Skip to main content

Privacy

Privacy Policy

Getvnt LLC

Set out in 7 parts and 21 numbered clauses. Every section number is a link of its own, so a single line of this policy can be cited without quoting the whole page.

Scope
Getvnt.com, its subdomains, and the schedules it serves on their owners' own domains § 01
Erasure
Final and irreversible § 15
Privacy contact
privacy@getvnt.com § 21
Last updated
October 4, 2026 § 20

I Who we are and what this covers

§ 01

Who We Are and What This Covers

This policy explains how Getvnt LLC ("Getvnt", "we") handles personal data on Getvnt.com, its subdomains, and the schedules it serves on their owners' own domains. PII (Personally Identifiable Information) means anything that identifies you, directly or together with other details.

For the data of the people who create accounts and visit the site, we decide what is collected and why, so we are its controller. The details an organizer collects through their schedule are different: the people who buy tickets, RSVP, book an appointment, follow, or sign up for its emails are that organizer's customers and audience. The organizer is the controller of those details, and we process them on the organizer's behalf to run the service. Questions about them are best put to the organizer; we help organizers answer them, and you can always write to us.

A selfhosted Getvnt is run by whoever installed it, on their own servers. This policy does not cover it, and we have no access to it.

§ 02

Security Procedures & Encryption

We implement technical safeguards to protect your data from unauthorized access. All data transmitted between our systems and users is encrypted using industry-standard encryption protocols (HTTPS/TLS). Passwords are stored only as one-way hashes, and the access tokens and credentials of the services you connect are encrypted at rest. Access to user data is restricted through authentication mechanisms and role-based access controls, and our administrators must use two-factor authentication to reach the admin tools.

Data obtained through Google APIs is handled in accordance with Google's policies. It is used only for the features you asked for, is never sold or used for advertising, and is shared only with the service providers in clause 10 as needed to run them. When you revoke access we delete the tokens and our sync records (clause 08); events already copied into your schedule stay there until you delete them.

II What we collect and why

§ 03

What We Collect

We collect the following personal information:

  • Your account: your name and email address, your password (stored only as a one-way hash), your language and timezone, and, if you add them, a profile photo and a phone number. If you sign in with Google or Facebook, the name, email address and account ID that service shares, and with Google your profile photo.
  • What you publish: your schedules and events, with their descriptions, images, venues and addresses. For a performer or venue page an organizer creates while listing an event: the name, and any email address or phone number the organizer enters, which is never shown in full.
  • Buying, booking and RSVPs: the name, email address, and phone number if the organizer asks for one, answers to the organizer's questions, what was bought or booked, and whether it was paid. Card details are entered with the payment provider and never reach us; for a ticket paid in installments we keep the card type and its last four digits.
  • Following and email lists: which schedules you follow. For a schedule's email sign-up: the address and name, the page language, the IP address it was entered from and the time it was confirmed, which are the record of your consent. For updates about a single event, asked for without an account: the email address you enter, the IP address it came from, and the language of the page. Schedule newsletters record whether each one was opened and which links were clicked.
  • What you send us: support chat messages, with the page you wrote from and your country; and comments, photos and videos you post to events.
  • Paid plans: billing is handled by Stripe, and we keep the card type, its last four digits, and the history of your plan.
  • How you found us: when you create an account, the page you first landed on, the site that sent you and any campaign tags, if you allowed marketing cookies or signed up in the same visit.
  • Security records: while you are signed in, your session with its IP address and browser; and a log of sensitive actions on your account with the IP address and browser, kept for 90 days.
  • Visit statistics: your country, worked out from your IP address, which itself is not stored. If you accept analytics cookies while signed in: the pages you view, and those you viewed in this browser just before signing in, kept for about one hour after your last activity (see "Analytics & Cookies").
  • Connected services: if you connect a calendar, the access tokens Google or Microsoft issue, stored encrypted, and which events are synced. If you turn on push notifications, the identifier the push service gives your browser. On Enterprise schedules, WhatsApp messages sent to the schedule's number to add events, with their images.

An address left for event updates ("Tell me when tickets go on sale" or "Tell me if anything changes") belongs to that one event and date. It does not create an account and is not a subscription to the schedule. It is used to email you about that event: when its tickets go on sale, a reminder shortly before it starts, a notice if it is cancelled, and any notice the organizer chooses to send if its date or venue changes. Every one of those emails has an unsubscribe link, and unsubscribing deletes the address. It is also deleted along with the event, and 30 days after the event at the latest.

A page an organizer creates for a performer or venue that is not on Getvnt shows the name and the dates listed for it, says that it has not been claimed, and stays out of search engines until it is. If the organizer asks us to, we send the email address or phone number they entered an invitation to claim the page. Claiming it means signing in with that same address or number.

§ 05

AI Features

Some features send content to an AI provider to do their job: reading an event from text or a flyer image that someone pastes or uploads, including events visitors submit to a schedule that accepts submissions; translating a schedule's and its events' text into other languages; writing event descriptions and email text when asked to; and generating images. A provider receives only what the feature needs, such as the text or the image being read, and never your password or payment details. Translations are published as they come back, and an event sent by WhatsApp message is created straight away; everything else the provider returns is shown to be checked and edited before it is published.

§ 06

What Schedule Owners Can See

When you follow a schedule, sign up for its emails, buy a ticket, RSVP, book with it, or submit content (such as a comment, photo or video) to its events, the schedule owner can see your name and email address so they can keep you informed and reach out if needed. If you open one of its newsletters, the owner can see that you did and which links you clicked. Owners can export their sales records to keep their own books. We never sell any of it. You can stop following a schedule at any time from your "Following" page, and leave its email list from any of its emails.

Signing up for a schedule's email updates works the same way: the schedule owner sees the address you enter, and confirming the link we send also sets up an account for you that follows the schedule. Submitting an event to a curator's schedule makes you a follower too, as the submission form says, and so does listing another schedule's venue or performer on an event you create, so it appears in your lists. Buying a ticket, RSVPing, or posting a comment, photo or video does not make you a follower.

III Calendar data

§ 07

Use of Google and Outlook Calendar Data

Users must explicitly authorize access to their Google Calendar or Microsoft Outlook calendar through that provider's OAuth authorization process. We access calendar data solely to provide and improve the core functionality of our services, including:

  • Viewing, creating, updating, or deleting calendar events as requested by the user
  • Synchronizing events between the user's calendar and Getvnt
  • Sending notifications and reminders related to calendar events

We do not use calendar data for advertising, marketing, or profiling purposes.

§ 08

Calendar Data Storage & Retention

The access tokens are stored encrypted. If you disconnect a calendar in Settings, we stop syncing at once and delete the tokens and our record of which events are synced; for Google we also ask Google to revoke our access. If you remove our access in your Google Account or Microsoft account settings instead, we notice the next time we use the connection, which for a calendar we sync from is usually within a couple of hours. For Google we then delete the same things. For Outlook we delete the tokens and stop syncing, but keep the record of which events are synced, because Microsoft reports a password change the same way and reconnecting should not copy every event again; that record goes when you disconnect in Settings or delete your account. Events already copied into your schedule stay there as your events until you delete them.

§ 09

Google Calendar Limited Use Compliance

Our use of Google Calendar data complies with the Google API Services User Data Policy, including the Limited Use requirements. We only access, use, store, and share Google Calendar data as permitted by these policies and only for the features and services explicitly requested by the user.

IV Who processes it, and where

§ 10

Service Providers

Per GDPR requirements, we disclose the service providers that may process your data to operate our system. Each one receives only what its job needs, and none of them may use it for anything else:

Schedule of service providers
Vendor Purpose
DigitalOcean Hosting, database and file storage, in New York, United States. Everything described in this policy is stored here.
Cloudflare Content delivery and security for every page, which means it sees every visitor's IP address; and the bot check on the sign-up, sign-in, password reset, checkout, booking, gift card and contact forms.
Sentry Error reports. When something breaks: the address of the page or request, with ticket, reset and unsubscribe secrets removed and email addresses masked, your browser, the IP address it connects from, and the error. Never what you typed into a form.
Google Apps Email and productivity services
SendGrid/Twilio Email delivery
Stripe Payment processing: paid plans and Boost, and ticket sales on schedules whose owner has connected Stripe, where Stripe receives the buyer's name and email address. Card details are entered with Stripe and never reach us.
PayPal Payment processing, on schedules whose owner has connected a PayPal account
Payfast Payment processing, on schedules whose owner has connected a Payfast account
Invoice Ninja Invoicing, on schedules whose owner has connected Invoice Ninja: the buyer's name, email address and what they bought.
Google Sign-in with Google, and calendar sync, only when you connect your calendar (clauses 07 to 09).
YouTube Videos added to schedules and events. On public pages they load only when you press play or allow marketing cookies, and their thumbnails are fetched by us, not by your browser.
Stay22 Accommodation search, on event pages where the schedule has enabled the accommodation map, and only once the map has been loaded

When a schedule owner connects their own payment account, calendar or email server, the data needed for that runs through the service they chose, under their agreement with it.

§ 11

Where Your Data Is Processed

Getvnt is run from the United States, and the service and its data are hosted there. Most of the providers above are based there too. If you use the service from the European Economic Area, the United Kingdom or Switzerland, your data is therefore transferred to the United States. Write to privacy@getvnt.com for a copy of the safeguards that apply to those transfers.

V Cookies, analytics and your choice

§ 12

Analytics & Cookies

When you first visit, a banner asks about two kinds of optional cookies and similar storage, and nothing optional is stored, or loaded from another company, until you choose:

  • Analytics: Google Analytics 4, and the identified version of our live view (below). Google Analytics is not loaded at all until you allow this: no script and no request to Google.
  • Marketing and embedded content: campaign attribution cookies; Google Analytics' advertising features; on events whose organizer runs a Boost, the Meta Pixel, and telling Meta about a ticket you buy as a one-way hash of your email address; ads on free schedules, where they are switched on; and maps, videos and booking widgets from other sites (Google Maps, YouTube, Stay22), which set their own cookies.

"Allow all" turns on both, "Decline" neither, and "Choose" lets you pick. Your choice is kept for twelve months and then asked again. Without marketing consent, a map or a video shows a button instead, and pressing it loads that one item and nothing else. Stay22, which pays a commission on bookings made through its map, is never loaded if your browser sends Global Privacy Control.

Separately from Google, we keep our own visit statistics, and those are deliberately built so that no individual can be picked out of them. We store only daily totals: views per device type, per referring source, per country, per campaign tag. These daily totals contain no per-visitor record. To avoid counting the same person twice in a day, and to filter out bots, your IP address and browser user-agent are combined into a one-way hash using a secret key and a salt that changes every day; that hash exists only as the key of a short-lived cache entry that expires by midnight, and is never stored in a record of your visit. Because none of this reads or writes anything on your device, it needs no cookie and no consent.

We also keep a short-lived record for a live view of the site that only our administrators can see, never schedule owners. What it holds depends on your analytics choice. If you allow analytics, each page you view is recorded with the page, the referring site and campaign tag, your country (looked up from your IP address, which itself is not stored), your device type, browser and operating system, and how long the page stays open, under a one-way hash of your IP address, browser and language settings that changes every day; while you are signed in it is linked to your account, including the pages you viewed in this browser just before signing in. If you decline, do not answer, or your browser sends Global Privacy Control, each page view is still counted, but with no identifier and nothing that links it to you or to your other page views: only the page (for pages behind sign-in, just which kind of page), your country, your device type and, when you arrive from another site or a tagged link, that site and campaign tag. Either way, records are deleted about an hour after your last activity, and if you withdraw your consent, the identifiers are removed from what this browser still has on its current network and, if you are signed in when you withdraw, from your account's records.

We honor the Global Privacy Control signal: if your browser sends GPC, we treat it as declining both categories, and the banner does not appear.

Your choice is stored in a cookie named cookie_consent, with the categories you allowed and when, so one choice holds across Getvnt.com and its subdomains and our server can honor it too; your browser keeps a copy in localStorage under the same name. A schedule on its own domain asks separately. It records nothing but the choice itself, and we do not store it against any account.

Cookies and browser storage
Name What it is for, and how long it lasts
getvnt_session
Always
Keeps you signed in, holds your cart and checkout, and protects forms. 24 hours after your last request.
XSRF-TOKEN
Always
Protects forms against requests forged by other sites. As long as the session.
remember_web_*
Always
Keeps you signed in on this device. Set when you sign in or create an account; up to 400 days, or until you log out.
last_login_method
Always
Whether you last signed in with a password, Google or Facebook, to show that option first. 1 year.
browser_timezone, browser_language
Always
Sets up a new account in your timezone and language. 1 hour, on the sign-in and sign-up pages only.
cookie_consent
Always
Your choice in the cookie banner. 12 months.
__cf_bm
Always
Bot protection by Cloudflare, which may set it on any page. 30 minutes.
Stripe (__stripe_mid, __stripe_sid)
Always
Fraud prevention by the payment provider, on payment pages only. __stripe_mid 1 year, __stripe_sid 30 minutes.
OneSignal (browser storage)
Push
Only if you turn on push notifications: the identifier the push service gives this browser. Until you turn them off.
_ga, _ga_<measurement-id>
Analytics
Google Analytics: tells visits and visitors apart. Up to 2 years, and deleted when you withdraw.
es_hero, es_hero_clicked
Analytics
Session storage: which homepage headline you saw and whether you then clicked sign up. Until the tab closes.
utm_params, utm_referrer_url, utm_landing_page
Marketing
Which link, campaign or site brought you here, credited if you later create an account or buy a ticket. 30 days.
es_attribution
Marketing
The same, written by your browser for the step from our marketing pages to sign-up: the page you landed on, the site that sent you, campaign and referral tags, and the homepage headline you saw. Until the browser closes; at most 2 KB.
_fbp, _fbc
Marketing
The Meta Pixel, on the pages of Boosted events. Up to 90 days, and deleted when you withdraw.
__gads, __gpi, __eoi
Marketing
Google AdSense, on free schedules where ads are switched on. Up to 13 months, and deleted when you withdraw.
Third-party cookies
Marketing
Set by Google Maps, YouTube and Stay22 when one of them loads. Their own policies apply.

Your browser also keeps a few things for your convenience, in localStorage, which stay in your browser until you use them: your theme and accessibility settings, the calendar view you picked, unsent form drafts, your cart, and the name, email and phone you entered at checkout, so you do not have to type them again. Those details are forgotten after 30 days, or once everything in the cart has been bought. A support chat started before signing in is remembered by a random identifier.

You can withdraw consent at any time, as easily as you gave it (GDPR Article 7(3)): use "Cookie preferences" at the bottom of the page (in the app, under About in the menu), or the button in the next section. Withdrawing deletes the cookies the withdrawn category set on this site, unloads any map, video or accommodation search already on the page, and clears the attribution cookies.

VI Keeping, deleting and your rights

§ 14

How Long We Keep It

How long each kind of data is kept
Data Kept
Your account, and the schedules and events you publish Until you delete them, or your account
Sales, bookings and RSVPs As long as the organizer keeps them. When an organizer deletes one, the buyer's name, email, phone and answers are removed 30 days later; the amounts stay in their books.
Email sign-ups that were never confirmed 30 days after the last confirmation email
Confirmed sign-ups and follows Until you leave, or delete your account
A schedule's newsletters: who they were sent to, and opens and clicks As long as the schedule keeps its newsletters
The list of addresses that unsubscribed Kept, so the unsubscribe keeps working
Interest lists for an event Until you unsubscribe, the event is deleted, or 30 days after the event
Waitlists for an event Until the organizer removes you, the event is deleted, or 30 days after the event
Support chats started without an account 12 months after the last message
Live view records About an hour after your last activity
Sessions 24 hours after your last request
Security log 90 days. For records of plan changes, schedule claims and connected payment or calendar accounts, which are kept, the IP address and browser are removed after 90 days.
Background tasks that failed, which can contain an email address 30 days
Exports you download 7 days
Records of webhooks sent to organizers' systems 30 days
Visit statistics Kept as daily totals, which contain nothing about you

Error reports, server logs and database backups are kept for limited periods, by us and by our providers, and then deleted or overwritten.

§ 15

Deleting Your Account

To permanently delete your account and all associated data:

  1. Log in to your account
  2. Click "Settings" in the main menu
  3. Scroll down to find the "Delete Account" option
  4. Click "Delete Account" to permanently remove your data

Deleting your account removes it at once, together with the schedules you own and their events, your images and other uploads, the comments, photos and videos you posted while signed in (and your email address on any you posted without signing in), your follows and email sign-ups, any interest list or waitlist entry under your address, your support chats, your sessions on every device, and your calendar connections, whose access we ask Google to revoke. The above method of data purge is final and irreversible.

Some records stay, because they are other people's or because we need them. A ticket, booking or gift card you bought stays in the organizer's records under the name and email you used, because it is their record of a sale; ask the organizer to remove your details. An event or newsletter you created for a schedule someone else owns stays with that schedule. A schedule keeps its record of the newsletters it sent you, including whether you opened them, and any mailing list an organizer imported your address into. If you unsubscribed from a schedule's emails, that opt-out is kept so the schedule cannot email you again. The security log keeps its entries for the account, with the IP address and browser, for up to 90 days, no longer linked to the account; records of plan changes, schedule claims and connected payment and calendar accounts are kept after that, without the IP address and browser.

If you left your email address to hear about an event, unsubscribing from any email about it deletes the address. If an organizer created a page in your name, choose "This is not me" on it. You sign in or create an account first, so we know who is asking: if the verified email address or phone number on that account matches the one on the page, the page comes down straight away, and otherwise your request is recorded for review.

§ 16

Your Rights

Wherever you are, you can ask us to:

  • Give you a copy of your data. "Download my data" in Settings emails you a link to a file with the personal data held about your account and email address, in a format other services can read. Your schedules' own content and images are in each schedule's backup.
  • Correct it. Most of it you can change yourself in Settings.
  • Delete it (clause 15), or restrict what we do with it while a question about it is settled.
  • Stop a use based on our legitimate interests, including product email (clause 17).
  • Withdraw consent you gave, such as for cookies, at any time, without affecting what was done before.

Write to privacy@getvnt.com for anything you cannot do in Settings. We answer within one month, and may ask you to confirm it is you. For details an organizer holds, such as a ticket you bought, write to the organizer, or to us and we will pass it on. If you are in the European Economic Area, the United Kingdom or Switzerland, you also have the right to complain to your data protection authority.

§ 17

Product Email & Unsubscribing

We send account holders occasional product news, tips, and digests about their own schedules to the email address on the account. You can say no on the sign-up page, switch them off under Settings, or use the "unsubscribe" link in any of them, which your email app may also show as a button; you can also write to privacy@getvnt.com. Note that we may still send legally required notifications, and the emails your account needs, such as receipts, password resets and security notices, to your registered email.

VII Minors, other sites, amendment and contact

§ 20

Changes to This Privacy Policy

We may update this privacy policy from time to time to reflect changes in our practices. The date at the top of this page shows when it last changed. If we make material changes, we will notify you by email and newsletter to your registered email address. We encourage you to periodically review this page for the latest information on our privacy practices.

§ 21

Communication & Resolution

If you have any questions about your privacy, data usage, or how to purge your data, please contact us at privacy@getvnt.com

End of policy

Back to the top of the document

The set

The other documents

Three more instruments sit beside this one: the Terms of Service cover the agreement, the accessibility statement covers the interface, and the selfhosting terms cover running Getvnt on your own server. The documentation covers what the features named above actually do.

Anything in this policy you want explained, or think is wrong, goes to privacy@getvnt.com. A real person reads it.