Legal
Privacy Policy
Last updated: June 10, 2026
I operate the Framed Events platform, which allows event organisers to create branded photo frame experiences for their guests. This Privacy Policy explains what personal data I collect, why I collect it, how I use it, and what rights you have over it.
By creating an account or using the service you agree to the practices described in this policy. If you do not agree, please do not use the service.
1. Who This Policy Applies To
This policy applies to two groups of people:
- Organisers — people who create an account to set up and manage events.
- Guests — people who scan a QR code to use the photo-frame camera at an event.
Guests do not need to create an account and I do not collect any personal information from them beyond what is described in section 3.
2. Information I Collect from Organisers
When you register for an account I collect:
- Name — used to personalise your account.
- Email address — used for authentication, account notifications, and support.
- Password (hashed) — if you register with email and password. I store only a secure bcrypt hash; I never store your plaintext password.
- Google account identifier — if you choose to sign in with Google, I store only your Google user ID and the email address returned by Google. I do not receive or store your Google password.
When you create an event I also store:
- Event name, date, and configuration settings (frame design, guest tier, accent colour).
- Any custom frame image you upload, stored as an image file (see section 6).
- A short unique slug used to generate the shareable QR code URL.
3. Information I Do Not Collect from Guests
When a guest scans a QR code and uses the in-browser camera, the following applies:
- No photos are uploaded or stored. All photo processing happens entirely in the guest's browser. The framed image is composed on-device and saved directly to the guest's camera roll. No image data is ever transmitted to my servers.
- No account is required. Guests don't sign up or provide any personal details such as a name or email.
- A device identifier is used only to count photos. When a guest takes a photo, a randomly generated device identifier is stored in a cookie on their device and recorded against the event. It is used solely to count unique guests, enforce the event's photo limit, and prevent abuse — it is not linked to a name, email, or any other personal detail, and is never shared or used for advertising.
- No camera feed is recorded or transmitted. Camera access is granted by the guest's browser solely for the purpose of rendering the live preview and composing the final photo locally.
In short: the only event image I ever store is the frame an organiser uploads — never a photo a guest takes.
4. How I Use Your Information
I use the information I collect from organisers to:
- Authenticate you and secure your account.
- Provide, operate, and improve the Framed Events platform.
- Display your event configuration to guests who scan your QR code (event name, frame design only — never your personal details).
- Send transactional emails (e.g. account confirmation, password reset). I do not send marketing emails without your explicit consent.
- Process one-time payments through my payment provider (Stripe). I do not store card details; all payment data is handled directly by Stripe in accordance with PCI-DSS.
- Respond to support enquiries.
5. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA) or United Kingdom, I process your personal data under the following legal bases:
- Contract — processing your account details and event data is necessary to provide the service you have signed up for.
- Legitimate interests — detecting and preventing fraud, securing the platform, and improving the service.
- Legal obligation — where I am required to retain or disclose data by law.
6. Data Storage and Security
Your data is stored in a PostgreSQL database hosted on Neon, a cloud database provider operating within the United States. I apply the following safeguards:
- Passwords are hashed with bcrypt (cost factor 12) before storage.
- All connections to the database and between the server and your browser are encrypted with TLS.
- Access to the production database is restricted to application service accounts only.
Custom frame images uploaded by organisers are stored as files using Vercel Blob storage and served over TLS. Guest photos, as described in section 3, are never uploaded or stored.
No security system is impenetrable. In the event of a data breach that is likely to result in a high risk to your rights and freedoms, I will notify you and the relevant supervisory authority as required by applicable law.
7. Data Retention
- Account data is retained for as long as your account is active.
- Deleted events are first soft-deleted (hidden and deactivated), and may be permanently purged from the database periodically thereafter.
- When you delete your account, all associated personal data and events are permanently deleted immediately.
- I may retain anonymised, aggregated data (e.g. total events created) indefinitely for analytical purposes. This data cannot be linked back to any individual.
8. Sharing Your Information
I do not sell, rent, or trade your personal data. I share data only with:
- Neon — database hosting. Data is stored in their secure infrastructure.
- Vercel — the hosting platform. Application code and server-side processing run on Vercel's infrastructure.
- Stripe — payment processing. I share only the minimum data required to process a payment.
- Google — only when you choose “Sign in with Google”. Google returns your name, email, and user ID to me in accordance with their own privacy policy.
- Resend — email delivery. Used to send transactional emails such as password resets; the only data shared is your email address and the contents of the message.
- Google Analytics & Google Tag Manager — website usage analytics. These collect data about how the site is used and share it with Google in accordance with their privacy policy.
- Law enforcement — where I am compelled to do so by a valid legal process.
9. Cookies and Tracking
Organiser session. I use a session cookie (set by NextAuth.js) to keep you logged in. It is strictly necessary for the service to function and does not track you across other websites.
Guest device identifier.When a guest takes a photo, a strictly-necessary cookie stores a random device identifier used only to count unique photos and enforce an event's photo limit (see section 3). It does not identify the guest personally or track them across other websites.
Analytics.I use Google Analytics and Google Tag Manager on the site to understand how it is used. These set analytics cookies and share usage data with Google in accordance with Google's privacy policy. I do not use advertising cookies. If you are in the EEA or UK, you can manage non-essential cookies through your browser settings.
10. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data I hold about you.
- Rectification — ask me to correct inaccurate data.
- Erasure — request deletion of your personal data. You can do this instantly from your account settings.
- Portability — request your data in a machine-readable format.
- Objection — object to processing based on legitimate interests.
- Restriction — ask me to restrict processing while a dispute is resolved.
To exercise any of these rights, contact me at legal@framed.events. I will respond within 30 days.
11. Children's Privacy
Framed Events is not directed at children under the age of 16. I do not knowingly collect personal information from children. If you believe a child has provided me with their data, please contact me and I will delete it promptly.
12. Changes to This Policy
I may update this Privacy Policy from time to time. When I do, I will revise the “Last updated” date at the top of this page. If the changes are material, I will notify you by email or by a prominent notice on the platform.
Your continued use of Framed Events after any changes constitutes your acceptance of the updated policy.
13. Contact Me
If you have questions, concerns, or requests regarding this Privacy Policy or my data practices, please contact me at:
Framed Events
Email: legal@framed.events
This policy was last updated on June 10, 2026.