligations

We do not sell your personal data or your guests' data to third parties.

4. Guest Data

As a Gevent user, you are responsible for the guest data you upload to the platform. We act as data processors on your behalf. This includes:

  • Names, confirmation statuses and table assignments
  • Dietary restrictions and menu preferences
  • Post-event survey responses
  • Event wall messages
  • Photos uploaded to the event gallery

You are responsible for informing your guests that their data will be processed through our platform and for obtaining their consent. If you upload data of minors as guests, you guarantee that you have the corresponding parental authorization.

5. Sharing Information — Sub-processors

We share information with the following infrastructure providers:

  • Supabase (database and storage) — United States
  • Vercel (hosting and edge functions) — United States
  • Resend (transactional email delivery) — United States
  • OpenAI (AI features, when activated) — United States
  • Stripe / MercadoPago (payment processing, when activated) — United States / Argentina
  • Meta (WhatsApp Cloud API): the messages you exchange with us on WhatsApp and your phone number — United States
  • Sentry (technical error logging, with personal data scrubbed before it leaves) — United States / EU
  • Google (the map of your venue and address autocomplete) — United States
  • Upstash (usage limits per IP address, no account data) — United States / EU
  • Telegram (internal alerts to the gevent team: the contact details of a new inquiry and the summary of an outage) — International

We also share information within your organization: your team members can see data according to their assigned role.

All our providers comply with security and data protection standards. We maintain standard contractual clauses with providers in the United States to ensure data protection in international transfers.

6. Web Push and Notifications

If you enable push notifications, we store your push subscription endpoint with your explicit consent. You can disable notifications at any time from your account settings or from your browser.

7. Photo Gallery

Photos uploaded to the event gallery are processed as follows:

  • EXIF data (location, camera model, etc.) is removed during processing
  • Photos are resized and converted to WebP format for optimization
  • Photos automatically expire 30 days after the event date and are irreversibly deleted

8. Technical Cookies

Gevent uses the following strictly necessary cookies:

  • sb-*-auth-token: Supabase authentication token to keep your session active
  • theme: your light/dark theme preference
  • NEXT_LOCALE: your language preference

We do not use third-party cookies for advertising or tracking. We do not use Google Analytics or third-party tracking tools.

9. Data Security

We implement security measures that include:

  • Data encryption in transit (HTTPS/TLS) and at rest
  • Secure authentication with JWT tokens and refresh tokens
  • Row-level security policies (RLS) in the database
  • Role-restricted access (owner, admin, manager, staff, receptionist)
  • Automatic daily backups

No system is 100% secure. In the event of a security breach affecting your data, we will notify you within 72 hours.

10. Data Retention

We retain your data while your account is active. When deleting your account:

  • You have 30 days to export your data
  • After that period, your personal data is irreversibly deleted
  • Event data is anonymized or deleted according to your preference
  • Backups are purged within 90 days
  • Data required by law may be retained for the legally established period

11. Your Rights

You have the right to:

  • Access: request a copy of your personal data
  • Rectification: correct inaccurate or incomplete data
  • Deletion: request the deletion of your data
  • Portability: receive your data in a structured and readable format
  • Objection: object to the processing of your data for specific purposes

To exercise these rights, contact us at hola@gevent.pro. We will respond within 30 business days.

12. Minors

Gevent is not directed at minors under 18 years of age. We do not intentionally collect data from minors. If you believe a minor has provided us with information, contact us so we can delete it.

13. International Transfers

Your data may be processed on servers located outside Argentina (United States) through our infrastructure providers. We maintain standard contractual clauses with these providers to ensure adequate levels of data protection.

14. Changes to this Policy

We may update this policy periodically. We will notify you of significant changes by email. The "last updated" date at the beginning of this document indicates when the last modification was made.

Subprocessors

To run Gevent we work with trusted third parties ("subprocessors") that process personal data on our behalf. Each one has signed a Data Processing Agreement (DPA) with the EU standard contractual clauses for international transfers.

ProviderServiceDataLocation
VercelHosting + CDN + cronsLogs, IPs, request bodiesUS / EU
SupabaseDatabase + Auth + StorageAccounts, events, guests, filesUS (us-west-2)
StripePayment processingEmail, address, card details (we never store the full number)US / EU
ResendTransactional emailRecipient email, content, delivery and open trackingUS
OpenAIAI assistant (belIA)Prompt text and event context (not used to train models)US
SentryError monitoringStack traces, anonymised IDs, breadcrumbsUS / EU
Google WorkspaceEmail + Calendar (support account)The hola@gevent.pro support inboxUS / global
Google Maps / PlacesVenue map and address autocompleteVisitor IP and the address searchedUS / global
UpstashRate limiting (Redis)IPs and tokens, short-lived and not persistedUS / EU
MetaWhatsApp Cloud API (conversations with Gevent)Phone number and message contentUS / global
TelegramInternal alerts to the Gevent teamContact details of a new inquiry; summary of a failureInternational

If we add a new subprocessor or change a processing location, we update this table and notify customers with active accounts by email at least 14 days in advance.

15. Contact

For privacy or data protection inquiries, contact us at hola@gevent.pro.