EventSnap

Privacy Policy

Last updated July 20, 2026

This Privacy Policy explains how EventSnap ("we", "us") collects, uses and protects information when you use our event photo-sharing platform.

1. Information we collect

  • Account data — name, email, phone, company name and password (stored only as a secure hash).
  • Event content — events, guest lists and photos that organizers upload.
  • Biometric / face data — when AI face search is enabled, facial features are processed to match attendees to photos. This is used only to power the feature and is stored per-event.
  • Payment data — handled by our payment processors (Razorpay/Stripe); we store only the plan, amount, currency and a gateway reference, never card numbers.
  • Usage & technical data — log data and a session cookie required to keep you signed in.

2. How we use information

To provide and secure the service, process payments and plan upgrades, send transactional emails (invitations, receipts, password resets), and to operate features you enable such as face search and integrations.

3. Sharing

We do not sell personal data. We share data only with service providers that help us run the platform (e.g. payment gateways, email and cloud/AI providers) under appropriate safeguards, or where required by law.

4. Cookies

We use a single essential session cookie to keep you signed in (HTTP-only, SameSite=Lax, and Secure over HTTPS). We do not use third-party advertising cookies.

5. Data retention & your rights

You can export your data or permanently delete your account at any time from your account settings; deletion removes your events, photos and guests. Depending on your location you may have rights to access, correct, or erase your personal data.

6. Security

We protect data with encrypted transport (HTTPS), hashed passwords, encryption of sensitive credentials at rest, CSRF protection and access controls. No system is perfectly secure, but we work to safeguard your information.

7. Contact

Questions about this policy? Contact us at support@example.com.

This document is a starting template and should be reviewed by your legal counsel before launch to ensure it reflects your actual data practices and the laws that apply to you (e.g. GDPR, CCPA, India DPDP Act).

Privacy Policy · Terms of Service · Sign in