Privacy Policy
Last Updated: February 18, 2025
Published: August 24, 2020
PLEASE CAREFULLY READ THIS PRIVACY POLICY, AS IT INCLUDES IMPORTANT INFORMATION REGARDING YOUR PERSONAL INFORMATION.
This Privacy Policy includes:
- When is your Personal Data collected by Glue Up and for what purpose?
- What is the legal basis for the collection and use of Your Personal Data by Glue Up?
- How is Your Personal Data shared, transferred or disclosed?
- How long do we keep your Personal Data?
- Use Of The Service By Organizers And Participants
- Organizer Undertakings With Respect To Personal Data
- Organizer’s Use Of Personal Data
- Email Tools
- Your rights
- How you can exercise your rights
- Security
- The Location Of Your Personal Data
- Changes To This Privacy Policy
- Minors
- Contacting Us
- Recourse and Dispute Resolution
This privacy policy (“Privacy Policy”) denotes Glue Up, formerly known as EventBank, EventBank, Inc., and all its affiliated companies, including EventBk, Inc., Eventbank Software Pte. Ltd., and, EventBK Limited (hereafter referred to as “Glue Up”, "EventBank", “we”, “us” or “our”) in the position of the controller to certain personal data. Glue Up or any of its subsidiaries or affiliates all connected to Glue Up responsible for the collection and processing of the Data and bound by this Privacy Policy. We, at Glue Up, know you (“you” or the “User”) care about how your personal information is used and shared – and we take your privacy seriously. Glue Up through this Privacy Policy adheres voluntarily to the certain principles of the General Data Protection Regulation (“GDPR”), and further supplemental provisions as outlined in the EU-U.S. Data Privacy Framework (DPF), including notice, choice, accountability for onward transfer, security, data integrity, and access. We are committed to ensuring that personal data transferred from the EU and other regions is handled in compliance with the DPF framework’s requirements or other applicable framework based on your jurisdiction.
Glue Up complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Glue Up has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union and the United Kingdom in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF. Glue Up has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this Privacy Policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. Glue Up is subject to the investigatory and enforcement powers of the Federal Trade Commission (FTC), which ensures that we comply with the requirements set forth under the EU-U.S. Data Privacy Framework (DPF). To learn more about the Data Privacy Framework (DPF) Program, and to view our certification, please visit https://www.dataprivacyframework.gov/
This Privacy Policy applies to all of your activities on our websites, services, web and mobile applications (www.glueup.com, www.paygage.us, www.eventbank.com, or on Glue Up mobile applications (including My Glue App and Glue Up Manager) (collectively, the “Service”). This Privacy Policy describes and governs our practices regarding the collection, processing and usage of information we collect from Users (“Personal Data”). Personal Data we collect from Users is used, disclosed and protected according to the internal Glue Up Data Protection Policy.
The Privacy Policy also explains how we may use your Personal Data, when (under certain circumstances) we may disclose your Personal Data and how you can access and update your Personal Data. This Privacy Policy also details the steps we have taken to secure your Data.
When is your Personal Data collected by Glue Up and for what purpose?
At Glue Up we limit the amount and type of Personal Data that we collect to what is necessary for the identified purposes.
Although the precise details of the Personal Data collected will vary according to the specific purpose, we may typically collect the following Personal Data from or in relation to you (i.e. Users, Participants, Organizers):
We may also contract with third-party advertising networks that collect IP addresses and other information from web beacons on our websites, from emails and on third-party websites mainly via Cookies collection.
Advertising networks may follow your online activities over time and across different websites or other online services by collecting device and usage data through automated means through the use of Cookies. These technologies may recognize you across the different devices you use, such as a desktop or laptop computer, smartphone or tablet. Third parties use this information to provide advertisements about products and services tailored to your interests. You may see their advertisements on other websites or mobile applications on any of your devices. This process also helps us manage and track the effectiveness of our marketing efforts.
What is the legal basis for the collection and use of Your Personal Data by Glue Up?
We collect, use, and share the data on the following legal basis:- as is necessary to fulfil our contractual terms;
- as consistent with your consent, which you can revoke at any time;
- as necessary for our legitimate interests, including our interest to operate our business in accordance with legitimate commercial practice, for example to provide Service and issue direct marketing; to maintain accounts and records; to prevent and address fraud, unauthorised use of the Glue Up Service, violations of our terms and policies, or other harmful or illegal activity; to protect ourselves (including our rights, property or Service), our Users or Organizers, including as part of investigations or regulatory inquiries; to secure systems and fight spam, threats, abuse, or infringement activities and promote safety and security across the Glue Up Services; internal group administration and administration of other relationships;
- as necessary to comply with our legal obligations; and
- to protect your interests, or those of others; and the public interest.
Aggregated Personal Data
In an ongoing effort to understand and serve our Users better, we often conduct research on our customers’ demographics, interests and behaviour based on Personal Data that we have collected. This research is typically conducted on an aggregate basis only that does not identify you. Once Personal Data is in an aggregated form, for purposes of this Privacy Policy, it is no longer Personal Data.
If we intend to use any Personal Data in any manner that is not consistent with this Privacy Policy, you will be informed of such anticipated use prior to or at the time the Personal Data is collected, and we will obtain your consent for any such use. You can also disable the consent by emailing support@glueup.com or from your account Settings.
How long do we keep your Personal Data?
We only keep your Personal Data for as long as is necessary to satisfy the specified purposes and ongoing Service, providing that no legal requirements exist to the contrary, such as in the case of retention periods required by trade or tax regulations, or to resolve disputes.
If you wish to manage, change, limit, or delete your data, please follow the instruction in Section 9.
If you have an account with us, we will typically retain your Personal Data for a period of 90 days after you have requested that your account is closed, or for up to seven years after your account becomes inactive but is not closed.
Use Of The Service By Organizers And Participants
The Service is used by event organizers, companies and other organizations (“Organizers”) to manage events, manage memberships, conduct e-mail campaigns, manage financial matters and interface with Customer Relationship Manager (“CRM”) systems; and by event participants or members as the case maybe (“Participants”,“Users”, or “Attendees”) to access event information, membership services, purchase tickets and for other purposes within the scope of the Service.
Organizer Undertakings With Respect To Personal Data
Each Organizer represents and warrants that its use of the Service, and the collection and use of any Personal Data collected in connection with the Service, will comply with all applicable laws and regulations (including with respect to privacy, cyber security and data protection).
Each Organizer further agrees that it is responsible for all its activity in connection with the Service. Each Organizers shall defend, indemnify, and hold harmless Glue Up, its affiliates and subsidiaries, and each of Glue Up’s employees, contractors, directors, suppliers and representatives from all liabilities, claims, expenses, and damages (whether direct, indirect, incidental, consequential or otherwise), including reasonable attorneys’ fees, that arise from or in connection with (i) the Organizer’s use or misuse of the Service; (ii) the Organizer’s access to any part of the Service; (iii) the Organizer’s content and/or links; (iv) the Organizer’s dispute(s) with any third party(ies); (v) the Organizer’s violation of this Privacy Policy and any agreements with Glue Up or EventBank; and (vi) the Organizer’s violation of any applicable law.
Organizer’s Use Of Personal Data
In conjunction with Organizer’s use of the Service, Organizer may, through its own channels, collect additional information from you including but not limited to your name, email address, phone number, physical address, credit/payment card numbers using their own billing and payment technologies with and expiration dates, credit card security codes and your birthday. All the information collected by Organizer shall be referred to herein as (“Organizer Collected Personal Data”) and should be distinguished from Personal Data collected by Glue Up or EventBank. While Organizer Collected Personal Data is stored by Glue Up or EventBank in conjunction with Organizer’s use of the Service, Glue Up nor EventBank does not access or use Organizer Collected Personal Data, except to the extent necessary to enable you and Organizer to use the various features of the Service. Organizer Collected Personal Data will be subject to the Organizer’s own privacy policies and any applicable laws.
Email Tools
We allow Organizers to use our email tools to contact their consumers for the Organizers’ events, so you may receive emails from our system that originate with such Organizers and that we send on their behalf. If you registered for an event on the Service, your email address is available to that Organizer. However, Organizers may also import email addresses they have from external sources and send communications through the Service to those email addresses, and we will deliver those communications to those email addresses on the Organizer's behalf. You can opt-out of receiving certain types of promotional and marketing emails – but in such case you may not receive the full benefit of the Service. Opting-out can be done under the Subscription function following the instruction. Organizers are responsible for following all applicable laws and regulations around SPAM and gaining your consent for emails utilizing email tools. Please contact Organizers directly to remove your contact information from any email lists utilized by Email Tools.
Your rights
As a User, you have the following rights:
- the right to request access to personal data relating to You from us under the conditions set out in Article 15 GDPR;
- the right to withdraw your consent to the processing of personal data processed by us on the basis of Your consent at any time under the conditions set out in Article 7 GDPR;
- the right to request correction of personal data under the conditions set out in Article 16 GDPR, restriction of processing of personal data under the conditions set out in Article 18 GDPR or erasure of data under the conditions set out in Article 17 GDPR;
- the right to raise an objection to the processing of personal data concerning him/her on the basis of Article 21 GDPR;
- the right to data transfer to another administrator under the conditions set out in Article 20 GDPR;
- the right not to be subject to any decision based solely on automated processing, including profiling under the conditions set out in Article 22 GDPR. No automated individual decision-making takes place in our processing of personal data, even on the basis of profiling, i.e. without human intervention;
- the right to obtain information about a breach of security of Your personal data under the conditions set out in Article 34 GDPR;
- the right to submit a complaint with DPA and under the conditions set out in Article 77 GDPR if You suspect that the processing of Your personal data violates the obligations set out in the GDPR.
How you can exercise your rights
Under the GDPR or other applicable privacy laws, you have the right to access, rectify, port, and erase your information, as well as the right to restrict and object to certain processing of your information, unless the processing is based on compelling legitimate grounds or is needed for legal reasons.
Subject to the limitations of applicable laws, where processing Personal Data is necessary for entering into or performing our obligations under a contract with you or is processed with your consent, you may request that your Personal Data be transferred to you or another designated party (where technically feasible).
Where we use your data for direct marketing, you may always object and opt out of future marketing notifications using the unsubscribe link in such communications or via email.
To the extent you have authorized us to collect and process your Personal Data, you may withdraw that authorization by deleting information, turning off device functions, or changing privacy settings on our website or in our software. Please note that some parts of the Service may not function properly if you remove our authorization to collect your Personal Data.
For any Personal Data that you have authorized the Organizers directly and not Glue up (even indirectly), you should contact the Organizers to withdraw such authorization.
Although certain Personal Data may still be retained to the extent necessary to fulfil our legitimate business needs, comply with any applicable law and regulation, resolve disputes, and enforce our contracts.
To exercise your rights in all other cases, please contact us. Our contact details can be found at the final part of this Privacy Policy.
Security
We take various precautions to protect your Personal Data from loss, misappropriation and misuse, and from being accessed, disclosed, modified or destroyed without permission. In order to ensure the safety of your Personal Data, we have established strict information security provisions and procedures to protect your Personal Data.
In the event of any Personal Data security breach, we will, in accordance with the requirements of applicable laws and in all cases within 30 days, notify you of the basic information and possible consequences of such security breach, actions we have taken or will take in response to the breach, suggestions on how you may prevent and reduce risks on your own, and actions we will take on your behalf. We will notify you of the relevant information through email, letter, phone, or push notification, or by publishing an announcement to www.glueup.com. Any such notice will be issued in compliance with all applicable laws.
Our multi-layered approach encompasses network security, data encryption, access control, and organizational policies designed to meet industry standards and best practices. Under this scope, the various methods we use to safeguard your Data include:
Network Security
We leverage Cloudflare's enterprise-grade protection services for both Distributed Denial-of-Service (DDoS) mitigation and Web Application Firewall (WAF) capabilities. This robust solution filters malicious traffic, prevents unauthorized access attempts, and helps maintain service availability even during attack scenarios.
Data Encryption
We implement industry-standard encryption protocols to protect information:
Data at Rest: All stored information is secured using AES-256 encryption, ensuring that sensitive data remains protected within our systems.
Data in Transit: We employ TLS 1.2 protocols to encrypt all data transmissions between your devices and our servers, preventing interception during network transfer.
Comprehensive Monitoring
Our Security Information and Event Management (SIEM) solution provides real-time monitoring and analysis of system activities. All security logs are:
Continuously monitored for suspicious patterns Securely stored according to our data retention policies Protected against unauthorized access and tamperingAccess Control Management
We enforce strict access control measures throughout our systems:
Multi-Factor Authentication (MFA): Implemented for both internal staff and external users where applicable, adding an essential layer of security beyond passwords. Role-Based Access Control: A formal protocol governs the assignment, periodic review, and timely revocation of access rights, ensuring the principle of least privilege is maintained.Organizational Security Measures
We foster a security-conscious culture through:
Regular Training: Security awareness education is conducted annually at minimum, covering critical topics such as data handling procedures, threat identification, and secure remote work practices. Device and Remote Work Policies: Comprehensive guidelines govern the secure use of personal devices and establish protocols for remote work environments.Physical Infrastructure Security
Our server infrastructure on AWS data centers reside in facilities equipped with:
24/7 video surveillance systems Advanced alarm and intrusion detection systems Strict access controls permitting entry only to authorized personnelPayment Processing Security
We prioritize the security of financial transactions by:
Integrating exclusively with PCI-certified payment gateways Ensuring no credit card information is stored on our servers Maintaining secure transmission channels that bypass our infrastructure for payment dataBusiness Continuity Planning
To ensure operational resilience, we:
Perform daily data backups Maintain secure backup repositories in separate locations Follow established recovery procedures to minimize service disruption in the event of an incidentThe Location Of Your Personal Data
If you are using the Service through glueup.com, Personal Data collected and generated within the United States of America (“USA”) will be primarily stored at hosting facilities located in the USA.
These facilities are either operated by Glue Up or our third-party providers. By using the Service, you are consenting to have this data stored, transferred and processed according to this Privacy Policy.
Changes To This Privacy Policy
This Privacy Policy was last updated on the date set forth at the top of this Privacy Policy. We will alert you to any future updates to this Privacy Policy by placing a notice on www.glueup.com, by sending you an email, by notifying you when you logon to the Service, and/or by some other means. We will also edit the date at the top of this policy to reflect the date of the changes. Please note that if you’ve opted not to receive legal notice emails from us (or you haven’t provided us with your email address), our legal notices (including this Privacy Policy) will still govern your use of the Service, and you are still responsible for reading and understanding them. Use of Personal Data we collect is subject to the Privacy Policy in effect at the time such Personal Data is collected. If you use the Service after any updated Privacy Policy has been posted, that means that you agree to all the changes made with respect to all Personal Data, whether collected previously or in the future.
Minors
We do not knowingly collect or solicit personal information from anyone under the age of 14. If you are under 14, please do not attempt to register for the Service or send any personal information about yourself to us. If we learn that we have collected personal information from a child under 14, we will delete that information as quickly as possible. If you believe that a child under 14 may have provided us with personal information, please contact us at support@glueup.com.
Contacting Us
If you have any questions or concerns regarding our privacy policies or to exercise your rights, please send us a detailed message by email to support@glueup.com or by mail to Glue Up, 1600 Tysons Blvd, Suite 400, McLean VA 22102, USA
Recourse and Dispute Resolution
If you have a complaint about how we handle your personal data, you can contact our designated privacy team as set forth above. If we are unable to resolve the issue, you have the right to contact the relevant local data protection authority in your jurisdiction. These authorities are responsible for enforcing data protection rights, and they can assist in resolving complaints regarding data handling.
In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Glue Up commits to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities (DPAs) and the UK Information Commissioner’s Office (ICO) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) with regard to unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF. Under the EU-U.S. Data Privacy Framework (DPF), individuals have the right to invoke binding arbitration to resolve disputes regarding data handling, as set forth in Annex I of the DPF Principles. If an individual wishes to initiate binding arbitration, they must deliver notice to us and follow the procedures outlined in Annex I.
In addition, you have the right to lodge a complaint with the supervisory authority. The competent supervisory authority is the supervisory authority of the country of your residence or the registered office of the Glue Up subsidiary.
- For the European Union (EU): You can contact the European Data Protection Board (EDPB) or the relevant national Data Protection Authority (DPA) in your country of residence.
- For the United Kingdom (UK): You can contact the Information Commissioner’s Office (ICO).
- For Switzerland: You can contact the Swiss Federal Data Protection and Information Commissioner (FDPIC).
- For California (USA): You can contact the California Attorney General’s Office for issues related to the California Consumer Privacy Act (CCPA)
- If you are located in any other jurisdiction with relevant data protection laws, you can contact the relevant data protection authority in that region.