This content is currently undergoing legal review and is not yet a final legal document.

Privacy and data protection

Last updated: July 31, 2026

What we do with personal data, on what legal basis, for how long, and what you can require of us. This page covers two regimes at once: the European Union and the United States.

What we process

One row per processing operation we actually carry out. Nothing here is aspirational: each row was checked against the code before being published.

What we process
PurposeLegal basisDataPeople concernedRetentionRecipients
Index facial templates so a guest can find their own photosExplicit consent (GDPR art. 9(2)(a))Facial templatesPhotographed guestsSame lifetime as the event photographsAmazon Web Services (Rekognition)
Compare a selfie against the event to return the guest's photosExplicit consent (GDPR art. 9(2)(a))Comparison selfie · Email given for a searchPhotographed guestsDeleted immediately after the search; orphans within 1 hourAmazon Web Services (Rekognition) · Cloudflare (R2, CDN, Workers)
Host and deliver the photographs of an eventPerformance of the contract, and consent for the guestEvent photographsPhotographed guestsPlan retention period, plus a grace period before purgeCloudflare (R2, CDN, Workers) · Supabase
Run the photographer's account and subscriptionPerformance of the contractAccount details · Contact detailsPhotographersUntil the account is deletedSupabase · Railway
Collect payments and issue invoicesLegal obligationBilling and payment data · Contact detailsPhotographersKept for the statutory accounting periodStripe · Paystack · CinetPay · Supabase
Tell a guest when the photos of their event are readyConsentContact details · Name given by the guestPhotographed guests12 monthsSupabase · Resend · Meta (WhatsApp Business)
Record downloads so the photographer can measure deliveryLegitimate interestTechnical and security logsPhotographed guests12 monthsSupabase
Measure site audience, only after the visitor acceptsConsentUsage dataSite visitorsGoogle Analytics retention periodGoogle Analytics 4
Measure page performance to fix what is slowLegitimate interestUsage dataSite visitors30 daysSupabase
Send in-app and email notices to the photographerPerformance of the contractContact detailsPhotographers12 monthsSupabase · Resend
Trace sensitive administrative actionsLegal obligationTechnical and security logsPhotographers · Administrators12 monthsSupabase
Collect an anonymous rating of an eventLegitimate interestAnonymous rating and commentPhotographed guests12 monthsSupabase

Marked durations are commitments we have published and are implementing; where a duration is not yet applied automatically, we say so rather than imply otherwise.

Who is responsible

For photographs and facial search, BLACKNIDEAS LLC and the photographer who created the event are joint controllers. The photographer decides the purpose — which event, which photographs, which guests. We decide the means — which recognition provider, what matching threshold, what retention, and the fact that facial search is switched on by default when an event is created. Because we make those decisions, we do not present ourselves as a mere technical processor. You may exercise your rights against either of us; we will not send you away.

Legal basis, regime by regime

Facial templates and comparison selfies are sensitive data everywhere they are processed. In the European Union we rely on your explicit consent under Article 9(2)(a) of the GDPR. In United States states with a dedicated biometric statute, we rely on your prior written consent. Account, billing and security data rest on the performance of our contract with the photographer, or on our legal obligations.

International transfers

Facial templates are processed and stored by Amazon Web Services in Ireland, inside the European Union. Our other providers host in regions we are in the process of confirming contractually; until each is confirmed, we state it as unconfirmed on the sub-processors page rather than assert a guarantee we have not verified. Where a transfer leaves the European Union, we rely on the European Commission's standard contractual clauses.

How long we keep things

Your comparison selfie is deleted the moment the search has run, whether or not it found anything; a sweeper removes orphaned selfies every fifteen minutes, so at worst one lives about half an hour. Facial templates are kept alongside the event's photographs and are deleted with them, and also as soon as the photographer archives the event. Photographs follow the retention of the plan the photographer bought, plus a seven-day grace period. Download records, administrative audit logs, waiting-list sign-ups and in-app notifications are deleted after twelve months. An account with no sign-in for three years is anonymised: its content is destroyed and its invoices survive under a neutral identity, because accounting law requires them to. Invoices and payment records are kept for the same reason and outlive the deletion of an account. Web performance metrics are deleted after thirty days. Satisfaction feedback has no automatic deletion yet.

Your rights

You may ask for access to your data, correction, erasure, restriction, portability, and you may object to a processing operation. Where we rely on consent, you may withdraw it at any time, and withdrawing it is as easy as giving it. Write to [email protected]. We answer within one month; if a request is complex we will tell you why and how much longer we need. You do not have to go through the photographer — that route exists, but it is never the only one.

Complaining to an authority

If our answer does not satisfy you, you can complain to a supervisory authority without going through us. In the European Union, the supervisory authority of the country where you live, work, or where the problem occurred. In the United States, the attorney general of your state.

Children and young people

Today, uploading a selfie requires ticking a single box that states you are over 18 or have a parent's or guardian's permission. That statement is not verified, and we do not operate a separate parental consent process — we would rather say so than describe a safeguard that does not exist. The age at which a person can consent on their own differs by regime: between 13 and 16 in the European Union depending on the member state. If you believe a child's image is being processed and should not be, write to [email protected] and we will act on it.

Automated matching

Comparing a selfie against an event's photographs is entirely automated. No person looks at your selfie to decide. The result is binary — either photographs are returned to you, or none are. The matching threshold is deliberately strict, and no biometric measurement is ever shown to the photographer or to you.

Security

Access to data is restricted by role and enforced by the database itself, not only by the interface. Files are served through short-lived signed links rather than public addresses. Administrative actions are logged. We deliberately do not describe our measures in more detail here: a security page precise enough to be useful to an attacker is a weakness in itself.

If something goes wrong

We have a procedure for handling a personal data breach. Where a breach is likely to result in a risk to people, we notify the competent supervisory authority within 72 hours of becoming aware of it, and we inform the people concerned directly when the risk to them is high.

Changes to this policy

This policy carries a version number and a date, shown at the foot of the page. Previous versions stay available at a permanent address so you can see what was published when. When a change materially affects a processing operation that relies on your consent, we ask for it again rather than assume the old one still covers it.

Version 2.0.0 · in force since 2026-07-31 · EN is the authoritative language · corpus compliant

Previous versions

Privacy and data protection — SHAREFT