Skip to content
Candid Cam

Legal

Privacy Policy

Last updated: August 2026

1. Who we are

Candid Cam ("we", "us", "our") operates candidcam.app , a platform that lets event hosts collect and curate guest photos via QR code. You can reach us at hello@candidcam.app.

2. What we collect

  • Hosts: email address, name, and account credentials when you register. Payment details are handled by Stripe, we never store card numbers.
  • Venue and Event Pro accounts: business and contact details, team invitations and roles, client setup links, event associations, commission and payout records, and Stripe Connect onboarding status. Stripe stores payout-account details; we do not store bank-account numbers.
  • Guests: optional name and email address entered at upload time, plus any photos or videos you choose to upload.
  • Abuse-prevention data: when a guest uploads, we record a hashed (pseudonymized) version of their IP address and a device fingerprint. We never store the raw IP address. This is used solely for rate-limiting, spam and abuse prevention, and content moderation — never for advertising or tracking guests across other sites. We also retain a salted hash of the requesting IP address for up to one day to rate-limit changes to the advertising measurement preference.
  • Usage data: aggregate public marketing page views and category-level interactions when optional analytics is configured, plus operational counts such as uploads that help us run and improve the product.

3. Public marketing analytics and acquisition

On public marketing pages, we may use Plausible to count aggregate page views and category-level actions such as selecting an event-creation link or viewing the how-it-works section when that optional analytics service is configured. Event properties use fixed categories for page type, action position, copy version, campaign type, and device class. They do not contain raw link text, destinations, event names, email addresses, filenames, or guest tokens. Page views send only a sanitized public page pathname and, when present and valid, normalized source, medium, and campaign values. We do not track the raw query string, URL fragments, or any unrelated query parameters, and the analytics script is not loaded on login, dashboard, admin, guest album, upload, event, or checkout pages.

We also use a first-party acquisition cookie, named cc_attribution, for up to 30 days. When a visitor arrives with valid campaign categories or from an external website, the cookie can contain normalized source and medium categories, optional campaign and ad-content categories, the external referrer hostname, a sanitized landing pathname, and the capture time. It does not contain a raw query string, full referrer URL, name, email address, user or event identifier, or guest token. We use it to understand which marketing source first introduced a newly created host and to retain the same category-level attribution through checkout.

Unless this browser has opted out, we load the Meta Pixel on public marketing and event-setup pages. It records page views and sets Meta's first-party browser identifiers. After you successfully name an event, the Pixel may send Meta a Lead event. If you then complete a paid event activation, our server sends Meta a Purchase event with the order value and currency, a one-way hash of the account email and event identifier, a pseudonymous Stripe Checkout/order identifier, the selected event tier, your browser's user-agent string, and any Meta browser or click identifiers already set. Those measurement identifiers are kept in our private billing data and are not placed in Stripe metadata. We do not send guest uploads, event names, card details, payer-entered email addresses, or raw account email addresses to Meta. We use this data to measure and improve paid advertising. You can turn this measurement off below at any time without changing the service.

Your measurement preference and an opaque browser preference ID are stored in first-party cookies for up to 180 days. We keep the linked preference, revision, and expiry on our server for the same period. The ID does not contain account or event details. You can change your preference below at any time. While the ID remains in that browser, a saved opt-out stops new Pixel events and suppresses server Purchase events that have not begun delivery. A provider request that already began may complete.

Advertising measurement

Current setting: on.

You can remove the acquisition cookie through your browser's site-data controls. Browser privacy tools may also block optional aggregate analytics. If you have questions about this use of data, contact hello@candidcam.app.

4. How we use your data

  • To operate the service, storing uploads, sending album emails, and managing events.
  • To communicate with you about your account or your event.
  • To send optional product updates if you opt in (you can unsubscribe at any time).
  • To detect and prevent abuse or misuse of the platform.

5. Photo and media storage

Uploaded media is stored securely. Depending on how an event is configured, it can be accessed by the event host, authorised Venue owners, managers or event staff, an appointed Event Pro manager, and guests who receive an album link. Access is limited by each role. Hosts control their event media and can delete individual photos, videos, or the entire event at any time. Event media otherwise remains stored for as long as the host keeps the event or account active — there is no automatic deletion after a fixed period. We do not use guest photos for training, advertising, or any purpose beyond delivering the service.

6. Data sharing

We do not sell your data. We use a small number of trusted third-party services to run the platform, including Supabase (database and storage), Stripe (payments), and Resend (email delivery), and Meta (advertising measurement, unless this browser has opted out). Each provider is bound by their own privacy policy and applicable data protection laws.

7. Guest consent

Before adding photos or videos, every guest sees a short notice on the upload screen explaining that their contributions will be reviewed by the event host or authorised event team and may appear in a shared album, that we record limited technical data (an approximate, hashed IP address and a device fingerprint) to prevent abuse, and linking to this Privacy Policy and our Terms of Service. By proceeding to add photos or videos, guests acknowledge this notice. If a guest provides an email address, it is used for album delivery for that event; marketing updates require a separate opt-in. Guests can request deletion of their uploads by contacting the host or emailing us at hello@candidcam.app.

8. Data retention

Host accounts and associated data are retained while the account is active. Event media is retained for as long as the host keeps the event or account — hosts are in control of when their event media is deleted, and it is not automatically removed after a set period. Guests who provide an email for album delivery have that email stored only for the purpose of sending the album. Hashed IP and device fingerprint data collected for abuse prevention is retained only as long as needed for that purpose and is not linked back to a guest's identity. Hosts can request a download link or zip export for event media while it is retained. Guests can contact support to request removal of their contributions; hosts control deletion of their event's media. You may reach us at hello@candidcam.app.

9. Your rights

Depending on where you are located, you may have rights to access, correct, or delete your personal data. To exercise any of these rights, contact us at hello@candidcam.app.

10. Guest profile storage

To save guests from retyping their details at every event, Candid Cam stores the name and email they entered in their own browser's localStorage. This data never leaves the device unless the guest chooses to upload; we do not read it on our servers. To clear it, open your browser settings and remove site data for candidcam.app, or use your browser's private/incognito mode.

11. Report a security issue

If you believe you have found a security vulnerability in Candid Cam, please report it to hello@candidcam.app. We acknowledge reports within 2 business days and will keep you informed while we investigate. Please do not disclose the issue publicly until we have had a chance to address it.

12. Changes to this policy

We may update this policy from time to time. Material changes will be communicated via email or a notice on the site. Continued use of Candid Cam after changes constitutes acceptance of the updated policy.