Privacy
Privacy Policy
Getvnt LLC
Set out in 7 parts and 21 numbered clauses. Every section number is a link of its own, so a single line of this policy can be cited without quoting the whole page.
- Scope
- Getvnt.com, its subdomains, and the schedules it serves on their owners' own domains § 01
- Erasure
- Final and irreversible § 15
- Privacy contact
- privacy@getvnt.com § 21
- Last updated
- October 4, 2026 § 20
I Who we are and what this covers
Who We Are and What This Covers
This policy explains how Getvnt LLC ("Getvnt", "we") handles personal data on Getvnt.com, its subdomains, and the schedules it serves on their owners' own domains. PII (Personally Identifiable Information) means anything that identifies you, directly or together with other details.
For the data of the people who create accounts and visit the site, we decide what is collected and why, so we are its controller. The details an organizer collects through their schedule are different: the people who buy tickets, RSVP, book an appointment, follow, or sign up for its emails are that organizer's customers and audience. The organizer is the controller of those details, and we process them on the organizer's behalf to run the service. Questions about them are best put to the organizer; we help organizers answer them, and you can always write to us.
A selfhosted Getvnt is run by whoever installed it, on their own servers. This policy does not cover it, and we have no access to it.
Security Procedures & Encryption
We implement technical safeguards to protect your data from unauthorized access. All data transmitted between our systems and users is encrypted using industry-standard encryption protocols (HTTPS/TLS). Passwords are stored only as one-way hashes, and the access tokens and credentials of the services you connect are encrypted at rest. Access to user data is restricted through authentication mechanisms and role-based access controls, and our administrators must use two-factor authentication to reach the admin tools.
Data obtained through Google APIs is handled in accordance with Google's policies. It is used only for the features you asked for, is never sold or used for advertising, and is shared only with the service providers in clause 10 as needed to run them. When you revoke access we delete the tokens and our sync records (clause 08); events already copied into your schedule stay there until you delete them.
II What we collect and why
What We Collect
We collect the following personal information:
- Your account: your name and email address, your password (stored only as a one-way hash), your language and timezone, and, if you add them, a profile photo and a phone number. If you sign in with Google or Facebook, the name, email address and account ID that service shares, and with Google your profile photo.
- What you publish: your schedules and events, with their descriptions, images, venues and addresses. For a performer or venue page an organizer creates while listing an event: the name, and any email address or phone number the organizer enters, which is never shown in full.
- Buying, booking and RSVPs: the name, email address, and phone number if the organizer asks for one, answers to the organizer's questions, what was bought or booked, and whether it was paid. Card details are entered with the payment provider and never reach us; for a ticket paid in installments we keep the card type and its last four digits.
- Following and email lists: which schedules you follow. For a schedule's email sign-up: the address and name, the page language, the IP address it was entered from and the time it was confirmed, which are the record of your consent. For updates about a single event, asked for without an account: the email address you enter, the IP address it came from, and the language of the page. Schedule newsletters record whether each one was opened and which links were clicked.
- What you send us: support chat messages, with the page you wrote from and your country; and comments, photos and videos you post to events.
- Paid plans: billing is handled by Stripe, and we keep the card type, its last four digits, and the history of your plan.
- How you found us: when you create an account, the page you first landed on, the site that sent you and any campaign tags, if you allowed marketing cookies or signed up in the same visit.
- Security records: while you are signed in, your session with its IP address and browser; and a log of sensitive actions on your account with the IP address and browser, kept for 90 days.
- Visit statistics: your country, worked out from your IP address, which itself is not stored. If you accept analytics cookies while signed in: the pages you view, and those you viewed in this browser just before signing in, kept for about one hour after your last activity (see "Analytics & Cookies").
- Connected services: if you connect a calendar, the access tokens Google or Microsoft issue, stored encrypted, and which events are synced. If you turn on push notifications, the identifier the push service gives your browser. On Enterprise schedules, WhatsApp messages sent to the schedule's number to add events, with their images.
An address left for event updates ("Tell me when tickets go on sale" or "Tell me if anything changes") belongs to that one event and date. It does not create an account and is not a subscription to the schedule. It is used to email you about that event: when its tickets go on sale, a reminder shortly before it starts, a notice if it is cancelled, and any notice the organizer chooses to send if its date or venue changes. Every one of those emails has an unsubscribe link, and unsubscribing deletes the address. It is also deleted along with the event, and 30 days after the event at the latest.
A page an organizer creates for a performer or venue that is not on Getvnt shows the name and the dates listed for it, says that it has not been claimed, and stays out of search engines until it is. If the organizer asks us to, we send the email address or phone number they entered an invitation to claim the page. Claiming it means signing in with that same address or number.
Why We Use It, and on What Basis
The law asks us to name a reason for each use of your data. These are ours:
| What we do | Basis |
|---|---|
| Run your account and the features you use; sell, deliver and check in tickets; send receipts, reminders and the notices a booking needs | Contract |
| Keep sales records for organizers and for tax | Contract, and legal obligation |
| Keep the service secure, stop fraud and abuse, fix errors, keep the security log | Legitimate interests |
| Count visits as daily totals, and the anonymous version of our live view | Legitimate interests |
| Google Analytics and the identified live view | Your consent (analytics cookies) |
| Record the page or site that brought you, when you create an account or buy in the same visit | Legitimate interests |
| Campaign attribution kept across visits, the Meta Pixel and Conversions API, ads, and maps, videos and booking widgets from other sites | Your consent (marketing cookies), or your click on that one item |
| Push notifications | Your consent (your browser's permission) |
| Send account holders product news, tips and schedule digests | Legitimate interests, with a way to say no on the sign-up page and in every email |
| A schedule's newsletters and email updates | The organizer's basis, which is normally your consent: a confirmed sign-up, a Follow, or the unticked box at checkout |
| AI features you use, and translations of what organizers publish | Contract |
Where we rely on legitimate interests you can object, and where we rely on consent you can withdraw it at any time (clause 16). No decision about you is made by automated means alone.
AI Features
Some features send content to an AI provider to do their job: reading an event from text or a flyer image that someone pastes or uploads, including events visitors submit to a schedule that accepts submissions; translating a schedule's and its events' text into other languages; writing event descriptions and email text when asked to; and generating images. A provider receives only what the feature needs, such as the text or the image being read, and never your password or payment details. Translations are published as they come back, and an event sent by WhatsApp message is created straight away; everything else the provider returns is shown to be checked and edited before it is published.
What Schedule Owners Can See
When you follow a schedule, sign up for its emails, buy a ticket, RSVP, book with it, or submit content (such as a comment, photo or video) to its events, the schedule owner can see your name and email address so they can keep you informed and reach out if needed. If you open one of its newsletters, the owner can see that you did and which links you clicked. Owners can export their sales records to keep their own books. We never sell any of it. You can stop following a schedule at any time from your "Following" page, and leave its email list from any of its emails.
Signing up for a schedule's email updates works the same way: the schedule owner sees the address you enter, and confirming the link we send also sets up an account for you that follows the schedule. Submitting an event to a curator's schedule makes you a follower too, as the submission form says, and so does listing another schedule's venue or performer on an event you create, so it appears in your lists. Buying a ticket, RSVPing, or posting a comment, photo or video does not make you a follower.
III Calendar data
Use of Google and Outlook Calendar Data
Users must explicitly authorize access to their Google Calendar or Microsoft Outlook calendar through that provider's OAuth authorization process. We access calendar data solely to provide and improve the core functionality of our services, including:
- Viewing, creating, updating, or deleting calendar events as requested by the user
- Synchronizing events between the user's calendar and Getvnt
- Sending notifications and reminders related to calendar events
We do not use calendar data for advertising, marketing, or profiling purposes.
Calendar Data Storage & Retention
The access tokens are stored encrypted. If you disconnect a calendar in Settings, we stop syncing at once and delete the tokens and our record of which events are synced; for Google we also ask Google to revoke our access. If you remove our access in your Google Account or Microsoft account settings instead, we notice the next time we use the connection, which for a calendar we sync from is usually within a couple of hours. For Google we then delete the same things. For Outlook we delete the tokens and stop syncing, but keep the record of which events are synced, because Microsoft reports a password change the same way and reconnecting should not copy every event again; that record goes when you disconnect in Settings or delete your account. Events already copied into your schedule stay there as your events until you delete them.
Google Calendar Limited Use Compliance
Our use of Google Calendar data complies with the Google API Services User Data Policy, including the Limited Use requirements. We only access, use, store, and share Google Calendar data as permitted by these policies and only for the features and services explicitly requested by the user.
IV Who processes it, and where
Service Providers
Per GDPR requirements, we disclose the service providers that may process your data to operate our system. Each one receives only what its job needs, and none of them may use it for anything else:
| Vendor | Purpose |
|---|---|
| DigitalOcean | Hosting, database and file storage, in New York, United States. Everything described in this policy is stored here. |
| Cloudflare | Content delivery and security for every page, which means it sees every visitor's IP address; and the bot check on the sign-up, sign-in, password reset, checkout, booking, gift card and contact forms. |
| Sentry | Error reports. When something breaks: the address of the page or request, with ticket, reset and unsubscribe secrets removed and email addresses masked, your browser, the IP address it connects from, and the error. Never what you typed into a form. |
| Google Apps | Email and productivity services |
| SendGrid/Twilio | Email delivery |
| Stripe | Payment processing: paid plans and Boost, and ticket sales on schedules whose owner has connected Stripe, where Stripe receives the buyer's name and email address. Card details are entered with Stripe and never reach us. |
| PayPal | Payment processing, on schedules whose owner has connected a PayPal account |
| Payfast | Payment processing, on schedules whose owner has connected a Payfast account |
| Invoice Ninja | Invoicing, on schedules whose owner has connected Invoice Ninja: the buyer's name, email address and what they bought. |
| Sign-in with Google, and calendar sync, only when you connect your calendar (clauses 07 to 09). | |
| YouTube | Videos added to schedules and events. On public pages they load only when you press play or allow marketing cookies, and their thumbnails are fetched by us, not by your browser. |
| Stay22 | Accommodation search, on event pages where the schedule has enabled the accommodation map, and only once the map has been loaded |
When a schedule owner connects their own payment account, calendar or email server, the data needed for that runs through the service they chose, under their agreement with it.
Where Your Data Is Processed
Getvnt is run from the United States, and the service and its data are hosted there. Most of the providers above are based there too. If you use the service from the European Economic Area, the United Kingdom or Switzerland, your data is therefore transferred to the United States. Write to privacy@getvnt.com for a copy of the safeguards that apply to those transfers.
V Cookies, analytics and your choice
VI Keeping, deleting and your rights
How Long We Keep It
| Data | Kept |
|---|---|
| Your account, and the schedules and events you publish | Until you delete them, or your account |
| Sales, bookings and RSVPs | As long as the organizer keeps them. When an organizer deletes one, the buyer's name, email, phone and answers are removed 30 days later; the amounts stay in their books. |
| Email sign-ups that were never confirmed | 30 days after the last confirmation email |
| Confirmed sign-ups and follows | Until you leave, or delete your account |
| A schedule's newsletters: who they were sent to, and opens and clicks | As long as the schedule keeps its newsletters |
| The list of addresses that unsubscribed | Kept, so the unsubscribe keeps working |
| Interest lists for an event | Until you unsubscribe, the event is deleted, or 30 days after the event |
| Waitlists for an event | Until the organizer removes you, the event is deleted, or 30 days after the event |
| Support chats started without an account | 12 months after the last message |
| Live view records | About an hour after your last activity |
| Sessions | 24 hours after your last request |
| Security log | 90 days. For records of plan changes, schedule claims and connected payment or calendar accounts, which are kept, the IP address and browser are removed after 90 days. |
| Background tasks that failed, which can contain an email address | 30 days |
| Exports you download | 7 days |
| Records of webhooks sent to organizers' systems | 30 days |
| Visit statistics | Kept as daily totals, which contain nothing about you |
Error reports, server logs and database backups are kept for limited periods, by us and by our providers, and then deleted or overwritten.
Deleting Your Account
To permanently delete your account and all associated data:
- Log in to your account
- Click "Settings" in the main menu
- Scroll down to find the "Delete Account" option
- Click "Delete Account" to permanently remove your data
Deleting your account removes it at once, together with the schedules you own and their events, your images and other uploads, the comments, photos and videos you posted while signed in (and your email address on any you posted without signing in), your follows and email sign-ups, any interest list or waitlist entry under your address, your support chats, your sessions on every device, and your calendar connections, whose access we ask Google to revoke. The above method of data purge is final and irreversible.
Some records stay, because they are other people's or because we need them. A ticket, booking or gift card you bought stays in the organizer's records under the name and email you used, because it is their record of a sale; ask the organizer to remove your details. An event or newsletter you created for a schedule someone else owns stays with that schedule. A schedule keeps its record of the newsletters it sent you, including whether you opened them, and any mailing list an organizer imported your address into. If you unsubscribed from a schedule's emails, that opt-out is kept so the schedule cannot email you again. The security log keeps its entries for the account, with the IP address and browser, for up to 90 days, no longer linked to the account; records of plan changes, schedule claims and connected payment and calendar accounts are kept after that, without the IP address and browser.
If you left your email address to hear about an event, unsubscribing from any email about it deletes the address. If an organizer created a page in your name, choose "This is not me" on it. You sign in or create an account first, so we know who is asking: if the verified email address or phone number on that account matches the one on the page, the page comes down straight away, and otherwise your request is recorded for review.
Your Rights
Wherever you are, you can ask us to:
- Give you a copy of your data. "Download my data" in Settings emails you a link to a file with the personal data held about your account and email address, in a format other services can read. Your schedules' own content and images are in each schedule's backup.
- Correct it. Most of it you can change yourself in Settings.
- Delete it (clause 15), or restrict what we do with it while a question about it is settled.
- Stop a use based on our legitimate interests, including product email (clause 17).
- Withdraw consent you gave, such as for cookies, at any time, without affecting what was done before.
Write to privacy@getvnt.com for anything you cannot do in Settings. We answer within one month, and may ask you to confirm it is you. For details an organizer holds, such as a ticket you bought, write to the organizer, or to us and we will pass it on. If you are in the European Economic Area, the United Kingdom or Switzerland, you also have the right to complain to your data protection authority.
VII Minors, other sites, amendment and contact
Age of Consent Privacy
Our Service does not address anyone under the age of 18. We do not knowingly collect personally identifiable information from anyone under the age of 18. If you are a parent or guardian and you are aware that your child has provided us with personal data, please contact us immediately. If we become aware that we have collected personal data from anyone under the age of 18 without verification of parental consent, we will take steps to remove that information.
Links to Other Websites
Our website may contain links to other sites. Once you leave our site via these links, we have no control over that other website. We are not responsible for the protection and privacy of any information you provide on those sites, and they are not governed by this privacy policy or our terms of service.
Changes to This Privacy Policy
We may update this privacy policy from time to time to reflect changes in our practices. The date at the top of this page shows when it last changed. If we make material changes, we will notify you by email and newsletter to your registered email address. We encourage you to periodically review this page for the latest information on our privacy practices.
Communication & Resolution
If you have any questions about your privacy, data usage, or how to purge your data, please contact us at privacy@getvnt.com
End of policy
The set
The other documents
Three more instruments sit beside this one: the Terms of Service cover the agreement, the accessibility statement covers the interface, and the selfhosting terms cover running Getvnt on your own server. The documentation covers what the features named above actually do.
Anything in this policy you want explained, or think is wrong, goes to privacy@getvnt.com. A real person reads it.
Related