Privacy notice
How GuestAlbum handles photos, videos and the small amount of personal data it needs — in plain English, because that is the law’s requirement as well as ours.
Dated 20 September 2026 · Terms of service · Contact
Who we are
This notice explains what personal data GuestAlbum handles and why. The controller for the data described under “Organisers” and “Running the service” is Jack Devonshire, email support@guestalbum.app. We have no data protection officer; contact the email above.
Two roles
GuestAlbum works for two kinds of people, and the data is handled differently:
- Organisers — the person who creates and pays for an event. We decide how their account, payment and support data is used; we are the controller for it.
- Guests — people who add photos and videos, join a recording, or look at a shared album. The organiser collects that content for their own purposes and we host it for them. For an individual organising a family occasion this is their own personal activity; for a business organiser we act as their processor under the terms in our Terms. Either way we only do with the content what the service needs: store it, make display copies, analyse it for Highlights, show it to the people the organiser chooses, and delete it on schedule.
What we collect
From organisers: your email address (that is your login), the events you create (name, date, message, page design), your orders (what you bought, when, how much — Stripe holds the card details, we never see them), a delivery name, address and phone number (if you give one) when you order printed cards, support messages, and the record of what you did in your dashboard.
From guests: the photos, videos and recordings you add, with whatever the file itself carries (the time it was taken, the camera, and location coordinates if your phone put them in the file — we strip them from the copies we display but keep the original file exactly as it was); your first name if you type one in; and a random token in a cookie that ties your uploads to your phone so you can see and remove them. We do not ask guests for an email address or an account.
From everyone: the technical data any website receives — IP address, browser, the pages requested — kept in short-lived logs for security and to keep the service working.
Why, and the legal basis
- To run your event and deliver what you paid for — the contract with you (UK GDPR Article 6(1)(b)).
- To take payment, keep accounts and meet tax rules — legal obligation (6(1)(c)); order records are kept for six years.
- To email you about your event: it went live, uploads have closed, storage is ending — the contract, and our legitimate interest in you not losing your photos (6(1)(f)). These are service emails, not marketing. We send no marketing without asking first.
- To keep the service secure, enforce fair use and stop abuse — legitimate interest (6(1)(f)).
- To answer support requests and handle rights requests — legitimate interest and legal obligation.
- For Find me — your explicit consent, given on your own phone at the moment you use it (Article 9(2)(a)); see below.
We do not sell personal data, do not share it with advertisers, and make no decisions about you by automated means that have legal or similarly significant effects.
Highlights and faces
When an organiser opens their album, their own browser measures each photo — sharpness, lighting, and how many faces are in it — to pick out the best. We store those measurements (a score, a face count, an image fingerprint); none of them identifies anyone, and we never build a face index or identify people across events.
“Find me” in a shared album is different and entirely optional. A guest takes a live selfie on their own phone — never a photo from their library — and their phone compares it with the album to find the photos they are in. The selfie, the face description the phone works out from it, and the list of matches never leave the device and are not saved anywhere; our servers never receive them. Because of that we do not hold biometric data about anyone. The guest confirms before it runs that the face is their own and that they are happy for it to be matched on their device; other people’s faces are examined only to check for a match, with nothing about them kept. If you would rather your face were never compared even on a guest’s own phone, tell the organiser, who can hide your photos from the shared album.
Who handles the data for us
A small number of providers run parts of the service under contract with us; they may only use the data to provide that service:
- Cloudflare — hosting the application and storing photos, videos and recordings (R2), in buckets set to EU jurisdiction. Cloudflare also routes email sent to our support address.
- Supabase — the database and sign-in, hosted in the EU.
- Mailtrap — sending our emails (your sign-in link, event emails).
- Stripe — payments. Stripe is the controller for the card data it collects on its own pages and may process data in the United States under the UK’s transfer rules (the International Data Transfer Addendum).
- Prodigi (prodigi.com, a UK print-on-demand company) — printing and posting the table cards you order: they receive your name, delivery address and phone number (if given) and the card design — not your email address — keep the print file for 30 days, and send us back the order’s progress and the parcel’s carrier and tracking number.
Where a provider processes data outside the UK we rely on the UK adequacy regulations (for the EEA) or the International Data Transfer Agreement/Addendum. We do not share personal data with anyone else, except where the law requires it or to protect someone’s safety.
How long we keep things
- Photos, videos and recordings: until the event’s expiry date — 90 days from the event date on Event, 6 months on GuestAlbum Plus (or from payment if that came after) — plus a 14-day grace period; then deleted for good, with the thumbnails, display copies and measurements made from them.
- Guests’ names and tokens: deleted with the event. An event that is never paid for holds no media and is removed 90 days after its date.
- Organiser accounts: until you close your account or ask us to; events you delete are purged on the same schedule as expired ones.
- Orders and invoices: six years, for tax law.
- Delivery addresses on printed-card orders: the street address and phone number are removed from the order 90 days after the pack was posted (or the order was cancelled or refunded) — long enough to sort out a damaged pack; the name and town stay with the order record.
- Support messages: two years after the conversation ends.
- Server and security logs: no more than 30 days.
Deletion is real: it is done by a scheduled job that removes the stored files, and every deletion is logged.
Security
Everything travels over encrypted connections. Files are uploaded straight from the guest’s phone to storage using short-lived signed links, so no one else can put things in your album; storage is never publicly listable, and each file is served only to someone the organiser has allowed. Organiser data is protected by row-level rules in the database, so one account can only ever see its own events. Only the person running GuestAlbum has administrative access, and every administrative action is logged. If a breach ever affected your data we would tell you, and the ICO where required, without undue delay.
Your rights
Under UK data protection law you can ask to see the personal data we hold about you, to correct it, to have it deleted, to limit or object to how we use it, to receive it in a portable form, and to withdraw any consent you have given. Organisers can do most of this themselves: edit or delete an event, download everything, close the account. Guests can remove their own uploads through their private link until uploads close and can ask the organiser, or us, to remove a photo of them afterwards.
To exercise any right, email support@guestalbum.app. We answer within a month. If you are not happy with how we handled your data you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113 — we would appreciate the chance to put it right first.
Children
GuestAlbum is not aimed at children and you must be 18 to create an event. Children are often in the photos guests take at family events; the organiser is responsible for making sure the parents are content with that, and can hide or delete any photo. If you are a parent and want a photo of your child removed, contact the organiser or us.
Changes
We update this notice when the service changes; the date at the top of the page tells you when. Anything that materially changes how we use your data is also announced by email to organisers with live events. This version is dated 20 September 2026.
Prices, limits and day counts on this page come from the same configuration the app uses, so they can’t drift from what you’re sold. Fair use: 500 GB per event; photos up to 50 MB; videos up to 1 hour or 25 GB; events may be dated up to 18 months ahead (548 days).