House Of Green Media LLC (“photosnp,” “we,” “us”) operates an event-photography
platform that delivers photos to event guests and provides tools to photographers
and event organizers. This policy explains what we collect, how we use it, and the
choices you have. It covers both photographers/organizers (our customers)
and event guests.
For most event data, the photographer or organizer running the event is the
“controller” and photosnp acts as a “processor” on their behalf. Where photosnp
determines the purposes of processing (e.g. our own accounts and billing), we are
the controller.
1. Information we collect
Account information (photographers/organizers): name, email, a hashed
password, plan, and billing details processed by our payment provider (we do not
store full card numbers).
Event photos: images captured at an event, which may depict identifiable
individuals.
Pattern-recognition data: facial geometry/embeddings derived from photos to
group each guest’s pictures (see §2).
Guest contact information (optional): if an organizer enables lead capture
and a guest opts in, the email/phone/name they provide, with their consent.
Usage & device data: an anonymous session identifier (cookie), pages
viewed, downloads, shares, and similar analytics used to power dashboards and
sponsor reports in aggregate.
2. Pattern recognition & biometric data
When enabled for an event, photosnp uses pattern-recognition technology so a guest
can find all photos they appear in. To do this we compute a mathematical representation of
facial features (a “face embedding”) from event photos and compare embeddings to
group matching photos. Depending on your jurisdiction this may be considered
biometric information or special-category data (e.g. under the Illinois
Biometric Information Privacy Act (BIPA), the EU GDPR, or similar laws).
Purpose: solely to match and organize a guest’s own photos at the event.
We do not use face data to identify strangers, for advertising, or sell it.
Consent: guests choose to use pattern matching (“find my photos”) and can
decline. Organizers are responsible for providing any legally required notice and
obtaining consent from attendees (see our Terms).
Retention & deletion: face embeddings are permanently destroyed
90 days after the event they were created for,
automatically. They are destroyed sooner if the guest asks (the “Remove me” button on
their gallery page destroys their face template and every face embedding derived from
them), or if the event or its photos are deleted. Deleting face data does not delete
the photographer’s photos, which belong to the photographer.
3. How we use information
To deliver photos to guests and power galleries, QR codes, and the live wall.
To provide pattern matching so guests can find their own photos (when enabled).
To provide organizer tools: dashboards, lead capture/export, and sponsor reports
(sponsor reports use aggregate metrics only, without guest personal data).
To operate accounts, process subscriptions, provide support, and secure the
service.
To comply with legal obligations and enforce our Terms.
4. Legal bases (where GDPR/UK GDPR applies)
Consent — for pattern matching and opt-in lead capture.
Contract — to provide accounts and the service to our customers.
Legitimate interests — to secure, maintain, and improve the service, where
not overridden by your rights.
5. How we share information
The event’s photographer/organizer, who controls the event and its data.
Service providers that host and process data on our behalf under contract —
e.g. cloud image storage, our payment processor, error monitoring, and hosting.
Sponsors receive aggregate impression/click metrics only — never guest
personal data.
Legal — when required by law, to protect rights and safety, or in a
business transfer.
We do not sell personal information.
6. Cookies
Guest pages set small first-party cookies: an anonymous analytics session
(pg_s), your gallery link (pg_me), and a lead-captured flag
(pg_lead). They are used to operate the galleries and count distinct
visitors — not for cross-site advertising.
7. Data retention
Face embeddings (biometric data) are destroyed automatically
90 days after the event they were created for, or sooner
on request — see section 2. This schedule runs whether or not anyone asks.
Event photos and galleries are kept for as long as the organizer’s event and
account remain active, or until deletion is requested. A guest’s personal gallery keeps
working after its face data is destroyed; it simply stops adding new photos
automatically.
Account and billing records are kept as required for legal, tax, and
accounting purposes.
8. Your rights & choices
Guests: use pattern matching or not; delete your gallery and biometric data from
your gallery page; unsubscribe from any communications you opted into.
Depending on your location (e.g. GDPR/UK GDPR, CCPA/CPRA), you may have
rights to access, correct, delete, or port your data, and to object to or restrict
certain processing. Contact us to exercise these rights.
9. Children
Events may include minors in photos. Organizers are responsible for obtaining any
legally required parental/guardian consent for attendees who are minors, including for
pattern recognition / biometric processing. Contact us to request deletion of a minor’s data.
10. Security
We use industry-standard measures (encryption in transit, access controls, hashed
passwords) to protect data. No method of transmission or storage is 100% secure.
11. International transfers
We may process data in countries other than yours. Where required, we use
appropriate safeguards for such transfers. [Confirm with counsel.]
12. Changes
We may update this policy; we’ll revise the “last updated” date and, for material
changes, provide additional notice where required.