1. Who this policy applies to
Hosts create an account to set up events, moderate uploads, manage billing, and download photos.
Guests visit an event link or scan a QR code to upload photos and optionally react or comment — no account is required.
If you use on behalf of an organization, you are responsible for ensuring your use complies with applicable privacy laws, including informing guests that photos may be collected and displayed.
2. Personal data we collect
2.1 Host account data
When you create an account, we collect:
- Email address (required for sign-in)
- Password (stored and processed by our authentication provider; we do not store your password in our application database)
- Display name (optional at registration; you may update it later)
We also create a profile record linked to your account containing your email and name.
2.2 Event and content data (provided by hosts)
Event name, description, date, URL slug, moderation settings, and plan/access settings.
2.3 Guest uploads and interactions
Guests may provide:
- Photos (image files you choose from your device)
- Comments (text, up to 500 characters)
- Optional display name on comments (up to 40 characters)
- Reactions to photos (e.g. heart, clap)
We assign guests a random identifier (guest token) stored in your browser to support uploads, reactions, and comments. This token is pseudonymous — it is not linked to your name unless you choose to provide one on a comment.
Photos may contain images of identifiable individuals (including you or others). Hosts control whether uploads are auto-published or held for moderation.
2.4 Payment data
If you purchase a Photo Gallery upgrade or Iskra Pro subscription, payment card and billing details are collected by Stripe on Stripe-hosted checkout pages. We receive and store:
- Stripe customer and subscription identifiers
- Checkout session identifiers
- Purchase amounts and plan tier
- Subscription status and billing period dates
We do not store full payment card numbers.
2.5 Support and feedback
Signed-in hosts may submit free-text feedback from the dashboard.
2.6 Technical and security data
We process limited technical data to operate and protect the service, including:
- IP address (used for rate limiting and abuse prevention; stored in pseudonymized form as part of rate-limit records)
- Guest token (for rate limiting and associating your reactions/comments with your browser)
- Server logs (e.g. request identifiers, operational events; sensitive values such as passwords, tokens, and email addresses are redacted in application logs)
- Error and performance data (if error monitoring is enabled — see Section 5)
2.7 Cookies and browser storage
We use:
- Authentication cookies (Supabase Auth) to keep hosts signed in
- Browser local storage on guest devices for:
iskra_guest_token— pseudonymous guest identifieriskra_guest_name— optional comment name convenience
We do not use third-party advertising cookies or cross-site tracking pixels.
3. How we use personal data
We use personal data to:
- Provide the service (events, galleries, live display, moderation, social features)
- Authenticate hosts and manage accounts
- Process payments and manage subscriptions
- Prevent abuse (rate limiting, CSRF protections, access controls)
- Monitor reliability and fix errors
- Respond to support requests
We use personal data only for these operational purposes. We do not sell your personal data.
Emails: does not currently send product, marketing, or notification emails from the application. Account-related emails (such as sign-up confirmation or password reset, if enabled) may be sent by our authentication provider as part of the sign-in service. In-app email notification preferences are not yet available.
4. Legal bases (UK/EU users)
Where UK GDPR / EU GDPR applies, we rely on:
- Contract — to provide the service you sign up for, process paid upgrades, and manage your account
- Legitimate interests — to secure the platform, prevent abuse, maintain logs, and improve reliability, balanced against your rights
- Consent — where you optionally provide a guest display name or upload photos/comments (you may choose not to use those features)
- Legal obligation — where required (e.g. tax/accounting records via payment processors)
Hosts who upload photos of others should ensure they have an appropriate legal basis (often consent or legitimate interests) for sharing those images.
6. Public and shared content
Please understand:
- Approved event photos are stored in a publicly readable storage bucket and may appear in the event gallery, live view, and shared links/QR codes.
- Pending photos (when manual moderation is enabled) are stored in a private bucket viewable only by the event host until approved or deleted.
- Comments (including any optional display name you provide) and reaction counts may be visible to other visitors while the gallery is open.
- Anyone with a direct link to an approved photo file may be able to access that file even after the gallery UI closes, because approved files reside in public storage.
Do not upload content you do not have permission to share.
7. Data retention
7.1 Plan access windows
Event data is subject to plan-based access windows (not automatic deletion):
| Plan | Guest upload period | Guest gallery access | Host dashboard access |
|---|---|---|---|
| Free | 7 days | 7 days | 30 days |
| Photo Gallery | 30 days | 90 days | 90 days |
After these windows, guest upload and gallery features are disabled by the application, but data generally remains stored unless deleted as described below.
7.2 Deletion
- Hosts may archive events, delete individual photos/comments via moderation, or delete their account from Account settings. Account deletion cancels active Stripe subscriptions, deletes account-linked database records (including events, photos, comments, reactions, purchases, and feedback, subject to database cascading rules), and attempts to remove associated photo files from storage.
- Self-service data export is not available in the application. Contact hello@iskra.app to request a copy of your data.
- Guests (without accounts) should contact hello@iskra.app or the event host to request removal of comments or photos.
7.3 Other records
- Rate-limit and operational logs are retained for short-term security and troubleshooting periods consistent with our infrastructure providers' defaults.
- Stripe may retain payment and transaction records after account deletion in accordance with Stripe's legal and contractual obligations.
We do not currently run automated scheduled deletion of expired event data.
8. Security
We implement technical and organizational measures including:
- Database row-level access controls
- Server-side validation for guest uploads and social actions
- Separation of pending (private) and approved (public) photo storage
- Content Security Policy and other HTTP security headers
- Redaction of sensitive values in application logs
- Rate limiting on uploads, comments, reactions, authentication, and billing actions
No method of transmission or storage is 100% secure. Report concerns to hello@iskra.app.
9. International transfers
Our infrastructure providers may process data in countries outside your own, including the United States. Where required, we rely on appropriate safeguards (such as standard contractual clauses offered by our providers). Provider regions depend on our Supabase and Vercel project configuration: [Supabase region — to confirm].
10. Your rights
Depending on where you live, you may have rights to access, rectify, erase, restrict, object to processing, and data portability, and to withdraw consent where processing is consent-based.
How to exercise rights today:
- Update display name: Account → Your details
- Delete account: Account → Delete account (requires email confirmation)
- Manage Pro subscription: Account → Plan & limits (Stripe billing portal where applicable)
- Export or other requests: email hello@iskra.app
We will respond within the timeframe required by applicable law.
UK users may complain to the Information Commissioner's Office (ICO). EEA users may contact their local supervisory authority.
11. Children
is intended for event organizers and adult guests. It is not directed at children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided personal data, contact us and we will take appropriate steps.
12. Changes to this policy
We may update this policy from time to time. We will post the updated version on this page and revise the “Last updated” date. Material changes may be communicated through the service or by email where appropriate.
13. Contact
[Legal Entity Name]
[Registered Address]
Email: hello@iskra.app
This policy should be reviewed by qualified legal counsel before publication. Replace bracketed controller details and confirm your Supabase region before going live.