Spotted

Privacy policy

Version 2026-09-14-credit-packages

Who is responsible

The seller identified above operates Spotted and is responsible for its own account, billing, support and service-security processing. The organizer decides who joins a wedding, when photos are revealed and how the wedding album is used. A professional organizer may have its own controller responsibilities. Contact support if you need help identifying the organizer for your wedding.

Information we process

Organizer sign-in supplies a Google account identifier, email, name and profile image. We use an authenticated session to keep the organizer signed in. Wedding records contain the details the organizer enters, invitation credentials, settings and cover image. A guest receives a random browser identifier and a separate session for each wedding; guests are not required to supply their name or email.

Camera photos are linked to a wedding, category and guest session, with dimensions, file size, upload status and timestamps. Book requests can contain name, email, delivery address, notes, selected photos, design approval and tracking. Billing records include the purchased plan, payment references and status, accepted purchase terms and timestamps. Stripe (only for any previous online payments) handles card details; Spotted does not store full card numbers.

The hosting and payment providers may also process connection details such as IP addresses and security logs needed to deliver or protect their services. Spotted does not perform face recognition or create biometric profiles from wedding photos.

Purposes and legal bases

We use organizer and order information to perform the requested service and contract, billing information to meet applicable legal obligations, and limited session and security data for our legitimate interests in preventing misuse and keeping weddings private. Where consent is required for an optional purpose, we ask separately and allow it to be withdrawn. Refusing optional marketing does not prevent use of the paid product.

The organizer is responsible for the lawful basis of its collection and use of guest photos. Device camera permission permits technical camera access and is not consent on behalf of everyone pictured. Spotted processes wedding content to provide the requested event experience and respond to authorized instructions and rights requests. We do not sell personal information, use wedding photos for advertising without separate permission or use them for AI training.

Who can see the information

The wedding account owner can review and download its photos. Invited participants can view gallery previews when the organizer’s settings allow and the reveal opens. A forwarded invitation can give its recipient access; guests cannot assume a revealed gallery is confidential from other participants. Spotted support accesses information only as needed for support, security or an order.

Service providers include Google for organizer sign-in; OpenAI Sites and its Cloudflare-backed database and object storage for hosting the app and photos; and Stripe (only for any previous online payments) when processing payments. A chosen print supplier and carrier receive the selected book files and delivery information needed to fulfill a paid book order; their identity is confirmed before the book is sent to print. We may disclose information when legally required or to establish or defend a legal claim.

Providers can operate in countries other than yours. Where applicable data-protection law requires a transfer safeguard, an appropriate safeguard must cover the transfer. Contact support for the current provider and transfer information. We do not promise that all data remains within the EU.

Cookies, camera and browser storage

Spotted uses essential authentication and guest-session cookies. Guest cookies allow a repeat QR scan in the same browser to resume the same identity; clearing them or changing browsers may start a new one. Browser storage also remembers a wedding draft, a gallery preference and temporary photo uploads awaiting server confirmation. Pending photos are removed from the upload queue after confirmation. Signing out ends the organizer’s session; browser data can be cleared through browser settings.

The camera opens only after the guest starts the camera flow and grants permission. The camera is paused outside the viewfinder or while the page is hidden. The existing camera connection can be reused during the photo flow to avoid repeated access requests; it is stopped when leaving that flow or closing the page. Spotted does not need microphone permission. The app uses Google-hosted fonts and Google sign-in resources, which can receive connection information when loaded. Spotted currently adds no advertising or behavioral analytics cookies.

How long information is kept

Wedding access and album retention follow the published plan: the paid period, then 30 days read-only and a further 60-day archive period. We contact the organizer at least 30 days before scheduled permanent deletion; automatic expiry does not currently purge photos. The organizer can delete a wedding earlier, subject to resolving an open book order. Photo moderation initially hides a photo and is distinct from permanent privacy erasure.

Account, guest and support records are retained only as needed for the service, security and rights requests. Payment and accepted-contract records may need to remain for applicable accounting and legal-claim periods even after a wedding is deleted. The exact statutory period depends on the seller’s jurisdiction and the record; contact support for the period applicable to your purchase. We restrict separately retained records from ordinary gallery access.

Your rights and contact

Depending on applicable law you may request access, correction, erasure, restriction or portability of your information, object to processing based on legitimate interests, and withdraw consent for an optional purpose. Contact the support email above with your wedding or order reference. We may need proportionate information to verify the request; do not send passwords or payment-card details. You can also contact the organizer to remove a wedding photo.

We respond within the period required by applicable law, normally one month for GDPR requests, and explain any lawful extension or limitation. Erasure rights are subject to obligations such as keeping necessary tax records. You may complain to your competent data-protection authority. Contact support promptly about an exposed invitation or suspected security issue. We update this notice when processing changes and communicate material changes as appropriate.

Bank-transfer requests

For manual payments we store your contact details, selected package or plan, request reference, amount, payment status, confirmed access dates and the payment reference recorded by the Spotted team. Bank details and any transfer evidence are exchanged privately by email. The app does not connect to your bank or request banking credentials. Requests and confirmations are handled personally by Spotted; an app request does not itself send an email or execute a transfer.