Privacy Notice
This notice explains what EventPhotoFind collects, why, and how long it is kept. It covers two different groups of people: organizers who hold an account, and guests who visit an event page to find their photos.
Effective 21 August 2026
Who is responsible for your data
For account data — your name, email and workspace — EventPhotoFind is the controller.
For event photographs and the face data derived from them, the organizer who uploaded them is the controller and EventPhotoFind is a processor acting on their instructions. If you want photos of you removed from an event, contact that organizer; we act on their instruction.
What we collect from organizers
To operate an account we collect and keep:
- Your email address and display name.
- Your workspace name, timezone and the events you create.
- The photographs you upload, and the derived thumbnails and previews.
- Operational records of uploads and processing, so failures can be diagnosed.
- Billing records once you purchase, held by our payment provider as merchant of record.
What we collect from guests
When a guest uses selfie search, the selfie is received in memory, converted into a numeric face descriptor, compared against that one event, and discarded when the request finishes. The selfie is not written to disk, not stored in a database, not written to logs, and not sent to any third-party face recognition service. The descriptor derived from it is discarded at the same moment.
What we do keep for each search is a record with no biometric content: the event, the number of results, how long the search took, whether it matched, and irreversible salted hashes of the IP address and browser user agent. The hashes exist so that abuse can be rate limited; they cannot be turned back into an address.
We also record that consent was given, its version, and when — again with a hashed session identifier rather than an identifying one.
Face data from event photographs
Faces detected in uploaded event photographs are stored as numeric descriptors attached to that event. They are not readable by any browser client. They are used for one purpose: letting a guest at that event find photographs of themselves.
A descriptor cannot be used to search a different event. Every query is restricted to a single event in the database query itself, not by application logic that could be misconfigured.
These descriptors are deleted when the event is deleted or expires.
How long we keep things
Retention depends on what it is:
- Guest selfies: not retained at all.
- Guest face descriptors: not retained at all.
- Event photographs and their face descriptors: for the event's retention period, then deleted. A demo event is seven days.
- Uploaded originals used only for processing: removed after processing completes.
- Search records containing hashes and counts: retained for operational and abuse-prevention purposes.
- Account records: for as long as your account exists.
Who we share with
We use infrastructure providers to run the service: a database and authentication provider, an object storage and content delivery provider, and an application hosting provider. They process data on our instructions in order to run the service.
We do not sell personal data. We do not share face data with advertisers. We do not use a third-party face recognition API — the matching runs on infrastructure we control.
Your rights
Depending on where you live you may have rights to access, correct, delete, export or restrict the processing of your personal data, and to object to it.
For guests: because the selfie and its descriptor are never retained, there is nothing to access or delete after a search. For photographs of you held in an event, contact the organizer of that event.
To exercise a right against EventPhotoFind as controller, contact us using the details below.
Security
Access is enforced at the database level rather than by application code alone. Uploads use short-lived permissions scoped to a single object, so a browser never holds a reusable storage credential. Published images are re-encoded without camera metadata.
We do not currently hold a SOC 2 or ISO 27001 certification and do not claim one.
Contact
Questions about this notice, or a request about your data, can be sent to privacy@eventphotofind.com.