Privacy Policy
Last updated: 16 August 2026
1. Who is the data controller
For account data (your email, payment records), the data controller is Monika Mąka, an individual operating "Wedding Photos" at ul. Granitowa 20, 42-202 Częstochowa, Poland. Contact: [email protected]. For guest-uploaded photos, the account holder (the couple who created the gallery) determines what happens with their event's photos; we process them on the account holder's behalf. Under Article 28 GDPR, the account holder is the data controller for guest-uploaded photos and we act only as their processor - every account holder confirms this relationship with a dedicated checkbox when they register (see Terms of Service, section 6).
2. What we collect
- Account holder: email address, hashed password, event settings (header text, event date, language).
- Guest uploads: the photos themselves, and on the Flex plan, videos too if the account holder has turned that on (off by default). We don't require guests to create an account or provide personal details to upload - though a photo or video of someone's face is personal data under GDPR. It isn't biometric data unless it's processed with technology designed to uniquely identify someone (e.g. facial recognition) - we don't do that. A photo or video can still incidentally reveal special-category details (health, religious, or ethnic characteristics, for example) or show minors; the account holder is responsible for any additional consent that requires from guests or guardians.
- Payment data: handled directly by Stripe - we only receive your email and the amount paid, never your card details.
- Virtual photobooth (only if the account holder turns this on, off by default): the guest's browser asks for camera access and the capture happens entirely on the guest's own device - we never receive a live video feed, only the single finished photo the guest chooses to upload, which is stored exactly like any other guest upload.
- Digital guestbook (only if the account holder turns this on, off by default): the message and optional display name a guest chooses to leave are shown publicly in the gallery to anyone with the gallery link. We don't verify the name, and it isn't linked to any account or used to identify who uploaded which photos.
- Aggregate view counts (only if the account holder turns this on, off by default): we count how many times the gallery page and individual photos are loaded, as simple numeric counters. This isn't visitor tracking - no cookie, IP address, or other identifier is used, and there's no way to tell which guest generated a view.
3. Legal basis
Account data is processed under contract (Art. 6(1)(b) GDPR) - we need it to provide the service you signed up for. Guest photos at a private event are processed under legitimate interest (Art. 6(1)(f)) - guests attending a wedding reasonably expect photos to be taken and shared with those present. Because the account holder is the controller for that data (see section 1), our own handling of it is governed by a data processing agreement under Article 28 GDPR, which these terms and the account holder's registration confirmation together satisfy rather than a separately signed contract.
4. Who we share data with (processors)
- Stripe - payment processing.
- Resend - transactional emails (verification, deletion reminders).
- Google - Drive API storage for photos, and videos where the account holder has turned that on, only for couples on the Flex tier who choose to connect their own Google Drive; this is opt-in per account via OAuth.
- Our hosting provider, for infrastructure only.
We do not sell data to anyone.
5. Where your data is stored
Our primary database and photo storage run on our own infrastructure in the EU. Some processing is necessarily handled outside the EU by named sub-processors: Stripe (payments) and Resend (transactional email) are US-based, and for couples who opt into the Flex storage tier, photos - and videos, if enabled - are stored via Google Drive (also US-based). Each of these processors operates under the EU-US Data Privacy Framework and/or Standard Contractual Clauses as their GDPR safeguard for international data transfers. For details on backup storage location, contact us at the address above.
6. How long we keep data
Galleries stay accessible for 12 months after the event's upload window closes. The upload window itself runs from 00:00 UTC on your event's start date through 23:59 UTC on the 31st day after that (32 calendar days in total, since the start date counts as day one). What happens after the 12 months depends on your plan. Both the deletion and its 14-day-earlier reminder email are triggered by our nightly maintenance job, which runs once a day at 03:00 UTC - so each one goes out during the first nightly run on or after its due date, not at the exact minute the deadline is reached. On the Basic, Standard, and Premium plans, photos are stored on our own servers - the gallery and all photos are then automatically and permanently deleted. On the Flex plan, your photos (and videos, if you've turned that on) were never stored on our servers - they go straight to your own Google Drive as guests upload them - so nothing is deleted; we simply disconnect our app's access to your Drive account at the 12-month mark and email you the name of the Drive folder your photos are already saved in. You can delete your account (and, on non-Flex plans, all photos) immediately at any time from your dashboard.
Every photo you or your guests upload also has EXIF, GPS, and ICC metadata automatically stripped when it's re-encoded on upload, so location and device data embedded by phones and cameras never ends up stored or shared. On the Flex plan, if the account holder has turned on video uploads (off by default), the same applies to videos: we strip embedded location and device metadata from the video file before it reaches your Google Drive - without re-encoding or compressing the video itself, so the quality your guests recorded stays exactly as it was.
7. Your rights
You have the right to access, correct, delete, or export your data, and to object to processing. Account holders can exercise most of these directly from the dashboard; for anything else, or if you're a guest whose photo was uploaded, email us at the address above. You also have the right to lodge a complaint with the Polish data protection authority (UODO - Urząd Ochrony Danych Osobowych / President of the Personal Data Protection Office).
8. Data breaches
If a personal data breach occurs that's likely to put your rights or freedoms at risk, we'll notify the Polish data protection authority (UODO) within 72 hours of becoming aware of it, as required by Article 33 GDPR, and notify affected users directly without undue delay where the breach is likely to result in a high risk to them (Article 34 GDPR).
9. Cookies
We use two cookies for everyone: one to keep you logged in (
user_session) and one to remember your language choice (
user_locale). If you connect your Google Drive on the Flex tier,
we also set a short-lived cookie (google_oauth_state) during that
connection step only, to protect against cross-site request forgery. When you
pay through checkout, Stripe sets its own short-lived cookies to detect fraud
and card testing; see
Stripe's cookie policy for details. All of these are strictly necessary for the site or the payment
to function and don't require consent under ePrivacy rules. We don't use
analytics or marketing cookies. The aggregate view counts described in section 2
are simple server-side counters, not analytics cookies or tracking scripts -
nothing is set or tracked in your browser.
10. How your gallery link works
Your gallery's link and QR code aren't just a shortcut - they're the only thing standing between your event's photos and anyone who has them. We don't ask guests to log in or prove who they are: whoever holds the link can upload photos during the 31-day upload window and, unless the account holder hides the gallery from their dashboard, view every photo already uploaded, for as long as the gallery exists. If the link ends up somewhere more public than intended (posted online, forwarded outside the guest list, a QR code photographed by a stranger), anyone who finds it gets the same access. Account holders can hide the gallery from guest viewing at any time from the dashboard, and can generate a new access link/QR code from the "Danger Zone" if the old one is compromised - existing photos aren't affected either way.