Legal

Privacy Policy

Privacy

What we collect, and what we do with it

GoodVibes Foundation is a small Austrian non-profit association. This page describes every piece of personal data this website actually handles — no more, and nothing we do not do. If anything here is unclear, write to sup@gvs.foundation and a human will answer you.

The short version
We sell event tickets, we email you your ticket, and we count page views. Card payments are handled by Stripe and card numbers never touch our server. Our analytics run on PostHog’s European servers. We do not sell data, we run no advertising trackers, and we build no profiles of you. The one thing we are not yet doing properly is asking your permission before the analytics script loads — that is written up honestly further down this page.

Who is responsible for your data

The controller within the meaning of Article 4(7) GDPR is:

  • GoodVibes – Essen, Kleidung und niederschwellige Hilfe in Wien für Menschen in Notlagen (“GoodVibes Foundation”), a non-profit association under the Austrian Associations Act 2002
  • ZVR number 1741769261, registered with the Vienna State Police Directorate
  • Spittelauer Lände 12 / Bogen 335A, 1090 Vienna, Austria
  • sup@gvs.foundation

We are below the threshold at which a data protection officer must be appointed, and we have not appointed one. Write to the address above and a board member will answer. Our full registration details, including the official register extract, are on the Imprint page.

Where this website runs

gvs.foundation runs on a single dedicated server rented from Scaleway (Online S.A.S.) in France. The site itself is WordPress with WooCommerce. The web server writes ordinary access logs — IP address, the address requested, the time and the browser user agent string. Those logs are used for troubleshooting and for spotting attacks, they are not analysed for anything else, and they are not combined with your order or with our analytics.

What we collect when you buy a ticket

The ticket shop is WooCommerce, running on our own server. When you place an order we store:

  • your first and last name
  • your email address
  • your billing address — street, postcode, city, country
  • what you ordered, how much you paid, in which currency, when, and the status of the order
  • the IP address and browser user agent that WooCommerce records alongside every order as a fraud-prevention record

We do not ask for a telephone number and we do not add an order note field. Checkout does not create a user account: ticket orders are placed as a guest.

Legal basis: Article 6(1)(b) GDPR — we need this data to perform the ticket contract with you. Once the order is complete, the accounting record is kept under Article 6(1)(c) GDPR, because Austrian tax law requires us to keep it.

Paying — Stripe

Card payments are processed by Stripe. The payment methods currently switched on are card, Link, EPS and Bancontact, plus the Apple Pay and Google Pay express buttons.

The payment field on our checkout page is drawn by Stripe inside our page. Your card number, expiry date and security code go straight to Stripe. They are never transmitted to our server, never processed by it, and never stored on it. What comes back to us is a payment reference and whether the payment succeeded.

Stripe is Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Dublin 2, Ireland. For its own fraud-prevention and regulatory duties Stripe acts as an independent controller, and it may transfer data to Stripe, Inc. in the United States on the basis of the European Commission’s standard contractual clauses. Stripe’s own privacy policy is at stripe.com/privacy.

If you are signed in to an account on this site, Stripe can keep your card on file as a reusable payment method. The card itself stays at Stripe; all we hold is a token that points at it. Guests are not offered this.

Your ticket and its QR code

When your payment succeeds we generate one ticket code for each ticket you bought and store, in this site’s own database: the code, the order number, which ticket it is, the day and session it admits you to, the price you paid, your name, your email address, the time the ticket was issued and — later — the time it was scanned at the door.

The QR image itself is generated once, at the moment the ticket is issued, by an outside service: api.qrserver.com, operated by goQR.me in Germany. The only thing sent to that service is the check-in address of the ticket, of the form https://gvs.foundation/door/?c=CODE. Your name, your email address, your order and the price are never sent there. The image that comes back is saved on our own server, and that service is never contacted about your ticket again.

At the door, our team opens that address and enters a shared PIN. Nothing about a ticket — not the name on it, not the session, not whether it has been used — is shown before the PIN is accepted. A photographed or forwarded QR code therefore gives away nothing on its own.

Legal basis: Article 6(1)(b) GDPR — issuing your ticket and checking it at the door is the contract you entered into.

Email we send you

Your order confirmation and your ticket are sent from sup@gvs.foundation by a mail server the foundation runs itself, on the same machine as this website. The messages are signed with DKIM and covered by SPF and DMARC records published for gvs.foundation. We do not use Mailchimp, Brevo, SendGrid or any other bulk-mail provider for these messages.

Your QR code is attached to the email itself rather than loaded from a server when you open it. That is deliberate: it means opening our email tells us nothing. We use no read receipts and no tracking pixels.

Mail you send to sup@gvs.foundation arrives through Google Workspace, which is our inbound mail provider (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4). So if you email us, that message sits in a Google Workspace mailbox.

Analytics — PostHog, and where we currently fall short

We use PostHog to count page views and see which pages people actually use. It is configured against PostHog’s European host, https://eu.i.posthog.com, so events are processed in the EU. Our project identifier phc_n7fN… is visible in this page’s source; that is how the product is designed and it is not a secret.

PostHog is set to identified_only, which means no person profile is created for an ordinary visitor. What is recorded is page views and events, together with the page address, the referring page, an approximate location derived from your IP address, browser and device type, and a random device identifier stored in your browser.

Plainly: this script currently loads on every page without asking you first. Austrian law (§ 165 TKG 2021, implementing the ePrivacy Directive) generally requires your consent before anything that is not strictly necessary is stored on or read from your device. We have not yet built that consent step. We are not going to dress that up as a legitimate interest — it is a gap on our side and we are working on closing it.

Until it is closed you can switch the analytics off completely and nothing on this site will break: block eu.i.posthog.com and eu-assets.i.posthog.com in your browser or content blocker, or use a browser with tracking protection turned on. Our own administrator sessions are already excluded from tracking.

PostHog is PostHog, Inc.; data on its EU cloud is processed on infrastructure in the European Union. We have not set a custom retention period, so PostHog’s own default retention applies. Their privacy policy is at posthog.com/privacy.

If you sign up for the newsletter

The newsletter form writes your email address to a table in this site’s own database, together with the fact that you ticked the consent box, which page you signed up from, which language you were reading in, a one-way hash of your IP address used only to stop the form being flooded, and the time. Nothing is sent anywhere else: there is no newsletter provider connected to this site at all, and every sign-up is currently held as unconfirmed.

Legal basis: Article 6(1)(a) GDPR — your consent. Email sup@gvs.foundation and we will delete your entry.

How a volunteer hears about your order

When an order is paid, this site sends a short message to the foundation’s own automation server (n8n.gvs.foundation, the same machine) so that a volunteer on duty gets a Telegram notification and can act on it. That message contains the order number, the status, the total, what was ordered and your name. It does not contain your email address, your postal address or anything about your payment. The notification itself travels over Telegram to the phones of the volunteers on duty.

Accounts and memberships

You do not need an account to buy a ticket and checkout will not create one for you. If you do register, or hold a membership with us, WordPress and WooCommerce store your username, email address, name, any address you enter and your order history, and set login cookies while you are signed in.

Cookies and what is stored in your browser

This is the complete list of what this site puts in your browser:

  • pll_language — set by Polylang on every page. Remembers which of our eight languages you are reading. Lasts one year. Strictly necessary for the site to serve you the right language.
  • woocommerce_items_in_cart, woocommerce_cart_hash and wp_woocommerce_session_… — set by WooCommerce only once you put something in your basket. They hold the basket and the session that belongs to it. Strictly necessary for the shop to work.
  • ph_phc_n7fN…_posthog — set by PostHog. A random device identifier so that repeat visits are counted as one device rather than many. Not strictly necessary; see the analytics section above for how to block it.
  • wordpress_logged_in_… and wp-settings-… — only ever set for people who log in to administer the site.

We set no advertising cookies. There is no Google Analytics, no Meta or Facebook pixel, no Google Ads tag and no TikTok pixel anywhere on this site.

Links on our pages to other sites — arneiron.net, or our Telegram channel, for example — are ordinary links. Nothing is loaded from them and nothing is sent to them until you click.

How long we keep things

  • Orders and payment records — seven years, because § 132 of the Austrian Federal Fiscal Code (BAO) requires accounting records to be kept that long.
  • Ticket codes and door check-in records — until the end of the event they belong to, plus three months to settle any dispute, then deleted.
  • Newsletter sign-ups — until you ask to be removed.
  • Analytics events at PostHog — PostHog’s own default retention; we have not extended it.
  • Server logs — short-term, for troubleshooting and security only.
  • Emails you send us — for as long as they are useful for answering you and for our records as an association.

Who your data is shared with

Nobody buys it from us and nobody receives it for their own marketing. This is the complete list of outside parties involved in running this site:

  • Stripe Payments Europe, Limited (Ireland) — processing your payment
  • PostHog, Inc. (EU cloud) — website analytics
  • goQR.me / api.qrserver.com (Germany) — generates the QR image once per ticket, and receives only the check-in address
  • Google Ireland Limited — inbound email to sup@gvs.foundation
  • Telegram — carries the volunteer notification described above
  • Scaleway / Online S.A.S. (France) — the server this site runs on

Beyond these, your data leaves us only where the law requires it — for instance to a tax authority or a court.

Your rights

Under the GDPR you may ask us at any time to:

  • tell you what we hold about you and give you a copy — Article 15
  • correct anything that is wrong — Article 16
  • delete your data — Article 17, subject to the records we are legally required to keep
  • restrict what we do with it — Article 18
  • hand it over in a machine-readable form — Article 20
  • object to processing, including to our analytics — Article 21
  • withdraw a consent you gave, without that affecting anything done lawfully before — Article 7(3)

Write to sup@gvs.foundation. We will answer within one month. We charge nothing for this, and we will not demand more identifying information from you than we need to be sure it is really you asking.

There is no automated decision-making and no profiling on this site within the meaning of Article 22 GDPR.

If you think we are handling your data wrongly, you can complain to the Austrian supervisory authority: Österreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Wien, dsb@dsb.gv.at, dsb.gv.at. If you live in another EU country you may complain to the authority there instead.

Changes to this page

This page was rewritten from scratch on 3 September 2026 to describe what this website actually does. If we add a service or change how something works, we change this page first. There is no older version we are hiding.

Anything unclear?

Ask us — you will get a plain answer

No forms and no ticket system. Write to sup@gvs.foundation and a person from the association will reply. Or drop by: Spittelauer Lände 12, Vienna.

Email us