This policy explains what Gathervo does with personal data in connection with Gathervo, the event platform at https://gathervo.com. It covers the website and the platform itself. It is written to be read, not
skimmed past — if anything here is unclear, ask us and we will answer in plain terms.
1. Who Is Responsible for Your Data
This matters more than anything else on the page, because it decides who you ask when
you want something changed or deleted. We act in two different capacities:
We are the controller
For your own account: the address you sign in with, your name and profile, your
security settings, your billing history, and how you use the platform. We decide what
is collected and why, and you can bring any request about it straight to us.
We are the processor
For everything an event organiser gathers through us: registrations, ticket
purchases, proposals, applications, form responses, attendance. The organiser decides
what to ask and why. We hold it and act on their instructions.
So if you registered for somebody's event and want your answers corrected or removed,
the organiser is the person to ask — they control that record, and we will act on their
instruction. If they cannot be reached, write to us and we will pass the request on and
tell you we have done so.
2. Information We Collect
a. What you give us
Name and email address
Password, stored only as a one-way hash
Phone number, if you add one
Organisation, job title, affiliation
Profile photo, if you upload one
Country, time zone and language
Files you upload to an event
Messages you send through the platform
b. What we record as you use the platform
IP address and approximate region
Browser and device type
Pages and features used, with timestamps
Sign-in attempts, successful and not
Actions taken on events you administer
Emails we sent you, and whether they were delivered
c. What we do not collect
We do not collect card numbers — those go directly to our payment processor. We do not
ask for special category data (health, beliefs, ethnicity, and so on) anywhere in the
platform. An organiser can build a form that asks for anything, including such data; if
they do, they are the controller for it and it is their responsibility to have a lawful
basis. We do not buy personal data from anyone, and we do not build advertising profiles.
d. Deleting your account
To delete your account permanently, see the account deletion policy, which sets out what is removed and what has to be kept.
3. Why We Are Allowed to Process It
Where data protection law requires us to name a legal basis, these are ours:
Performance of a contract. Running your account and the events you create or attend. Without this data there is no service to provide.
Legitimate interests. Keeping accounts secure, preventing abuse and fraud, and understanding which features are used so we can improve them. We do not pursue these where they would override your interests.
Legal obligation. Tax and accounting records for payments, and responding to lawful requests.
Consent. Optional things you switch on: non-essential cookies, marketing mail, and the assistant features that send your text to a third party. You can withdraw it at any time.
4. How We Use Information
Give you an account, and let you create, run and attend events
Confirm that an email address belongs to you, and let you reset a password
Check a second factor at sign-in, when you have turned one on
Take payments, issue invoices, and pay out money collected through the platform
Send the mail the platform exists to send: confirmations, tickets, reminders, notices from organisers
Detect and stop abuse — automated sign-ups, credential stuffing, spam through public forms
Work out which features are used, and where the platform is slow or failing
Meet our legal and tax obligations
We do not use your data to train machine-learning models, and we do not sell it or rent
it to anyone, for any purpose.
5. How We Share Information
We do not sell personal data. It is shared in four situations, and no others:
With event organisers
When you register for, buy a ticket to, apply to or submit anything to an event, the
organiser of that event sees what you submitted. That is the point of submitting it.
With the services we run on
Named individually in the next section, each with a written agreement that limits them
to acting on our instructions.
When the law requires it
In response to a valid legal request. We satisfy ourselves that a request is lawful
and no broader than it has to be, and we tell you unless we are forbidden from doing so.
If the business changes hands
In a merger or acquisition, data may transfer with it. You would be told before that
happened, and this policy would continue to apply until you were given a new one.
6. Services We Rely On
Naming these is what makes the section above meaningful. Some are only involved if the
operator of this deployment has switched the relevant feature on, or if you choose to
use it.
Service
What for
What it receives
Stripe
Card payments and payouts, processed for Gathervo
Name, email, billing country and the amount. Card numbers go straight to Stripe and never reach our servers.
Cloudflare
Bot protection on public forms (Turnstile)
IP address and a short-lived challenge token, at the moment a form is submitted.
Google
Sign in with Google, where the operator has enabled it
Your Google account identifier, email address and name — only if you choose to use that button.
OpenAI
The in-product assistant and writing help
The text of the question you ask it, and the content you ask it to help with. Nothing is sent unless you use those features.
Our email provider
Confirmation links, password resets, event mail
Recipient address and the contents of the message.
Our hosting and storage provider
Running the platform and storing uploaded files
Everything stored on the platform, at rest.
7. Payments
Payments are processed for Gathervo by Stripe. That is the name that will appear on your statement.
Card details are entered into a form served by Stripe and go straight to Stripe. They
do not pass through our servers and we never store them — we could not show you your own
card number if you asked. What we keep is the record of a payment: what was bought, how
much, when, in what currency, whether it succeeded, and the last four digits and card
brand where Stripe returns them. That record is kept for as long as tax law requires,
which is longer than we keep anything else, and it is not deleted when an account is
closed.
8. How Long We Keep Things
Event data: 5 years after the event ends
An event and everything attached to it — its agenda, registrations, tickets,
submissions, uploads and reports — is kept for 5 years after the event's end date. Before that period runs out we will write to the
event's owner, and they can either take out a subscription that keeps the event
active or export what they want to keep. If neither happens, the event and its data
are deleted. This is a deletion, not an archive: once it has happened we cannot get
the data back for you.
Your account
Kept while the account exists. Deleting it removes your profile and personal
details; see the account deletion policy for what survives and why.
Payment and invoice records
Kept for the period tax and accounting law requires, regardless of whether the
account still exists.
Security and audit logs
Sign-in attempts and administrative actions, kept for up to 12 months so an
incident can be investigated after it is noticed.
Confirmation and reset links
The tokens behind them expire in hours and are single-use. Two-factor secrets are
deleted the moment you turn the feature off.
9. Data Security
Everything travels over TLS. Passwords are stored as one-way hashes and cannot be read back, by us or anyone else.
Two-factor secrets, recovery codes and integration credentials are encrypted at rest, so a leaked database backup does not hand over the second factor with the first.
Two-factor authentication is available on every account. Turning it on is the single most effective thing you can do here.
Changing a password signs out every other session. So does issuing new recovery codes.
Public forms are rate limited per address and per network, and carry a bot check, so a stolen password list cannot be tried against them at speed.
Access to production data is limited to the people who need it to run the service.
None of this makes a system impossible to breach, and we would rather say so than
claim otherwise. What we can promise is that we do not treat security as finished.
10. Your Rights
Depending on where you live, some or all of these apply. Where we are the processor
rather than the controller — see section 1 — we will route your request to the
organiser rather than decide it ourselves.
✓Access. A copy of the personal data we hold about you.
✓Correction. Have inaccurate or incomplete data put right.
✓Deletion. Have your data erased where we have no overriding reason to keep it.
✓Portability. Receive your data in a structured, machine-readable form.
✓Restriction. Ask us to pause processing while a dispute is resolved.
✓Objection. Object to processing we carry out on the basis of legitimate interests.
✓Withdraw consent. Where we relied on consent, take it back — without affecting what came before.
✓Complain. Take a complaint to your local data protection authority at any time.
To exercise any of these, write to https://gathervo.com. We answer within 30 days, and we will not charge you or make you explain why.
11. International Transfers
The services in section 6 operate internationally, so your data may be processed
outside the country you are in, including in the United States. Where it leaves a
region whose laws restrict such transfers, we rely on the transfer mechanisms those
laws provide — standard contractual clauses, or an adequacy decision where one covers
the destination. You can ask us which applies to a particular service and we will tell
you.
12. Cookies and Local Storage
We keep this short because there is not much to it. We do not run advertising trackers.
Strictly necessary
Your session token and the identifiers that go with it. Without these you cannot stay
signed in, so they are set without asking — there is no version of the service that
works without them.
Preferences
Small things your browser remembers for you: light or dark mode, a chosen language,
which tab you had open. They never leave your browser.
Bot protection
Cloudflare Turnstile sets what it needs to tell a person from a script when you
submit a public form. It is not used to follow you around.
Analytics
Where the operator of this deployment has enabled analytics, it is asked for
separately and you can decline without losing anything.
Your browser can block or clear all of it. Blocking the strictly necessary ones will
sign you out.
13. Children’s Privacy
The platform is not intended for children under 13, or under the higher minimum age
that applies where you live. We do not knowingly collect their data. If you believe a
child has given us personal data, tell us and we will delete it.
14. Content Moderation
What you may and may not post is set out in the Terms of Service. Abusive content and abusive behaviour are removed, and accounts that produce them
are suspended.
Reporting
Anything posted through the platform can be reported to the event's organiser, and
to us if the organiser is the problem.
No automated decisions
Nothing that affects your account is decided by software alone. A person reviews a
suspension, and you can ask for that decision to be looked at again.
15. If Something Goes Wrong
If personal data is exposed in a way that is likely to put you at risk, we will notify
the relevant supervisory authority within 72 hours of becoming aware of it, and tell
affected people without undue delay. The notice will say what happened, what data was
involved, what we have done, and what you should do. Where we are the processor for an
organiser's data, we notify that organiser so they can meet the same obligation.
16. Changes to This Policy
We may update this policy. The date at the top always reflects the current version. If
a change materially affects your rights or what we do with your data, we will tell you
by email before it takes effect rather than quietly changing the page.
17. Contact Us
Questions about this policy, or a request about your data: