Legal
Privacy, in plain language
What we collect, why we need it, who helps us provide the site and how to exercise your rights.
Privacy policy
Your data and Svelte Summit
Last updated: August 2026. This policy applies to the Svelte Summit website, event forms and virtual-ticket service.
1. Who is responsible
Svelte Summit AB is the data controller for the processing described here. Our postal address is Hummelhaga 13, 153 95 Järna, Sweden. Email privacy questions or requests to [email protected].
2. Data we collect
- Tickets and access: your email address and locally stored order, checkout, customer and product identifiers; entitlement status; relevant purchase, update and access-email timestamps; and hashed, expiring magic-link tokens. For abuse prevention, we also temporarily process a one-way hash of the IP address used to request a recovery email. We do not receive or store your full payment-card number.
- Accounts and programme submissions: if you sign in with GitHub or use a call-for-papers feature, we receive the account identifiers and profile details GitHub makes available and store your submitted proposal, notes, status and related timestamps.
- Messages and forms: contact details and the contents of messages, ticket-interest forms, sponsorship enquiries or other forms you choose to send.
- Technical data: IP address, request time, browser and device details, referring page, requested URL and security or diagnostic events may appear in our or our infrastructure providers’ logs.
3. Why we use it
- To take the steps you request and perform our contract with you: confirm an order, provide ticket access, send secure access emails and administer submissions.
- For our legitimate interests in operating, securing, debugging and improving the service, preventing abuse, answering enquiries and keeping appropriate business records, balanced against your rights.
- To meet legal obligations, including accounting, consumer-protection and lawful requests. Where we specifically ask for consent, you may withdraw it at any time.
We do not use your data for solely automated decisions with legal or similarly significant effects.
4. Services that help us
- Polar: the merchant of record and reseller for virtual tickets. Polar collects checkout and payment information, calculates tax, invoices you and handles billing and refunds under its own privacy notice. It sends us the order and customer data needed to provide or revoke access.
- Resend: processes your email address and delivery data to send purchase and ticket-access messages for us.
- Cloudflare and our hosting providers: deliver and host the service and process network, request-log and security data needed for availability and abuse prevention.
- GitHub: acts as the sign-in provider where GitHub login is offered. GitHub receives the login request and applies its own privacy notice.
- YouTube: recordings embedded on the site use YouTube’s privacy-enhanced mode. When you load or interact with an embed, particularly when you press play, YouTube/Google may receive device, network and usage data and may set or read its own storage according to Google’s privacy notice.
We may also disclose data to professional advisers, authorities when legally required, or a successor in a business reorganisation. We do not sell your personal data.
5. Cookies and similar storage
We use only essential first-party cookies or browser storage needed for secure sign-in, request integrity and virtual-ticket access. Cloudflare may use strictly necessary security cookies. These cannot be switched off through a consent preference because the relevant feature would not work without them. We do not set advertising cookies. Third-party YouTube storage may be used when you interact with its player as described above.
6. Retention and security
We keep ticket and order records while they are needed to provide ongoing replay access and afterwards where required for accounting, disputes or legal claims. Recovery links expire after 15 minutes; hashed IP records are used for short-window rate limiting and retained only as reasonably needed for security. Other records are kept for the relevant event or relationship and then deleted or anonymised unless law or a live dispute requires longer retention.
We use access controls, token hashing, encryption in transit and other proportionate measures. No internet service can promise absolute security.
7. International processing
Some providers may process data outside Sweden or the European Economic Area. Where GDPR requires it, we use a recognised transfer mechanism such as an adequacy decision or the European Commission’s standard contractual clauses, together with supplementary measures where appropriate.
8. Your rights
Depending on the circumstances, you may request access, correction, deletion, restriction or portability of your personal data, and object to processing based on legitimate interests. You may withdraw consent without affecting earlier lawful processing. These rights can have legal exceptions. Contact us at the address above; we may need to verify your identity.
You may complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se, or to the data-protection authority where you live or work.