Legal

Privacy policy

JoinAlbum is designed to collect event photos privately. We do not sell personal data or use your photos and videos for advertising.

Controller and contact

The data controller is JoinAlbum. For privacy requests and product support, email contact@joinalbum.com.

This generic legal identity should be replaced with the final company details before relying on these pages in production.

Data we process

Hosts provide account details through Firebase Authentication, event titles, event dates, plan/payment status, and album settings.

Guests provide a display name or identifier and upload photos or videos. The browser also stores an anonymous guest token so guests can identify their own uploads.

Uploaded files are stored privately in Cloudflare R2. The app creates short-lived signed links to show files in the gallery.

Hosts and co-hosts may also upload one background image for each saved QR design. It is stored privately in Cloudflare R2 and deleted when that design is deleted.

Why we process data

We process data to create and manage albums, let guests upload media, let hosts download media, provide support, secure the service, and process one-time payments.

Videos are uploaded to storage as received from the guest device. Photos are optimized (resized and re-encoded) in the guest's browser before upload, and we store the optimized file.

Processors

JoinAlbum currently uses Firebase/Google for authentication and Firestore, Cloudflare R2 for private file storage, Lemon Squeezy for checkout, Resend for sending email, and Vercel for hosting.

These providers process data only to provide the service to JoinAlbum, subject to their own processing terms.

Service emails

We email the address on your host account: a confirmation when you create an album, carrying your album link and QR code; reminders in the days before your event date; and an alert if your album reaches its upload limit. Only hosts are emailed — we never email your guests.

The confirmation is part of delivering the service you asked for (Article 6(1)(b) GDPR). The reminders and the full-album alert rest on our legitimate interest in you getting a working album out of the product (Article 6(1)(f)), and every one of them carries a link to stop them.

Stopping them applies to that album and takes effect immediately. Your album, your media, and any payment receipts are unaffected — receipts and other essential messages are not something you can be opted out of. You can also write to contact@joinalbum.com and we will do it for you.

Messages are delivered by Resend, which processes the recipient address and message contents on our behalf.

Album visibility and host responsibility

By default an album is private: each guest only sees the photos and videos they upload, and only the host can view or download the whole album.

The host may instead make the album public (anyone with the link or QR sees everything) or password-protected (guests see everything after entering a password). When the host enables either option, the host decides that guests' photos, videos, and names are shared with other guests and becomes the data controller for that shared content under the GDPR. JoinAlbum acts only as a processor on the host's behalf.

Hosts must only enable shared visibility with the consent of the people in the album and are responsible for handling access, rectification, and deletion requests for the content they chose to share.

Retention and deletion

Every album runs on a fixed schedule measured from its event date: guests can upload for 30 days, and 6 months after the event the album and every photo and video in it are permanently erased from our database and from storage. The host is emailed 3 days before each of those dates. Deletion is automatic and cannot be undone, so download the album while it is still online.

Hosts can delete individual uploads, delete all uploads, and download the album at any time before then. We keep account, event and payment data while needed to provide the service or meet legal obligations.

Privacy requests can be sent to contact@joinalbum.com.