Legal approval is still required
This page documents implemented product behavior and provides an operational request channel. It is not the final approved privacy notice. Counsel must approve the controller identity, lawful bases, retention schedule, transfers, subprocessors, complaint routes, and final wording.
Missing approval configuration: controller name, privacy contact email, notice version, effective date.
Privacy and data rights
Clear controls for shared event media.
Notice version UNAPPROVED-DRAFT. The configured controller is pending legal confirmation.
Data used by the product
Host account details, event settings, guest nicknames, photos and videos, capture and upload metadata, purchase records, moderation reports, share-link activity, and security/audit records.
How the product uses it
To create and operate events, accept and organise uploads, enforce event controls, process purchases, moderate content, secure the service, and respond to privacy requests. Counsel must approve the lawful basis for each purpose.
Who can access event media
The event host can view and download event uploads. Guests see media only when the host’s gallery visibility and reveal settings allow it. Time-limited share links can expose a gallery to anyone who receives the secret link until it expires, reaches its download cap, or is revoked.
Retention and deletion
Hosts can choose a permanent-deletion date at least 24 hours in the future. Automated deletion runs only after the event is ended or archived, and pauses when an event has an active legal hold or an unresolved privacy request. No default retention period is imposed.
Data-rights handling
Signed-in hosts and joined guests can request access, correction, deletion, restriction, objection, portability, consent withdrawal, or appeal. Requests receive a reference and status trail. Identity may be verified through a separate secure process before data is disclosed or changed.
International transfers and providers
The app currently relies on hosting, database/storage, analytics, and payment providers configured by the operator. The final provider list, processor terms, hosting regions, transfer safeguards, and subprocessor disclosures require legal and operational approval.
Data-rights requests
Submit a request and keep its reference code. Identity verification may be required before data is disclosed, corrected, or deleted.
Checking your session…
Are you pictured in event media?
You can ask for a photo or video to be located and removed even if you never joined the event.
Contact and complaints
A controller privacy contact and applicable supervisory-authority complaint routes have not yet been legally approved or configured.