Skip to content

Privacy Policy

Last updated August 25, 2026

These terms are written against how this service actually works, and they have not yet been reviewed by a lawyer in every market we operate in. If a clause here matters to a decision you are making, ask us and we will confirm it in writing.

This policy explains what we collect, why, and what you can do about it. The short version: hosts have accounts, guests do not, and we never sell anything to anyone.

Who controls what — the important part

For an event's photos, video and voice notes, the host is the data controller and we are their data processor. The host decides whose photos are collected, who can see them and how long they are kept; we act on the host's instructions and provide the tools that carry them out.

For a host's own account — their email address, sign-in records and payment history — we are the controller.

Hosts using GuestTale for an event with a commercial purpose may need a data processing agreement with us. Contact support and we will provide one.

What we collect from hosts

Only what running an account requires.

  • Email address, and name if you provide one
  • Sign-in records — session times, IP address and browser, kept for security
  • Purchase records — amount, currency and date. Card details are handled by Stripe and never reach our servers
  • Events you create and their settings

What we collect from guests

Guests have no account and we do not ask them to create one. We store the files a guest uploads and, if they choose to give one, the name they typed — which is optional and which they can skip.

We set one cookie in a guest's browser containing a random identifier. It exists so a guest can delete their own uploads and so their name can be attached to the photos they sent. It identifies a browser, not a person, and it is not used for tracking or advertising.

Uploaded photographs carry whatever metadata the camera recorded, which commonly includes the time and may include GPS coordinates. We keep originals unmodified because the host paid for original quality, so that metadata is preserved and is visible to the host.

What we do not do

We do not sell personal data. We do not share it with advertisers. We do not use anyone's photographs to train machine learning models or to market this service.

We do not run facial recognition or face grouping. Facial geometry is biometric data under the GDPR and requires explicit consent that a guest at a wedding has not given.

Who processes data for us

A short list, and each one only does what it says here.

  • Cloudflare R2 — stores uploaded files
  • Neon or an equivalent Postgres host — stores the database
  • Resend — sends sign-in links and service email
  • Stripe — takes payments; we never see full card details
  • Vercel — runs the application

How long we keep things

An event's files are kept until the end of the storage period the host bought, then permanently deleted. We warn the host at 30 and 7 days beforehand.

Host accounts are kept until deleted. Deleting your account deletes your events and their files. Records of payments are kept for as long as tax law requires, typically several years.

Sign-in and upload diagnostic records are kept for up to 90 days.

Your rights

If you are in the EU, UK, or another region with equivalent law, you can ask for a copy of your data, correct it, delete it, restrict or object to its processing, and take it elsewhere. Hosts can do most of this from the account page directly.

If a photograph of you was uploaded to someone's event and you want it removed, ask the host, who controls that album and can delete it. If you cannot reach them, contact us and we will act — we can always remove content from the service.

You have the right to complain to your data protection authority.

Security

Traffic is encrypted in transit and files are encrypted at rest. Uploads go from the guest's browser straight to storage without passing through our application servers.

An event link is a secret. Anyone holding it can reach the album, which is what makes the product work without accounts — so treat it the way you would treat a key, and rotate it from the event's settings if it ends up somewhere it should not be.