Legal

Privacy policy

This Privacy Policy describes how we collect, use, store, and share personal data when you use as an event host (organizer) or guest. It reflects how the application is built and operated today.

Effective 6 September 2026 · Last updated 6 September 2026

Controller: [Legal Entity Name] (“we”, “us”, “our”)

Contact: hello@iskra.app

Product: — event photo sharing at https://iskra.app

1. Who this policy applies to

Hosts create an account to set up events, moderate uploads, manage billing, and download photos.

Guests visit an event link or scan a QR code to upload photos and optionally react or comment — no account is required.

If you use on behalf of an organization, you are responsible for ensuring your use complies with applicable privacy laws, including informing guests that photos may be collected and displayed.

2. Personal data we collect

2.1 Host account data

When you create an account, we collect:

  • Email address (required for sign-in)
  • Password (stored and processed by our authentication provider; we do not store your password in our application database)
  • Display name (optional at registration; you may update it later)

We also create a profile record linked to your account containing your email and name.

2.2 Event and content data (provided by hosts)

Event name, description, date, URL slug, moderation settings, and plan/access settings.

2.3 Guest uploads and interactions

Guests may provide:

  • Photos (image files you choose from your device)
  • Comments (text, up to 500 characters)
  • Optional display name on comments (up to 40 characters)
  • Reactions to photos (e.g. heart, clap)

We assign guests a random identifier (guest token) stored in your browser to support uploads, reactions, and comments. This token is pseudonymous — it is not linked to your name unless you choose to provide one on a comment.

Photos may contain images of identifiable individuals (including you or others). Hosts control whether uploads are auto-published or held for moderation.

2.4 Payment data

If you purchase a Photo Gallery upgrade or Iskra Pro subscription, payment card and billing details are collected by Stripe on Stripe-hosted checkout pages. We receive and store:

  • Stripe customer and subscription identifiers
  • Checkout session identifiers
  • Purchase amounts and plan tier
  • Subscription status and billing period dates

We do not store full payment card numbers.

2.5 Support and feedback

Signed-in hosts may submit free-text feedback from the dashboard.

2.6 Technical and security data

We process limited technical data to operate and protect the service, including:

  • IP address (used for rate limiting and abuse prevention; stored in pseudonymized form as part of rate-limit records)
  • Guest token (for rate limiting and associating your reactions/comments with your browser)
  • Server logs (e.g. request identifiers, operational events; sensitive values such as passwords, tokens, and email addresses are redacted in application logs)
  • Error and performance data (if error monitoring is enabled — see Section 5)

2.7 Cookies and browser storage

We use:

  • Authentication cookies (Supabase Auth) to keep hosts signed in
  • Browser local storage on guest devices for:
    • iskra_guest_token — pseudonymous guest identifier
    • iskra_guest_name — optional comment name convenience

We do not use third-party advertising cookies or cross-site tracking pixels.

3. How we use personal data

We use personal data to:

  • Provide the service (events, galleries, live display, moderation, social features)
  • Authenticate hosts and manage accounts
  • Process payments and manage subscriptions
  • Prevent abuse (rate limiting, CSRF protections, access controls)
  • Monitor reliability and fix errors
  • Respond to support requests

We use personal data only for these operational purposes. We do not sell your personal data.

Emails: does not currently send product, marketing, or notification emails from the application. Account-related emails (such as sign-up confirmation or password reset, if enabled) may be sent by our authentication provider as part of the sign-in service. In-app email notification preferences are not yet available.

5. How we share personal data

We share personal data with service providers that help us operate :

ProviderPurposeData involved
SupabaseAuthentication, database, file storage, realtime updatesAccount, event, photo, comment, reaction, and operational data
StripePayment processing and subscription billingPayment and billing identifiers; checkout metadata
VercelApplication hostingHTTP request data, deployment logs
Sentry (if configured)Error monitoringError details, diagnostic logs (sensitive fields redacted by our application)
Vercel Speed InsightsCore Web Vitals performance measurementPage performance metrics

These providers process data on our behalf under their respective terms and privacy policies. Payment data you enter on Stripe is governed by Stripe's Privacy Policy.

We may also disclose data if required by law or to protect rights, safety, and security.

6. Public and shared content

Please understand:

  • Approved event photos are stored in a publicly readable storage bucket and may appear in the event gallery, live view, and shared links/QR codes.
  • Pending photos (when manual moderation is enabled) are stored in a private bucket viewable only by the event host until approved or deleted.
  • Comments (including any optional display name you provide) and reaction counts may be visible to other visitors while the gallery is open.
  • Anyone with a direct link to an approved photo file may be able to access that file even after the gallery UI closes, because approved files reside in public storage.

Do not upload content you do not have permission to share.

7. Data retention

7.1 Plan access windows

Event data is subject to plan-based access windows (not automatic deletion):

PlanGuest upload periodGuest gallery accessHost dashboard access
Free7 days7 days30 days
Photo Gallery30 days90 days90 days

After these windows, guest upload and gallery features are disabled by the application, but data generally remains stored unless deleted as described below.

7.2 Deletion

  • Hosts may archive events, delete individual photos/comments via moderation, or delete their account from Account settings. Account deletion cancels active Stripe subscriptions, deletes account-linked database records (including events, photos, comments, reactions, purchases, and feedback, subject to database cascading rules), and attempts to remove associated photo files from storage.
  • Self-service data export is not available in the application. Contact hello@iskra.app to request a copy of your data.
  • Guests (without accounts) should contact hello@iskra.app or the event host to request removal of comments or photos.

7.3 Other records

  • Rate-limit and operational logs are retained for short-term security and troubleshooting periods consistent with our infrastructure providers' defaults.
  • Stripe may retain payment and transaction records after account deletion in accordance with Stripe's legal and contractual obligations.

We do not currently run automated scheduled deletion of expired event data.

8. Security

We implement technical and organizational measures including:

  • Database row-level access controls
  • Server-side validation for guest uploads and social actions
  • Separation of pending (private) and approved (public) photo storage
  • Content Security Policy and other HTTP security headers
  • Redaction of sensitive values in application logs
  • Rate limiting on uploads, comments, reactions, authentication, and billing actions

No method of transmission or storage is 100% secure. Report concerns to hello@iskra.app.

9. International transfers

Our infrastructure providers may process data in countries outside your own, including the United States. Where required, we rely on appropriate safeguards (such as standard contractual clauses offered by our providers). Provider regions depend on our Supabase and Vercel project configuration: [Supabase region — to confirm].

10. Your rights

Depending on where you live, you may have rights to access, rectify, erase, restrict, object to processing, and data portability, and to withdraw consent where processing is consent-based.

How to exercise rights today:

We will respond within the timeframe required by applicable law.

UK users may complain to the Information Commissioner's Office (ICO). EEA users may contact their local supervisory authority.

11. Children

is intended for event organizers and adult guests. It is not directed at children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided personal data, contact us and we will take appropriate steps.

12. Changes to this policy

We may update this policy from time to time. We will post the updated version on this page and revise the “Last updated” date. Material changes may be communicated through the service or by email where appropriate.

13. Contact

[Legal Entity Name]

[Registered Address]

Email: hello@iskra.app

This policy should be reviewed by qualified legal counsel before publication. Replace bracketed controller details and confirm your Supabase region before going live.