Legal

Privacy, in plain language

What we collect, why we need it, who helps us provide the site and how to exercise your rights.

Controller Svelte Summit AB
Cookies Essential only
Your rights GDPR protected

Privacy policy

Your data and Svelte Summit

Last updated: August 2026. This policy applies to the Svelte Summit website, event forms and virtual-ticket service.

1. Who is responsible

Svelte Summit AB is the data controller for the processing described here. Our postal address is Hummelhaga 13, 153 95 Järna, Sweden. Email privacy questions or requests to [email protected].

2. Data we collect

  • Tickets and access: your email address and locally stored order, checkout, customer and product identifiers; entitlement status; relevant purchase, update and access-email timestamps; and hashed, expiring magic-link tokens. For abuse prevention, we also temporarily process a one-way hash of the IP address used to request a recovery email. We do not receive or store your full payment-card number.
  • Accounts and programme submissions: if you sign in with GitHub or use a call-for-papers feature, we receive the account identifiers and profile details GitHub makes available and store your submitted proposal, notes, status and related timestamps.
  • Messages, forms and mailing lists: contact details and the contents of messages, ticket-interest forms, sponsorship enquiries or other forms you choose to send. If you join an email list, we also process your list or segment membership, subscription or unsubscribe status, and delivery and unsubscribe data.
  • Technical data: IP address, request time, browser and device details, referring page, requested URL and security or diagnostic events may appear in our or our infrastructure providers’ logs.

3. Why we use it

  • To take the steps you request and perform our contract with you: confirm an order, provide ticket access, send secure access emails and administer submissions.
  • For our legitimate interests in operating, securing, debugging and improving the service, preventing abuse, answering enquiries and keeping appropriate business records, balanced against your rights.
  • With your consent, to send ticket-sale announcements and occasional event updates you asked to receive. You may withdraw that consent at any time by unsubscribing from marketing broadcasts.
  • To meet legal obligations, including accounting, consumer-protection and lawful requests.

We do not use your data for solely automated decisions with legal or similarly significant effects.

4. Services that help us

  • Polar: the merchant of record and reseller for virtual tickets. Polar collects checkout and payment information, calculates tax, invoices you and handles billing and refunds under its own privacy notice. It sends us the order and customer data needed to provide or revoke access.
  • Resend: generally processes recipient and message data on our behalf as our email delivery provider and data processor. It stores mailing-list contact information, including your name, email address, segment membership and subscription status, and processes delivery and unsubscribe data to send ticket announcements, event updates, purchase messages and ticket-access messages for us. We do not enable Resend’s open or click tracking.
  • Cloudflare and our hosting providers: deliver and host the service and process network, request-log and security data needed for availability and abuse prevention.
  • GitHub: acts as the sign-in provider where GitHub login is offered. GitHub receives the login request and applies its own privacy notice.
  • YouTube: recordings embedded on the site use YouTube’s privacy-enhanced mode. When you load or interact with an embed, particularly when you press play, YouTube/Google may receive device, network and usage data and may set or read its own storage according to Google’s privacy notice.

We may also disclose data to professional advisers, authorities when legally required, or a successor in a business reorganisation. We do not sell your personal data.

5. Cookies and similar storage

We use only essential first-party cookies or browser storage needed for secure sign-in, request integrity and virtual-ticket access. Cloudflare may use strictly necessary security cookies. These cannot be switched off through a consent preference because the relevant feature would not work without them. We do not set advertising cookies. Third-party YouTube storage may be used when you interact with its player as described above.

6. Retention and security

We keep ticket and order records while they are needed to provide ongoing replay access and afterwards where required for accounting, disputes or legal claims. Recovery links expire after 15 minutes; hashed IP records are used for short-window rate limiting and retained only as reasonably needed for security. Other records are kept for the relevant event or relationship and then deleted or anonymised unless law or a live dispute requires longer retention.

We keep mailing-list contact details in Resend while the relevant list is active. We do not retain a separate live copy of ticket-list signups in our application database. If you unsubscribe, Resend keeps the subscription status needed to honour that choice. You may ask us to delete your contact record, subject to legal exceptions. Legacy backup copies may remain until their ordinary retention period ends.

We use access controls, token hashing, encryption in transit and other proportionate measures. No internet service can promise absolute security.

7. International processing

Some providers may process data outside Sweden or the European Economic Area. Where GDPR requires it, we use a recognised transfer mechanism such as an adequacy decision or the European Commission’s standard contractual clauses, together with supplementary measures where appropriate. Resend states that it stores customer data in the United States and that its primary processing operations take place there. Its data processing addendum incorporates standard contractual clauses for covered transfers.

8. Your rights

Depending on the circumstances, you may request access, correction, deletion, restriction or portability of your personal data, and object to processing based on legitimate interests. You may withdraw consent without affecting earlier lawful processing. These rights can have legal exceptions. Contact us at the address above; we may need to verify your identity.

You may complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se, or to the data-protection authority where you live or work.