Privacy Policy
DRAFT — FOR ATTORNEY REVIEW. NOT YET IN EFFECT. Placeholders in [brackets] must be completed before publication. This draft was prepared to describe the product's actual data practices; it is not legal advice.
Effective date: [DATE] Who we are: [COMPANY LEGAL NAME] ("Fotoccasion", "we", "us"), [ADDRESS]. Contact: [privacy@fotoccasion.com].
Fotoccasion is a shared-album service for events: guests join an event, add photos and videos, and can optionally enroll a face so the album can show them the photos they appear in. This policy explains what we collect, why, how long we keep it, and the choices you have. The short version: we sell photos, not data. We do not sell or rent your personal information, and your faceprint never leaves our systems.
1. What we collect
Account data. Name, email address, and authentication identifiers, handled by our sign-in provider (Clerk).
Photos and videos you or other guests upload. Media added to an event album, plus metadata such as capture time and, for film-camera events, the capture location you share for venue verification.
Faceprints (biometric identifiers) — optional and consent-gated. If you choose to enroll a face, we create a numeric representation of it (a 512-number "faceprint") on our own servers and store it to recognize you in that event's photos. Enrollment requires your explicit, affirmative consent, recorded with a timestamp and the version of the consent language you accepted. Full detail, including retention and destruction, is in our Biometric Data Policy, which is part of this policy.
Faces detected in uploaded media. When face recognition is enabled for an event, we detect faces in uploaded photos/videos and compute faceprints for matching against enrolled members of that same event only. Detected faces that don't match an enrolled member stay unidentified.
Payment data (marketplace). If you buy photos from, or sell photos as, a professional photographer, payments are processed by Stripe. We do not receive or store card numbers.
Usage and device data. Standard logs (IP address, device/browser type, timestamps) for security, debugging, and abuse prevention.
2. What we use it for
•Operating event albums: storing, processing, and displaying media to event members.
•Face recognition within an event: showing you "photos of you" and enforcing each event's privacy mode (including blurring or hiding you on request — including in video).
•Enforcing organizer settings (join approval, film-camera venue checks, reveal times).
•Marketplace transactions between photographers and customers.
•Security, fraud and abuse prevention, and legal compliance.
We do not: sell, rent, trade, or otherwise profit from disclosure of your personal information or biometric data; use your faceprints to train models; match your face across unrelated events; or permit advertisers access to your data.
3. The consent model (how your face data is controlled)
•Face enrollment is opt-in and per-account. Skipping it never blocks you from an event — you simply aren't auto-recognized.
•Every event has a privacy mode disclosed before you join: open (all photos shared), blur-me (shared by default; any recognized person may blur their face or hide a photo they're the main subject of), or hidden-until-released (photos stay hidden until the people in them release them).
•Redaction is enforced on our servers — a blurred face is blurred in the copy that is delivered, including in video.
•You can delete any enrolled faceprint at any time in the app; deletion is immediate.
4. Who else touches the data (sub-processors)
We use a small set of infrastructure providers, each under a data-processing agreement:
| Provider | Role | Data |
|---|---|---|
| Neon (Postgres) | Primary database | Account data, event data, faceprints, consent records |
| Cloudflare R2 | Media storage/delivery | Photos, videos, generated variants |
| Clerk | Authentication | Name, email, auth identifiers |
| Vercel | Application hosting | Request logs |
| Stripe | Marketplace payments | Payment and payout data |
| Upstash | Rate limiting | Transient request counters |
Face detection and recognition run in our own application processes — no third-party face-recognition API receives your images or faceprints.
5. Retention
•Faceprints: deleted immediately when you delete them, and destroyed on the schedule in the Biometric Data Policy (no later than [3 years] after your last interaction with the service, or sooner once the purpose of collection is fulfilled).
•Photos/videos: kept while the event album exists; deleted when the uploader or organizer deletes them, when you leave an event and request removal of your uploads, or when the event is deleted.
•Account data: kept while your account is active; deleted on account deletion, subject to short backup-cycle and legal-hold windows.
6. Your rights
Depending on where you live (GDPR, UK GDPR, CCPA/CPRA, Illinois BIPA, and similar laws), you may have rights to access, correct, delete, port, or restrict processing of your personal information, and to withdraw consent. Many of these are self-service in the app (delete faceprints, delete photos, leave events, delete account). For anything else, contact [privacy@fotoccasion.com]; we respond within the time the applicable law requires. We do not discriminate against you for exercising your rights. California residents: we do not "sell" or "share" personal information as those terms are defined by the CPRA, and we honor Global Privacy Control signals for any future practices that would require it.
For users in the EU/UK, the legal bases we rely on are: contract (operating the service), consent (biometrics, which is explicit consent under Article 9), and legitimate interests (security and abuse prevention). You may lodge a complaint with your supervisory authority.
7. Children
Fotoccasion is not directed to children under 13, and we do not knowingly collect personal information from children under 13 without verifiable parental consent. A parent or legal guardian may enroll a face profile for their child, but a child's faceprint is only created after we obtain and verify parental consent for that child (COPPA); a guardian may delete the child's faceprint at any time. [ATTORNEY: confirm the verifiable-consent METHOD is sufficient — "trained personnel review" ships now; card/ID verification are planned stronger methods.]
8. Security
Originals are stored under unguessable keys; access to gated media is authorized per request and delivered via short-lived signed URLs; biometric processing is in-process rather than sent to third parties; production access is restricted. No system is perfectly secure — if a breach affects your data we will notify you and regulators as applicable law requires.
9. Changes
We'll post changes here with a new effective date; material changes affecting biometric data will require renewed consent before continued biometric processing.
10. Contact
[COMPANY LEGAL NAME] · [ADDRESS] · [privacy@fotoccasion.com]