PRIVACY & PROTECTION

Privacy Policy

Last updated: August 2026

1. Overview & Data Ownership

Snapsy Events ("Snapsy", "we", "our") respects your privacy and data ownership. We provide an app-free photo sharing platform where event hosts collect photos and memories from guests via QR codes and instant AI face matching. We do not sell your personal data or uploaded photos to anyone. We do use a small number of trusted service providers to operate the platform (payment processing, storage, email, push notifications, error monitoring) — see Section 9, Third-Party Service Providers, for the full list of who they are and what they handle.

2. Information We Collect

  • Account & Event Metadata: Email address, host name, event titles, event dates, and custom venue branding.
  • Uploaded Media Content: Photos, short video clips, and voice audio notes uploaded by hosts or event guests.
  • AI Facial Embeddings: When AI face search is enabled for an event, mathematical vector embeddings are extracted solely to allow guests to retrieve photos they appear in.
  • Contact Details: If you reach out via our contact form, we collect your name, email address, and optionally your phone number to respond to your inquiry.
  • Technical & Analytics Data: IP addresses, browser types, and device telemetry used for security monitoring, rate limiting, and (where you've accepted optional cookies) product analytics — see Section 8, Cookies & Analytics, below.

3. How We Use Your Data

Your data is processed exclusively to deliver your live event galleries, power live venue slideshows, index guest photos using AI face matching, and enable high-resolution event archive downloads. We never train public AI models on your private photos.

4. Facial Recognition Data Processing

When a host enables AI Face Search or Best Shot Selection for their event, facial embeddings may be generated automatically for every uploaded photo — not only for guests who actively search for their own photos — so the host's gallery can be organized and searched. Embeddings are stored in our database as vector data scoped strictly to your private event capsule, protected by strict Row-Level Security (RLS) policies. They are never sold, shared publicly, or used to train any external or third-party AI model, and face-matching runs on our own infrastructure — no photo or embedding is sent to an external AI provider. Guests can delete their own face index data at any time directly from the AI Face Search screen of a checked-in event, or via the deletion request process in Section 6 below.

5. Data Retention

We keep uploaded photos, videos, and voice notes for a set number of days after your event ends, based on the plan the event was created on. Once that period passes, media is automatically and permanently deleted from our systems — this happens automatically, without anyone needing to request it. As of this policy's last update, the retention windows are:

  • Basic plan: 7 days after your event ends.
  • Standard plan: 30 days after your event ends.
  • Premium plan: 45 days after your event ends.

Your event dashboard, guest list, and analytics remain accessible after media is purged — only the photos, videos, and voice notes themselves are removed. We'll email and notify you before this happens so you have time to download or upgrade. These windows may be updated from time to time; the current period for your specific event is always shown on your event dashboard.

6. Self-Service Data Deletion (GDPR & CCPA)

Under GDPR, CCPA, and global privacy standards, hosts and guests have full control to purge their uploaded media and facial vector indexes. You can submit a deletion request anytime via our Data Deletion Request Page. All associated media and vector data will be permanently wiped within 48 hours.

7. Data Security & Storage

Media files are encrypted both in transit (TLS 1.3) and at rest (AES-256) using Supabase PostgreSQL databases and enterprise cloud infrastructure.

8. Cookies & Analytics

We use a small set of cookies to keep you signed in and to remember your cookie preference. With your consent (shown via the cookie banner on your first visit, which you can change any time by clearing your browser's site data), we also use:

  • Sentry — error and performance monitoring, so we can detect and fix bugs. Sentry may receive technical details about your browser and the error that occurred, not your uploaded photos.
  • Microsoft Clarity — optional product-usage analytics (e.g. anonymized click and scroll behavior) to help us improve the site. Declining the cookie banner keeps Clarity disabled for your visit.

Neither service is used for advertising, and neither receives your event photos, videos, or facial embeddings.

9. Third-Party Service Providers

We use the following trusted service providers to operate Snapsy. Each only receives the specific data needed to perform its function — none of them receive your uploaded photos, videos, voice notes, or facial embeddings unless explicitly noted:

  • Supabase — our database and account authentication provider. Stores your account details and event data.
  • Cloudflare R2 — our media storage provider. This is where your uploaded photos, videos, and voice notes are actually stored.
  • Razorpay — our payment processor. Handles your name, email, phone number, and payment amount when you purchase a plan. Snapsy never stores your full card or payment details ourselves.
  • Firebase Cloud Messaging (Google) — powers optional push notifications (e.g. "new photo uploaded"). Receives a device notification token, not your photos.
  • Resend — sends transactional emails (receipts, check-in confirmations, password resets) on our behalf.
  • WhatsApp Business Platform (Meta) — where a host's plan includes this, sends a pre-approved template message (e.g. a gallery link) to a phone number the host enters, on the host's request. That number is often a guest's, since this is how a host invites or reminds a specific guest.
  • Sentry and Microsoft Clarity — see Section 8, Cookies & Analytics, above.

10. Children's Personal Data

Snapsy is used to capture memories at weddings, birthdays, family gatherings, and other events where children may appear in photos, videos, or voice notes uploaded by guests. We do not knowingly use images or information about children for advertising, behavioral tracking, or profiling of any kind — Snapsy does not run ad-targeting on any personal data, child or adult. If you are a parent or guardian and want a photo of your child removed, you can request it through our Data Deletion Request Page or by contacting us directly (Section 11 below).

11. Contact & Grievance Officer

If you have privacy questions, regulatory inquiries, or a complaint about how your personal data has been handled, contact our Grievance Officer, Syed Farrukh, at privacy@snapsy-events.com. We aim to acknowledge grievances within 7 days and resolve them within 30 days.