Skip to content
HackMeridian 2026 Lisbon
Build
Partner Program
Program Proposal Resources
Contribute Events FAQ Apply

Legal

Privacy Policy

Effective 13 August 2026 · Last updated 6 September 2026

Privacy Policy Terms of Service Cookies Settings

Contents

  1. Who we are
  2. Scope of this policy
  3. Information we collect
  4. How we use your information
  5. Legal bases (GDPR)
  6. Cookies & similar technologies
  7. How we share information
  8. Third-party services
  9. Travel & visa support requests
  10. International data transfers
  11. Data retention
  12. How we protect your data
  13. Your rights (EEA / UK)
  14. Your rights (California)
  15. Other U.S. state rights
  16. Children's privacy
  17. Changes to this policy
  18. Contact us

01Who we are

HackMeridian is a developer hackathon held in Lisbon, Portugal, on 25–26 October 2026. The HackMeridian website (the "Site") is operated by Grow with Guava LLC ("Guava", "we", "us", or "our"), which acts as the data controller responsible for the personal information described in this policy. HackMeridian takes place within the Stellar ecosystem; Stellar Development Foundation and event partners are separate organizations with their own privacy practices.

If you have any questions about this policy or how we handle your information, contact us at hello@growwithguava.com.

02Scope of this policy

This policy explains how we collect, use, disclose, and safeguard personal information when you visit the Site, apply to or register for HackMeridian, contact us, or otherwise interact with us online. It applies to the Site and related web pages that link to it.

It does not apply to third-party websites, platforms, or services that we link to or embed — including the registration platform, translation service, and the services of our event partners — each of which is governed by its own privacy policy. See Third-party services below.

03Information we collect

Information you provide to us

When you apply, register, or communicate with us, you may provide:

  • Identity & contact details — name, email address, and (optionally) phone number, country/city, and social or professional profile links.
  • Application & participant details — experience level, track of interest, team information, project ideas, dietary or accessibility needs, and travel-support requests where applicable.
  • Communications — the content of emails or messages you send us, and your preferences for updates about the event.

Most application and registration data is collected through our registration provider, Bizzabo, on our behalf. Please provide only the information requested and avoid sharing sensitive personal information that is not needed for the event.

Information we collect automatically

When you visit the Site, we and our service providers may automatically collect:

  • Device & connection data — IP address, browser type, operating system, and device characteristics.
  • Usage data — pages viewed, referring pages, links clicked, and the dates and times of your visits.
  • Cookie data — identifiers and preferences stored through cookies and similar technologies, subject to your consent. See Cookies.

Information from third parties

We may receive information about you from our registration provider, event partners and sponsors (for example, if you consented to be introduced to them), and analytics or hosting providers that support the Site.

04How we use your information

We use personal information to:

  • Review applications, manage registrations, and run HackMeridian, including team formation, logistics, and travel support.
  • Communicate with you about your application, schedule changes, and important event updates.
  • Provide and maintain the Site, including translation and other on-page features you enable.
  • Understand and improve how the Site and event are used (with your consent for analytics cookies).
  • Send you updates, invitations, or marketing about HackMeridian and future events where you have opted in or where otherwise permitted by law — you can opt out at any time.
  • Protect the security and integrity of the Site, prevent fraud or abuse, and comply with legal obligations.

05Legal bases for processing (GDPR)

If you are in the European Economic Area (EEA) or the United Kingdom, we rely on the following legal bases under the GDPR / UK GDPR:

  • Consent — for non-essential cookies, optional analytics, and marketing communications. You may withdraw consent at any time.
  • Contract — to process your application and let you participate in the event you registered for.
  • Legitimate interests — to operate, secure, and improve the Site and event, provided your rights do not override those interests.
  • Legal obligation — where we must process data to comply with applicable law.

06Cookies & similar technologies

Cookies are small files stored on your device. We use them to run the Site, remember your preferences, and — only with your consent — to understand usage and support marketing. On your first visit, a consent banner lets you accept all, reject non-essential cookies, or set your preferences by category.

You can change your choices at any time via the Cookies Settings link in the footer of every page. We honor the Global Privacy Control (GPC) signal: if your browser sends it, analytics and marketing cookies stay off by default.

CategoryPurposeExamplesConsent?
Strictly necessary Core delivery, security, and remembering your cookie choices. Hosting/CDN (Vercel); consent preference cookie (hm_consent). Always on
Functional Optional conveniences you enable. On-page translation (Transifex); registration widget (Bizzabo). Opt-in
Analytics Aggregated understanding of how the Site is used. Google Analytics 4 and PostHog (load only after you opt in). Opt-in
Marketing Measuring and tailoring event promotion. Google Tag Manager, which carries the X (Twitter) Ads pixel (loads only after you opt in; its cookies are removed when you reject). Opt-in

You can also block or delete cookies through your browser settings, though some parts of the Site may not function as intended if you do.

07How we share information

We do not sell your personal information. We share it only as follows:

  • Service providers (processors) — vendors who process data on our behalf under contract, such as registration, hosting, translation, email, and analytics providers.
  • Event partners & sponsors — only where you have consented (for example, opting in to be contacted by a sponsor) or as clearly disclosed at the point of collection.
  • Legal & safety — where required to comply with law, enforce our terms, or protect the rights, property, or safety of participants, the public, or us.
  • Business transfers — in connection with a merger, acquisition, or reorganization, subject to this policy.

08Third-party services on the Site

The Site relies on the following third-party services, each with its own privacy policy:

  • Vercel — website hosting and content delivery.
  • Bizzabo — event application and registration platform (loads when you open the application flow, subject to your functional-cookie choice).
  • Transifex — on-page translation/localization (subject to your functional-cookie choice).
  • Google Fonts — web font delivery, which involves a request to Google's servers to load fonts.
  • Notion — hosts forms embedded on certain pages, such as partner proposals.
  • Airtable — hosts the speaker, mentor and judge application forms embedded on the Contribute pages.
  • Luma — the events calendar embedded on the Events page; Luma may set its own cookies inside that frame.
  • Google Tag Manager and X (Twitter) Ads — event promotion measurement (subject to your marketing-cookie choice).

We encourage you to review these providers' privacy notices to understand how they handle your information.

Services used for travel & visa support requests

  • Airtable — the operations database that holds support requests and decisions. Airtable is a US company and stores data in the United States.
  • Resend — sends the transactional emails described in the next section (confirmation, requests for missing details, your invitation letter, payout confirmations). It receives your email address, your name and the content of those messages, including the letter as an attachment.
  • Vercel — hosts the Site and runs the server code that handles your request. Request data passes through Vercel in transit and is not stored there beyond short-lived operational logs, which contain no personal data by design.

09Travel & visa support requests

If you ask us for a visa invitation letter, help with travel costs or a place to stay through the travel-support request on the Site, this section describes what happens to that information. The Travel Support Terms set out what the support itself is.

What we collect

  • Screening answers: email address, name, whether you are 18 or over, whether you can attend in person, whether you have registered, country of residence, departure city, what support you need, who referred you, and — for travel support — whether you could attend without support and an estimated fare.
  • Letter details: job title or occupation, company or organisation, and the city and country of the consulate handling your application. We do not collect your passport number, date of birth or nationality on this form; the letter is prepared without them.
  • Stay details: arrival and departure dates, and a yes/no/prefer-to- discuss answer about accessibility. We never ask for medical detail on the form.
  • Payout details, only if a travel grant is approved: a Stellar payment address, whether it is your own wallet or an exchange account, and a memo. A payment address is a public ledger identifier; we treat it as payment-critical rather than secret.
  • Two acknowledgments: that you have read this policy and the Support Terms, and that support is not guaranteed.

How we use it

  • To decide on your request. Every decision is made by a named person; we do not make automated decisions about you.
  • To prepare and send your invitation letter, and to email you about your request: confirmation, anything we are missing, the letter itself, and confirmation of any change to your payout details.
  • To reimburse an approved travel grant to the address you supplied.
  • To match your request to your event registration by email address, so we do not hold two records for one person.
  • To report on the programme in aggregate (how many asked, how many were helped). We share counts with partners who referred applicants, never names.

Your status token

When you submit, we give you a status token and email it to you. We store only a one-way hash of it, so we cannot recover it for you; it lets you check your status and supply missing details without an account. Treat it like a password for that purpose.

Audit trail

We keep a record of what happened to your request and when — submitted, letter sent, details updated, payout address changed — that deliberately records field names and never their values. It exists so that a change to your payout address can be traced, and it contains no personal data beyond the link to your request.

Legal bases

Processing your request and issuing a letter or payment is necessary to take steps at your request before, and to perform, the support arrangement (Art. 6(1)(b) GDPR). Matching to your registration, the audit trail and aggregate reporting rest on our legitimate interest in running the programme accurately and safely (Art. 6(1)(f)). Where local law requires it, we rely on your consent.

Retention

  • Request and decision records: until the event has concluded and all reimbursements are settled, then no later than the period we state here.
  • Payout details: deleted once your reimbursement is paid and reconciled.
  • Invitation letters: the copy we hold is deleted once you have told us the outcome of your application, or at the retention limit above, whichever is sooner.
  • The audit trail, which holds no values, may be kept for the same period as our financial records.

Where it is processed

Guava is in the United States and the services above process data there. If you are in the EEA or UK, see International data transfers for the safeguards we rely on.

10International data transfers

We are based in the United States, and our service providers may process data in the United States and other countries. Where we transfer personal information from the EEA, UK, or Switzerland to a country that has not been deemed to provide adequate protection, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum, where applicable). You may request more information about these safeguards using the contact details below.

11Data retention

We keep personal information only for as long as needed for the purposes described in this policy — to run the event, meet legal, accounting, or reporting requirements, and resolve disputes. Application and registration data is generally retained for the duration of the event cycle and a reasonable period afterward, after which it is deleted or anonymized. Marketing preferences are kept until you opt out.

12How we protect your data

We use reasonable technical and organizational measures designed to protect personal information against loss, misuse, and unauthorized access — including HTTPS encryption in transit and access controls with our providers. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

13Your rights (EEA / UK)

If you are in the EEA or UK, you have the right to:

  • Access the personal information we hold about you and receive a copy.
  • Rectify inaccurate or incomplete information.
  • Erase your information ("right to be forgotten") in certain circumstances.
  • Restrict or object to certain processing, including direct marketing.
  • Data portability — receive your data in a portable format.
  • Withdraw consent at any time, without affecting prior processing.

To exercise any of these rights, email hello@growwithguava.com. You also have the right to lodge a complaint with your local data protection authority. In Portugal this is the Comissão Nacional de Proteção de Dados (CNPD); in the UK, the Information Commissioner's Office (ICO).

14Your rights (California — CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA, gives you specific rights regarding your personal information.

Categories of personal information we collect

CategoryExamplesCollected?
IdentifiersName, email, IP addressYes
Customer recordsPhone number, professional details you provideYes, if provided
Internet/network activityPages viewed, usage dataYes
GeolocationApproximate location from IP addressYes (coarse)
Professional/employmentExperience, role, team infoYes, if provided
Sensitive personal informationWe do not intentionally collect sensitive PINo

We collect these categories for the business purposes described in How we use your information, and disclose them to service providers as described in How we share information.

Your California rights

  • Know / access — request the categories and specific pieces of personal information we have collected about you.
  • Delete — request deletion of your personal information, subject to exceptions.
  • Correct — request correction of inaccurate personal information.
  • Opt out of sale/sharing — we do not sell or share personal information as those terms are defined under the CPRA. We also honor the Global Privacy Control (GPC) signal.
  • Limit use of sensitive PI — we do not use sensitive personal information for purposes that require this option.
  • Non-discrimination — we will not discriminate against you for exercising your rights.

To exercise these rights, email hello@growwithguava.com. We will verify your request using the information we hold, and you may use an authorized agent where permitted.

15Other U.S. state privacy rights

Residents of other U.S. states with comprehensive privacy laws (such as Virginia, Colorado, Connecticut, Utah, and Texas) may have similar rights to access, correct, delete, and opt out of targeted advertising or the sale of personal information. We do not sell personal information or use it for cross-context behavioral advertising. To exercise any available rights, contact us using the details below.

16Children's privacy

HackMeridian and the Site are intended for adults and are not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, contact us and we will delete it.

17Changes to this policy

We may update this policy from time to time. When we do, we will revise the "Last updated" date above and, for material changes, provide a more prominent notice. Your continued use of the Site after an update means you accept the revised policy.

18Contact us

For any privacy question or to exercise your rights, reach us at:

HackMeridian — Privacy

Operated by Grow with Guava LLC

Email: hello@growwithguava.com

Governing law: State of Delaware, United States

HackMeridian 2026 Lisbon
Build Program Lisbon Partner Program Contribute Events FAQ
© 2026 HackMeridian. All rights reserved. Privacy Policy Terms of Service Cookies Settings