Privacy Policy
Last updated: October 8, 2026
Who is responsible for your data
The controller of personal data in Gevent is Olexyn Systems LLC, a company organized in Wyoming, United States, whose address is that of its registered agent: doola, 30 N Gould St, STE R, Sheridan, WY 82801, United States. For any question about your data, write to hola@gevent.net.
1. Information We Collect
We collect the following information when you use Gevent:
Information you provide
- Account data: name, email, password (hashed), venue name, phone
- Event data: guest names, table numbers, dietary restrictions, confirmation statuses
- Business data: inquiry information, budgets, billing data
- Team data: names and emails of the people on your team
Automatically collected information
- Usage data: pages visited, features used, access times
- Technical data: IP address, browser type, operating system, device type
- Cookies: the essential ones for your session and your preferences, and one of our own that records the link that brought you here (section 7). We do not use advertising or third-party cookies.
2. Legal Basis for Processing
We process your data under the following legal bases:
- Consent: granted when creating your account and accepting these terms
- Contractual fulfillment: necessary to provide you with the contracted service
- Legitimate interest: to improve the service, prevent fraud and ensure security
- Legal obligation: when the law requires us to retain or share data
3. How We Use Your Information
We use your data to:
- Provide and maintain the Gevent service
- Process RSVP confirmations and send event-related notifications
- Send transactional emails (confirmations, alerts, account changes)
- Send push notifications (only with your explicit consent)
- Improve the platform based on aggregated usage patterns
- Prevent fraud and ensure service security
- Comply with legal obligations
We do not sell your personal data or your guests' data to third parties.
4. Guest Data
As a Gevent user, you are responsible for the guest data you upload to the platform. We act as data processors on your behalf. This includes:
- Names, confirmation statuses and table assignments
- Dietary restrictions and menu preferences
You are responsible for informing your guests that their data will be processed through our platform and for obtaining their consent. If you upload data of minors as guests, you guarantee that you have the corresponding parental authorization.
5. Sharing Information — Sub-processors
We share information with the following infrastructure providers:
- Supabase (database and storage) — United States
- Vercel (hosting and edge functions) — United States
- Resend (transactional email delivery) — United States
- OpenAI (AI features, when activated) — United States
- Stripe / MercadoPago (payment processing, when activated) — United States / Argentina
- Meta (WhatsApp Cloud API): the messages you exchange with us on WhatsApp and your phone number — United States
- Sentry (technical error logging, with personal data scrubbed before it leaves) — United States / EU
- Google (the map of your venue and address autocomplete) — United States
- Upstash (usage limits per IP address, no account data) — United States / EU
- Telegram (internal alerts to the gevent team: the contact details of a new inquiry and the summary of an outage) — International
- Cloudflare (the check that you are not a robot, Turnstile: your IP address and technical data from your browser) — United States / global
- SerpAPI (searching for venues that are not customers yet: each venue's public data on Google, such as name, address, phone and website) — United States
- HeyGen (introduction videos for venues that are not customers yet: the venue's name and the IP address of whoever watches the video) — United States
- Google Gemini (the belIA AI assistant, only when it uses a Google model: the text of each message and the event context) — United States
- GitHub (the monthly backup: an encrypted copy of the database and the files) — United States
We also share information within your organization: your team members can see data according to their assigned role.
The subprocessor table at the end of this policy shows what data each provider receives and where it is processed.
If you connect an AI assistant to your account (for example, Claude or ChatGPT), that assistant receives the data from your venue that you ask it for. You choose and authorize it: it does not work for Gevent and is governed by its own privacy policy.
6. Web Push and Notifications
If you enable push notifications, we store your push subscription endpoint with your explicit consent. You can disable notifications at any time from your account settings or from your browser.
7. Cookies
Gevent uses the following strictly necessary cookies:
- sb-*-auth-token: Supabase authentication token to keep your session active
- theme: your light or dark theme preference. It is not a cookie: it is stored in your browser.
- NEXT_LOCALE: your language preference
- gevent-es and gevent-es-invitado: which variety of Spanish the dashboard and the guest portal show you (the one from Argentina, Uruguay and Paraguay, or neutral Spanish), depending on the venue's country. They last one year.
We don't use third-party cookies for advertising or tracking. To know how many people visit our pages, we use a visit counter that uses no cookies and keeps no data that identifies you.
We also use one cookie of our own, gevent-origen, that records where you came from on your first visit and on which day: the campaign of the link (its utm parameters) or the site that sent you (for example, google.com), and the first page you saw. It does not store your name, your email or any identifier, and it lasts 90 days. If you then write to us, request a demo or create your account, that information is saved with your request so we know which channels work. We do not use it for visits from the European Union, the European Economic Area, the United Kingdom or Switzerland.
8. Data Security
We implement security measures that include:
- Data encryption in transit (HTTPS/TLS) and at rest
- Secure authentication with JWT tokens and refresh tokens
- Row-level security policies (RLS) in the database
- Role-restricted access (owner, admin, manager, staff, receptionist)
- Automatic daily backups
No system is 100% secure. In the event of a security breach affecting your data, we will notify you within 72 hours.
9. Data Retention
We keep your data while your account is active. To request a full copy of your data or to delete your account, write to us at hola@gevent.net.
- Copy of your data: we send it to you within 10 calendar days, as CSV files that open in any spreadsheet.
- Deletion: we delete your account and your organization's data (venues, events, guests, photos and settings) within 5 business days, and let you know when it is done.
- If you pay by card, the plan is cancelled when the account is deleted and you are not charged again.
- Backups: your data may remain for up to 90 days in backups that already existed. We only use them to restore the service after a failure; if we ever restore one, we delete your data again.
- Data required by law may be retained for the legally established period
10. Your Rights
You have the right to:
- Access: request a copy of your personal data
- Rectification: correct inaccurate or incomplete data
- Deletion: request the deletion of your data
- Portability: receive your data in a structured and readable format
- Objection: object to the processing of your data for specific purposes
To exercise these rights, contact us at hola@gevent.net. We answer access requests within 10 calendar days and correction or deletion requests within 5 business days, free of charge.
If you believe we are not respecting your rights, you can file a complaint with the data protection authority of your country, such as the AEPD in Spain or the ANPD in Brazil.
Argentina: the AGENCIA DE ACCESO A LA INFORMACIÓN PÚBLICA (Agency for Access to Public Information), as the Control Body of Law No. 25.326, has the power to handle the complaints and claims filed by anyone whose rights are affected by non-compliance with the rules in force on personal data protection.
11. Minors
Gevent is not directed at minors under 18 years of age. We do not intentionally collect data from minors. If you believe a minor has provided us with information, contact us so we can delete it.
12. International Transfers
Our providers process data in the United States and in other countries (see the subprocessor table). Those transfers rely on each provider's data processing agreement, with the European Union standard contractual clauses when the provider offers them.
13. Changes to this Policy
We may update this policy periodically. We will notify you of significant changes by email. The "last updated" date at the beginning of this document indicates when the last modification was made.
Subprocessors
To run Gevent we work with these providers («subprocessors»), which process personal data on our behalf. Each name links to its data processing agreement (DPA) or, if it does not publish one, to its privacy policy.
| Provider | Service | Data | Location |
|---|---|---|---|
| Vercel | Hosting + CDN + crons | Logs, IPs, request bodies | US / EU |
| Supabase | Database + Auth + Storage | Accounts, events, guests, files | US (us-west-2) |
| Stripe | Payment processing | Email, address, card details (we never store the full number) | US / EU |
| MercadoPago | Payments in Argentina, when paid that way | Name, email and payment details | Argentina |
| Resend | Transactional email | Recipient email, content, delivery and open tracking | US |
| OpenAI | AI assistant (belIA) | Prompt text and event context (not used to train models) | US |
| Google Gemini | AI assistant (belIA), only with a Google model | Message text and event context | US / global |
| Sentry | Error monitoring | Stack traces, anonymised IDs, breadcrumbs | US / EU |
| Google Workspace | Email + Calendar (support account) | The hola@gevent.net support inbox | US / global |
| Google Maps / Places | Venue map and address autocomplete | Visitor IP and the address searched | US / global |
| Upstash | Rate limiting (Redis) | IPs and tokens, short-lived and not persisted | US / EU |
| Cloudflare | Anti-robot check (Turnstile) | IP and technical browser data | US / global |
| Meta | WhatsApp Cloud API (conversations with Gevent) | Phone number and message content | US / global |
| Telegram | Internal alerts to the Gevent team | Contact details of a new inquiry, including the WhatsApp number of whoever writes; summary of a failure | International |
| SerpAPI | Searching for venues to offer them Gevent | Searches by city and category; returns public venue data | US |
| HeyGen | Introduction video for venues that are not customers yet | Venue name; IP of whoever watches the video | US |
| GitHub | Encrypted monthly backup | Copy of the database and the files, encrypted | US |
If we add a new subprocessor or change a processing location, we update this table and notify customers with active accounts by email at least 14 days in advance.
14. Contact
For privacy or data protection inquiries, contact us at hola@gevent.net.