Privacy notice

How GuestAlbum handles photos, videos and the small amount of personal data it needs — in plain English, because that is the law’s requirement as well as ours.

Dated 20 September 2026 · Terms of service · Contact

Who we are

This notice explains what personal data GuestAlbum handles and why. The controller for the data described under “Organisers” and “Running the service” is Jack Devonshire, email support@guestalbum.app. We have no data protection officer; contact the email above.

Two roles

GuestAlbum works for two kinds of people, and the data is handled differently:

What we collect

From organisers: your email address (that is your login), the events you create (name, date, message, page design), your orders (what you bought, when, how much — Stripe holds the card details, we never see them), a delivery name, address and phone number (if you give one) when you order printed cards, support messages, and the record of what you did in your dashboard.

From guests: the photos, videos and recordings you add, with whatever the file itself carries (the time it was taken, the camera, and location coordinates if your phone put them in the file — we strip them from the copies we display but keep the original file exactly as it was); your first name if you type one in; and a random token in a cookie that ties your uploads to your phone so you can see and remove them. We do not ask guests for an email address or an account.

From everyone: the technical data any website receives — IP address, browser, the pages requested — kept in short-lived logs for security and to keep the service working.

Highlights and faces

When an organiser opens their album, their own browser measures each photo — sharpness, lighting, and how many faces are in it — to pick out the best. We store those measurements (a score, a face count, an image fingerprint); none of them identifies anyone, and we never build a face index or identify people across events.

“Find me” in a shared album is different and entirely optional. A guest takes a live selfie on their own phone — never a photo from their library — and their phone compares it with the album to find the photos they are in. The selfie, the face description the phone works out from it, and the list of matches never leave the device and are not saved anywhere; our servers never receive them. Because of that we do not hold biometric data about anyone. The guest confirms before it runs that the face is their own and that they are happy for it to be matched on their device; other people’s faces are examined only to check for a match, with nothing about them kept. If you would rather your face were never compared even on a guest’s own phone, tell the organiser, who can hide your photos from the shared album.

Cookies

We use only the cookies the service needs to work — no analytics cookies, no advertising cookies, and nothing that follows you to other sites, so we don’t ask you to accept them (they are “strictly necessary” under PECR):

Who handles the data for us

A small number of providers run parts of the service under contract with us; they may only use the data to provide that service:

Where a provider processes data outside the UK we rely on the UK adequacy regulations (for the EEA) or the International Data Transfer Agreement/Addendum. We do not share personal data with anyone else, except where the law requires it or to protect someone’s safety.

How long we keep things

Deletion is real: it is done by a scheduled job that removes the stored files, and every deletion is logged.

Security

Everything travels over encrypted connections. Files are uploaded straight from the guest’s phone to storage using short-lived signed links, so no one else can put things in your album; storage is never publicly listable, and each file is served only to someone the organiser has allowed. Organiser data is protected by row-level rules in the database, so one account can only ever see its own events. Only the person running GuestAlbum has administrative access, and every administrative action is logged. If a breach ever affected your data we would tell you, and the ICO where required, without undue delay.

Your rights

Under UK data protection law you can ask to see the personal data we hold about you, to correct it, to have it deleted, to limit or object to how we use it, to receive it in a portable form, and to withdraw any consent you have given. Organisers can do most of this themselves: edit or delete an event, download everything, close the account. Guests can remove their own uploads through their private link until uploads close and can ask the organiser, or us, to remove a photo of them afterwards.

To exercise any right, email support@guestalbum.app. We answer within a month. If you are not happy with how we handled your data you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113 — we would appreciate the chance to put it right first.

Children

GuestAlbum is not aimed at children and you must be 18 to create an event. Children are often in the photos guests take at family events; the organiser is responsible for making sure the parents are content with that, and can hide or delete any photo. If you are a parent and want a photo of your child removed, contact the organiser or us.

Changes

We update this notice when the service changes; the date at the top of the page tells you when. Anything that materially changes how we use your data is also announced by email to organisers with live events. This version is dated 20 September 2026.

Prices, limits and day counts on this page come from the same configuration the app uses, so they can’t drift from what you’re sold. Fair use: 500 GB per event; photos up to 50 MB; videos up to 1 hour or 25 GB; events may be dated up to 18 months ahead (548 days).