1. Who we are
PhotoShare Events is operated by Aerial Aspect Media LLC, a Virginia limited liability company. Where this policy uses "we," "us," or "our," it refers to Aerial Aspect Media LLC.
Contact for privacy matters: [email protected]
2. Scope
This policy describes how we handle personal information when:
- an account holder — a Host or a Photographer (Pro) — signs up for and uses the Service to host events;
- a Guest visits an event page, views photos, downloads them, or uploads their own;
- a Visitor browses our marketing site.
It does not cover personal information that a account holder handles on their own behalf using the Service. For that, the account holder is the data controller and you should contact them directly. We act as a processor for any guest content uploaded to a account holder's event.
3. Information we collect
From account holders
| Category | Examples | Source |
|---|---|---|
| Account info | Email address, password (hashed), display name | You |
| Billing info | Name, billing address, last 4 of card, transaction history | You via our payment processor (currently Stripe, Inc.) |
| Event metadata | Event name, date, settings, storage usage | You |
| Communications | Support tickets, email correspondence | You |
From Guests
| Category | Examples | Source |
|---|---|---|
| Uploaded photos | Image files. On upload we strip GPS/location and other identifying metadata from the stored copy, keeping only image orientation and the capture date/time | You |
| Comments | Text you submit with photos | You |
| Technical info | IP address, browser type, request timestamps | Automatic |
We do not require Guests to create an account or provide an email address to view or upload to an event.
We do not perform facial recognition on uploaded photos, and we do not collect, generate, or store biometric identifiers (such as faceprints or facial-geometry scans).
From all users
| Category | Examples |
|---|---|
| Logs | HTTP request logs, error logs, application metrics |
| Cookies | A session cookie used to keep you signed in (account holders only). No third-party advertising cookies. |
| Device info | User-agent string, screen size (for responsive layout) |
4. How we use it
We process personal information to:
- provide and operate the Service (host events, store and serve photos);
- bill account holders and prevent fraud;
- respond to support requests;
- secure the Service (rate limiting, abuse detection, audit logs);
- send transactional emails (account confirmation, billing receipts, service notices);
- comply with legal obligations and enforce our Terms;
- keep records of consent and acceptance of our Terms — including a privacy-preserving record (a keyed hash of the IP address, never the raw address) when a Guest uploads a photo or posts a comment;
- operate the in-app help assistant — questions you type into the help chat are sent to our AI subprocessor (Anthropic) to generate an answer and are logged to improve our help content;
- improve the Service through aggregated, non-identifying usage analysis;
- with your consent, send marketing emails to account holders (you can opt out at any time).
5. Legal bases (GDPR / UK GDPR)
Where applicable law requires us to identify a legal basis, we rely on:
- Contract (Art. 6(1)(b)) — to provide the Service you signed up for.
- Legitimate interests (Art. 6(1)(f)) — to operate, secure, and improve the Service; to prevent fraud; to communicate operationally with account holders.
- Consent (Art. 6(1)(a)) — for marketing emails and any optional cookies beyond the strictly necessary session cookie.
- Legal obligation (Art. 6(1)(c)) — to comply with tax, accounting, and law-enforcement requirements.
For guest-uploaded photos, the account holder is the controller and is responsible for identifying the lawful basis under which guests upload.
6. Who we share information with
We share personal information only with our subprocessors:
| Subprocessor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. (R2) | Object storage for photos and ZIP archives | Global |
| Cloudflare, Inc. (CDN, DNS) | Content delivery, DDoS protection | Global |
| Stripe, Inc. | Payment processing, tax calc, billing data | Global |
| Anthropic, PBC | AI help assistant — processes questions you type into the in-app help chat to generate answers | Global (US) |
We do not sell personal information. We do not share it with advertisers. We may disclose information in response to a valid legal process or to protect the Service or a person from imminent harm.
The list above is the current state. Material changes (a new subprocessor or a change in purpose) will be reflected here and, where required, notified to account holders in advance.
7. International transfers
We are based in the United States and our subprocessors operate globally. Where personal information is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, we rely on Standard Contractual Clauses or equivalent safeguards.
8. How long we keep it
| Data | Retention |
|---|---|
| Account holder | While account is active + 30 days after deletion |
| Event photos (active event) | Life of the event + 90 days |
| Event photos (archived event) | 180 days after archival |
| Backups | Up to 30 days beyond deletion |
| Billing records | 7 years (US tax requirements) |
| Application logs | 90 days |
| Consent & acceptance records | 2 years |
| Support correspondence | 2 years |
After the retention period, data is deleted or irreversibly anonymized.
9. Your rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate information.
- Delete your information (subject to legal retention obligations).
- Export a portable copy of your information.
- Restrict or object to certain processing (GDPR).
- Opt out of marketing emails at any time.
- Withdraw consent where processing is based on consent.
To exercise any of these, email [email protected]. We will respond within 30 days (or as required by applicable law).
California residents have additional rights under the CCPA / CPRA, including the right to know what information we collect, the right to delete, and the right not to be discriminated against for exercising those rights. We do not sell personal information and do not "share" it for cross-context behavioral advertising.
If you are a Guest whose photo was uploaded to a account holder's event, your first stop should be the account holder (the controller of that content). We will assist them as a processor.
If you are depicted in a photo uploaded to an event and want it removed, email [email protected] or contact the event's account holder. We can remove or hide content under our Terms even if you do not have an account.
10. Children
The Service is not directed to children under 13 (or under 16 in jurisdictions that set that bar). We do not knowingly collect personal information from children. If you believe a child has provided personal information through the Service, contact us and we will delete it.
This does not prevent an account holder from hosting photos of children at an event they are photographing; that content is governed by the account holder's own consent and release practices, which our Terms require to include a parent or guardian's consent for any recognizable minor.
11. Security
We protect personal information with measures appropriate to its sensitivity, including:
- TLS encryption in transit;
- encryption at rest for stored photos and backups;
- password hashing with a modern KDF;
- access controls limiting employee/contractor access to a need-to-know basis;
- application and infrastructure logging for incident response;
- regular dependency and vulnerability updates.
No system is perfectly secure. If we become aware of a personal-data breach, we will act without undue delay to investigate and contain it, and will notify those affected as the law requires:
- Account-holder data (where we are the controller): we notify the affected account holder, and any regulator, as required by applicable law.
- Guest content (where the account holder is the controller and we are the processor): we notify that account holder without undue delay so they can meet their own duties to notify guests and regulators — for example, the 72-hour regulator-notification window under the GDPR. We assist them as a processor.
If you are a guest and believe your content may have been exposed, contact the event's account holder (the controller), or email [email protected] and we will help route your concern.
12. Cookies
We use a single strictly necessary session cookie to keep account holders signed in. We do not use third-party advertising or behavioral tracking cookies.
If we add any analytics in the future, we will use a privacy-preserving solution (e.g. Plausible, self-hosted) that does not set cross-site tracking cookies, and we will update this policy.
13. Changes to this policy
We may update this policy. Material changes will be announced by email or prominent in-app notice at least 30 days before they take effect. The "Last updated" date at the top of this document reflects the most recent change.
14. Contact
For privacy questions or to exercise your rights:
Aerial Aspect Media LLC
Commonwealth of Virginia, United States
[email protected]