SnapUpEvents

Legal & privacy

Privacy Policy

This notice explains what personal data SnapUp Events processes, why we process it, who may receive it, how long it may be kept, and the choices and rights available to you.

Effective date 26 July 2026 Last updated 26 July 2026 Version 1.0
Pre-launch legal checklist

Before publishing this page, replace every item marked [TO BE COMPLETED], confirm the actual retention periods and service-provider locations, and have the final notice reviewed for the countries where SnapUp Events is offered.

01

Plain-language summary

SnapUp Events helps event organizers create shared event spaces where guests can upload photos, videos, and messages. We process the information needed to provide that service, keep accounts and events secure, respond to requests, and improve reliability.

You control what you upload

Only upload content you are allowed to share. Event media may contain personal data about you and other people.

Organizers manage event access

Organizers choose event settings, may approve content, and can control whether a gallery is restricted or shareable.

We use infrastructure providers

Hosting, database, media delivery, and security providers may process data on our behalf to operate the service.

You can make a privacy request

Depending on applicable law, you may ask to access, correct, delete, restrict, or obtain information about your data.

02

Scope and privacy roles

This Privacy Policy applies to the SnapUp Events website, account areas, event creation tools, guest upload experience, galleries, and related support interactions (collectively, the “Service”).

For account administration, platform security, service analytics, and direct support, the data controller is:

Controller: [LEGAL NAME / SOLE TRADER NAME — TO BE COMPLETED]

Address: [REGISTERED ADDRESS — TO BE COMPLETED]

Privacy email: [WORKING PRIVACY EMAIL — TO BE COMPLETED]

An event organizer decides why an event is created, who is invited, what guests are asked to upload, and how event content is used. Depending on the circumstances and applicable law, the organizer may be an independent data controller for that event content, while SnapUp Events may act as a service provider or data processor on the organizer’s behalf. Guests should contact the organizer first for event-specific questions when practical.

This policy does not cover third-party websites or services linked from the Service, nor an organizer’s independent use of media after downloading or exporting it.

03

Personal data we collect

Category Examples Usually relates to
Account data Name, email address, phone number, account status, password hash Organizers and registered users
Event data Event name, date, description, access code, settings, organizer ID Organizers
Guest data Guest name or display name, event association, participation time Guests
Uploaded content Photos, videos, captions, messages, filenames, media type, upload status Uploaders and people depicted
Engagement data Likes, approvals, moderation actions, gallery interactions Users, guests, organizers
Technical data IP address, browser and device type, operating system, timestamps, error and security logs All visitors
Support data Messages, issue details, screenshots, and correspondence sent to us People who contact us

We do not intentionally use facial recognition, biometric identification, precise location tracking, advertising profiles, or automated decisions that produce legal or similarly significant effects. Photos or videos may nevertheless reveal sensitive information—such as health, religion, political views, or biometric characteristics—depending on what they show. Do not upload such content unless you have a lawful basis and all necessary permissions.

04

How we collect personal data

  • Directly from you when you register, create or join an event, upload media, change settings, or contact support.
  • From organizers or other guests when they add your name, invite you, or upload content in which you appear.
  • Automatically when your browser or device communicates with the Service, including security and error logs.
  • From service providers when they return technical, delivery, security, or error information needed to operate the Service.
05

Why we use data and our legal bases

The legal basis depends on the data, your relationship with us, and the law that applies. We may process personal data for the following purposes:

Provide the Service

Create accounts and events, accept uploads, display galleries, apply event settings, and provide requested features.

Contract performance · Requested service

Secure and protect SnapUp

Authenticate users, prevent abuse, investigate errors, moderate content, and protect rights, safety, and property.

Legitimate interests · Legal obligations

Operate and improve reliability

Diagnose failures, measure technical performance, maintain backups, and improve usability without unnecessary profiling.

Legitimate interests · Consent where required

Communicate with you

Send transactional notices, respond to support and privacy requests, and notify you of material service or policy changes.

Contract performance · Legal obligations

Comply with law and legal claims

Keep records where required, respond to lawful requests, and establish, exercise, or defend legal rights.

Legal obligations · Legal claims

Optional processing

Use non-essential cookies or send marketing only if and when those features are introduced and the required choice is given.

Consent

Where processing relies on consent, you may withdraw consent at any time for future processing. Withdrawal does not make earlier lawful processing unlawful. Where we rely on legitimate interests, we balance those interests against your rights and reasonable expectations.

06

Event content, visibility, and organizer responsibilities

An event code is not the same as a password.

Anyone who receives or forwards a working event code or link may be able to reach the related event, subject to its settings. Do not publish codes for private events in public places.

  • Uploaders must have permission to share their content and must respect the privacy, publicity, copyright, and other rights of people shown or heard in it.
  • Organizers should clearly inform attendees that event media may be collected and shared, obtain any legally required permission, and use appropriate approval and access settings.
  • Content marked “pending” may be visible to the organizer and authorized administrators before it appears in a gallery.
  • Approved content may be visible to other event participants or anyone with access to the gallery, depending on event settings.
  • Organizers may download or export event media. After export, their independent storage and use is outside SnapUp Events’ control and may be governed by their own privacy obligations.
  • We may restrict or remove content reasonably believed to be unlawful, unsafe, abusive, infringing, or contrary to applicable terms.
07

When personal data may be shared

We do not sell personal data. We may disclose data to:

  • Event organizers and participants according to the event’s access, approval, and gallery settings.
  • Infrastructure and service providers that host the application, database, media, network delivery, security, logs, and support tools on our instructions.
  • Professional advisers such as legal, security, audit, or insurance advisers when reasonably necessary and subject to confidentiality duties.
  • Authorities or other parties when required by law, a valid legal process, or to protect rights, safety, and security.
  • A successor organization in connection with a merger, reorganization, financing, acquisition, or transfer of the Service, subject to applicable notice and legal safeguards.

Supabase

Database, authentication-related records, and application data.

Cloudinary

Uploaded media storage, transformation, and delivery.

Render

Backend application hosting and technical logs.

Netlify

Frontend hosting, delivery, and basic operational logs.

Provider list based on the current SnapUp Events architecture. Update this section before launch whenever a provider or purpose changes. Each provider also publishes its own privacy and security information.

08

International data transfers

The providers that operate SnapUp Events may process or store data in countries other than the country where you live. This may include countries whose data-protection laws differ from local law.

Where required, international transfers will be supported by an applicable legal mechanism, such as an adequacy decision, approved standard contractual clauses, binding corporate rules, explicit consent in limited cases, or another safeguard permitted by law. For transfers subject to Türkiye’s Law No. 6698, SnapUp Events will use a mechanism allowed under the applicable cross-border transfer rules. For transfers subject to the GDPR, appropriate safeguards may include EU Standard Contractual Clauses and supplementary measures where necessary.

Deployment detail to confirm before launch

Record the selected regions for Supabase, Cloudinary, Render, and Netlify and document the transfer mechanism used for each: [TO BE COMPLETED].

09

How long we keep data

We keep personal data only for as long as reasonably necessary for the purposes described in this policy, including providing the Service, maintaining security, resolving disputes, enforcing agreements, and meeting legal obligations.

Data Proposed retention rule
Active account data While the account remains active and as needed to provide the Service.
Event and uploaded media [DEFINE EVENT EXPIRY / ORGANIZER DELETION RULE — TO BE COMPLETED]
Deleted account or event data [DEFINE PRODUCTION DELETION WINDOW — TO BE COMPLETED]
Backups [DEFINE BACKUP ROTATION AND FINAL DELETION WINDOW — TO BE COMPLETED]
Security and technical logs [DEFINE LOG RETENTION WINDOW — TO BE COMPLETED]
Legal and request records For the period required by law or reasonably needed to establish or defend claims.

Deletion from the active Service may not immediately remove copies from rotating backups or cached delivery systems. Those copies should be isolated from ordinary use and deleted or overwritten according to the applicable backup lifecycle, unless preservation is legally required.

10

How we protect data

We use technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Measures may include password hashing, authentication tokens, access controls, encrypted transport, provider security features, least-privilege database rules, logging, moderation controls, backups, and dependency maintenance.

No online service can guarantee absolute security. You are responsible for protecting your account credentials and event access codes, using a secure device, and notifying us promptly if you suspect unauthorized access. If a personal-data breach occurs, we will assess it and provide notices to affected people and authorities where and when applicable law requires.

11

Cookies, tokens, and local storage

SnapUp Events may use browser storage that is necessary to keep you signed in, remember security state, preserve an intended destination after login, and provide requested functionality. For example, an authentication token may be stored under a local browser key such as snapup_token.

Strictly necessary storage is used to deliver or secure a service you request. If analytics, advertising, or other non-essential cookies are introduced, this policy and the consent interface must be updated before those technologies are activated. You can clear browser storage through your browser settings, but doing so may sign you out or reset features.

12

Your privacy rights

Your rights depend on the law that applies and may be subject to exceptions. We may need to verify your identity and authority before completing a request. We will not ask for more information than reasonably necessary for verification.

Rights under Türkiye’s Law No. 6698 (KVKK)

Subject to Article 11 and other applicable provisions, you may have the right to:

  • learn whether your personal data is processed;
  • request information about processing;
  • learn the purpose of processing and whether data is used accordingly;
  • know third parties to whom data is transferred domestically or abroad;
  • request correction of incomplete or inaccurate data;
  • request deletion or destruction where legal conditions are met;
  • request notification of correction, deletion, or destruction to relevant recipients;
  • object to a result against you produced exclusively by automated analysis; and
  • claim compensation if you suffer damage due to unlawful processing.

Rights under the GDPR/EEA framework

Where the GDPR applies, you may have rights to be informed, access, rectification, erasure, restriction, data portability, objection, withdrawal of consent, and safeguards relating to automated decision-making. You may also complain to the supervisory authority in the country where you live, work, or believe an infringement occurred.

Event-specific requests

Include the event name or code, your guest/display name, the approximate upload date, and a description of the relevant media. Do not send your password or unnecessary identity documents by ordinary email.

13

Children’s privacy

SnapUp Events is not directed to children who cannot lawfully consent to the relevant processing in their country. Children should not create accounts or upload personal data without the involvement and permission of a parent, guardian, or otherwise authorized adult where required.

Organizers of events involving children are responsible for selecting appropriately restricted settings, giving required notices, obtaining permissions, and avoiding public sharing. If you believe a child’s data was provided without proper authorization, contact us with enough information to locate the content.

14

Changes to this Privacy Policy

We may update this policy when the Service, providers, processing activities, or law changes. The “Last updated” date and version at the top will identify the current notice. If a change materially affects how personal data is used, we will provide an appropriate additional notice before the change takes effect where required. Earlier versions should be archived for accountability.

15

Contact us or submit a request

To ask a privacy question or exercise a privacy right, contact the controller using the details below. Please state that your message is a “Privacy Request” and describe the request clearly.

Controller [LEGAL NAME — TO BE COMPLETED]
Privacy email [WORKING PRIVACY EMAIL — TO BE COMPLETED]
Postal address [REGISTERED ADDRESS — TO BE COMPLETED]

We may request reasonable information to verify identity, locate the relevant data, and prevent unauthorized disclosure. Authorized agents may be required to show evidence of authority.