Gluebox LLC ("we," "us," "our") operates gluebox.com. This policy describes what personal data we collect, why, and your rights over it. We keep this deliberately plain: no hidden processing, no data brokers, no advertising networks.
Last updated: August 2026
Who we are
Gluebox LLC is a software development company based in Philadelphia, PA, building calendar, reservation, and event systems on Drupal. Contact us at [email protected] for privacy-related questions.
Data we collect automatically
When you visit any page, our web server records a standard access log entry containing your IP address, the page requested, your browser and operating system, and the date and time. These logs are retained for up to 90 days and used solely for security and operational troubleshooting. They are not shared with third parties.
Security screening
Each request is screened by a self-hosted CrowdSec security layer. Your IP address is checked against a private threat-intelligence database hosted on our own infrastructure (not the CrowdSec community cloud). If your IP has been flagged for abusive behaviour, you may be asked to complete a brief human-verification challenge or, in severe cases, see an access-denied page. No information about you is sent to CrowdSec’s external services.
If you pass the human-verification challenge, a short-lived cookie (gluebox_crowdsec_verified) is set in your browser so you are not re-challenged on subsequent pages. This cookie expires after 12 hours and contains only a cryptographic timestamp — no personal data.
Cookies
We use a consent manager (Klaro) so you can choose which optional cookies are set. The table below describes all cookies this site may set.
| Cookie | Purpose | Duration | Consent required? |
|---|---|---|---|
SESS… / SSESS… |
Drupal session — keeps you logged in and enables forms to work correctly. | Session (closes with browser) | No — strictly necessary |
klaro |
Stores your cookie consent choices so you are not asked every page load. | 180 days | No — strictly necessary |
gluebox_crowdsec_verified |
Records that you passed a security challenge, preventing repeated interruptions. | 12 hours | No — strictly necessary |
| YouTube cookies | Set when you play an embedded YouTube video. Subject to Google’s privacy policy. | Varies (set by Google) | Yes — optional |
| Vimeo cookies | Set when you play an embedded Vimeo video. Subject to Vimeo’s privacy policy. | Varies (set by Vimeo) | Yes — optional |
You can review or change your consent choices at any time using the cookie settings button in the site footer.
Analytics
We do not currently run any analytics service on gluebox.com. Matomo is installed on our infrastructure but is not active on this site. If we enable it in the future, we will update this policy and seek your consent via the Klaro consent manager before setting any analytics cookies.
Embedded content
Pages may include videos hosted on YouTube or Vimeo. These embeds are blocked by default until you grant consent. Once you do, the third-party provider may set their own cookies and collect data according to their privacy policies (linked in the table above).
Data sharing
We do not sell personal data. We do not share data with advertising networks, data brokers, or any third party except as described above (i.e., YouTube or Vimeo when you explicitly consent to embedded video).
We may disclose data if required by law or a valid legal process. We will notify affected users where legally permitted to do so.
Your rights
Depending on your location, you may have rights to access, correct, delete, or obtain a copy of personal data we hold about you, and to object to or restrict certain processing. Vermont residents have additional rights under the Vermont Data Privacy Act (Act 90, effective July 2025).
To exercise any of these rights, email [email protected]. We will respond within 45 days. We will not discriminate against you for exercising your rights.
Data retention
Server access logs: up to 90 days. Security event logs (CrowdSec): decisions expire automatically, typically within 24–48 hours. Cookie consent records: 180 days (stored in your browser, not on our servers).
Security
We use HTTPS for all traffic. Security screening is applied to every request. Cache files containing security decisions are stored on the server in a restricted directory, not accessible via the web.
Changes to this policy
We will update the "Last updated" date at the top of this page when we make material changes. If you return to this page and the date has changed, please review the updated policy.