In shortThis policy explains what Partyreel keeps about you, why, who can see it, and what you can do about it.
This Privacy Policy describes how [ENTITY NAME], doing business as Partyreel (“Partyreel”, “we”, “us”), collects, uses, shares and protects information when you use partyreel.com, the Partyreel host application, event links and QR codes, and the related services (together, the “Service”). It applies to hosts who create events, guests who view or contribute to them, visitors to our website, and anyone who writes to us.
For your account, our website, billing and our own communications, Partyreel decides how and why information is processed (in European terms, we are the controller). Inside an event, the host decides who may see the album, whether guests must verify an email, and what stays in it; we store and serve the album on the host’s instructions and under this policy. Where this policy treats hosts and guests differently, the difference comes from that split.
Each section opens with a plain-language summary. The summary is there to help you understand the section; if the two ever seem to differ, the full text governs. This policy forms part of our Terms of Service.
In shortAn email and a display name, the events and media you add, and a small technical record around each upload and visit.
We collect only what the Service needs to run, and we collect it in the categories below.
Account information (hosts)
- Email address, verified when you sign up. It is your sign-in and the address our service email goes to.
- Display name, which is required and is shown wherever you appear: on your events, beside your uploads, in guest lists and on your profile if you claim one.
- Avatar, if you add one. Avatars are stored at a public address, so anyone who has that address can view the image.
- Sign-in details. A password, if you set one, is held only as a protected hash by our authentication provider and is never visible to us. If you sign in with Google, we receive your name, email address and Google account identifier, and we request nothing else from Google. One-time codes we email you expire after a short time.
- Billing references. When you buy a plan, Stripe gives us a customer reference and a subscription or purchase reference, your plan, and the invoice history. Your full card number never reaches us.
Guest information
- A verified email address when the host of an event requires one (the default for new events). It is visible to that event’s host and never to other guests.
- A session token stored in your browser that ties you to the events you have joined. It carries no name and nothing about you.
- If you sign in as a guest, the display-name rule for hosts applies to you. Uploads made without signing in, where a host allows them, carry no name and are attributed to “Anonymous”.
Events and media
- The event name, date, description, cover and settings a host chooses.
- The photos and videos you upload, and the smaller preview image we generate from each one for browsing.
- Likes, saved events, follows and blocks, if you use those features, and any reports you file. Reports are stored without your identity.
Upload records
For every completed upload we keep a technical record: the IP address the upload came from, the time, the browser and device description your browser sends (including any client hints), a coarse location derived from the IP address (country and region, never a street address), a random identifier our site stores in your browser so we can recognise the same device across events, and which host or guest made the upload. We keep this record solely to investigate abuse, respond to valid legal process and meet our legal obligations. It is never shown to hosts or guests, it is never used to build a profile of you, and it is deleted with the upload it belongs to.
Technical and usage information
- The cookies and browser storage described under Cookies.
- A hashed form of your IP address, kept for 24 hours, so we can limit abusive bursts of requests. The hash cannot be turned back into the address.
- For each event, a daily count of QR scans and album views. The count is a number; no visitor identity is stored with it.
- On our marketing pages only, cookieless, aggregate analytics: the page viewed, the referring site, the country and the device type. It never identifies you and does not follow you to other sites. The host application, event pages and admin pages carry no analytics at all.
- When something breaks, an error report: the technical details of the fault and, for some errors, a masked replay of the page interaction in which all text is hidden and all images and video are blocked, so we can reproduce what went wrong. Error reports strip email addresses and signed links before they leave the browser.
Communications
- If you write to us through the contact page: your name, email, subject, message, the topic you chose and your browser description.
- If you apply for a role: your name, email, links, message and browser description.
- If you opt in to our newsletter: your email address and when you opted in.
We do not collect information for advertising, we do not track you across other websites, and we do not sell personal information. That is the whole list.
In shortTo run the album, keep the service safe, bill you, and answer you. Nothing else.
We use the information above for the purposes in this table, and for no other purpose without telling you first. The right-hand column names the legal basis that applies where European or United Kingdom data-protection law governs.
| Purpose | What it covers | Legal basis |
|---|---|---|
| Providing the Service | Creating events, storing and serving media, verifying guest emails, generating previews and reels, bundling downloads, showing profiles and guest lists | Performing our contract with you |
| Safety and abuse prevention | Rate limits, upload records, reviewing reports, legal holds and preservation | Our legitimate interest in a safe service, and legal obligation where one applies |
| Billing | Processing payments through Stripe, applying plan entitlements, receipts and renewal notices | Contract; legal obligation for tax and accounting records |
| Service communications | One-time codes, storage and deletion warnings, replies to your messages | Contract; legitimate interest in keeping you informed about your account |
| Marketing email | The newsletter, only if you opted in | Consent, which you can withdraw at any time |
| Improving the Service | Aggregate analytics and error reports | Legitimate interest in understanding and fixing the Service |
| Legal compliance | Responding to valid requests, keeping required records, protecting rights | Legal obligation; legitimate interest |
We do not use your media or your information for automated decisions that have legal or similarly significant effects on you, and we do not use your content to train artificial-intelligence models.
In shortFor the common photo and video formats, location data is removed on your phone before upload. A few formats are stored exactly as sent.
Photos and videos often carry embedded metadata, including the GPS location where they were taken. Before a JPEG, PNG or WebP image, or an MP4 or MOV video, leaves your device, our uploader removes that metadata in your browser, without re-encoding the file. The picture arrives; where it was taken does not, and our servers never see the removed data.
This removal is not available for every format. HEIC, HEIF and AVIF images and WebM videos are stored exactly as your device sends them, and any metadata inside them stays with the file. If that matters to you, convert to JPEG or MP4 before uploading (many phones offer a most-compatible format setting), or ask the host to remove the item. The preview images we generate never carry location data, whatever the original format.
In shortAn album opens exactly as wide as its host chooses, and never to search engines.
Every event has a visibility setting chosen by its host. An open event can be viewed by anyone who has its link or QR code. A password-protected event shows only its name and item count until the password is entered. A private event shows a locked screen to everyone but the host. Hosts may also require a verified email before a guest can see the full album or upload, which is the default for new events.
Event links are excluded from search engines by our site settings and by instructions on every event page, and media files are never served from public addresses: the album hands out short-lived signed links as you browse, and a guest's access reaches only the event they joined.
Inside an album, your uploads are attributed to your display name, or to Anonymous. The host of an event can see the email address of each signed-in uploader; other guests cannot. Anyone who can see the album can download items from it, download the whole album, and watch a highlight reel the host publishes.
Hosts can turn on a guest list for an event. When it is on, every signed-in uploader is listed by display name to everyone who can see the album. There is no per-guest opt-in, because uploads are already attributed by name on the same page. If you would rather not appear, upload without signing in where the host allows it, or do not upload to that event. You can also hide any event from your own public profile.
If you claim a public profile, it is visible to anyone at its address, may be indexed by search engines, and lists the events you host and choose to show, and the open events you have contributed to where their hosts show a guest list and you have not hidden them. Profiles never show your email address or your follower counts. Blocking a person removes each of you from the other's social surfaces.
In shortIn the United States, in two regions, with a write-once backup and a daily database backup.
Media is stored with Cloudflare in the eastern United States and copied within seconds to a second location in the western United States. A separate backup copy is kept in write-once storage for at least 35 days, a daily job reconciles storage against our database, and the database itself is backed up off-site every day. None of this is marketing garnish: it is how the storage runs, so that a once-in-a-lifetime album survives our bad day too. The privacy feature page describes it in more detail.
International transfers
Partyreel operates from the United States and its providers store information there. If you use the Service from outside the United States, including from the European Economic Area, the United Kingdom or Switzerland, your information is transferred to and processed in the United States, where privacy law may differ from that of your country. Where such law requires it, we rely on recognised safeguards for those transfers, including the standard contractual clauses in our providers' data-processing terms and, where a provider is certified, the EU-U.S. Data Privacy Framework.
In shortAlbums stay until deleted. Deletion is real, with a 30-day safety net, and every other record has a clock.
There is no expiry clock on an album: events stay up until their host takes them down, or until one of the lifecycle rules below applies. We keep other information only as long as the purpose it was collected for requires. This table sets out the clocks.
| Information | Kept for |
|---|---|
| Events and media | Until the host deletes them, or a lifecycle rule below applies |
| Deleted media and events (the recovery bin) | 30 days, then permanently deleted. Items can leave the bin sooner when the bin holds more than the account's storage allowance, oldest first |
| Media on a lapsed paid plan that is over its storage cap | A 45-day grace period, after which the largest items are removed, largest first, until the account is within its cap. Removed items pass through the recovery bin |
| Events on free accounts with no activity | Removed after about 6 months without activity, with an email warning 14 days before, then the recovery bin |
| Event Pass events | A pass covers about one year from purchase; when it lapses, the free-account rules apply |
| Upload records | As long as the upload they describe |
| Rate-limiting records (hashed IP addresses) | 24 hours |
| Items under a legal hold | For the duration of the hold. Preserved evidence is kept for up to one year, or longer where the law requires |
| Backups | Backup copies are removed on a delayed schedule after the primary copy is deleted. Until our automated backup clean-up is fully enabled, a backup copy may persist beyond the 30-day window. Backups are never restored into an album |
| Account information | Until you delete your account |
| Billing records | As long as tax and accounting law requires |
| Support messages, job applications and newsletter signups | Until you ask us to delete them, or they are no longer needed |
When something is permanently deleted, it is removed from primary storage first and then from our database. An upload that a signed-in guest removes from someone else's event cannot be restored by that event's host.
In shortDownload everything, delete what is yours, leave whenever.
- Download. Everything you uploaded comes back out at the quality it went in, one item at a time or the whole album at once.
- Delete your uploads. If you signed in, you can delete your own uploads from the Uploads tab of your dashboard, in any event, at any time. If you uploaded without signing in, ask the host, who can remove the item instantly.
- Delete your events. Hosts can delete any item or any whole event. Deleted items sit in the recovery bin for 30 days, where they can be restored or purged sooner.
- Stay out of view.Hide any event from your public profile, and stay off an event’s guest list by not uploading to it while signed in.
- Delete your account. For now, account deletion is handled through support: write to us from the contact pageusing the email on your account, and we will delete it and confirm. Events you host are deleted with the account; your uploads to other people’s events stay in their albums unless you delete them first. A self-serve deletion control is planned. Details: your data and deleting your account.
- Marketing email. The newsletter is opt-in. To stop receiving it, write to privacy@partyreel.com and we will remove you within 30 days. Service emails about your account (sign-in codes, storage and deletion warnings) continue while you have an account, because the Service cannot run safely without them.
- Analytics. The opt-out is described under Cookies.
- Google.You can remove Partyreel from your Google account’s connected apps at any time; your Partyreel account continues with email sign-in.
In shortWherever you live, you can ask to see, correct, export or delete your information. Here is how.
You can exercise any of the rights below by writing to privacy@partyreel.com or through the contact page. We will verify that the request comes from you, usually by asking you to write from the email on your account, and respond within 30 days or tell you why we need longer. Exercising your rights never costs you anything and never changes how we treat you.
European Economic Area, United Kingdom and Switzerland
If you are in the EEA, the UK or Switzerland, you have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict or object to its processing (including any processing based on our legitimate interests), to receive it in a portable format, and to withdraw consent at any time where consent is the basis. You also have the right to lodge a complaint with your local supervisory authority. Providing your information is never a statutory requirement; it is what the Service needs in order to run.
California
If you are a California resident, the California Consumer Privacy Act gives you the right to know what personal information we collect, use and disclose (this policy is that notice), to delete it, to correct it, and to limit the use of sensitive personal information. We do not sell personal information and we do not share it for cross-context behavioural advertising, and we have not done either in the preceding 12 months, so there is nothing to opt out of.
In the Act's categories, we collect: identifiers (email address, display name, IP address, device identifier); commercial information (plan and purchase history); internet activity (album views and upload records); coarse geolocation derived from IP address; and the content you upload, including any images of people in it. We use sensitive personal information (account credentials and the content of your messages to us) only to provide the Service. We disclose these categories to the service providers listed under How we share information, for the purposes listed there. We will not discriminate against you for exercising your rights, and an authorised agent may make a request on your behalf if we can verify their authority.
Other United States states
Residents of other states with comprehensive privacy laws (including Colorado, Connecticut, Virginia, Texas and Oregon) have similar rights to access, correct, delete and export personal information, and to opt out of targeted advertising, sale and profiling. We do none of those three. If we decline a request, you may appeal by replying to our response, and we will explain the outcome of the appeal.
In shortHosts must be 18 or older. Guests must be at least 13. We do not knowingly collect information from younger children.
Creating a host account requires you to be at least 18 years old. Contributing to an event as a guest requires you to be at least 13, or older where the law of your country sets a higher age for consenting to online services (16 in much of the European Union). We do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account or uploaded to an event, write to privacy@partyreel.com and we will delete the information promptly.
Photos of children appear at family events. A host who collects and shares such photos is responsible for having permission to do so, and a parent or guardian who wants an image of their child removed can report it from the album or write to us.
In shortEncrypted in transit, served only through signed links, locked down at the database. No system is perfect, and we will tell you if something goes wrong.
We protect information with measures appropriate to its sensitivity: encryption in transit for every connection; media served only through short-lived signed links, never public addresses; database access enforced row by row, so a host can reach only their own events and a guest only theirs; upload and moderation actions validated on our servers rather than trusted from the browser; multi-factor authentication for operator access; and providers chosen for their own security programmes. Location metadata is removed before upload for the common formats, so it is never at risk on our side.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a breach affects your personal information, we will notify you and the relevant authorities as applicable law requires, without undue delay.
In shortAnyone can report anything in an album. Every report is reviewed before anything comes down, and some material must, by law, be preserved and reported.
Anyone who can see an album can report it, or an item in it. Reports are stored without the reporter's identity, and filing one never removes content by itself. Every report is reviewed, and content is removed when it breaches our Terms. Hosts can remove anything from their own album instantly, and removals made by our operators cannot be undone by the host.
When an investigation or a legal obligation requires it, we may place an item under a legal hold, which keeps it out of every deletion path, and preserve a copy of the item together with its upload record in segregated storage. We keep it for as long as the matter requires. For content that sexually exploits minors, we preserve it for as long as United States law requires and report it to the authority that law designates.
In shortUpdates are posted here with a new version and date. Questions get answered.
We may update this policy as the Service changes. The version number and date at the top tell you which version you are reading. For material changes we will give notice before the change takes effect, in the app or by email to the address on your account, and your continued use of the Service after that date means the updated policy applies to you. Earlier versions are available on request.
Questions, requests and complaints about privacy go to privacy@partyreel.com or through the contact page.