Trust
Trust and data handling
Effective Date: September 6, 2026
Built for GDPR, and for the rooms you run
Lime-n.io is built so that a venue or promoter in the EU, Switzerland, the UK or Quebec can use it with their guests' details handled the way their privacy rules expect. This page says exactly what we do, in plain words, so you can hand it to whoever signs off on that.
1. Who is responsible for what
When you run an event on Lime-n.io, you are responsible for your guests' details (the "controller", in GDPR terms). Harvest Technology Systems, Inc., trading as Lime-n.io, keeps and handles those details on your behalf and on your instructions (the "processor"). For your own account details — your name, email and sign-in — we are the responsible party.
Inside your organization, everyone on your team who has an account — owners, admins, promoters and door staff — can see the details of guests on your organization's events; owners and admins see everything. Guests are told on the sign-up form that the promoter who invited them and their team can see their details.
2. Where your data is kept
All data is kept on Google Cloud in the United States: stored in the nam5 (US multi-region) and handled in us-east4. Lime-n.io itself is a Canadian company in Ontario, Canada.
How that is lawful for EU, Swiss and UK guests. Canada holds an adequacy decision from the European Commission, and equivalent recognition from Switzerland and the UK, for data handled by commercial organisations, so the transfer to us needs no extra paperwork. From us to Google, Google's Cloud Data Processing Addendum applies, which includes the EU Standard Contractual Clauses; Google is also certified under the EU-US Data Privacy Framework. The same kinds of terms cover our other providers, listed below. The full chain is written into our Data Processing Agreement.
Quebec. Because the details leave Quebec, a Quebec organizer needs to assess that transfer under Law 25. We publish a transfer fact sheet with everything that assessment asks for.
3. Who else handles it
Four providers handle data for us. We tell organizers by email at least 30 days before adding one.
| Provider | What for | What they see | Where | Transfer basis |
|---|---|---|---|---|
| Google Cloud / Firebase Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA, USA | Hosting, stored data, processing, sign-in, and (after consent) product analytics | All account and guest data held by the service | United States (nam5 multi-region storage; us-east4 processing) | Google Cloud Data Processing Addendum with EU Standard Contractual Clauses; Google LLC is certified under the EU-US Data Privacy Framework and its UK and Swiss extensions |
| Resend Resend, Inc., USA | Delivery of transactional email (confirmations, invitations, reminders, recaps, billing notices) | Recipient name and email address, event and organization details in the message | United States | Resend Data Processing Agreement with EU Standard Contractual Clauses |
| Stripe Stripe, Inc., USA (and Stripe Payments Company) | Subscription billing for organizer accounts; card details are collected and held by Stripe only | Billing name, email, subscription status | United States | Stripe Data Processing Agreement with EU Standard Contractual Clauses; Stripe is certified under the EU-US Data Privacy Framework |
| Sentry Functional Software, Inc. (Sentry), USA | Error reports from the app and its services, so faults can be fixed | Technical error context only; no names, email addresses or guest data by design | United States | Sentry Data Processing Addendum with EU Standard Contractual Clauses; Sentry is certified under the EU-US Data Privacy Framework |
4. How long we keep it
- Guest details: deleted automatically 90 days after the event date. This runs every day.
- Account and organization data: deleted within 180 days of the account ending.
- Backups: kept 7 days, so deleted data leaves them within a week.
- A deletion request is actioned within 14 days.
5. Your rights, and your guests' rights
Organizers can export any event's guest list from the event page at any time, and can ask us to delete a guest, a team member or the whole organization by writing to privacy@lime-n.io.
Guests ask the organizer of their event first, since the organizer is responsible for their details. A guest can also write to us directly; we route the request to the organizer and act on their instruction, or act ourselves if the organizer cannot be reached.
Anyone can complain to a regulator:
- European Union / EEA: Your national data protection authority (see the EDPB members list)
- Switzerland: Federal Data Protection and Information Commissioner (FDPIC)
- United Kingdom: Information Commissioner's Office (ICO)
- Quebec: Commission d'accès à l'information du Québec (CAI)
- Canada: Office of the Privacy Commissioner of Canada (OPC)
6. How we protect it
- Encrypted in transit and at rest.
- Access is by role: every read and write is checked against who you are and what your organization allows.
- An activity trail that only our own trusted code can write to.
- Daily backups, kept 7 days.
- Anyone opening a promoter's link without signing in sees the list without email addresses or phone numbers.
- Error reports never include names, email addresses or guest details.
- If something goes wrong with your data, we tell you within 48 hours of learning of it, with what you need for your own notices.
7. Documents
- Data Processing Agreement (version 1.0) — read online, or download the PDF. It applies to every account; if your organization needs a countersigned copy, ask.
- Privacy Policy
- Terms of Service
- Quebec transfer fact sheet
8. Contact
privacy@lime-n.io
Person responsible for personal information: Stu Doherty, Harvest Technology Systems, Inc., Ontario, Canada.