Privacy Policy

Last updated: 20 September 2026 · Effective from: 4 October 2026 · Document version: privacy-2026-09-20

1. Data controller

The controller of personal data within the meaning of Article 4(7) GDPR is Bartosz Różycki, a registered sole proprietorship (JDG) at ul. Bednarska 26 lok. 56, 93-030 Łódź, Poland, NIP 7292772054, REGON 545403173 (the Controller or AlbumQR).

For any matter concerning the processing of personal data, contact the Controller at team@albumqr.io or in writing at the address above.

The Controller is not required to appoint a data protection officer under Article 37 GDPR and has not appointed one. The Controller acts as the contact point for data protection matters.

2. Data we process

The data we process depends on the role in which you use the Service. The categories below apply to each role.

  • Organizers — Email address and basic Google profile data shared during sign-in (OAuth), event name and configuration, data needed to process payment (Przelewy24 in Poland, Stripe outside Poland — we never store card numbers), and technical data including IP address and server logs.
  • Guests — Uploaded photos and their thumbnails (sent directly to Amazon S3 using presigned URLs), an optional name and message, file metadata (capture date, size, EXIF) and technical data. Photo likes are stored only locally in the Guest's browser and never reach our servers.
  • Site visitors — Traffic and interaction data collected by Google Analytics 4 and Microsoft Clarity — only after consent is given in the cookie banner (Google Consent Mode v2). Without consent neither tool is loaded. Data is transferred to Google LLC and Microsoft Corporation respectively, both in the United States.
  • Photo analysis (AI) — Every photo uploaded to an Album is analysed automatically by Amazon Rekognition: image labels and properties are detected, faces are detected together with attributes such as smile, open eyes and emotion, and the content is screened for prohibited material. The analysis serves photo quality scoring, automatic selection of the best shots and label-based filtering. We do not build a database of facial templates and do not match faces across photos, so we do not process biometric data within the meaning of Article 9 GDPR.

3. Purposes and legal bases

We process personal data only for the purposes set out below and only to the extent necessary to achieve them.

  • Creating an account and providing the Service — Account data, event configuration, photos and metadata (Article 6(1)(b) GDPR — performance of a contract)
  • Processing payments and settlements — Transaction and billing data (Article 6(1)(b) and (c) GDPR — contract and legal obligation)
  • Issuing and retaining accounting records — Billing data (Article 6(1)(c) GDPR — tax and accounting law)
  • Automatic photo analysis and detection of prohibited content — Photos, image labels and attributes (Article 6(1)(b) and (f) GDPR — contract and legitimate interest)
  • Ensuring security and preventing abuse — IP address, server logs, request data (Article 6(1)(f) GDPR — legitimate interest)
  • Traffic and usage analytics — Cookie identifiers, events, device data (Article 6(1)(a) GDPR — consent)
  • Optional Google Drive integration — Access token for the selected folder (Article 6(1)(a) GDPR — consent)
  • Handling complaints and establishing or defending claims — Contact details, correspondence, transaction data (Article 6(1)(f) GDPR — legitimate interest)

Providing data is voluntary, but the data needed to conclude and perform the Contract is a condition of using the Service — without an email address and the data required to settle payment, an account cannot be created and an Album cannot be shared. A Guest providing a name and a message is entirely voluntary and is not a condition of uploading a photograph. Data processed on the basis of consent is provided voluntarily, and withholding or withdrawing consent carries no negative consequences other than the loss of access to the feature it covers.

4. Allocation of roles and image rights

For photos and Guest data uploaded to an Album the Organizer is the controller and AlbumQR acts as a processor on the Organizer's documented instructions. The data processing agreement forming part of the Terms of Service governs that relationship. For Organizer account data and analytics data, AlbumQR is the controller.

5. Recipients and transfers outside the EEA

We share data only with the providers necessary to deliver the Service, under processing agreements meeting the requirements of Article 28 GDPR.

  • Vercel Inc. — Application and website hosting (USA — standard contractual clauses (SCC))
  • Amazon Web Services EMEA SARL — Photo storage (S3), delivery (CloudFront) and automatic image analysis (Rekognition) (EEA — eu-central-1 region (Frankfurt))
  • Neon Inc. — PostgreSQL database (EEA — AWS eu-central-1 infrastructure)
  • PayPro S.A. (Przelewy24) — Domestic payment processing (Poland — separate controller)
  • Stripe Inc. — International payment processing (USA — separate controller; standard contractual clauses (SCC))
  • Google LLC — OAuth sign-in, Google Analytics 4, optional Google Drive (USA — Data Privacy Framework and standard contractual clauses (SCC))
  • Microsoft Corporation — Microsoft Clarity — behavioural analytics, consent only (USA — Data Privacy Framework and standard contractual clauses (SCC))

Data is transferred to a third country only where the provider ensures an adequate level of protection — under a European Commission adequacy decision or the standard contractual clauses referred to in Article 46(2)(c) GDPR. A copy of the safeguards applied is available on request at team@albumqr.io.

6. Data security

We apply technical and organisational measures appropriate to the risk, in line with Article 32 GDPR. These include:

  • HTTPS/TLS encryption on all connections;
  • photo uploads sent directly to Amazon S3 using presigned URLs valid for 15 minutes;
  • encryption at rest on Amazon S3 (SSE-S3);
  • private gallery access restricted by signed CloudFront cookies valid for 24 hours;
  • rate limiting on file upload endpoints;
  • least-privilege access to production infrastructure and accountability for administrative operations.

7. Retention periods

We keep data no longer than necessary for the purposes for which it was collected, or for the period required by law.

  • Album photos and metadata — Until deleted by the Organizer or until the Album's active period set out in the Terms of Service expires
  • Organizer account data — For as long as the account exists; deleted promptly once it is closed
  • Accounting records and billing data — 5 years from the end of the tax year in which the tax obligation arose
  • Data needed to defend against claims — Until the limitation period under the Polish Civil Code expires
  • Technical and security logs — Up to 90 days
  • Analytics data (with consent) — Up to 14 months in Google Analytics 4; per Microsoft's policy in Clarity

8. Your rights

In connection with the processing of your data you have:

  • the right of access to your data and to obtain a copy of it (Article 15 GDPR);
  • the right to rectification of inaccurate or incomplete data (Article 16 GDPR);
  • the right to erasure (Article 17 GDPR);
  • the right to restriction of processing (Article 18 GDPR);
  • the right to data portability for data processed under a contract or consent (Article 20 GDPR);
  • the right to object to processing based on legitimate interest (Article 21 GDPR);
  • the right to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal (Article 7(3) GDPR).

To exercise any of these rights, email team@albumqr.io. We respond without undue delay and no later than one month from receiving the request. Organizers can also delete their account and all associated data themselves from the /settings panel.

If you consider that the processing of your data infringes the GDPR, you have the right to lodge a complaint with the supervisory authority — the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl.

9. California privacy rights (CCPA/CPRA)

California residents have additional rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act. We honour these rights independently of the rights arising under the GDPR.

Right to know

You have the right to know which categories of personal information we collect. They are:

  • identifiers — email address and profile data shared through Google sign-in;
  • event configuration data — Album name, dates and settings;
  • metadata of uploaded photos — file size, dimensions, EXIF date, orientation;
  • usage data — IP address, browser and device information;
  • transaction data — handled by Przelewy24 and Stripe; we never store card numbers.

Right to delete

You may request deletion of your personal information. Organizers can delete their account and all associated data themselves from the /settings panel, or by contacting us at team@albumqr.io.

Right to opt out of sale or sharing

AlbumQR does not sell personal information and does not share it in exchange for money or other valuable consideration. We also do not share data for cross-context behavioral advertising.

Right to non-discrimination

Exercising your CCPA rights will never result in denial of service, a higher price or a lower standard of service.

How to submit a request

Send requests to team@albumqr.io. We respond within 45 days of receiving a verifiable consumer request, with a possible extension of a further 45 days, of which we will notify you separately.

10. Cookies and browser local storage

The Service relies on necessary cookies: NextAuth session cookies that handle sign-in, and signed CloudFront cookies that grant access to a private gallery for 24 hours. Browser local storage holds photo likes and the selected language. None of this data reaches the Controller's servers.

Once consent is given in the cookie banner we set Google Analytics 4 cookies (_ga, _ga_*, stored for up to 2 years) and load the Microsoft Clarity script, which writes its own analytics cookies. Without consent neither tool runs. You can withdraw consent at any time by clearing site data in your browser settings.

Google Consent Mode v2 may apply behavioural modelling, including conversion modelling, even where analytics consent has not been given in full. This means Google estimates traffic patterns from aggregated data stripped of identifiers. The mechanism is documented here: Google Consent Mode v2.

11. Automated decision-making and profiling

Photos uploaded to an Album are screened automatically for prohibited content. A photo flagged by the system as prohibited is hidden and marked as rejected without prior review by a human. In the Controller's assessment this mechanism produces no legal effects concerning data subjects and does not similarly significantly affect them within the meaning of Article 22 GDPR. Regardless of that assessment, we guarantee the right to obtain human intervention, to express your point of view and to contest such a decision — simply write to team@albumqr.io. Apart from the mechanism described here we apply no automated decision-making and no profiling for marketing purposes.

12. Minimum age

The Service is intended for users aged 16 and over. This requirement follows from Article 8 GDPR and, for users in the United States, from the Children's Online Privacy Protection Act (COPPA).

AlbumQR does not knowingly collect personal data from anyone under 16. Should we become aware that such data has been collected, we will delete it promptly.

Ensuring that event participants using an Album meet the minimum age requirement is the Organizer's responsibility.

13. Personal data breaches

In the event of a personal data breach the Controller notifies the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl) without undue delay and no later than 72 hours after becoming aware of it, in accordance with Article 33 GDPR.

Where a breach is likely to result in a high risk to the rights and freedoms of natural persons, the Controller notifies those persons directly and without undue delay, in accordance with Article 34 GDPR.

Please report suspected security incidents to team@albumqr.io. Every report is treated as a priority.

14. Changes to this Privacy Policy

The current version of this Privacy Policy is always available at albumqr.io/en/privacy together with its effective date and version number. Organizers with an active account are notified of material changes by email at least 14 days in advance. Changes that are purely technical or editorial take effect on publication.

15. Contact

Bartosz Różycki, ul. Bednarska 26 lok. 56, 93-030 Łódź, Poland, NIP 7292772054, REGON 545403173. Correspondence on data protection matters: team@albumqr.io.

Questions about your data?

We respond to every data protection request within 30 days of receiving it.