Privacy Policy • Glue Up

Contact our office in Beijing

We're here to help. Please fill out this quick form and we'll get back to you shortly

Privacy Policy

Last Updated: February 18, 2025

Published: August 24, 2020

PLEASE CAREFULLY READ THIS PRIVACY POLICY, AS IT INCLUDES IMPORTANT INFORMATION REGARDING YOUR PERSONAL INFORMATION.

This Privacy Policy includes:

  1. When is your Personal Data collected by Glue Up and for what purpose?
  2. What is the legal basis for the collection and use of Your Personal Data by Glue Up?
  3. How is Your Personal Data shared, transferred or disclosed?
  4. How long do we keep your Personal Data?
  5. Use Of The Service By Organizers And Participants
  6. Organizer Undertakings With Respect To Personal Data
  7. Organizer’s Use Of Personal Data
  8. Email Tools
  9. Your rights
  10. How you can exercise your rights
  11. Security
  12. The Location Of Your Personal Data
  13. Changes To This Privacy Policy
  14. Minors
  15. Contacting Us
  16. Recourse and Dispute Resolution

This privacy policy (“Privacy Policy”) denotes Glue Up, formerly known as EventBank, EventBank, Inc., and all its affiliated companies, including EventBk, Inc., Eventbank Software Pte. Ltd., and, EventBK Limited (hereafter referred to as “Glue Up”, "EventBank", “we”, “us” or “our”) in the position of the controller to certain personal data. Glue Up or any of its subsidiaries or affiliates all connected to Glue Up responsible for the collection and processing of the Data and bound by this Privacy Policy. We, at Glue Up, know you (“you” or the “User”) care about how your personal information is used and shared – and we take your privacy seriously. Glue Up through this Privacy Policy adheres voluntarily to the certain principles of the General Data Protection Regulation (“GDPR”), and further supplemental provisions as outlined in the EU-U.S. Data Privacy Framework (DPF), including notice, choice, accountability for onward transfer, security, data integrity, and access. We are committed to ensuring that personal data transferred from the EU and other regions is handled in compliance with the DPF framework’s requirements or other applicable framework based on your jurisdiction.

Glue Up complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Glue Up has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union and the United Kingdom in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF. Glue Up has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this Privacy Policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. Glue Up is subject to the investigatory and enforcement powers of the Federal Trade Commission (FTC), which ensures that we comply with the requirements set forth under the EU-U.S. Data Privacy Framework (DPF). To learn more about the Data Privacy Framework (DPF) Program, and to view our certification, please visit https://www.dataprivacyframework.gov/

This Privacy Policy applies to all of your activities on our websites, services, web and mobile applications (www.glueup.com, www.paygage.us, www.eventbank.com, or on Glue Up mobile applications (including My Glue App and Glue Up Manager) (collectively, the “Service”). This Privacy Policy describes and governs our practices regarding the collection, processing and usage of information we collect from Users (“Personal Data”). Personal Data we collect from Users is used, disclosed and protected according to the internal Glue Up Data Protection Policy.

The Privacy Policy also explains how we may use your Personal Data, when (under certain circumstances) we may disclose your Personal Data and how you can access and update your Personal Data. This Privacy Policy also details the steps we have taken to secure your Data.

  1. When is your Personal Data collected by Glue Up and for what purpose?

    At Glue Up we limit the amount and type of Personal Data that we collect to what is necessary for the identified purposes.

    Although the precise details of the Personal Data collected will vary according to the specific purpose, we may typically collect the following Personal Data from or in relation to you (i.e. Users, Participants, Organizers):

     

    DataPurpose of collection

    Information about your use of the Service ("Usage Data"). It may include your IP address, geographical location, browser type and version, operating system, referral source, length of visit, page views and website navigation paths, as well as information about the timing, frequency and pattern of Service use. The source of the Usage Data is analytics tracking third party system. Usage Data also contain information on computer equipment: including hardware model, device MAC address and operating system.

    The Usage Data may be processed to operate, provide, improve, understand, customize, support, and market our Services to you.

    Information included in your personal profile on the Service ("Account Information"). It may include, but not limited to:

     

    • Your Name(s) (first name, surname, any other name)
    • Postal Address incl. country of residence
    • Telephone/Mobile Number
    • Email Address
    • Date of Birth
    • Your Transaction Data

     

    We use Account Information and some Usage Data and Cookies:

     

    • to operate and maintain the Service (including for the purposes of fixing malfunctions and testing our security systems);
    • to provide you with the features, functions and benefits of the Service;
    • to enhance, improve and further develop the Service (including creating new features or functions, refining the user experience, and increasing Service technical performance);
    • to provide you with notices related to your use of the Service;
    • to provide you with promotional and marketing emails (you can opt-out of receiving certain types of promotional and marketing emails – but in such case you may not receive the full benefit of the Service; opting-out can be done under Settings when you are logged in to your Service account);
    • to help personalize the Service experience for you (including remembering your information so you will not have to enter it each time you use the Service);
    • to show you ads for our products that we think may interest you;
    • for AI features, to improve upon LLM’s that we utilize;
    • to meet our legal obligations, requests for information by the competent public bodies and judicial authorities

     

    Information contained in any enquiry you submit to us regarding Service or to access your Personal Data ("Enquiry Data").

    The Enquiry Data may be processed for the purposes of offering, marketing and selling relevant Service to you or to respond to requests for information as listed in the section above.

    Information relating to transactions, including purchases and delivery of services that you enter into through the Service ("Transaction Data"). The Transaction Data may include your contact details, the card details provided and the transaction details.

    The Transaction Data may be processed for the purpose of supplying the Service, allowing to manage the Service and keeping proper records of those transactions.

    Information that you provide to us, through the Service, for the purpose of subscribing to our email notifications and/or newsletters ("Notification Data").

    The Notification Data may be processed for the purposes of sending you the relevant notifications and/or newsletters.

    Information contained in or relating to any communication through the Service ("Correspondence Data"). The Correspondence Data may include, but is not limited to, the communication content and metadata associated with the communication and eventually your response.

    The Correspondence Data may be processed for the purposes of communicating with you and record-keeping.

    Automated decision-making

    The existence of automated decision-making, including profiling. This means a decision based solely on automated profiling which produces legal effects concerning the individual, and which must not be based on special categories of (i.e. sensitive) Personal Data without explicit consent or substantial public interest with safeguards. Meaningful information about the logic involved, as well as the significance and the envisaged consequences of the processing for the individual must also be provided.

    We do not use automated decision-making which produces legal effects or similarly significant effects.

    We do however undertake profiling. We undertake data analytics on purchases to understand how we can improve our services to enhance customer interaction with us. We also use web analytics on our Sites which affects website visitors.

    We do not base profiling on special categories of Personal Data, that is Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation.

    We may also transfer small files to your browser or device (“Cookies”) that allow us to collect certain information. We also use third-party services to collect usage information to better understand and improve the user experience. Usage information collected using third-party services is stored on the servers of the third-party service providers.

    Cookies are used as the essential tool for the Service to function properly. Under cookie consent cookies may be used to advertise or market directly to you.

     

    We may also contract with third-party advertising networks that collect IP addresses and other information from web beacons on our websites, from emails and on third-party websites mainly via Cookies collection.

    Advertising networks may follow your online activities over time and across different websites or other online services by collecting device and usage data through automated means through the use of Cookies. These technologies may recognize you across the different devices you use, such as a desktop or laptop computer, smartphone or tablet. Third parties use this information to provide advertisements about products and services tailored to your interests. You may see their advertisements on other websites or mobile applications on any of your devices. This process also helps us manage and track the effectiveness of our marketing efforts.

  2. How is Your Personal Data shared, transferred or disclosed?

    With WhomProtection
    • Group companies and affiliates. When you provide Personal Data to us, we may use that information to provide Services to you as requested. We may need to share your information with affiliated and business group companies to help operate, provide, improve, understand, customize, support, and market our Services. We also share information to fight spam, threats, abuse, or infringement activities and promote safety and security across the Service. We will only share necessary Personal Data (for example, in order to facilitate your use of the products or services of our affiliate with your Glue Up or EventBank account, we will share your account information as necessary with such affiliate), and if we intend to share your Sensitive Personal Data, or if the affiliate changes the purpose of using and processing your Personal Data, we will obtain your authorization and consent again. (“Sensitive Personal Data”) includes, without limitation, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, personal biometric information, genetic data, bank account numbers, financial information, transaction information, and personal information of children age 14 and under.
    • Whenever we share or transfer data to group companies or affiliates, we require them to use your data in accordance with this Privacy Policy, in particular to ensure protection via implementation of appropriate technical and organisational measures.
    • All Group companies and affiliates adhere to this Privacy Policy principles.
    • Authorized Third-Party Service Providers. We work with third-party service providers to help us operate, provide, improve, understand, customize, secure, support, and market our Service to you.
    • When we share information with third-party service providers to perform support services for us, they may access your Personal Data only for the purposes of performing those support services (in accordance with our guidelines) and must keep your Personal Data secure.
    • We have applicable agreements negotiated with such Third-Party Service Providers to secure your Personal Data to ensure protection via implementation of appropriate technical and organisational measures.
    • Authorities and Insurance companies. In addition to the specific disclosures of information set out in the Privacy Policy, we may also have to disclose your information where such disclosure is necessary to protect your vital interests or the vital interests of another person, exercise or defence of legal claims, whether in court proceedings or in an administrative or out-of-court procedure or in order to meet national security or law enforcement compliance.
    • When we share information with the authorities, they may access your Personal Data only on legitimate grounds and for the aforementioned purposes.

     

    We may anonymize your Personal Data so that you are not individually identified and provide that information to our partners. We may also provide aggregate usage information to our partners, who may use such information to understand how often and in what ways people use the Service, so that they, too, can provide you with an optimal online experience. However, we will never disclose aggregate information to any third party in a manner that would identify you personally, as an individual.

    AI Feature

    Our third-party LLM providers may receive details about your interactions with our AI Features (including the contents of your chats, upvotes, etc.) to provide and generally improve their services, which they may process in their legitimate business interests. Your Services user account information (e.g., username and email) is not shared with any third-party LLMs or developers. Third-party developers that create AI Features using APIs may view and store your chats on their servers in order to train their models.

    Keep in mind that any information you provide to the AI Features will be shared with third-party LLM providers and developers powering the bots, and there is no need to share Sensitive Personal Data with the bots.

    Other transfers

    Except for the purposes described above, we will not transfer your Personal Data to any company, organization or individual, except in the following circumstances:

    • we may transfer your Personal Data to other parties with your explicit consent; or
    • in case of any acquisition, merger, insolvency or liquidation of Glue Up or EventBank, if the transfer of Personal Data is involved, we will require the new company, organization or individual in possession of your Personal Data to continue to be bound by this Privacy Policy, or we will require such company, organization or individual to obtain your authorization and consent for any use of your Personal Data.
    • In the event that we transfer personal data to third parties, Glue Up remains liable for any violations of the EU-U.S. Data Privacy Framework (DPF) Principles by those third parties. We ensure that third-party recipients adhere to the same data protection standards that we follow under the DPF.

     

  3. How long do we keep your Personal Data?

    We only keep your Personal Data for as long as is necessary to satisfy the specified purposes and ongoing Service, providing that no legal requirements exist to the contrary, such as in the case of retention periods required by trade or tax regulations, or to resolve disputes.

    If you wish to manage, change, limit, or delete your data, please follow the instruction in Section 9.

    If you have an account with us, we will typically retain your Personal Data for a period of 90 days after you have requested that your account is closed, or for up to seven years after your account becomes inactive but is not closed.

  4. Use Of The Service By Organizers And Participants

    The Service is used by event organizers, companies and other organizations (“Organizers”) to manage events, manage memberships, conduct e-mail campaigns, manage financial matters and interface with Customer Relationship Manager (“CRM”) systems; and by event participants or members as the case maybe (“Participants”,“Users”, or “Attendees”) to access event information, membership services, purchase tickets and for other purposes within the scope of the Service.

  5. Organizer Undertakings With Respect To Personal Data

    Each Organizer represents and warrants that its use of the Service, and the collection and use of any Personal Data collected in connection with the Service, will comply with all applicable laws and regulations (including with respect to privacy, cyber security and data protection).

    Each Organizer further agrees that it is responsible for all its activity in connection with the Service. Each Organizers shall defend, indemnify, and hold harmless Glue Up, its affiliates and subsidiaries, and each of Glue Up’s employees, contractors, directors, suppliers and representatives from all liabilities, claims, expenses, and damages (whether direct, indirect, incidental, consequential or otherwise), including reasonable attorneys’ fees, that arise from or in connection with (i) the Organizer’s use or misuse of the Service; (ii) the Organizer’s access to any part of the Service; (iii) the Organizer’s content and/or links; (iv) the Organizer’s dispute(s) with any third party(ies); (v) the Organizer’s violation of this Privacy Policy and any agreements with Glue Up or EventBank; and (vi) the Organizer’s violation of any applicable law.

  6. Organizer’s Use Of Personal Data

    In conjunction with Organizer’s use of the Service, Organizer may, through its own channels, collect additional information from you including but not limited to your name, email address, phone number, physical address, credit/payment card numbers using their own billing and payment technologies with and expiration dates, credit card security codes and your birthday. All the information collected by Organizer shall be referred to herein as (“Organizer Collected Personal Data”) and should be distinguished from Personal Data collected by Glue Up or EventBank. While Organizer Collected Personal Data is stored by Glue Up or EventBank in conjunction with Organizer’s use of the Service, Glue Up nor EventBank does not access or use Organizer Collected Personal Data, except to the extent necessary to enable you and Organizer to use the various features of the Service. Organizer Collected Personal Data will be subject to the Organizer’s own privacy policies and any applicable laws.

  7. Email Tools

    We allow Organizers to use our email tools to contact their consumers for the Organizers’ events, so you may receive emails from our system that originate with such Organizers and that we send on their behalf. If you registered for an event on the Service, your email address is available to that Organizer. However, Organizers may also import email addresses they have from external sources and send communications through the Service to those email addresses, and we will deliver those communications to those email addresses on the Organizer's behalf. You can opt-out of receiving certain types of promotional and marketing emails – but in such case you may not receive the full benefit of the Service. Opting-out can be done under the Subscription function following the instruction. Organizers are responsible for following all applicable laws and regulations around SPAM and gaining your consent for emails utilizing email tools. Please contact Organizers directly to remove your contact information from any email lists utilized by Email Tools.

  8. Your rights

    As a User, you have the following rights:

    • the right to request access to personal data relating to You from us under the conditions set out in Article 15 GDPR;
    • the right to withdraw your consent to the processing of personal data processed by us on the basis of Your consent at any time under the conditions set out in Article 7 GDPR;
    • the right to request correction of personal data under the conditions set out in Article 16 GDPR, restriction of processing of personal data under the conditions set out in Article 18 GDPR or erasure of data under the conditions set out in Article 17 GDPR;
    • the right to raise an objection to the processing of personal data concerning him/her on the basis of Article 21 GDPR;
    • the right to data transfer to another administrator under the conditions set out in Article 20 GDPR;
    • the right not to be subject to any decision based solely on automated processing, including profiling under the conditions set out in Article 22 GDPR. No automated individual decision-making takes place in our processing of personal data, even on the basis of profiling, i.e. without human intervention;
    • the right to obtain information about a breach of security of Your personal data under the conditions set out in Article 34 GDPR;
    • the right to submit a complaint with DPA and under the conditions set out in Article 77 GDPR if You suspect that the processing of Your personal data violates the obligations set out in the GDPR.
  9. How you can exercise your rights

    Under the GDPR or other applicable privacy laws, you have the right to access, rectify, port, and erase your information, as well as the right to restrict and object to certain processing of your information, unless the processing is based on compelling legitimate grounds or is needed for legal reasons.

    Subject to the limitations of applicable laws, where processing Personal Data is necessary for entering into or performing our obligations under a contract with you or is processed with your consent, you may request that your Personal Data be transferred to you or another designated party (where technically feasible).

    Where we use your data for direct marketing, you may always object and opt out of future marketing notifications using the unsubscribe link in such communications or via email.

    To the extent you have authorized us to collect and process your Personal Data, you may withdraw that authorization by deleting information, turning off device functions, or changing privacy settings on our website or in our software. Please note that some parts of the Service may not function properly if you remove our authorization to collect your Personal Data.

    For any Personal Data that you have authorized the Organizers directly and not Glue up (even indirectly), you should contact the Organizers to withdraw such authorization.

    Although certain Personal Data may still be retained to the extent necessary to fulfil our legitimate business needs, comply with any applicable law and regulation, resolve disputes, and enforce our contracts.

    To exercise your rights in all other cases, please contact us. Our contact details can be found at the final part of this Privacy Policy.

  10. Security

    We take various precautions to protect your Personal Data from loss, misappropriation and misuse, and from being accessed, disclosed, modified or destroyed without permission. In order to ensure the safety of your Personal Data, we have established strict information security provisions and procedures to protect your Personal Data.

    In the event of any Personal Data security breach, we will, in accordance with the requirements of applicable laws and in all cases within 30 days, notify you of the basic information and possible consequences of such security breach, actions we have taken or will take in response to the breach, suggestions on how you may prevent and reduce risks on your own, and actions we will take on your behalf. We will notify you of the relevant information through email, letter, phone, or push notification, or by publishing an announcement to www.glueup.com. Any such notice will be issued in compliance with all applicable laws.

    Our multi-layered approach encompasses network security, data encryption, access control, and organizational policies designed to meet industry standards and best practices. Under this scope, the various methods we use to safeguard your Data include:

    Network Security

    We leverage Cloudflare's enterprise-grade protection services for both Distributed Denial-of-Service (DDoS) mitigation and Web Application Firewall (WAF) capabilities. This robust solution filters malicious traffic, prevents unauthorized access attempts, and helps maintain service availability even during attack scenarios.

    Data Encryption

    We implement industry-standard encryption protocols to protect information:

    Data at Rest: All stored information is secured using AES-256 encryption, ensuring that sensitive data remains protected within our systems.

    Data in Transit: We employ TLS 1.2 protocols to encrypt all data transmissions between your devices and our servers, preventing interception during network transfer.

    Comprehensive Monitoring

    Our Security Information and Event Management (SIEM) solution provides real-time monitoring and analysis of system activities. All security logs are:

    Continuously monitored for suspicious patterns Securely stored according to our data retention policies Protected against unauthorized access and tampering

    Access Control Management

    We enforce strict access control measures throughout our systems:

    Multi-Factor Authentication (MFA): Implemented for both internal staff and external users where applicable, adding an essential layer of security beyond passwords. Role-Based Access Control: A formal protocol governs the assignment, periodic review, and timely revocation of access rights, ensuring the principle of least privilege is maintained.

    Organizational Security Measures

    We foster a security-conscious culture through:

    Regular Training: Security awareness education is conducted annually at minimum, covering critical topics such as data handling procedures, threat identification, and secure remote work practices. Device and Remote Work Policies: Comprehensive guidelines govern the secure use of personal devices and establish protocols for remote work environments.

    Physical Infrastructure Security

    Our server infrastructure on AWS data centers reside in facilities equipped with:

    24/7 video surveillance systems Advanced alarm and intrusion detection systems Strict access controls permitting entry only to authorized personnel

    Payment Processing Security

    We prioritize the security of financial transactions by:

    Integrating exclusively with PCI-certified payment gateways Ensuring no credit card information is stored on our servers Maintaining secure transmission channels that bypass our infrastructure for payment data

    Business Continuity Planning

    To ensure operational resilience, we:

    Perform daily data backups Maintain secure backup repositories in separate locations Follow established recovery procedures to minimize service disruption in the event of an incident
  11. The Location Of Your Personal Data

    If you are using the Service through glueup.com, Personal Data collected and generated within the United States of America (“USA”) will be primarily stored at hosting facilities located in the USA.

    These facilities are either operated by Glue Up or our third-party providers. By using the Service, you are consenting to have this data stored, transferred and processed according to this Privacy Policy.

  12. Changes To This Privacy Policy

    This Privacy Policy was last updated on the date set forth at the top of this Privacy Policy. We will alert you to any future updates to this Privacy Policy by placing a notice on www.glueup.com, by sending you an email, by notifying you when you logon to the Service, and/or by some other means. We will also edit the date at the top of this policy to reflect the date of the changes. Please note that if you’ve opted not to receive legal notice emails from us (or you haven’t provided us with your email address), our legal notices (including this Privacy Policy) will still govern your use of the Service, and you are still responsible for reading and understanding them. Use of Personal Data we collect is subject to the Privacy Policy in effect at the time such Personal Data is collected. If you use the Service after any updated Privacy Policy has been posted, that means that you agree to all the changes made with respect to all Personal Data, whether collected previously or in the future.

  13. Minors

    We do not knowingly collect or solicit personal information from anyone under the age of 14. If you are under 14, please do not attempt to register for the Service or send any personal information about yourself to us. If we learn that we have collected personal information from a child under 14, we will delete that information as quickly as possible. If you believe that a child under 14 may have provided us with personal information, please contact us at support@glueup.com.

  14. Contacting Us

    If you have any questions or concerns regarding our privacy policies or to exercise your rights, please send us a detailed message by email to support@glueup.com or by mail to Glue Up, 1600 Tysons Blvd, Suite 400, McLean VA 22102, USA

  15. Recourse and Dispute Resolution

    If you have a complaint about how we handle your personal data, you can contact our designated privacy team as set forth above. If we are unable to resolve the issue, you have the right to contact the relevant local data protection authority in your jurisdiction. These authorities are responsible for enforcing data protection rights, and they can assist in resolving complaints regarding data handling.

    In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Glue Up commits to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities (DPAs) and the UK Information Commissioner’s Office (ICO) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) with regard to unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF. Under the EU-U.S. Data Privacy Framework (DPF), individuals have the right to invoke binding arbitration to resolve disputes regarding data handling, as set forth in Annex I of the DPF Principles. If an individual wishes to initiate binding arbitration, they must deliver notice to us and follow the procedures outlined in Annex I.

    In addition, you have the right to lodge a complaint with the supervisory authority. The competent supervisory authority is the supervisory authority of the country of your residence or the registered office of the Glue Up subsidiary.

    • For the European Union (EU): You can contact the European Data Protection Board (EDPB) or the relevant national Data Protection Authority (DPA) in your country of residence.
    • For the United Kingdom (UK): You can contact the Information Commissioner’s Office (ICO).
    • For Switzerland: You can contact the Swiss Federal Data Protection and Information Commissioner (FDPIC).
    • For California (USA): You can contact the California Attorney General’s Office for issues related to the California Consumer Privacy Act (CCPA)
    • If you are located in any other jurisdiction with relevant data protection laws, you can contact the relevant data protection authority in that region.