Privacy notice

Version 1.1 · last updated 2 August 2026

This notice explains how photos, videos, and related information are handled when guests upload to a couple's wedding gallery through this service. Guest media is personal data, and we treat it that way. It is written first for the guests who upload, and it also covers the host (the couple).

Who is the data controller

The data controller is the party legally responsible for the personal data described in this notice, and the party you address a rights request to.

Legal entity:
Theerakorn Prasutchai
Registered address:
17 PUNNAWITH50 BANGKOK THAILAND
Email for rights requests:
seanmthai@gmail.com

We have appointed a Data Protection Officer: Theerakorn Prasutchai. You can reach them at seanmthai@gmail.com about anything on this page, including a rights request.

What we collect

From a guest who uploads: (1) the photo and video files you choose to share, together with their size, file type, pixel dimensions, and the capture time read from the file's own EXIF data; (2) a first-party device identifier — we store only a ONE-WAY CRYPTOGRAPHIC HASH of the token your browser generated (today that is SHA-256), never the token itself, and it is used solely to group your own files together and to count contributors; (3) a display name, if you choose to type one (optional); and (4) the time your consent was captured. The token itself stays in your own browser's storage; it is what lets the upload page recognise your files without an account. We set no advertising cookies and nothing that tracks you across other websites. From a host: the email or social-login identity used to sign in, and the event details you enter (couple names, wedding date, venue). Payments are handled by our payment processor: we keep only the transaction reference and the amount, never your card number. Please upload only photographs and videos you have the right to share.

Our lawful basis for each category

By category: guest media, display names, and consent timestamps are processed on the basis of CONSENT — tapping upload is how that consent is given, and you can withdraw it at any time. Host account data, event details, and payment records are processed on the basis of CONTRACT, to provide the service the couple purchased. Error diagnostics and aggregate product analytics are processed on the basis of LEGITIMATE INTERESTS, to keep the service working; we configure our error reporting not to attach personally identifying data. Keeping the service secure is also a LEGITIMATE INTEREST rather than consent — preventing and investigating abuse, fraud, and unauthorised access, and defending the service against attack. We have assessed these interests as necessary and proportionate to running the service at all, and as not overriding your rights and freedoms: we collect no more than the purpose needs and keep it no longer than the purpose needs. Our audit log is kept on the basis of LEGAL OBLIGATION, because it is the evidence that we honoured a rights request and actually deleted what we said we deleted. One consequence is worth saying plainly: withdrawing consent removes your media, but it does not erase the security and audit records showing that the upload and the withdrawal happened — those records are the proof that we did what you asked, and they contain no personal content.

The couple's role, and ours

Both the couple and we are responsible for your data, for different decisions, and we would rather state our position than leave it open. WE are the data controller for the decisions we take on our own and not on anyone's instruction: how long an event's data is kept, when it is erased, how consent is recorded, how the service is secured, and how a rights request is answered. Retention is the clearest illustration — we set the period ourselves and it can only ever be extended, never shortened, not even at the couple's request. That is not a decision taken on their behalf. THE COUPLE is the data controller for the decisions that are genuinely theirs: whether to gather photos at all, who may see the gallery, whether to open it to other guests or show it on the venue slideshow, whether to give their planner or photographer access, and what they do with the files once they have downloaded them — copies we cannot reach. What this means for you does not depend on how the law finally characterises the split: you can always bring a rights request to us directly, we will act on it ourselves, and we will never refuse you by sending you off to ask the couple. If our position changes, this notice changes with it.

Who sees your photos

The couple sees every file you upload — that is the purpose of the service — and the couple decides who else may see it. That can include: anyone they send a view-only link to (the link does not give access to full-resolution originals, is not indexed by search engines, and the couple can switch it off at any time); other guests, but only if the couple opens the shared gallery, which is OFF by default; and everyone in the room, if your photo appears on the venue slideshow. If the couple gives their planner, venue, or photographer access to the gallery, those people see it too — we do not grant that access, but the couple can. On our side, access is limited to the people who need it to run the service and answer support requests, and to what those jobs require; as the service is built today, the internal console our team uses renders no guest photo at all — no thumbnail, no link, not even a storage key. We do not sell personal data and we do not use it for advertising.

Where your data is stored

Every one of our processors is outside Thailand, so every transfer of your data to them is a CROSS-BORDER TRANSFER under Thailand's PDPA — not just the distant ones. We chose Asia-Pacific locations for the image files themselves and for the database, as the closest practical option available today, but our payment processing happens in the United States. The table below names each processor, what it does, the region it processes in, and the basis we rely on to make that transfer lawful. For every one of them that basis is the company's own standard data-protection agreement; we have not negotiated bespoke terms with any of them, and the table says so per row rather than in a blanket sentence. Each of these companies may in turn engage its own sub-processors under equivalent obligations; those lists are theirs and not ours, so we point you to the list each company publishes rather than restate it here and let it go stale.

The companies that process data for us

We use these companies to run the service. Each sees only what its job requires, and each is bound by data-protection terms. All of them are outside Thailand.

ProcessorWhat it doesProcessing regionBasis for the transfer
SupabaseTheir sub-processor listDatabase and host sign-in — metadata about the media, never the files themselvesSingaporeData-processing agreement
Cloudflare R2Their sub-processor listObject storage — this is where your actual photo and video files liveAsia-PacificData-processing agreement
StripeTheir sub-processor listTakes payment from the host (PromptPay and card) — never sees guest mediaUnited StatesData-processing agreement
SentryTheir sub-processor listError diagnostics, configured not to attach personally identifying dataEuropean UnionData-processing agreement
PostHogTheir sub-processor listAggregate product analytics, to see which steps are failing peopleEuropean UnionData-processing agreement

How we protect it

We describe this as what we undertake rather than as the particular tools we happen to use this month, because a notice that names one becomes untrue the day we improve it. Data is encrypted in transit. Your files live in private storage, not at a public address, and are reached through short-lived links rather than permanent ones. Access to the systems holding personal data is restricted to the people who need it, authenticated individually, and limited to what their job requires; access to the internal console is limited to an explicit list of staff. Privacy-significant actions — a disclosure, a deletion, a purge — are written to an audit trail. Our deletion path is tested automatically rather than assumed to work. No service is perfectly secure and we will not claim ours is; what we will say is that we have designed it to hold as little about you as the product allows, which is the protection that does not depend on our getting everything else right.

How long we keep it, and what deletion actually does

An event's media is kept for 12 months measured from the wedding date, and is then deleted. The couple can extend hosting in blocks of 12 months for ฿590, and an extension can only ever push the date further out, never pull it in. When the time comes, deletion is real rather than a hiding of files: every stored copy of your files is erased from our active storage — originals, thumbnails, transcoded video, and download zips alike; every guest row and media row for that event is deleted from the database; and the event itself remains only as a closed record with the couple's names and venue wiped. We prove this rather than assert it: an automated drill runs the real deletion against a seeded event and checks both that the target is gone AND that a second, untouched event beside it is byte-for-byte intact — “it deleted only that” is the claim, not merely “it deleted something”. Two honest limits. Copies the couple or anyone else has already downloaded to their own device are beyond our reach entirely. And where our providers keep routine backups, an erased record can survive in those backups until they expire on the providers' own cycle; an erased record can survive in those backups for up to 7 days after we delete it, and is gone from those too once they expire; we never restore deleted data from a backup. The one thing we keep on purpose is the audit entry recording that the deletion happened and how much it covered — it contains no personal content, and it exists precisely so the erasure can be proven.

Children

Wedding photographs include children; that is part of what a wedding is. We do not knowingly collect personal data directly from a child, and there is nothing here a child is expected to use — uploading is done by adult guests. If you upload a photograph that includes a child, please do so only where you have the standing to share it: as the child's parent or guardian, or with their permission. If a parent or guardian believes a photograph of their child should not be here, contact the data controller and we will remove it. You will not have to justify the request, and we will not tell you who uploaded it. Whether a particular upload additionally requires a guardian's consent under Thai law is a question we are taking advice on, and this section will be updated to match.

Your rights, and how to use them

Under the PDPA you have the right to access your data and obtain a copy of it, to have inaccurate data corrected, to have your data deleted, to withdraw consent, to object to processing, to ask that processing be restricted, and — where the right applies — to receive your data in a machine-readable form so it can be moved elsewhere. Withdrawing consent does not undo processing already carried out before you withdrew. You also have the right to complain to Thailand's Personal Data Protection Committee, and you may go to them directly without telling us first. Most of these work immediately from the upload page, on the same phone you uploaded from, with no account and without writing to anyone — your browser holds the device token that proves those files are yours. There you can see the files you uploaded, delete any of them one by one, change or clear your display name, and tap “everything you hold about me” to view and save a copy of your data as a file. If you switch phones, clear your browser data, or uploaded in a private window, that token is gone and the page will no longer recognise you. Contact the data controller — but understand the difficulty first, because it is a consequence of how little we hold: with only a hash and no name, email, or phone number for you, there is no field to look you up by, and an email address alone cannot resolve to your files. What helps, strongest first, is the device hash quoted from a copy you saved earlier, which matches exactly; failing that, the display name you typed, roughly when you uploaded, and what the photographs show. If that narrows it to exactly one contributor we will act on it; if it does not, we will tell you so and decline, because acting on a guess would mean handing your photographs to someone else. We will not ask you for an identity document, and you should not send one. Finally, two similar-looking things differ: when YOU delete one of your files it is erased, whereas when the COUPLE removes an item from their gallery it merely stops appearing in the gallery, on the slideshow, and in their download, while we still hold the file until the event's deletion date — and you can still delete it yourself at any time.

Your rights, and how to use each one

RightHow
Access, and a copy of your dataTap “everything you hold about me” on the upload page, on the same phone. It shows everything we hold about you and lets you save it as a file straight away, with no account. Or send a request to the data controller.
Correction of inaccurate dataYour display name is the only thing you typed yourself; change or clear it on the upload page from the same phone. Everything else we hold is a technical fact the system recorded itself.
DeletionDelete your own files one by one on the upload page. This works at any time, including after the event stops accepting uploads, and it erases the actual bytes — original and thumbnails alike. To have everything removed in one go, send a request to the data controller. Either way, the whole event's data is deleted after 12 months. The couple removing a file from their gallery is not a deletion — we still hold it. For it to actually be erased, delete it yourself or ask us.
Withdrawal of consentStop uploading, and delete what you already uploaded using the step above; that is what withdrawal consists of here. It does not undo processing already carried out, and it cannot reach copies the couple has already downloaded.
Objection, and restriction of processingSend a request to the data controller. We will stop displaying your files while the request is considered.
PortabilityThe copy you can download from the upload page is machine-readable JSON, where that right applies to your data. For the original image files themselves, ask the data controller.
ComplaintYou can complain directly to Thailand's Personal Data Protection Committee (PDPC), without telling us first.

How to contact us

To exercise a right, or to ask a question about this notice, contact the data controller named at the top of this page. We aim to respond within 30 days, and if a request needs longer than that we will tell you, and why, before the time is up. If your request concerns one particular wedding you can also raise it with the couple hosting it — but you do not have to go to them first, and we will not send you back to them as a way of refusing your request.

Automated decisions

We do not use face recognition, we do not automatically tag or identify people in photographs, and we do not build a profile of you. We do not make decisions about you that produce legal effects, or effects that are similarly significant, by automated means. The only judgements the service makes on its own are operational — counting how many devices contributed to an event, and working out when an event's retention period has ended — and neither one evaluates you as a person.

Disclosure to authorities, and what happens if something goes wrong

We do not sell personal data, and we do not pass it to anyone for their own purposes. We may disclose data where the law obliges us to — a court order, or a lawful demand from a Thai authority acting within its powers. We will check that a demand is actually valid rather than treat anything on letterhead as binding, we will disclose no more than it compels, and where we are permitted to tell you it happened, we will. If personal data is lost, exposed, or reached by someone who should not have it, we will investigate and contain it, and notify the Personal Data Protection Committee and the people affected as the law requires. One practical difficulty is worth flagging in advance: because we hold no way to contact a guest, we generally cannot email you. In that case we will notify the host of the event and publish the notice on this service.

Changes to this notice

When this notice changes we update the version and date shown at the foot of the page, and the previous versions stay listed there so you can see that it changed and when. If a change materially affects how your data is handled we will surface it inside the service rather than rely on you re-reading this page. If the service is ever sold, merged, or transferred to another company, personal data may transfer with it; the receiving company would be bound by this notice as it stands and by anything stricter the law requires, and every right described here would remain yours against them.

Version history

In force since 2 August 2026

Read the terms of service