Privacy policy

Version: v3 · Effective from: 7/29/2026

This policy describes how photos and related data are handled when you use this service, whether as an event host, a guest, or a customer.

Data we collect: customer account and contact details (name, phone, email, and billing details where provided); event details (title, type, date, and an optional cover photo); photos and greetings uploaded by guests, with the uploader-chosen display name where given; order and invoicing records; consent records (terms, privacy, cookie, and marketing decisions); and technical service logs kept for security and auditing.

Purpose of use: personal data is used solely to provide the service and to complete the transaction: setting up and operating the event album, processing the order, issuing an invoice, and sending service messages about the purchase and the event. Data is never sold and is not used for any other purpose; marketing messages are sent only under a separate, explicit consent.

Storage and security: data is held with established cloud providers: a managed database and login system for records, and a dedicated object store for photo files. All traffic to and from the service is encrypted in transit (HTTPS/TLS), and the storage providers encrypt data at rest. Access is restricted through per-row database access policies, short-lived signed links for photo objects, and operator role restrictions; administrative actions are recorded in an audit log.

Payment details: payments are processed on the payment provider's own secure hosted page. Credit card details never reach or pass through this service's servers and are not stored by the service.

Retention and deletion: photos and the event album are kept for the purchased package's retention period and are deleted automatically when it ends. Account, order, and invoicing records are kept as long as applicable bookkeeping and tax law requires. Removal of a specific photo can be requested at any time through the album's removal-request flow or via the contact details in the footer.

Third-party processors: the service relies on a small set of processors, each receiving only the data its role requires: a database and authentication provider, an object-storage provider for photo files, a transactional email provider, an automated content-moderation provider (used only when the moderation add-on is enabled, and never using face recognition), and the payment provider named above.

Your rights: you may request access to, correction of, or deletion of personal data held about you, subject to the operator's legal record-keeping duties. Requests go to the contact details in the footer and are answered within the time the law requires.

Data responsibility: the event host is the controller of the uploaded photos; the operator holds and processes them on the host's behalf, solely to provide the service. Responsibility for obtaining guests' consent to being photographed and to having their photos uploaded rests solely with the event host: for upload, for privacy, for moderation, and for content removal requests.

Minors: responsibility for photographing and uploading photos of minors at an event rests solely with the event host. The service has no dedicated minor-detection mechanism.

Marketing use of photos: photos are never used for the operator's own marketing without a separate, explicit, non-bundled consent from the relevant rights holder, recorded distinctly from consent to this policy.

Data protection officer: whether a formal DPO appointment is required at this service's operating volumes is under review.

Cookies: see the separate cookie policy for how this site's cookie consent gate works.