Skip to content
Glentio
What's OnCreatePrivate EventsGo SoloOrganisers
Sign inCreate event

Privacy Policy

Version 2 · Last updated 3 July 2026.

1. Who is responsible for your data

Glentio is operated by Cuaresma Veloso Richard, an individual entrepreneur (empresario individual / autónomo) established in Spain — NIF 45695668G, registered business address Calle Montenegro 3, 2º Dcha 3, 07012 Palma, Spain, VAT number ES45695668G. References to “Glentio”, “we” or “us” mean this operator. You can reach us at legal@glentio.com.

The operator above is the data controller for the personal data described here. We have not appointed a Data Protection Officer; for any privacy matter, contact privacy@glentio.com.

2. What we collect

Account details (name, email); the events you create, save, RSVP to or buy tickets for; order and payout status for transactions; support messages; and limited technical data (IP address, device/browser, approximate location and cookies needed to run the service). We also receive some data from others — for example, payment status from Stripe, and details an organiser adds about their own guests. Card details are handled by Stripe and never stored by Glentio.

3. How we use your data and our legal bases

Under the GDPR we rely on:

  • Performance of a contract — to create and run your account, process orders, issue tickets and receipts, and manage subscriptions.
  • Legitimate interests — to keep Glentio secure, prevent fraud and abuse, and improve the product (balanced against your rights).
  • Legal obligation — to keep accounting and tax records and to meet reporting duties (see section 5).
  • Consent — where required, e.g. optional product analytics. You can withdraw consent at any time, without affecting processing already carried out.

We do not sell your personal data.

4. Fraud prevention and automated checks

We and our payment provider run automated checks to detect fraud and abuse (for example, unusual purchase or payout patterns). These support human review and are not used to make decisions producing legal effects about you by automated means alone; where an automated check flags an account, a person reviews it and you can contact us to contest the outcome.

5. Who we share data with

With providers that process data on our behalf under contract — Supabase (hosting/database, EU region), Vercel (application hosting), Stripe (payments and payouts), and our email and error-monitoring providers. When an event page shows a location map, the map is loaded from OpenStreetMap (OpenStreetMap Foundation), which receives your IP address at that moment so the map can display. With event organisers, for their own events (an organiser can see who is attending). With tax and public authorities where the law requires — including reporting of seller information under the EU platform tax-reporting rules (DAC7) for organisers who sell through Glentio. We never expose your data to other attendees beyond what an event requires.

6. International transfers

Our primary data region is the EU. Where a provider processes data outside the EEA (for example, group functions of a global processor), we rely on appropriate safeguards — principally the European Commission’s Standard Contractual Clauses — a copy of which you can request from us.

7. How long we keep it

We keep personal data only as long as needed for the purposes above:

  • Account data — while your account is active, then deleted or anonymised within a reasonable period after closure.
  • Order, invoice and tax records — retained for the period required by Spanish tax and commercial law (generally up to 4–6 years).
  • Consent and moderation logs — kept as long as needed to evidence compliance.
  • Support messages — kept for a limited period after your query is resolved.

8. Your rights

Subject to law, you may request access, rectification, erasure, restriction, portability, and may object to certain processing or withdraw consent. To exercise a right, email privacy@glentio.com. You also have the right to lodge a complaint with a supervisory authority — in Spain, the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD — www.aepd.es).

9. Children

Glentio is not intended for children under 14 (the age of digital consent in Spain). We do not knowingly collect data from children below that age; if you believe we have, contact us and we will delete it.

10. Cookies and analytics

We use the cookies needed to keep you signed in and run the service. Product analytics are privacy-first and optional: nothing is collected unless analytics is enabled, and we capture only explicit events — no session recording and no payment data.

11. Contact

Privacy requests: privacy@glentio.com.

Glentio

Glentio turns plans into trusted events people can discover, share, and join.

Get in touchsupport@glentio.com
ProductDiscoverDestinationsCreatePrivate eventsGo Solo
OrganisersOrganiser toolsPricingFounding organisersDashboardTrust & safety
AccountSign inCreate account
LegalTermsPrivacyRefundsCommunityOrganiser termsSubscription terms
© 2026 Glentio. All rights reserved.Discover · Connect · Go