Privacy Policy

Last updated: 2026-09-14.

Who we are. [LEGAL ENTITY NAME] ("Get The Photos"), [MAILING ADDRESS]. Contact: support@getthephotos.com.

What we collect

Hosts (the couple and anyone they add as an admin): email address, the album details you type in (names, date, a note for guests, a viewing password if you set one), payment records from Stripe (we never see your card number), and a log of sign-ins and album actions. We keep that log so we can help when someone asks us to undo something.

Guest emails you send: when you use the album to email guests the upload link, the addresses are used once to send that message. We store how many were sent and when, not the addresses.

Printed cards: when you request delivery, we collect the recipient’s name, postal address, email, card design and order details. Get The Photos shares the information needed to print and deliver your cards with Gelato, and payment and shipping details with Stripe. You do not need your own printing-service account. Draft and delivered orders have their address and print files removed from Get The Photos after 90 days; unresolved orders keep those details while we resolve fulfillment. Accounting records remain separately.

Guests (people who upload): the photos, videos and text you choose to add; a name and caption if you type one; the time of upload; your IP address in server logs (kept up to 30 days); and a random cookie so the page can show you your own uploads and remember one reaction per device. No account, no tracking across sites, no advertising.

Photos contain metadata. Camera files usually include the time and often the location where they were taken. We store the original file untouched (that is the point of the service), so the host who downloads it will see that metadata. Preview copies shown on the web page are regenerated and do not carry location data.

Why and on what basis

Who else sees it

Sub-processors we use: a cloud host for the application and database; an object-storage provider for the files (Cloudflare R2, Backblaze B2, or Amazon S3 depending on deployment); Cloudflare for networking and its child-safety scanning; Stripe for payments; Resend for email. Each is bound by its own data-processing terms. We never sell your photos or personal data, and we never share them for advertising. We disclose data when the law requires it (for example, mandatory reports under 18 U.S.C. § 2258A).

Where it lives

Servers and storage are in the United States unless a host has chosen a different region. If you are in the EU/UK, your data is transferred to the US under standard contractual clauses used by our providers.

How long

Albums are kept for 12 months after the wedding date (or 12 months from creation if no date was given); the exact date is shown on the album page and in reminder emails. When that passes, or when a host deletes the album, the photos are removed from active storage; a deleted album can be restored by us for 30 days in case it was a mistake, after which the files are gone. We also keep salted hashes of network addresses for a day to limit repeated sign-ups. Database backups are pruned after 30 days. Storage-provider recovery copies may briefly remain after deletion. Account, payment and security records are kept separately from the photos for as long as tax and fraud rules require.

Your rights

You can ask us to show, correct or delete personal data about you, or object to processing. Guests: the fastest route for a photo of you is the host (they have a delete button) or the Report link on the page, which reaches us directly. Hosts: use the dashboard, or email support@getthephotos.com. We answer within 30 days. EU/UK residents can also complain to their data-protection authority. California residents have the rights described in the CCPA; we do not sell or share personal information as those terms are defined there.

Children

The service is for adults. We do not knowingly collect personal information from children under 13 and there are no child accounts. Photos of children at a family event are the host's responsibility as the person who collects them.

Cookies

First-party cookies only: a session cookie for signed-in hosts, a random device cookie on upload pages so you can see and remove your own uploads, and, if the couple set a viewing password, a cookie that remembers you entered it. Our marketing pages (home, sign-up, sign-in) may load a Google Ads measurement tag when we run ads; the upload and album pages never do.

Changes

We will post changes here and email hosts about material ones.