Privacy Policy
Effective date: 24 April 2026
This Privacy Policy explains how MomentoShake collects, uses, stores, shares, and deletes personal data when people use the MomentoShake application and related pages.
1. Who This Policy Applies To
This policy applies to:
- Organizers who create an account, create paid events, manage event galleries, download event assets, or contact MomentoShake.
- Guests who access an event through a QR code, provide their name, upload one photo, add an optional message, view a generated polaroid, or view an event gallery.
- Gallery visitors who access a public or password-protected gallery link.
- Visitors to the MomentoShake landing page, where Google Analytics may be used separately from the application.
In this policy:
- Organizer means the account holder who creates and pays for an event.
- Guest means a person who uploads a photo to an event.
- Gallery visitor means a person who views an event gallery.
- Event content means photos, generated polaroids, thumbnails, optional guest messages, event names, event dates, QR links, gallery links, and ZIP exports.
- App means the MomentoShake application used for organizer dashboards, guest uploads, and public galleries.
- Landing page means the marketing/homepage surface that may be maintained separately from the application.
2. Controller Roles
For organizer account data, payment records held in the application, account security data, application emails, and platform operation, MomentoShake acts as the data controller.
For event content uploaded by guests at the invitation of an organizer, MomentoShake generally acts as a processor or service provider for the organizer, because the organizer decides to create the event, invite guests, share QR links, choose the plan, decide whether to use gallery password protection where available, manage the gallery, and delete event photos from the dashboard.
In some cases, MomentoShake may also act as an independent controller for limited processing needed to operate, secure, bill, troubleshoot, and comply with legal obligations relating to the service.
Organizers are responsible for having a lawful basis to invite guests, collect photos, publish gallery links, and use event content. Organizers must not use MomentoShake for unlawful, harmful, non-consensual, or privacy-invasive collection of photos.
3. Data We Collect
3.1 Organizer Account Data
When an organizer creates and uses an account, MomentoShake collects:
- Name.
- Email address.
- Password, stored in hashed form.
- Email verification status.
- Preferred language, if selected.
- Account creation, update, and deletion timestamps.
- Remember-login token, where applicable.
- Two-factor authentication secret, recovery codes, and confirmation timestamp if the organizer enables two-factor authentication.
3.2 Authentication and Session Data
To keep organizers signed in and protect the service, MomentoShake may process:
- Session identifier.
- Related user account identifier.
- IP address.
- Browser or device user agent.
- Session payload.
- Last activity timestamp.
- Password reset token data.
Session cookies and authentication cookies are used only where needed for login, account security, guest flow continuity, gallery password checks, and normal application operation.
3.3 Event Data
When an organizer creates or manages an event, MomentoShake collects:
- Event name.
- Event date.
- Selected plan.
- Event status, such as draft, active, or expired.
- QR token and QR link.
- Gallery share token and gallery link.
- Gallery expiration timestamp.
- Paddle transaction identifier.
- Gallery password for Premium events, stored in hashed form.
- ZIP export status and storage key if a ZIP export is generated.
- Event creation, update, soft-delete, and purge-related timestamps.
3.4 Guest Upload Data
When a guest participates in an event, MomentoShake collects:
- Guest first name.
- Guest last name.
- Uploaded photo.
- Optional message, up to the application limit.
- Upload timestamp.
- Generated polaroid file.
- Generated thumbnail file.
- Storage keys for the original photo, generated polaroid, and thumbnail.
- Session data used to maintain the guest flow for that event.
Guests do not need a MomentoShake account.
3.5 Gallery Data
When a person views a gallery, MomentoShake may process:
- Gallery share token.
- Gallery password verification state for password-protected Premium galleries.
- Browser session data needed to display the gallery.
- Temporary signed or controlled URLs used to load stored media.
Basic and Event plan galleries are accessible through a public share link. Premium galleries may be password protected if the organizer sets a password.
3.6 Payment and Billing Data
MomentoShake uses Paddle for payment processing. When an organizer pays for an event, MomentoShake may store:
- Paddle customer identifier.
- Customer name and email as provided through Paddle.
- Paddle transaction identifier.
- Invoice number, if provided.
- Transaction status.
- Total, tax amount, and currency.
- Billing timestamp.
Paddle processes payment card details and related checkout information. MomentoShake does not store full payment card numbers.
Paddle may act as a payment provider, merchant of record, independent controller, or processor depending on the specific Paddle service and legal configuration. Organizers should also review Paddle’s own privacy terms during checkout.
3.7 Support and Communication Data
If a person contacts MomentoShake by email or another support channel, MomentoShake may process:
- Name and email address.
- Message content.
- Event or account identifiers provided in the request.
- Attachments voluntarily provided.
- Internal notes needed to resolve the request.
3.8 Landing Page Analytics Data
The MomentoShake landing page may use Google Analytics. This analytics use is limited to the landing page and is separate from the core application unless explicitly changed later.
Google Analytics may process information such as:
- Page views.
- Approximate location derived from IP address.
- Device and browser information.
- Referrer information.
- Interactions with the landing page.
- Analytics identifiers and cookies, depending on consent and configuration.
Where required by EU/EEA cookie and privacy law, Google Analytics should be loaded only after valid consent for non-essential analytics cookies or similar technologies.
The core application should not use Google Analytics or non-essential tracking unless the privacy policy and cookie controls are updated before that change.
4. Special Category Data and Photos
Photos can reveal sensitive information, including a person’s appearance, location context, health-related information, religious symbols, political expression, ethnicity, or other sensitive details. MomentoShake does not ask guests to provide special category data, but uploaded photos may contain it incidentally.
Organizers must only invite uploads and publish galleries where they have a lawful basis and appropriate consent or permission from the relevant participants. Organizers should avoid using MomentoShake for sensitive events or situations where participants would not reasonably expect photos to be collected or shared.
Guests should not upload photos of people who have not agreed to be included or where the upload would violate privacy, image rights, venue rules, employment rules, school rules, or applicable law.
5. Children’s Data and Minors in Photos
Organizer accounts and paid purchases are intended for people who are at least 18 years old.
Guests may include minors in event photos only where the organizer and uploader have the necessary authority, permission, and lawful basis. For events involving children, the organizer is responsible for obtaining any required parental or guardian consent and for deciding whether a public or password-protected gallery is appropriate.
MomentoShake should not be used by children to create paid organizer accounts. If MomentoShake learns that a child created an organizer account without appropriate authority, the account may be deleted.
Requests about a minor’s photo can be sent to privacy@momentoshake.com. MomentoShake may need enough information to locate the event and photo.
6. Why We Process Personal Data
MomentoShake processes personal data for these purposes:
- Create and manage organizer accounts.
- Authenticate organizers and protect accounts.
- Verify organizer email addresses.
- Let organizers create paid events.
- Route organizers to Paddle checkout.
- Activate events after successful payment.
- Provide QR links for guests.
- Let guests upload one photo and optional message.
- Generate polaroid-style images and thumbnails.
- Display guest waiting, reveal, and gallery experiences.
- Enforce plan limits, event status, gallery expiration, and duplicate-guest rules.
- Provide dashboard event management.
- Let organizers delete photos from the dashboard.
- Generate and provide ZIP exports where included in the plan.
- Send transactional emails, such as event activation, gallery expiration warnings, and ZIP-ready notifications.
- Provide account settings, password reset, email verification, and two-factor authentication.
- Prevent abuse, rate-limit upload endpoints, troubleshoot errors, and maintain service security.
- Comply with tax, accounting, chargeback, legal, and regulatory obligations.
- Improve the landing page through consent-based analytics.
- Respond to privacy, support, and legal requests.
7. Legal Bases Under GDPR
MomentoShake relies on the following legal bases under Article 6 GDPR:
| Processing activity | Legal basis |
|---|---|
| Creating and maintaining organizer accounts | Contract necessity |
| Authenticating users and maintaining sessions | Contract necessity and legitimate interests |
| Email verification, password reset, and account security | Contract necessity and legitimate interests |
| Creating events, guest upload flows, galleries, and ZIP exports | Contract necessity for organizers; organizer-controlled lawful basis for guest content |
| Processing guest names, photos, and messages for an event | Organizer’s lawful basis, with MomentoShake processing as service provider where applicable |
| Payment activation and transaction records | Contract necessity and legal obligation |
| Tax, accounting, chargeback, fraud, and compliance records | Legal obligation and legitimate interests |
| Transactional emails about event activation, expiry, and ZIP readiness | Contract necessity and legitimate interests |
| Security logging, rate limiting, abuse prevention, and troubleshooting | Legitimate interests |
| Responding to privacy and legal requests | Legal obligation and legitimate interests |
| Optional landing page Google Analytics | Consent, where required |
Where MomentoShake relies on legitimate interests, those interests include operating a secure paid event-photo service, preventing abuse, keeping records needed to resolve payment and service disputes, maintaining service reliability, and protecting users and guests from unauthorized access or misuse.
Where consent is required, a person may withdraw consent at any time. Withdrawal does not affect processing that occurred before withdrawal.
8. Cookies and Similar Technologies
The application uses essential cookies and similar session technologies to:
- Keep organizers logged in.
- Protect authenticated areas.
- Remember guest flow state for an event.
- Remember that a gallery password was verified during a session.
- Protect forms and requests.
- Maintain language or user-interface preferences, where applicable.
These cookies are necessary for the service and are not used for advertising.
The landing page may use Google Analytics cookies or similar technologies only where configured and legally permitted. In the EU/EEA, analytics cookies generally require prior consent unless configured in a way that qualifies for a narrow exemption under applicable law.
Users can control cookies through their browser settings. Blocking essential cookies may prevent parts of the application from working.
9. How Photos and Event Files Are Stored
Photos and generated media are stored using Cloudflare R2. The application server runs on a Hetzner VPS.
Depending on the event plan:
- Basic: original uploaded photos are deleted after successful polaroid generation; generated polaroids and thumbnails remain available until the event retention lifecycle deletes them.
- Event: original uploaded photos are deleted after successful polaroid generation; generated polaroids and thumbnails remain available until the event retention lifecycle deletes them.
- Premium: original uploaded photos are retained during the gallery lifetime so the organizer can download original high-quality photos, together with generated polaroids and thumbnails.
Generated ZIP exports are stored only when requested and only while the related gallery remains within its retention lifecycle.
10. Data Retention
MomentoShake keeps personal data only as long as needed for the purposes described in this policy, unless a longer retention period is required or permitted by law.
10.1 Event and Photo Retention by Plan
| Plan | Gallery availability | Original photo retention | Generated polaroid and thumbnail retention |
|---|---|---|---|
| Basic | 30 days from event date | Deleted after successful polaroid generation | Kept during gallery lifetime, then deleted during purge |
| Event | 180 days from event date | Deleted after successful polaroid generation | Kept during gallery lifetime, then deleted during purge |
| Premium | 365 days from event date | Kept during gallery lifetime for organizer download | Kept during gallery lifetime, then deleted during purge |
10.2 Expiry and Purge Lifecycle
Event expiry is calculated from the event date plus the plan duration. The application uses the event’s share_expires_at value as the source of truth.
When a gallery expires:
- The event is marked expired.
- The event is soft-deleted.
- Related photos are soft-deleted.
- The gallery is no longer available through the normal public gallery flow.
- Storage files are not immediately hard-deleted at the expiry moment.
Expired, soft-deleted events are permanently purged after they have been soft-deleted for at least 30 days. During purge:
- Event records are permanently deleted.
- Photo records are permanently deleted.
- Original photo files are deleted where still present.
- Generated polaroid files are deleted.
- Generated thumbnail files are deleted.
- Event ZIP exports are deleted.
This means event content may remain in storage for up to the plan duration plus the scheduled purge delay after expiry.
10.3 Organizer-Initiated Photo Deletion
If an organizer deletes a photo from the dashboard, the photo record is soft-deleted immediately. Storage cleanup is deferred to the scheduled purge lifecycle rather than deleted instantly.
10.4 Organizer Account Deletion
Organizers can delete their account themselves from account settings. Account deletion soft-deletes the organizer account and related events. Related event files are removed through the normal purge lifecycle.
Some records may be retained where needed for legal obligations, tax/accounting records, payment disputes, fraud prevention, chargeback handling, or defense of legal claims.
10.5 Payment and Accounting Records
Payment and transaction data may be retained for as long as required by tax, accounting, consumer, anti-fraud, chargeback, and legal limitation rules.
10.6 Support Records
Support and privacy-request correspondence may be retained as long as needed to answer the request, document compliance, resolve disputes, and protect legal rights.
10.7 Backups
Backups, if used, may retain data for a limited period after deletion from production systems. Backup data is not used for active service delivery and is overwritten or deleted according to backup rotation schedules. If data has been deleted from production systems, it should not be restored from backup except where necessary for security, disaster recovery, or legal reasons.
11. Who We Share Data With
MomentoShake shares personal data only where needed to operate the service, process payments, send emails, store files, host the application, comply with law, or protect rights.
Current service providers include:
| Provider | Purpose | Data involved |
|---|---|---|
| Hetzner | VPS hosting and server infrastructure | Application data processed by the server, logs, database content depending on deployment |
| Cloudflare R2 | Photo, polaroid, thumbnail, and ZIP storage | Event media files and storage metadata |
| Paddle | Checkout, payments, tax handling, invoices, transaction management | Organizer billing and transaction data |
| Resend | Transactional email delivery | Recipient email address, email content, delivery metadata |
| Google Analytics | Landing page analytics only | Landing page analytics data, subject to consent and configuration |
MomentoShake may also disclose data:
- To comply with applicable law, court orders, regulatory requests, or lawful government requests.
- To enforce terms, investigate abuse, prevent fraud, or protect the security of the service.
- To professional advisers, such as lawyers or accountants, where necessary.
- In connection with a future business transfer, acquisition, or restructuring, subject to appropriate safeguards.
MomentoShake does not sell personal data.
12. International Transfers
MomentoShake aims to use EU/EEA-friendly infrastructure where practical, including Hetzner hosting and Cloudflare R2 storage. Some providers, such as Paddle, Resend, Google, or Cloudflare, may process data outside the EU/EEA depending on their infrastructure, support, subprocessors, and legal setup.
Where personal data is transferred outside the EU/EEA, MomentoShake relies on appropriate safeguards where required, such as:
- European Commission adequacy decisions.
- Standard Contractual Clauses.
- Data Processing Agreements.
- Provider technical and organizational safeguards.
- Supplementary measures where appropriate.
Users should also review the relevant provider privacy documentation where a provider acts as an independent controller, especially Paddle and Google.
13. Security Measures
MomentoShake uses technical and organizational measures intended to protect personal data, including:
- Password hashing.
- Email verification.
- Optional two-factor authentication for organizers.
- Authenticated dashboard access.
- Public guest access through unguessable QR tokens.
- Gallery access through unguessable share tokens.
- Optional Premium gallery password protection.
- Rate limiting for guest upload endpoints.
- File validation for uploaded images.
- Plan-based retention rules.
- Background jobs for media generation and ZIP generation.
- Scheduled expiry and purge commands.
- Separation between application logic, storage service, and payment provider.
No internet service is completely secure. Users and organizers must protect their account credentials, use strong passwords, keep gallery links private where needed, and avoid sharing QR or gallery links with unintended recipients.
14. Public and Shared Links
Basic and Event galleries use public share links. Anyone with the gallery link may be able to view the gallery while it is active. QR links also allow guest participation while the event is active.
Premium galleries may be protected by a password if the organizer sets one. Password protection reduces casual access but does not replace careful link sharing, guest consent, or organizer responsibility.
Organizers are responsible for deciding who receives QR links, gallery links, and gallery passwords.
15. Your Rights
Depending on the situation and applicable law, individuals in the EU/EEA and similar jurisdictions may have the right to:
- Access their personal data.
- Correct inaccurate personal data.
- Delete personal data.
- Restrict processing.
- Object to processing based on legitimate interests.
- Receive a portable copy of personal data.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with a data protection authority.
To exercise rights, contact privacy@momentoshake.com.
MomentoShake may need to verify identity or request enough information to locate the relevant account, event, guest upload, or gallery photo. For guest photo requests, this may include the event name, organizer, approximate upload time, guest name used during upload, gallery link, or a description of the photo.
Some requests may need to be handled with the organizer because the organizer controls the event and may be the controller for guest content.
16. Complaints
Individuals may contact MomentoShake first at privacy@momentoshake.com.
Individuals may also complain to their local data protection authority. If MomentoShake is operated from the Netherlands, the likely supervisory authority is the Dutch Data Protection Authority, Autoriteit Persoonsgegevens. Depending on the user’s location and the facts, another EU/EEA supervisory authority may also be competent.
17. Organizer Responsibilities
Organizers must:
- Use MomentoShake only for lawful events and lawful photo collection.
- Inform guests that photos and optional messages will be uploaded to MomentoShake.
- Explain who can view the gallery.
- Share QR links, gallery links, and passwords responsibly.
- Obtain consent or another valid lawful basis where required.
- Avoid uploading or encouraging upload of unlawful, harmful, private, or non-consensual images.
- Handle requests from guests or photo subjects promptly.
- Choose Premium password protection where the event content needs more restricted access.
- Avoid using public gallery links for sensitive events or children-focused events unless appropriate consent and safeguards are in place.
18. Guest Responsibilities
Guests should:
- Upload only one photo as intended by the service.
- Upload only photos they have the right to share.
- Avoid uploading photos of people who object or who could reasonably expect not to be included.
- Avoid uploading sensitive, illegal, harmful, offensive, or exploitative content.
- Use a truthful name if the organizer needs to identify contributions.
- Contact the organizer or MomentoShake if they need a photo removed.
19. Changes to This Policy
MomentoShake may update this Privacy Policy when the service, providers, legal requirements, or business structure changes.
If changes are material, MomentoShake will take reasonable steps to notify organizers, such as updating the effective date, posting a notice, or sending an email where appropriate.
Continued use of the service after an updated policy takes effect means the updated policy applies from that point forward.
20. Contact
For privacy requests, data protection questions, deletion requests, or complaints:
MomentoShake
privacy@momentoshake.com