Privacy Policy

Gluebox LLC ("we," "us," "our") operates gluebox.com. This policy describes what personal data we collect, why, and your rights over it. We keep this deliberately plain: no hidden processing, no data brokers, no advertising networks.

Last updated: August 2026

Who we are

Gluebox LLC is a software development company based in Philadelphia, PA, building calendar, reservation, and event systems on Drupal. Contact us at [email protected] for privacy-related questions.

Data we collect automatically

When you visit any page, our web server records a standard access log entry containing your IP address, the page requested, your browser and operating system, and the date and time. These logs are retained for up to 90 days and used solely for security and operational troubleshooting. They are not shared with third parties.

Security screening

Each request is screened by a self-hosted CrowdSec security layer. Your IP address is checked against a private threat-intelligence database hosted on our own infrastructure (not the CrowdSec community cloud). If your IP has been flagged for abusive behaviour, you may be asked to complete a brief human-verification challenge or, in severe cases, see an access-denied page. No information about you is sent to CrowdSec’s external services.

If you pass the human-verification challenge, a short-lived cookie (gluebox_crowdsec_verified) is set in your browser so you are not re-challenged on subsequent pages. This cookie expires after 12 hours and contains only a cryptographic timestamp — no personal data.

Cookies

We use a consent manager (Klaro) so you can choose which optional cookies are set. The table below describes all cookies this site may set.

CookiePurposeDurationConsent required?
SESS… / SSESS… Drupal session — keeps you logged in and enables forms to work correctly. Session (closes with browser) No — strictly necessary
klaro Stores your cookie consent choices so you are not asked every page load. 180 days No — strictly necessary
gluebox_crowdsec_verified Records that you passed a security challenge, preventing repeated interruptions. 12 hours No — strictly necessary
YouTube cookies Set when you play an embedded YouTube video. Subject to Google’s privacy policy. Varies (set by Google) Yes — optional
Vimeo cookies Set when you play an embedded Vimeo video. Subject to Vimeo’s privacy policy. Varies (set by Vimeo) Yes — optional

You can review or change your consent choices at any time using the cookie settings button in the site footer.

Analytics

We do not currently run any analytics service on gluebox.com. Matomo is installed on our infrastructure but is not active on this site. If we enable it in the future, we will update this policy and seek your consent via the Klaro consent manager before setting any analytics cookies.

Embedded content

Pages may include videos hosted on YouTube or Vimeo. These embeds are blocked by default until you grant consent. Once you do, the third-party provider may set their own cookies and collect data according to their privacy policies (linked in the table above).

Data sharing

We do not sell personal data. We do not share data with advertising networks, data brokers, or any third party except as described above (i.e., YouTube or Vimeo when you explicitly consent to embedded video).

We may disclose data if required by law or a valid legal process. We will notify affected users where legally permitted to do so.

Your rights

Depending on your location, you may have rights to access, correct, delete, or obtain a copy of personal data we hold about you, and to object to or restrict certain processing. Vermont residents have additional rights under the Vermont Data Privacy Act (Act 90, effective July 2025).

To exercise any of these rights, email [email protected]. We will respond within 45 days. We will not discriminate against you for exercising your rights.

Data retention

Server access logs: up to 90 days. Security event logs (CrowdSec): decisions expire automatically, typically within 24–48 hours. Cookie consent records: 180 days (stored in your browser, not on our servers).

Security

We use HTTPS for all traffic. Security screening is applied to every request. Cache files containing security decisions are stored on the server in a restricted directory, not accessible via the web.

Changes to this policy

We will update the "Last updated" date at the top of this page when we make material changes. If you return to this page and the date has changed, please review the updated policy.