Controller
SnapTogether is operated by Jan Tempel, Wiesenstraße 1, 67487 Maikammer, Germany, snaptogether@web.de.
Scope and service
This policy applies to registered users and guests who join a shared event gallery by link or QR code. Hosts can configure events, invite participants, collect photos and captions, enable interactions, moderate participation, and offer downloads or archives.
Guest sessions
Guests do not have to provide an email address. When a guest joins, SnapTogether creates an anonymous authentication account with a unique user identifier and a session credential stored on the device. Anonymous in this product context means without registration details; it does not mean that the associated data is anonymous under data protection law. The identifier, membership, display name, profile image, content, interactions and technical records can still be personal data. The active session proves control of that guest identity. Losing the session, clearing app data or changing devices may make automatic recovery or secure attribution impossible. We do not collect an email address solely so that a future rights request can be identified.
Data we process
We process account or guest identifiers, email only if supplied for a registered account, authentication status and timestamps; display name, profile image, invite context, memberships, roles and approval status; event configuration for events created by a user; uploaded photos, previews, captions, comments, likes, award votes, compliments and mission participation; app, browser, request, IP, security, diagnostic, synchronization and upload or download metadata; and support or legal-request data when you contact us.
Purposes and legal bases
We process this data to provide and secure SnapTogether, authenticate registered and guest sessions, synchronize event data, enforce membership and permissions, deliver media, provide interactions and exports, moderate content, prevent abuse, diagnose errors, answer requests and comply with law. Depending on the processing, the legal basis is performance of the user agreement or steps requested before it, our legitimate interests in operating and securing the service, consent where specifically requested, or a legal obligation. Optional device permissions and uploading content are voluntary; the applicable basis must be assessed for the particular processing.
Visibility and photos
Event data is shared only with event members according to roles and settings. Hosts and moderators can manage participants and content. You keep your rights in content you upload and grant only the permission needed to store, resize, display, transmit, synchronize, cache, moderate, export and delete it for the service. Hosts and uploaders remain responsible for an appropriate legal basis when photos show other people, especially minors.
Processors and transfers
We use Supabase for authentication, database, functions and security rules, and Cloudflare Pages, network services and R2 for application and media delivery. These providers process data for operating the service. Where a transfer outside the European Economic Area requires safeguards, appropriate transfer mechanisms such as standard contractual clauses are used.
Local storage
The app stores session information, event data, sync state, media previews, language settings and legal-content cache locally so it can work across sessions and with limited connectivity. Clearing app data or uninstalling the app can remove the local session but does not itself delete server data.
Retention and deletion
Guest authentication and membership data are retained while needed for event access and the account or event lifecycle. Event media follows the configured storage duration and deletion flows. Removed participants and deleted or expired events are processed according to the implemented deletion flow. Limited records may remain where required for security, legal obligations, pending requests or backups. Truly anonymized data may be retained because it is no longer personal data.
Your rights and export
Under the GDPR you may have rights of access, rectification, erasure, restriction, objection, portability, withdrawal of consent and complaint to a supervisory authority. Registered users and guests with an active session can use the in-app personal-data export without providing an email address. It supplies a file containing the assigned data and separately downloads the user's own stored media. The export covers data assigned to the authenticated user or guest identifier; it does not automatically identify photos uploaded by another person merely because the requesting person appears in them. For those photos, technical logs, data no longer available in the app, or a more specific request, contact us and provide the event and membership or content details reasonably available to you. We may request only additional information necessary to verify identity and must also protect the rights of other people. A lost guest session may limit what we can securely attribute, and we do not retain or collect additional identity data solely for future requests.
Contact
For privacy requests contact snaptogether@web.de. No email is required to use the guest export; email is only the contact channel for requests that cannot be handled securely in the active session.