Privacy Policy
Last updated 17 July 2026
This policy explains what personal information is collected when you receive photos through EventSnap, why it is collected, who it is shared with, and the rights you have over it.
Who is responsible for your data
EventSnap is photo-delivery software operated by Jon Jason (“we”, “us”). Each event belongs to a photography company — at some events that is us, at others it is an independent company using EventSnap under their own brand.
The photography company running your event decides what is photographed and how long photos are kept — they are the data controller. We operate the software on their behalf as a processor. The gallery you receive shows you which company it is. If you cannot tell, contact us and we will tell you and pass your request on.
What we collect
| Data | When | Why |
|---|---|---|
| Your name (optional) | When you tap/scan a card and fill the form | To label your gallery |
| Your mobile number | Same | To identify your gallery and text you your link |
| Your email (optional) | Same | A backup way to send your link if the text fails |
| Photographs of you | When the photographer takes them | To deliver and sell them to you |
| Selfie and derived face data (optional) | Only if an event offers selfie search and you choose to upload one | To suggest possible matches from that event |
| Consent record | When you submit the form | Proof you agreed, and when |
| Purchase records | If you buy photos | Order history, refunds, tax and accounting |
Default matching is not facial recognition. Your photos are normally matched to you by when they were taken — the moment you tapped in at the camera. Some events may offer optional selfie search. That feature is used only if the event enables it and you explicitly upload a selfie for that event.
Optional selfie search
If selfie search is offered, we ask for a separate affirmative consent before accepting your selfie. The selfie and a face-derived representation are used only to suggest possible matches from the same event. Suggestions are not proof of identity and should be treated as possible matches. We do not use this data for advertising, cross-event identification, sale, or general model training. See the full Biometric Data & Face Search Policy.
Face-search records are scoped to one event. Before the feature opens, the event must have a retention period and a verified deletion schedule. At the deadline, the selfie image, derived face data, provider collection, and open match suggestions are queued for permanent deletion. You can ask us to delete your selfie-search data at any time.
Cookies
We set two cookies, both strictly necessary: es_guest, which keeps you signed in to your own gallery, and es_staff, which signs photographers in to their console. That is all.
We run no analytics, no advertising, no tracking pixels and no third-party trackers.We do not profile you and we do not follow you across other websites. Because these cookies are strictly necessary to deliver a service you asked for, no consent banner is required.
Who we share it with
These companies process data so we can run the service. We do not sell your personal information — to anyone, ever.
| Who | What they get | Why |
|---|---|---|
| Supabase (US) | Your name, number, email, purchase records | Database hosting |
| Cloudflare R2 | Your photographs and temporary selfie objects | Private photo and selfie storage |
| AWS Rekognition (US) | Selfie and event-scoped face-match data, only when selfie search is enabled | Possible-match suggestions |
| Vercel (US) | Technical request logs | Running the website |
| Stripe | Your payment details, directly | Taking payment |
| GoHighLevel | Your name and mobile number | Sending your photo texts |
| Resend | Your email address | Sending your photo emails |
We never see or store your card number. Card details go straight to Stripe, a PCI-DSS Level 1 provider. We only keep a payment reference and the amount.
We may also disclose information if the law requires it, or if the business is sold or merged.
Text messages
By giving your number you agree to receive texts about your photos from that event. Message and data rates may apply. Reply STOP to any message to opt out immediately. We use your number only to send your gallery link and photo updates — never for marketing unrelated to the event, and we never sell it.
How long we keep it
Each photography company sets a retention period for their event. Beyond that, we keep your data only as long as needed to provide the service and meet legal obligations — purchase records are typically kept around 7 years for tax purposes, which we cannot delete on request.
Face-search safeguard: selfie search remains closed until its retention schedule, consent copy, privacy review, and production approval are active. When enabled for an event, the deletion worker removes face-search data at the recorded deadline. If you want your selfie data or photos deleted sooner, email us and we will process the request.
Your rights
Wherever you live, you can ask us to:
- Show you what we hold about you
- Correct anything wrong
- Delete your data and your photos
- Export your data in a portable format
- Stop texting or emailing you (or just reply STOP)
- Object to or restrict how we use it
UK/EU (GDPR): our legal bases are your consent (texts, emails, and being photographed at an event you attended), contract (delivering photos you bought), and legal obligation (keeping purchase records). You may complain to your local Data Protection Authority. California (CCPA/CPRA): you have the rights above and we will not discriminate against you for using them. We do not sell or share personal information as those terms are defined.
Email us and we will respond within 30 days. There is no charge.
Where your data goes
We are based in the United States and our providers process data there. If you are in the UK or EEA, your data is transferred to the US under Standard Contractual Clauses and equivalent safeguards offered by the providers listed above.
Security
Everything travels over HTTPS. Your gallery is protected at the database level — the system is built so one guest cannot load another guest’s photos, even by guessing. Photo files are private and served over expiring links. Card data never touches our servers.
Children
EventSnap is not directed at children under 13, and we do not knowingly collect their data. If a child has been photographed and you are their parent or guardian, contact us and we will delete the photos.
Changes
If this policy changes materially, we will update the date above and post the new version here.
Contact
Email info@jonjason.com for any privacy request, or to reach the photography company responsible for your event.
This document is written in plain English so it is actually readable. It is not legal advice. If you are a photography company relying on EventSnap, have your own lawyer review it before you put it in front of clients.
Privacy · Biometric policy · Terms · Home