Legal
Privacy policy
Last updated: July 6, 2026
Who we are
EventFrame is operated by [COMPANY LEGAL NAME], [REGISTERED ADDRESS] (“we”, “us”). We provide a service that lets event hosts collect photos and videos from their guests via a QR code, view them live, and download the originals. For anything in this policy, contact us at support@eventframe.app.
The short version
- We collect what we need to run the service — nothing for advertising.
- Guest uploads belong to the event's host and its guests, not to us.
- Galleries are deleted after the event's retention window ends.
- We never sell personal data.
Data we process
Hosts (account holders). Name, email address, and password hash; the events you configure; billing and payment records (handled by Stripe — we never see full card numbers); support conversations.
Guests (uploaders). The photos and videos you upload, including embedded metadata such as capture time and, if your camera stores it, location (EXIF). Guests do not need an account; we process technical data (IP address, browser type) to deliver the upload and prevent abuse.
Visitors. Standard server logs. We use no advertising trackers and no cross-site analytics cookies.
Why we process it (legal bases)
- To provide the service (contract): storing and delivering uploads, rendering galleries and live walls, preparing ZIP exports, processing payments.
- To keep the platform safe (legitimate interest): abuse prevention, including automated screening of uploads for prohibited content before they appear in a gallery, rate limiting, and CAPTCHA (Cloudflare Turnstile).
- To respond to you (legitimate interest / contract): support requests and service emails. We do not send marketing email without consent.
Guest photos: our role and the host's role
When guests upload media to an event, the host decides what the event collects and who can see it; we store and process that media on the host's behalf. Hosts are responsible for telling their guests that photos are being collected (the event page and QR materials help make this visible). For platform operations — security, moderation, billing — we act as an independent controller.
Who we share data with
We use a small number of processors to run the service:
- Cloudflare (hosting, content delivery, storage, CAPTCHA)
- Stripe (payments)
- [AI MODERATION PROVIDER] (automated content screening of uploads)
- [EMAIL DELIVERY PROVIDER] (transactional email)
Where these providers process data outside the EU/EEA, transfers rely on the EU Commission's adequacy decisions or Standard Contractual Clauses.
Retention and deletion
- Event galleries are kept for the retention window of the plan you purchased and deleted afterwards. Download your ZIP export before the window ends.
- Trial events are deleted when the 3-day trial ends.
- Accounts you delete enter a grace period, after which the account and its data are purged.
- Billing records are kept as long as tax law requires.
Your rights
Under the GDPR you can request access to, correction of, or deletion of your personal data, ask for a copy in a portable format, and object to processing based on legitimate interest. Guests can ask the event's host to remove an upload, or contact us directly. You can also lodge a complaint with your local supervisory authority. To exercise any right, email support@eventframe.app.
Cookies
We use only essential cookies: a session cookie to keep hosts signed in and the cookies Cloudflare Turnstile needs to distinguish humans from bots. No advertising or cross-site tracking cookies.
Changes
If this policy changes materially, we will note it here and, for significant changes, notify hosts by email. Continued use of the service after a change means the updated policy applies.