Privacy Policy
Last updated: 11 August 2026
1. Who is the data controller
For account data (your email, payment records), the data controller is Monika Mąka, an individual operating "Wedding Photos" at ul. Granitowa 20, 42-202 Częstochowa, Poland. Contact: [email protected]. For guest-uploaded photos, the account holder (the couple who created the gallery) determines what happens with their event's photos; we process them on the account holder's behalf.
2. What we collect
- Account holder: email address, hashed password, event settings (header text, event date, language).
- Guest uploads: the photos themselves. We don't require guests to create an account or provide personal details to upload - though a photo of someone's face is personal data under GDPR.
- Payment data: handled directly by Stripe - we only receive your email and the amount paid, never your card details.
3. Legal basis
Account data is processed under contract (Art. 6(1)(b) GDPR) - we need it to provide the service you signed up for. Guest photos at a private event are processed under legitimate interest (Art. 6(1)(f)) - guests attending a wedding reasonably expect photos to be taken and shared with those present.
4. Who we share data with (processors)
- Stripe - payment processing.
- Resend - transactional emails (verification, deletion reminders).
- Google - Drive API storage, only for couples on the Flex tier who choose to connect their own Google Drive; this is opt-in per account via OAuth.
- Our hosting provider, for infrastructure only.
We do not sell data to anyone.
5. Where your data is stored
Our primary database and photo storage run on our own infrastructure in the EU. Some processing is necessarily handled outside the EU by named sub-processors: Stripe (payments) and Resend (transactional email) are US-based, and for couples who opt into the Flex storage tier, photos are stored via Google Drive (also US-based). Each of these processors operates under the EU-US Data Privacy Framework and/or Standard Contractual Clauses as their GDPR safeguard for international data transfers. For details on backup storage location, contact us at the address above.
6. How long we keep data
Galleries (photos + account) are kept for 12 months after the event's upload window closes (31 days from the event start date), then automatically and permanently deleted, with a reminder email 14 days beforehand. You can delete your account and all photos immediately at any time from your dashboard.
Every photo you or your guests upload also has EXIF, GPS, and ICC metadata automatically stripped when it's re-encoded on upload, so location and device data embedded by phones and cameras never ends up stored or shared.
7. Your rights
You have the right to access, correct, delete, or export your data, and to object to processing. Account holders can exercise most of these directly from the dashboard; for anything else, or if you're a guest whose photo was uploaded, email us at the address above. You also have the right to lodge a complaint with the Polish data protection authority (UODO - Urząd Ochrony Danych Osobowych / President of the Personal Data Protection Office).
8. Cookies
We use two cookies for everyone: one to keep you logged in (
user_session) and one to remember your language choice (
user_locale). If you connect your Google Drive on the Flex tier,
we also set a short-lived cookie (google_oauth_state) during that
connection step only, to protect against cross-site request forgery. All of
these are strictly necessary for the site to function and don't require
consent under ePrivacy rules. We don't use analytics or marketing cookies.