Snapuj
Log in
HomeLog in

Snapuj · Documents

Privacy Policy (GDPR)

Version 0.1-draft · effective 22 August 2026

This is a working draft for testing and launch prep. It is not legal advice. Complete the controller details and have a lawyer review the text before a public launch.

TermsPrivacy policyCookies

1. Controller

The personal data controller is Tomasz Słowicki.

Address: Warszawa, ul. Marii Callas 10/76, 03-289.

Privacy contact: slowickitomasz0@gmail.com.

2. Data we process

Host: email, password (hashed by the auth provider), display name, event data (name, date, location, upload window).

Guest (including without email): display name, anonymous session id, photos/files (including filename and size), wish text, optional guestbook video, optional quiz answers.

After the gallery closes, the preview password is stored only as a cryptographic hash.

Technical data: hosting/security logs (IP, browser) if collected by infrastructure.

3. Purposes and legal bases (GDPR Art. 6)

Providing the gallery and guestbook — Art. 6(1)(b) (contract / terms; for Guests: performing the requested join-to-event service).

Host account and service messages (e.g. invite email if used) — Art. 6(1)(b).

Security, abuse prevention, establishing claims — Art. 6(1)(f).

Strictly necessary cookies (session, language, cookie-notice acknowledgement) — Art. 6(1)(f) and the ePrivacy exception for essential cookies. We do not currently use advertising or analytics cookies that need marketing consent.

4. Recipients

Database and file provider (Supabase).

App hosting (e.g. Netlify).

Invite email provider (Resend), only if the Host uses it and the feature is enabled.

The Host sees Content and members of their event. Other guests of the same event may see photos, names and wishes in the gallery.

5. Retention

Event data and Content: until the Host deletes the event or account, and as needed to defend claims.

Guest session: until sign-out, cookie expiry, or clearing site data.

The guest name in localStorage stays on the device until the Guest clears site data.

6. Your rights

Access, rectification, erasure, restriction, portability, and objection to Art. 6(1)(f) processing.

You may lodge a complaint with the Polish DPA (UODO) or your local authority.

Requests: controller email. For Content inside a specific event, contact the Host first.

7. Transfers outside the EEA

Cloud providers may process data outside the EEA using GDPR transfer tools (e.g. SCCs). See the provider documentation for regions.

8. Children

The Service is not directed at children under 16. The Host is responsible for whom they invite and which photos they publish.

TermsPrivacy policyCookies