DRAFT — this page is a factual skeleton of how the service works. Have it reviewed (and completed with company details) by someone qualified before charging the first customer.
Privacy
This service exists to share event photos with the people who were there, and with no one else. That principle shapes everything below.
What we store
- Photos and videos uploaded to an event, on our server in the EU, until the event's gallery lifetime ends — then they are permanently deleted, as promised at purchase.
- Event owners: your email address (used to sign in — we never store passwords for customers), your events, and your order history.
- Guests: no account, no name, no email. A random identifier stored in your own browser lets you delete your own uploads; it identifies your device, not you.
- Logs: operational logs never contain album links. Rate-limiting counters keyed by IP address protect galleries from guessing and expire within hours.
What we never do
- No advertising, no analytics scripts, no tracking pixels.
- No face recognition of you or your guests, ever.
- Gallery pages are excluded from search engines and are never handed to third parties — no fonts, scripts or images load from other domains on any guest page.
Who processes data on our behalf
- Paddle — payment processing, as merchant of record (your card details go to Paddle, never to us).
- Resend — sending transactional email (sign-in codes, receipts, expiry notices).
- [HOSTING PROVIDER] — the server the service runs on.
Your rights
Download everything we hold about your account from your dashboard (your data as JSON, your photos as zip archives). To have your account or an event deleted before its natural expiry, email [CONTACT ADDRESS] — deletion is performed, not queued.
Cookies
One strictly necessary session cookie, only when you sign in as an event owner. Guests get no cookies at all. There is nothing to consent to, so there is no banner.
[COMPANY NAME · ORG NUMBER · ADDRESS · CONTACT]