Privacy Policy
Last updated: 4 October 2026
This policy explains how Event Photos Plus handles personal information, in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. It covers two groups of people: Studios (photographers with an account) and Guests (people photographed at a Studio’s event).
1. What we collect
- Studios: business name, login email, password (stored only as a secure hash), branding assets, billing status. Card details go directly to Stripe; we never see or store full card numbers.
- Guests: the details entered at event sign-up or booking (typically name and email, plus any custom fields the Studio asks for), the photos taken of them, booking times, and delivery status of the emails we send them (delivered, bounced).
- Technical: standard server logs (IP address, request time) used for security and troubleshooting. We do not run advertising trackers.
2. How we use it
- Delivering private photo galleries to Guests and emails about them (their gallery link, booking confirmations, retention reminders).
- Operating Studio accounts, subscriptions, and retouching payments.
- Keeping the Service secure, debugging, and preventing abuse.
We do not sell personal information, and we do not use Guest details for marketing of our own.
3. Who we share it with
- The Studio that photographed you (for Guests): your sign-up details, gallery activity, and retouching selections are visible to that Studio - they are the ones delivering your photos.
- Service providers: Cloudflare (photo storage), Stripe (payments), Resend (email delivery), and our hosting provider. Each receives only what it needs to perform its function, and some may store data outside Australia (for example the United States).
- Authorities where the law requires it.
4. Retention and deletion
- Guest photos are kept for the retention window offered at sign-up (or the Studio’s job settings) and then permanently deleted. Where a Guest chose a window and gave an email address, we send a reminder about 24 hours before deletion.
- Unmatched photos on headshot jobs are deleted automatically 24 hours after upload.
- Closed Studio accounts and their data are deleted from live systems; encrypted backups age out within days.
5. Security
Photos are stored in private cloud storage and are only served through each Guest’s own unguessable gallery link. Passwords are hashed, payment pages are Stripe’s own, all traffic is encrypted in transit, and we keep verified nightly backups.
6. Access, correction, and complaints
You can ask us for access to, or correction of, personal information we hold about you by emailing info@eventphotos.com.au. Guests can also contact their Studio directly, who controls the event’s guest list. If you have a privacy complaint, contact us first and we will respond within a reasonable time; you can also complain to the Office of the Australian Information Commissioner (oaic.gov.au).
7. Contact
Event Photos Plus · info@eventphotos.com.au