Back to home

Legal

Privacy Policy

Last updated: August 13, 2026

Your privacy matters. This Privacy Policy describes what data galeriecop collects, why, and how we protect it.

1. Information We Collect

  • Account info — your name, email and a securely hashed password.
  • Event info — the name, date, type and description you provide for your event.
  • Uploaded content — photos, videos and guestbook messages uploaded by you or your guests.
  • Guest info — the display name a guest types when uploading. We do not require guests to register.
  • Payment info — handled entirely by Stripe. We only receive the transaction reference and tier purchased.
  • Usage data — basic logs (IP, browser, page views) to keep the Service running and secure.

2. How We Use Your Information

  • To operate, maintain and improve the Service.
  • To allow guests to upload to your private gallery via your QR code or link.
  • To send transactional emails (account, payment, expiry reminders).
  • To detect, prevent and address abuse, fraud or security issues.

We do not sell your personal data or your guests’ uploaded content to anyone.

3. Content Ownership

100% of the copyright of uploaded photos, videos and messages stays with you and your guests. We only host this content to operate your gallery.

4. Data Storage & Security

Data is stored on encrypted infrastructure. Passwords are hashed with bcrypt. Payments are tokenized via Stripe. Access to production systems is restricted to authorized engineers.

5. Third-Party Services (Data Processors)

We use the following processors to operate galeriecop. Each has their own privacy policy and appropriate GDPR safeguards:

  • Stripe — payment processing (PCI DSS compliant, stores card data on your behalf; we never see the card number)
  • Cloudflare R2 — photo & video storage (encrypted at rest, EU-region option available)
  • Resend — transactional email delivery
  • Emergent LLM — powers the AI Highlights Reel and Help chat (only event metadata + prompts are sent; no personally identifying content leaves our servers)
  • Frankfurter.app — daily FX rates for multi-currency pricing (no personal data sent)

6. Legal Basis for Processing (GDPR / UK GDPR)

  • Contract — to deliver the paid service you signed up for (account, events, uploads, payments).
  • Legitimate interest — service abuse prevention, security, and product improvements.
  • Consent — non-essential cookies (analytics), guest uploads (uploader consent captured on the upload page).
  • Legal obligation — tax/accounting records for paid transactions (retained 6 years).

7. Cookies

We use essential cookies for authentication and Service operation, and optional cookies for analytics. You can accept, reject, or customise your choices from the cookie banner shown on your first visit — or by clicking "Cookie settings" in the footer at any time.

8. Your Rights & How to Exercise Them

Under GDPR / UK GDPR you have the right to:

  • Access your data — self-service via the "Download my data" button on your dashboard.
  • Erasure — self-service via the "Delete my account" button on your dashboard (cascades across events, uploads, payments; irreversible).
  • Rectification — email privacy@galeriecop.com and we'll correct any inaccurate data within 30 days.
  • Portability — the "Download my data" export is a machine-readable JSON; you can import it elsewhere or ask us to transmit it.
  • Object / restrict processing — email us to withdraw consent for non-essential processing.
  • Complain — you may lodge a complaint with your national supervisory authority (in the UK: the Information Commissioner's Office, ico.org.uk).

Guest photo take-downs: if you appear in a photo on someone's gallery and want it removed, email the event host directly (their email is visible on the event page) or contact us at privacy@galeriecop.com and we will forward your request.

9. Data Retention

  • Account & event data — retained while your account is active.
  • Uploaded photos & videos — retained while the event is active. After the event tier expires and is not renewed, media is deleted 90 days after expiry.
  • Payment records — retained 6 years to satisfy accounting/tax obligations.
  • Consent audit log — retained 6 years for regulatory compliance.
  • Backups — residual copies are purged within 30 days of deletion.

10. Children

The Service is not directed at children under 16. We do not knowingly collect personal information from children under 16 without verifiable parental consent.

11. Changes

We may update this Privacy Policy from time to time. Material changes will be communicated via email or the Service.

12. Contact / Data Controller

galeriecop is the data controller for the personal data we process. Questions or requests about your privacy? Email privacy@galeriecop.com.

We use cookies to run galeriecop and improve your experience

Essential cookies keep you signed in and the site working. Analytics cookies help us understand which features get used. You're in control — pick what you're comfortable with. Read our Privacy Policy.