This privacy policy explains which personal data we process when you use guest-pictures.com – as an event host, as a guest at an event, or simply as a visitor to the website.
Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Steffen KnödlerRothschildallee 41
60389 Frankfurt am Main
Germany
Email: hello@guest-pictures.com
Contact form: guest-pictures.com/contact
We have not appointed a data protection officer because there is no legal obligation to do so. For any privacy question, simply write to hello@guest-pictures.com.
Overview
The main processing activities at a glance (details in the following sections):
| Data | Purpose | Location | Deletion |
|---|---|---|---|
| Photos and photo booth collages | Event gallery | Google Cloud Storage, USA (us-east1) | about 30 days after the event date (unlocked: about 12 months) |
| Event data, photo records, challenges | Running the event | Google Cloud Firestore, EU (eur3) | about 30 days after the event date (unlocked: about 12 months) |
| Account (email, password hash) | Host sign-in | Firebase Authentication (Google) | when the account is deleted |
| Reminder emails (email address, send log) | Service emails around the event date | Google Cloud Firestore, EU (eur3); sent via Resend | with the event |
| Payment data | Unlocking unlimited photos | Stripe | statutory retention periods |
| Feedback, error reports | Fixing errors, improving the service | Google Cloud Firestore, EU (eur3) | 365 / 90 days |
| Server logs (IP, user agent) | Security, troubleshooting | Google Cloud Logging | 30 days |
Hosting and server log files
guest-pictures.com is served via Firebase Hosting, a service of Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and Google LLC, USA), through Google's worldwide content delivery network (CDN). When you open a page, your browser necessarily transmits your IP address, the date and time, the requested address, the referrer and browser/operating-system details (user agent). Google processes this data to deliver the pages and to protect the service against abuse and attacks.
Requests to our server functions (e.g. counters, feedback, photo uploads) are additionally recorded in Google Cloud's logs (Cloud Logging); these logs may contain IP address and user agent and are deleted automatically after 30 days. We only look at them when there is a reason, e.g. to fix errors or to fend off attacks.
The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the secure and stable provision of the website. Google acts as our processor under the Google Cloud/Firebase data processing terms (Art. 28 GDPR).
Host account
To create and manage events, you create an account with an email address and password. Sign-in is handled by Firebase Authentication (Google); your password is stored there only as a hash, and we never see it. In our database we keep your email address and the creation time, plus your events, purchases and – if you take part in the partner programme – the details listed there. For "forgot password" and when you change your email address, Firebase sends you an email on our behalf. Around the date of your events you receive short service emails (see "Reminder emails around the event date"). We do not send marketing emails or newsletters.
You can delete your account at any time under "Account". This deletes your events including all photos and your account data; we keep payment records only where the law requires us to (see "Retention"). The legal basis is Art. 6(1)(b) GDPR (contract of use).
Events
For an event we store what you enter: name, date, optionally a description or welcome text, the settings (photo booth, slideshow, gallery visibility, upload deadline if any), photo challenges, the plan (free or unlocked) and, where applicable, the partner or campaign link through which the event was created. Name, date, description and settings can be retrieved by anyone who has the event link or QR code – otherwise guests could not open the event. Only share the link with people who are meant to take part. The legal basis is Art. 6(1)(b) GDPR.
Reminder emails around the event date
So that your guests get the event link in time, we send you up to 5 short service emails around the event date to your account email address: one week before (print QR cards), the day before, on the day (live slideshow), the day after (collect your guests' photos) and before the upload period ends (for free events with the date the photos will be deleted). Emails that no longer fit – for example because the event was created shortly before – are skipped. The emails only contain information and links about your event, no advertising. For this we process your email address, the event's name, date, plan and upload deadline, the language detected when the event was created, and a send log (which email was sent or skipped, and when). The legal basis is Art. 6(1)(b) GDPR (providing the service you use by creating the event).
You can unsubscribe from the reminders for each event separately: via the link at the end of every email or in the event settings ("Reminder e-mails for this event"). We delete the send log together with the event.
We send these and our other automatic emails (e.g. acknowledgements of receipt and contract confirmations) via Resend (Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA) as our processor (Art. 28 GDPR); sending runs on servers in the EU (Ireland). Resend receives the recipient address, subject and content of the email for this and stores sending data (e.g. the delivery status). Access from the USA is possible; Plus Five Five, Inc. is certified under the EU-US Data Privacy Framework, so the transfer relies on the European Commission's adequacy decision (Art. 45 GDPR) and additionally on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).
Uploading photos (guests and hosts)
Guests do not need an account. When you first upload or open the gallery, our app signs you in anonymously with Firebase Authentication (random identifier, no email address) and stores a random guest ID on your device. We do not ask for your name.
What happens to a photo: Your browser downsizes the image before uploading (longest side at most 1600 pixels), converts it to JPEG and in doing so removes all metadata of the original, including EXIF and GPS location data. We then store the image file in Google Cloud Storage in the USA (region us-east1) and a record about it in our database in the EU: storage path, original file name, file size and type, time, the selected challenge if any, and the anonymous sign-in ID and guest ID. For the gallery overview we also store a smaller copy of the photo (longest side about 400 pixels) that your browser creates when uploading; it sits next to the photo, is visible to the same people and is deleted with it. Uploads are possible from the creation of the event until 5 days after the event date (for unlocked events until a deadline set by the host, at most 30 days after the event).
Who sees the photos: The host sees all photos of their event. If the gallery is set to "private" (default), guests only see their own photos. If it is "public", everyone with the event link sees all photos, including in the slideshow. Every photo has an unguessable address; anyone who knows that address (e.g. because it was forwarded) can open the photo. Exception: photos beyond the free allowance of an event that has not been unlocked can only be seen by the person who uploaded them until the event is unlocked; everyone else – including the host – only sees a heavily reduced, blurred preview (about 32 pixels wide) that your browser creates when uploading and that we store and delete together with the photo record.
Legal bases: For you as the uploader, Art. 6(1)(b) GDPR (you use the service to share photos with the event). For people shown in photos, Art. 6(1)(f) GDPR: the legitimate interest of the participants and the host is to share souvenir photos of a shared event within a closed group. Anyone shown in a photo who does not want this can object and request deletion – from the host or directly from us at hello@guest-pictures.com. Whoever uploads a photo is responsible for making sure the people shown agree to it being shared; for children, their parents.
Note for hosts: You decide who receives the link and whether the gallery is public. For private celebrations among family and friends, this is usually a purely personal activity. If you use Guest Pictures for professional or business purposes (e.g. a company party, or as a service provider for couples), you are responsible for informing your guests; contact us if you need a data processing agreement (Art. 28 GDPR).
Photo booth and camera
The online photo booth only uses your device's camera after you allow it in your browser's prompt; you can revoke that permission at any time in the browser settings. The camera image is processed exclusively on your device – no video or audio is recorded or transmitted, and there is no face recognition. On iPhones the phone's camera app may open instead. Only the finished collage is uploaded to the event gallery like a normal photo (see above). In addition, the booth keeps your collages in a gallery on your device so you can view or share them again later; you can switch this off in the booth settings. If you use a shared device (e.g. a tablet as a photo booth), remember to clear that gallery after the party.
Disposable camera: If the host has switched on disposable camera mode, guests can take a number of photos set by the host with their device's camera (as with the photo booth, only after you allow the camera; the camera image is processed on your device). Each shot is uploaded like a normal photo (see above); in addition we store, for your anonymous sign-in ID, how many shots you have taken at this event, and delete that counter together with the event. Until the time chosen by the host (e.g. the next morning at 10:00, the end of the party, or when the host releases them) these photos are hidden from all guests – including you. Only the host can see them before then and remove individual ones. After that, the rules above on who sees the photos apply.
Interface for AI assistants
At guest-pictures.com/mcp we provide an interface (Model Context Protocol) through which AI assistants such as ChatGPT or Claude can retrieve a link to our online photo booth, effect suggestions and guidance on collecting guest photos. When an assistant calls this interface, we only receive the parameters it passes (language, effect, layout, optionally a short occasion such as "wedding" and a caption for the collage such as names and a date). We use them solely to generate the response and do not store them; only the server logs apply. The card in the chat loads example images of the effects from our website; as with any page visit, your browser transmits its IP address (server logs). The interface has no accounts and cannot read your conversation, which the assistant's provider processes under its own responsibility. The photo booth itself runs on photobooth-free.com or fotobox-online.com, where their privacy policy applies. The legal basis is Art. 6(1)(f) GDPR.
Gallery, slideshow, download and sharing
The gallery and slideshow load photos via our server function. The ZIP archive with all photos is created by your browser itself; no extra copy is made on our servers. QR codes and the QR poster (PDF) are also generated in your browser, without external services. If you choose "Share via WhatsApp" or "Ask the host", we open WhatsApp (Meta) with a prepared text containing the event name and link; whatever you send there is subject to WhatsApp's terms. The same applies to the app you choose in your device's share menu.
Unlocking unlimited photos and payment (Stripe)
Every event starts free with a photo allowance. Anyone who wants to – host or guest – can unlock unlimited photos for the event with a one-time payment. Payments are processed by Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland). You enter your payment details directly on Stripe's checkout page; we never receive full card details.
We send Stripe: price and currency, the product name (which contains the event name), the preferred language, the name given voluntarily for the thank-you note if any (see below) and internal identifiers (event, host account, any code redeemed). Stripe itself collects, among other things, your email address, payment details, country and device/fraud-prevention data. From Stripe we receive the payment status, amount, transaction IDs and – visible in our Stripe account – your email address and truncated payment details (e.g. card type, last four digits). If the event has already been unlocked by someone else or has been deleted in the meantime, we refund your payment automatically.
Stripe processes payment data partly as an independent controller (e.g. for fraud prevention and to meet legal obligations) and partly on our behalf. Stripe may transfer data to Stripe, Inc. in the USA; Stripe is certified under the EU-US Data Privacy Framework and additionally uses EU Standard Contractual Clauses. Stripe privacy policy: stripe.com/privacy. The legal bases are Art. 6(1)(b) GDPR (contract) and Art. 6(1)(c) GDPR (tax and commercial retention obligations).
Voluntary name credit: When unlocking you can voluntarily enter a name (at most 40 characters). It is shown in the event as a thank-you ("… thanks to [name]!") and is visible to everyone who opens the event (guests and host). We send it to Stripe with the order and store it with the event after the payment; there it is deleted together with the event, at Stripe it remains part of the order data. Without a name, a neutral thank-you is shown ("thanks to a guest" or "thanks to the host"). The legal basis is your consent (Art. 6(1)(a) GDPR); you can withdraw it at any time – a short message to hello@guest-pictures.com is enough and we remove the name from the event.
Discount, referral and partner codes
If you redeem a discount or partner code, we store which code was used for which payment. If you arrive via a partner link, your browser remembers the partner code for 30 days so that you get the partner price; the event may then show "Photos & photo booth by [partner]".
Partner programme (invitation only): For partners we store the partner profile (name, website, short description, discount offered), which is shown publicly, the personal code (it may be derived from the start of your email address), the invitation redeemed, the unlocks and commissions generated via the code and, for payout requests, the account holder and IBAN. The legal bases are Art. 6(1)(b) GDPR and – for accounting records – Art. 6(1)(c) GDPR.
Usage counters, feedback and error diagnostics
We use no third-party analytics or tracking services (no Google Analytics, no advertising pixels) and set no cookies. Instead we run three small first-party functions. The data goes to our own server functions on Google Cloud (region us-central1, USA) and is stored in our Google Cloud Firestore database in the EU (region eur3).
Anonymous usage counters
When certain pages are opened and at individual steps (e.g. "photo booth opened", "collage created", "feedback sent"), your browser sends only the name of the event and the website to our server. We use it to increase a daily counter (e.g. "12 × collage created today"). Only these totals are stored – no IP address, no identifier, no URL, nothing that relates to a person. If you arrive via a link with a source parameter (e.g. ?ref=…), we count that source as a total as well. To limit abuse, your IP address is used briefly as a truncated hash in the server's memory and is not stored.
Feedback form and quick ratings
If you send us feedback via the feedback form or a quick rating (e.g. 👍/👎 after a collage), we store what you submit (rating, selected reasons, your message) and – only if you enter it yourself – your email address, which we use solely to reply to you. Please do not include sensitive data in your message. The technical details described in the next paragraph are attached automatically. If you report a camera problem, we also store the full browser identifier (user agent), because camera errors can often only be traced with it. Feedback is deleted automatically after 365 days. If the form cannot be sent, your email program opens instead; the section "Contact by email" then applies.
Error diagnostics
When a technical error occurs in our app, or when you send us feedback through the feedback form, we automatically transmit technical details to our own server (Google Firebase / Google Cloud): device type, operating system and browser (family and major version only), screen size, language, connection status, the app pages you visited most recently (page type only, e.g. "event upload page", without URL parameters), your most recent steps in the app (e.g. "upload started", "camera error"), an error message without any content you typed, and a random session identifier that exists only in your browser's memory and is lost when you close or reload the page. On event pages, the (pseudonymous) event identifier is included as well. We do not store cookies, IP addresses, names, photos or file names for this purpose. The sole purpose is to detect and fix errors and keep the service secure. There is no profiling and no disclosure to third parties. Error reports and technical details are deleted automatically after 90 days.
Legal basis for all three functions is Art. 6(1)(f) GDPR (legitimate interest in a working, secure and improving service); for feedback also your voluntary submission. Reading technical device properties (e.g. screen size, connection type) serves to keep the service you are using working (Section 25(2) no. 2 TDDDG). For the transfer to the USA see "Recipients and transfers to the USA". You may object to this processing at any time under Art. 21 GDPR.
Storage on your device (no cookies)
We set no cookies and use no tracking technologies. To make the app work, we keep a few entries in your browser storage (localStorage, sessionStorage, IndexedDB, Cache Storage). These entries stay on your device; a value is only sent to our server where stated below. All entries are strictly necessary for functions you explicitly use (Section 25(2) no. 2 TDDDG) and therefore require no consent. You can remove them at any time in your browser settings ("clear site data").
| Entry | Type | Purpose | Duration |
|---|---|---|---|
firebaseLocalStorageDb | IndexedDB | Sign-in session (Firebase Authentication) – for hosts after logging in, for guests an anonymous ID so uploads and the gallery are linked to you | until you sign out or clear the site data |
fotobox_guest_id | localStorage | Random guest ID so that you can see your own photos in private galleries | until you clear the site data |
language | localStorage | The language you chose | until you clear the site data |
photobooth_settings_v1, photobooth_sound_muted, booth_camera_mode | localStorage | Your photo booth settings (effect, layout, custom text, countdown, sound, camera mode) | until you clear the site data |
photobooth-local | IndexedDB | On-device gallery: your photo booth collages, so you can view, share or print them again later (can be switched off in the booth settings; entries can be deleted) | until you delete the entries or the site data |
photobooth-pending, photobooth_pending_collage_*, photobooth_pending_checkout_* | IndexedDB | Keeps a collage you just made while you are redirected to payment, so it can be uploaded afterwards | until it is uploaded or the tab is closed |
feedback_asked_* | localStorage | Remembers that a short feedback question was already shown, so it does not appear again | until you clear the site data |
staleBuildReloadAt | sessionStorage | Technical guard against endless reloads after a website update | until the tab is closed |
The guest ID (fotobox_guest_id) and the anonymous sign-in ID are sent to our server when you upload a photo and stored with the photo, so your own photos can be linked to you.
Contact by email and contact form
If you write to us by email, we process your email address, your name (if given) and the content of your message to handle your request. Our mailboxes are provided by Microsoft (Outlook.com) and Google (Gmail); data may also be processed in the USA. Emails to addresses at guest-pictures.com (e.g. hello@guest-pictures.com, the reply address of our emails) are forwarded to our mailbox by Cloudflare Email Routing (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA) without storing their content; Cloudflare, Inc. is certified under the EU-US Data Privacy Framework. We delete the correspondence once it is settled and no statutory retention obligations (e.g. for business letters, up to 6 years) apply.
Through our contact form you send us your name, email address, topic and message. We store them with the time of receipt in Google Cloud Firestore (EU, eur3) and delete them automatically after 12 months. To prevent abuse we limit requests per IP address; for this the address is only used hashed in memory and is not stored with the message. We notify ourselves of a new message by email via Resend (Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA; sent from servers in the EU (Ireland); certified under the EU-US Data Privacy Framework, additionally EU Standard Contractual Clauses).
The legal basis is Art. 6(1)(b) GDPR where a contract or pre-contractual steps are concerned, otherwise Art. 6(1)(f) GDPR (legitimate interest in answering enquiries and in preventing abuse).
Recipients and transfers to the USA
We do not sell data or share it for advertising. Recipients are only the providers we need to run the service:
| Recipient | Task | Place of processing |
|---|---|---|
| Google (Firebase / Google Cloud) | Hosting, sign-in, database, photo storage, server functions, logs | Database EU (eur3); photos USA (us-east1); server functions USA (us-central1); sign-in and delivery network worldwide |
| Stripe | Payment processing | EU and USA |
| Resend | Sending automatic emails (e.g. event reminders) | EU (Ireland); company in the USA |
| Microsoft, Google | Email mailboxes | EU and USA |
Google acts as our processor (Art. 28 GDPR). Authorities only receive data where we are legally obliged to provide it (Art. 6(1)(c) GDPR).
Transfers to the USA: Google LLC (USA) is certified under the EU-US Data Privacy Framework. For transfers to certified companies there is an adequacy decision of the European Commission (Art. 45 GDPR). Where data is not covered by the certification, the transfer relies on the EU Standard Contractual Clauses offered by Google (Art. 46(2)(c) GDPR). Despite these safeguards, US authorities may be able to access data in certain circumstances.
Retention
- Events and photos are deleted automatically about 30 days after the event date, unlocked events about 12 months after the event date; in both cases earlier if the host deletes them. A name given voluntarily for the thank-you note is deleted with the event. Deleted image files then remain in Google's recovery storage for up to 7 days before they are removed for good.
- Account: until you delete it.
- Send log of the reminder emails: until the event is deleted.
- Feedback: 365 days; error reports and diagnostic data: 90 days.
- Server logs: 30 days.
- Usage counters: contain no personal data and are kept as daily totals.
- Payment and accounting records (including the partner programme): as long as tax and commercial law require, usually 8 years (Section 147 German Fiscal Code).
- Emails: until the request is settled, subject to statutory retention obligations.
Your rights
You have the following rights regarding your personal data:
- access (Art. 15 GDPR),
- rectification (Art. 16 GDPR),
- erasure (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- withdrawal of consent with effect for the future (Art. 7(3) GDPR).
Right to object (Art. 21 GDPR): Where we process data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you may object at any time on grounds relating to your particular situation. We will then stop processing the data unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims.
An informal message to hello@guest-pictures.com is all it takes. So that we can reliably identify your data (e.g. photos of a guest without an account), please send us the link to the event and describe the photos concerned as precisely as possible.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), for example the authority responsible for us: Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, Postfach 3163, 65021 Wiesbaden, Germany, datenschutz.hessen.de.
No automated decision-making
We do not make automated decisions, including profiling, within the meaning of Art. 22 GDPR.
Obligation to provide data, security
You are under no statutory or contractual obligation to provide personal data. Without the technically necessary data (e.g. your IP address when opening a page), however, the website cannot be used. All connections are encrypted via TLS (HTTPS).
Changes to this privacy policy
We update this privacy policy when our service or the law changes. The version published here applies; the date at the top shows when it was last updated.