Skip to content
Candid Cam

Legal

Privacy Policy

Last updated: October 2026

1. Who we are

Candid Cam ("we", "us", "our") operates candidcam.app, a platform that lets event hosts collect and curate guest photos via QR code. You can reach us at hello@candidcam.app.

2. What we collect

  • Hosts: email address, name, and account credentials when you register. Payment details are handled by Stripe, we never store card numbers.
  • Venue and Event Pro accounts: business and contact details, team invitations and roles, client setup links, event associations, commission and payout records, and Stripe Connect onboarding status. Stripe stores payout-account details; we do not store bank-account numbers.
  • Guests: optional name and email address entered at upload time, plus any photos or videos you choose to upload.
  • Abuse-prevention data: when a guest uploads, we record a hashed (pseudonymized) version of their IP address and a device fingerprint. We never store the raw IP address. This is used solely for rate-limiting, spam and abuse prevention, and content moderation — never for advertising or tracking guests across other sites.
  • Usage data: aggregate public marketing page views and category-level interactions when optional analytics is configured, plus operational counts such as uploads that help us run and improve the product.

3. Public marketing analytics and acquisition

On public marketing and event-setup pages, we may use Plausible to count aggregate page views and category-level actions such as selecting an event-creation link or completing a setup step when that optional analytics service is configured. After a private Draft is created, a small set of fixed lifecycle events may also be sent from the private event screen using a virtual event-starter URL. Event properties use fixed categories for page type, action position, copy version, campaign type, device class, and setup state. They do not contain raw link text, destinations, private page URLs, event or user identifiers, event names, email addresses, filenames, or guest tokens. Page views send only a sanitized public page pathname and, when present and valid, normalized source, medium, and campaign values. We do not track the raw query string, URL fragments, or any unrelated query parameters.

We also use a first-party acquisition cookie, named cc_attribution, for up to 30 days. When a visitor arrives with valid campaign categories or from an external website, the cookie can contain normalized source and medium categories, optional campaign and ad-content categories, the external referrer hostname, a sanitized landing pathname, and the capture time. It does not contain a raw query string, full referrer URL, name, email address, user or event identifier, or guest token. We use it to understand which marketing source first introduced a newly created host and to retain the same category-level attribution through checkout.

Plausible analytics is cookieless: it does not set cookies or other identifiers in your browser, and it does not track you across websites.

Some of these actions (saving a Draft to your account, creating a Draft, publishing an event, and starting or completing a checkout) are sent to Plausible from our server, so that they are counted reliably. For this, we keep your IP address, your browser’s user agent and the setup page address with the action for up to 7 days, and then delete them. We use them only to send that action to Plausible, in the same form as Plausible’s own script would send them from your browser. We never send them to Meta unless you allow ad measurement.

Outside the UK, the European Union, the European Economic Area and Switzerland, we load the Meta Pixel on public marketing and event-setup pages by default. You can turn it off, and back on, at any time with “Ad measurement choices” in the site footer or below. We honour Global Privacy Control: when your browser sends it, the Pixel does not load. Do Not Track has the same effect unless you later allow ad measurement here. Inside the UK, the EU, the EEA and Switzerland, the Pixel loads only after you select Accept in our consent banner, and you can change that choice in the same way. We decide which rule applies from the country of your IP address, which we store for one day in a first-party cookie named cc_region. If we cannot tell the country, we apply the consent rule.

The Pixel records page views and sets Meta's first-party browser identifiers. After you successfully create a private event draft, the Pixel may send Meta a draft-created measurement event. Its event ID is a keyed one-way hash of an internal identifier: it lets Meta count each draft once and match the browser copy with the copy our server sends, and it cannot be turned back into your account or event identifier. We do not use Meta's automatic advanced matching, so the Pixel does not read form fields such as your email address.

Under the same rules, our server sends Meta these events: draft created, account registration, event published, checkout started, and purchase (including plan upgrades). Checkout and purchase events include the order value and currency. With each event we send a one-way hash of your account email, a one-way hash of your account ID, your IP address, your browser's user-agent string, and any Meta click or browser identifiers already set. Those measurement identifiers are kept in our private billing data and are not placed in Stripe metadata. We do not send guest uploads, event names, card details, payer-entered email addresses, raw account email addresses, or internal event identifiers to Meta. We use this data to measure and improve paid advertising.

You can remove the acquisition cookie through your browser's site-data controls. Browser privacy tools may also block optional aggregate analytics. If you have questions about this use of data, contact hello@candidcam.app.

4. How we use your data

  • To operate the service, storing uploads, sending album emails, and managing events.
  • To communicate with you about your account or your event.
  • To send optional product updates if you opt in (you can unsubscribe at any time).
  • To detect and prevent abuse or misuse of the platform.

5. Photo and media storage

Uploaded media is stored securely. Depending on how an event is configured, it can be accessed by the event host, authorised Venue owners, managers or event staff, an appointed Event Pro manager, and guests who receive an album link. Access is limited by each role. Hosts control their event media and can delete individual photos, videos, or the entire event at any time. For newly enrolled Free events, first publication fixes the expiry deadline at 30 days after the scheduled event end. We email the host 7 days and 1 day before that deadline, and the host can download media from the dashboard while it remains available. Paid event media otherwise remains stored until the host deletes it. Existing Draft and complimentary event records keep their existing terms. We do not use guest photos for training, advertising, or any purpose beyond delivering the service.

6. Data sharing

We do not sell your data. We use a small number of trusted third-party services to run the platform, including Supabase (database and storage), Stripe (payments), and Resend (email delivery), and Meta (advertising measurement, under the rules in section 3). Each provider is bound by their own privacy policy and applicable data protection laws.

7. Guest consent

Before adding photos or videos, every guest sees a short notice on the upload screen explaining that their contributions will be reviewed by the event host or authorised event team and may appear in a shared album, that we record limited technical data (an approximate, hashed IP address and a device fingerprint) to prevent abuse, and linking to this Privacy Policy and our Terms of Service. By proceeding to add photos or videos, guests acknowledge this notice. If a guest provides an email address, it is used for album delivery and two upload reminders for that event; marketing updates require a separate opt-in. Guests can request deletion of their uploads by contacting the host or emailing us at hello@candidcam.app.

8. Data retention

Host accounts and associated data are retained while the account is active. For newly enrolled Free events, first publication fixes the expiry deadline at 30 days after the scheduled event end. We send the host warnings at least 7 days and 1 day before that deadline. If either warning is missing or late, we delay removal until the full notice is given. Paid event media is retained until the host deletes it. Guests who provide an email for event updates have that email stored only for the purpose of sending the album and the two event upload reminders. Hashed IP and device fingerprint data collected for abuse prevention is retained only as long as needed for that purpose and is not linked back to a guest's identity. Hosts can download event media from the dashboard while it is retained. Guests can contact support to request removal of their contributions; hosts control deletion of their event's media. You may reach us at hello@candidcam.app.

9. Your rights

Depending on where you are located, you may have rights to access, correct, or delete your personal data. To exercise any of these rights, contact us at hello@candidcam.app.

10. Guest profile storage

To save guests from retyping their details at every event, Candid Cam stores the name and email they entered in their own browser's localStorage. This data never leaves the device unless the guest chooses to upload; we do not read it on our servers. To clear it, open your browser settings and remove site data for candidcam.app, or use your browser's private/incognito mode.

11. Report a security issue

If you believe you have found a security vulnerability in Candid Cam, please report it to hello@candidcam.app. We acknowledge reports within 2 business days and will keep you informed while we investigate. Please do not disclose the issue publicly until we have had a chance to address it.

12. Changes to this policy

We may update this policy from time to time. Material changes will be communicated via email or a notice on the site. Continued use of Candid Cam after changes constitutes acceptance of the updated policy.