Privacy Policy
Last updated · August 16, 2026
What this site collects, why, who else sees it, and how to get it removed. It is short because we collect very little.
Who we are
Better Events (betterevents.co) is run by Yerapter LLC. We are the data controller for everything described on this page. Our address is Hrachya Kochar Str. 13, apt. 95, 0012, Yerevan, Republic of Armenia. Questions about this page: [email protected].
What we collect, why, and on what basis
Your brief. The form asks for your work email and one line on what you sell. Your website and the show are optional. We store it in our own database and send it to our inbox as a single notification email, with reply-to set to you, so that we can answer you and build your list. You do not have to give us your email, but without it we cannot answer you or deliver a list. The other fields can stay empty. Submitting the form does not put you on a mailing list. Basis: Art. 6(1)(b) GDPR – steps taken at your request before a contract, and then the contract itself.
Running the site. Like every web server, ours keeps short-lived request logs – IP address, requested page, time – and the form is rate-limited per IP address to keep bots out. Cloudflare sits in front of the site as a CDN and security proxy, so it sees that traffic. Basis: Art. 6(1)(f) GDPR, our legitimate interest in running a secure, available site.
Cookies. The site sets exactly one cookie, _better_events_session. It is first-party, it carries the token that protects the brief form from forged submissions, and it expires when your browser session ends. It is strictly necessary for the site to work, so it needs no consent (§ 25(2) No. 2 TDDDG) – which is why there is no cookie banner here.
Analytics. We count how the site is used – which pages people open, which links and buttons they click – using PostHog on its EU servers. It writes nothing to your browser: no cookie, no local storage. So it cannot connect this visit to your next one.
Each event carries the page address, what was clicked, your browser and screen size, and the page you came from. The analytics code is served from our own server, not from PostHog’s.
We send no IP address with the events. PostHog’s servers still see the address your browser connects from – every website you open sees this – and use it to work out an approximate country. We also send our server’s error reports to the same PostHog account. The contents of a brief are stripped out of them first. Basis: Art. 6(1)(f) GDPR, our legitimate interest in knowing which pages work. You can object at any time – see Your rights.
Buying. Card purchases run through Lemon Squeezy as merchant of record – the authorized reseller you actually buy from. At checkout you give your billing and payment details to Lemon Squeezy, not to us, under its own terms and privacy policy. Lemon Squeezy then sends us the order record. We never see your card details. If you pay by bank transfer instead, you buy from us directly and we hold those invoice details ourselves. Basis: Art. 6(1)(b) GDPR for the sale, Art. 6(1)(f) for keeping accurate business records.
That is everything. There is no account system, no advertising or retargeting trackers, no cross-site tracking, and no third-party content loaded into the page – fonts and scripts are served from our own server.
Who else sees it, and where
Five companies see data along the way, each for one job:
- Aruba S.p.A. (Italy, EU) – hosting. The application, its database and your brief sit on a server we operate there.
- Cloudflare, Inc. (US, global network) – CDN and security proxy for all traffic to the site.
- Fastmail (Fastmail Pty Ltd, Australia, with US servers) – email. Your brief passes through its systems on the way to our inbox.
- PostHog, Inc. (US company; event data on its EU servers in Frankfurt) – analytics and our own error reports.
- Lemon Squeezy (US) – payments, as merchant of record. It runs checkout under its own privacy policy and sends us the order record; it is the seller you buy from, not a supplier working for us.
Nobody else. We do not sell personal data and we do not share it for advertising.
Outside the EEA. We are based in Armenia and work on your brief from there, and every company above except Aruba is outside the EEA. The European Commission has issued no adequacy decision for Armenia or Australia. It has issued one for the United States, and that decision covers companies certified under the EU–US Data Privacy Framework. If you want to know how a particular transfer is handled, email [email protected] and we will tell you.
How long we keep it
Your brief. While we work with you on it, through the show it names, and after that for as long as we keep ordinary business correspondence. If you ask, we delete it sooner – both the database record and the notification email.
Server request logs. Capped by size, not by age: when the log is full, the oldest entries are dropped, so the logs only ever cover a recent, short period.
Analytics events. They stay in our PostHog project for as long as we keep the project. They carry no identifier that ties them to you, so a deletion request has nothing to delete.
Your rights
You can ask us to:
- show you the data we hold on you
- correct it
- delete it
- limit how we use it
- send you a copy you can take elsewhere
One email to [email protected] is enough for any of these – no forms to fill in – and we answer within a month.
Where we rely on legitimate interest – the server logs, the rate limit that keeps bots out, and the analytics – you may object at any time, on grounds relating to your particular situation. Email [email protected] and we stop, unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms (Art. 21(1) GDPR).
You can also lodge a complaint with a data-protection supervisory authority – in particular the one where you live, where you work, or where you think something went wrong.
Changes
If we change what we collect or who handles it, we update this page and the date at the top before the change takes effect. This policy has no silent edits.