Privacy Policy for SortWedPics

Last Updated: December 8, 2025

This Privacy Policy explains how SortWedPics ("SortWedPics", "we", "us", or "our") collects, uses, shares, and protects information about you when you use our services. This includes our website at https://sortwedpics.com, any related web application, and any mobile applications we may offer (together, the "Service"), as well as our marketing communications and customer support channels.

SortWedPics helps Hosts and Guests organize, search, and share photos and other content around weddings and similar events. Because we process information about Hosts, their Guests, and other individuals (including photos that may contain faces), we take privacy and data protection seriously. This Privacy Policy is designed to meet the expectations of the EU General Data Protection Regulation (GDPR) and similar laws, especially for users in the European Union and the United Kingdom.

By using the Service, you acknowledge that you have read this Privacy Policy. If you do not agree with it, you should not use the Service.

1. Who we are and roles under data protection law

1.1 SortWedPics is the provider of the Service and is established in the Netherlands. For the purposes of applicable data protection laws (such as the GDPR), we may act as:
  (a) a "data controller" in relation to certain personal data we collect directly from you (for example, account, billing, support, and marketing data, or when you browse our marketing site); and
  (b) a "data processor" in relation to personal data that Hosts upload or otherwise provide to the Service about their Events and Guests (for example, guest lists and event photos), which we process on the Host's documented instructions.

1.2 When we refer to "Host", we mean the person or organization (such as a couple or a professional photographer) that creates an account, configures an Event, and invites Guests. When we refer to "Guest", we mean an individual invited to access Event content (for example, via a link or gallery).

1.3 In many situations, particularly where Hosts upload or manage information about Guests and other attendees, the Host will be the "data controller" for that information and SortWedPics will act as the Host's "data processor". When we act as a processor, we only process Event-related personal data on the documented instructions of the Host, except where applicable law requires otherwise. Hosts are responsible for ensuring they have an appropriate legal basis (such as consent or legitimate interests, where applicable) to collect and upload Guest information and photos to the Service, and for providing any required notices to Guests and other individuals.

1.4 Professional or enterprise Hosts may enter into a separate data processing agreement (DPA) with SortWedPics, which describes our processor obligations in more detail, including sub-processors, security measures, and assistance with data subject rights. Our standard DPA is available on request or at https://sortwedpics.com/dpa (or another link we may provide from time to time).

2. Information we collect

We collect different kinds of information depending on how you interact with the Service.

2.1 Information you provide to us directly

As a Host or account holder, you may provide:
  - Account details: name, email address, password (stored in hashed form), and basic profile information.
  - Event details: event name, date, location, and other descriptive information you choose to provide.
  - Billing and payment details: information needed to complete purchases, such as billing address, VAT number, and limited payment details (note that card details are processed by our payment providers and are not stored in full by us).
  - Communications: information you send us via email, support requests, or feedback forms.

As a Host, photographer, or event organizer, you may also provide:
  - Guest information: names, email addresses, phone numbers, group or table assignments, and other contact details or metadata related to Guests and attendees.
  - Photos and event content: photos and videos from the Event, including images of Guests and other individuals, and related metadata (such as time, date, and basic device information embedded in images).

As a Guest or site visitor, you may provide:
  - Contact details: your name and email address when you access a gallery, sign up for updates, or contact us.
  - Preferences and interactions: favorites, reactions, and other actions you take within galleries or shared links.

2.2 Information we collect automatically

When you access or use the Service, we may automatically collect:
  - Usage data: your interactions with the Service (such as pages viewed, galleries accessed, features used, links clicked, and time spent on the Service).
  - Device and technical data: IP address, browser type and version, operating system and platform, device identifiers, language preferences, and similar technical information.
  - Log data: access logs, error logs, and other diagnostic data generated by our systems to help us keep the Service secure and reliable.

We may collect this information using cookies and similar technologies (see section 6 below).

2.3 Information we receive from third parties and others

We may receive personal data about you from:
  - Hosts or photographers, when they upload Guest information or photos that include you.
  - Payment providers (such as Stripe), who may confirm that a payment has been made or declined.
  - Analytics and marketing tools, which may provide aggregated or pseudonymized insights about how users interact with the Service or our marketing campaigns.
  - Authentication or identity providers (for example, when you sign in using a third-party method, if available).

2.4 Photos, AI features, and biometric considerations

When photos are uploaded to the Service, we may process them using automated tools (including AI-based face recognition and grouping) to help Hosts and Guests find and organize images based on who appears in them. In some jurisdictions, facial recognition and similar processing may be considered the processing of biometric or special category data. As a Host, you are responsible for ensuring that you have an appropriate legal basis before uploading photos or enabling features that involve face recognition, including obtaining valid consent from data subjects or relying on legitimate interests where allowed by applicable law. SortWedPics does not use your photos or recognition outputs for law enforcement, credit scoring, employment decisions, or any similarly high-risk or sensitive profiling.

3. How we use your information and legal bases

We use the information we collect for the following purposes and on the following legal bases:

3.1 To provide and operate the Service
  - Creating and managing accounts, enabling you to log in, configure Events, upload and organize photos, invite Guests, and access galleries.
  - Processing payments, managing subscriptions and plans, and issuing invoices.
  - Enabling AI-powered features such as face recognition and grouping, search, and personalized galleries.
  - Where we train or improve our models using data from the Service, we will do so using data that is either aggregated, de-identified, or otherwise used only for the purpose of improving SortWedPics and not for training unrelated external models.
Legal bases: performance of a contract (Article 6(1)(b) GDPR) where we have a contract with you as a Host; our legitimate interests in running and improving the Service (Article 6(1)(f) GDPR); and, for certain AI or biometric-related processing where required, consent (Article 6(1)(a) and, where relevant, Article 9(2)(a) GDPR). If we rely on Article 9 GDPR for biometric or special category data, we will only do so where explicitly required and based on explicit consent or another applicable derogation under Article 9(2).

3.2 To communicate with you
  - Sending transactional and administrative messages (such as account notifications, service updates, security alerts, and billing-related messages).
  - Responding to your support requests and feedback.
  - Sending onboarding or product education messages to help you use the Service effectively.
Legal bases: performance of a contract; our legitimate interests in providing customer support and keeping you informed about the Service; and, where required, your consent.

3.3 To maintain security, prevent abuse, and enforce our terms
  - Monitoring for suspicious or fraudulent activity.
  - Protecting against unauthorized access and maintaining the integrity of our systems.
  - Enforcing our Terms and Conditions and other policies.
Legal bases: our legitimate interests in securing the Service and preventing fraud or abuse; compliance with legal obligations.

3.4 To analyze, improve, and develop the Service
  - Monitoring usage patterns and performance to fix bugs, optimize features, and plan capacity.
  - Running analytics and experiments to understand how the Service is used and how we can improve it.
  - Developing new features, including improvements to AI models and algorithms.
Legal bases: our legitimate interests in improving and developing the Service; where applicable, consent for certain types of analytics cookies or tracking.

3.5 For marketing and optional communications
  - Sending you newsletters, product updates, offers, or recommendations that we think may interest you (for example, if you sign up to hear from us or if you are an existing customer).
  - Running remarketing or advertising campaigns, where permitted.
Legal bases: your consent (for example, where required for email marketing or cookies) and our legitimate interests in promoting and growing our business, in each case subject to applicable e-privacy and marketing laws. We will only send you marketing communications where permitted by applicable e-privacy and marketing laws, and you can opt out of marketing communications at any time by following the unsubscribe link in our emails or contacting us at support@sortwedpics.com.

3.6 To comply with legal obligations
  - Keeping records required by tax, accounting, or other laws.
  - Responding to lawful requests from courts, law enforcement agencies, or regulators.
Legal bases: compliance with legal obligations (Article 6(1)(c) GDPR) and, where applicable, our legitimate interests in cooperating with authorities and protecting our legal rights.

4. How we share your information

We do not sell your personal data. We share information only as necessary for the purposes described in this Privacy Policy, including with:

4.1 Service providers and sub-processors
We may share personal data with trusted third-party service providers who act on our behalf, such as:
  - Hosting and infrastructure providers (for example, cloud data centers, storage, and content delivery networks).
  - Payment processors and billing providers (for example, Stripe).
  - Email, notification, and communication tools (for example, transactional email services and customer support tools).
  - Analytics and performance monitoring services.
  - Tools that help us manage customer support, logging, and security.

These service providers are engaged under written contracts, act as our "processors" in relation to personal data, and may only process personal data on our documented instructions, using appropriate technical and organizational measures to protect it. Further information about our sub-processors may be available in our data processing agreement (DPA) or on request.

4.2 Other users and Guests
Depending on how you configure your Event and sharing settings, certain information (such as photos, guest names, and gallery links) may be visible to Guests and other people you share links with. Hosts control many of these settings and are responsible for choosing who can access Event content.

4.3 Business transfers
If we are involved in a merger, acquisition, asset sale, corporate reorganization, or similar transaction, your information may be transferred as part of that transaction, subject to appropriate confidentiality protections and continued use in line with this Privacy Policy.

4.4 Legal and compliance
We may disclose your information if we believe, in good faith, that such disclosure is reasonably necessary to:
  - comply with any applicable law, regulation, legal process, or governmental request;
  - enforce our Terms and Conditions or other agreements;
  - protect the rights, property, or safety of SortWedPics, our users, or the public.

5. International data transfers

5.1 We generally store and process personal data in the European Union (for example, in EU-based cloud infrastructure). However, some of our service providers or partners may be located or may process data outside of the European Economic Area (EEA), the United Kingdom, or your country of residence.

5.2 Where we transfer personal data to countries that do not provide an adequate level of data protection according to the European Commission or other relevant authorities, we will implement appropriate safeguards, such as entering into Standard Contractual Clauses (SCCs) or relying on other valid transfer mechanisms, and we will take additional technical and organizational measures where appropriate.

6. Cookies and similar technologies

6.1 We use cookies and similar technologies (such as pixels and local storage) to:
  - enable essential features of the Service (for example, keeping you logged in and maintaining session security);
  - understand how the Service is used and to improve it (analytics cookies);
  - (where applicable) support marketing and advertising activities.

6.2 When you visit our website, we may ask for your consent to use certain categories of cookies (for example, analytics or advertising cookies). We may use third-party analytics tools to help us understand how the Service is used; more details about the specific cookies and tools we use may be provided in our cookie banner or a dedicated cookie information page. You can manage your cookie preferences through any cookie banner or settings we provide, and you can also adjust your browser settings to refuse or delete cookies. Please note that disabling certain cookies may affect the functionality of the Service.

7. Mobile app, device permissions, and notifications

7.1 If you use a SortWedPics mobile application (where available), we may collect additional information, such as:
  - Device information: device type, operating system, app version, language, and device identifiers.
  - App usage data: how you interact with the app, crash logs, and performance metrics.
  - Permissions: with your consent, access to your device's camera and photo library, so you can capture or upload photos directly; access to notifications so we can send you push notifications; and, if used, optional access to contacts or location data to support specific features.

7.2 You can control many of these permissions through your device settings (for example, disabling camera or photo access for the app, or turning off push notifications). If you revoke certain permissions, some app features may become unavailable.

8. How long we keep your information

8.1 We retain personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy, including providing the Service, complying with legal obligations, and resolving disputes.

8.2 In general:
  - Event content (such as galleries and photos) is retained for at least the period communicated on our website or during purchase (for example, we may keep galleries available for around twelve (12) months after the Event date), after which content may be archived, anonymized, or deleted, subject to our legitimate business needs and legal obligations.
  - Account information is retained for as long as your account is active and for a reasonable period afterward if needed to comply with legal obligations or to resolve disputes (for example, certain account and contract information may be retained for several years after account closure to meet tax and accounting requirements).
  - Payment and billing records are retained for the periods required by tax and accounting laws.
  - Log and analytics data may be retained for shorter periods (for example, a few months) unless we need to keep them longer for security, fraud prevention, or legal reasons.

8.3 We may retain aggregated or anonymized data (which cannot reasonably be used to identify you) for longer periods for analytics, service improvement, and business planning.

9. How we keep your information safe

9.1 We implement appropriate technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures may include encryption in transit, access controls and authentication, regular backups, monitoring, and internal policies and training.

9.2 However, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential and for notifying us promptly if you suspect any unauthorized access or misuse of your account.

10. Your privacy rights

10.1 Depending on your location and applicable law (particularly if you are located in the EEA, UK, or Switzerland), you may have some or all of the following rights in relation to your personal data:
  - Right of access: to obtain confirmation of whether we process your personal data and to request a copy of it.
  - Right to rectification: to request that we correct inaccurate or incomplete personal data.
  - Right to erasure ("right to be forgotten"): to request that we delete your personal data in certain circumstances.
  - Right to restriction of processing: to request that we restrict the processing of your personal data in certain circumstances.
  - Right to data portability: to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit it to another controller where technically feasible.
  - Right to object: to object, on grounds relating to your particular situation, to certain processing based on our legitimate interests, including profiling; and to object at any time to processing for direct marketing purposes.
  - Right to withdraw consent: where we rely on your consent to process your personal data, you have the right to withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing based on consent before its withdrawal.

10.2 To exercise these rights, you can contact us using the details in section 13. We may ask you to verify your identity before responding to your request, and certain rights may be limited or subject to conditions under applicable law.

10.3 If you are a Guest and your data has been uploaded by a Host (for example, because they uploaded photos or guest lists about you), we may refer your request to the relevant Host if they are the data controller for that processing. We will, where reasonably possible and as required by law, provide Hosts with assistance in handling such requests.

10.4 You also have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State or UK country where you live or work, or where you consider that your rights have been infringed. If SortWedPics is established in the Netherlands, the relevant supervisory authority is the Autoriteit Persoonsgegevens (Dutch Data Protection Authority).

11. Children’s privacy

11.1 The Service is not intended for use by children as account holders. We do not knowingly allow persons under the age of 16 (or a higher age if required by local law) to create accounts or directly enter into contracts with us.

11.2 Hosts may upload photos or Guest information that includes children as part of Event content. Hosts are responsible for having an appropriate legal basis (and, where required, parental consent) before uploading such content.

11.3 If you are a parent or guardian and believe that we have collected personal data directly from a child in a way that is not permitted by law, please contact us at support@sortwedpics.com. We will take reasonable steps to delete such information or otherwise address the issue in line with applicable law.

12. Changes to this Privacy Policy

12.1 We may update this Privacy Policy from time to time, for example to reflect changes in our practices, in the Service, or in applicable laws. When we make material changes, we will take reasonable steps to inform you, such as by updating the "Last Updated" date at the top of this page, displaying a notice in the Service, or sending you an email.

12.2 Unless otherwise stated, the updated Privacy Policy will take effect when it is posted on our website. If you continue to use the Service after the updated Privacy Policy takes effect, your use will be subject to the new version.

13. Contact us

13.1 If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, you can contact us at:

Email: support@sortwedpics.com

13.2 Our current legal entity details (including company name, registered office address, registration number, and VAT ID where applicable) are made available on our website (for example, in our imprint, legal, or billing information pages) and during the signup or billing process. If you need this information or cannot find it, please contact us at support@sortwedpics.com.

If you use SortWedPics, you acknowledge that you have read this Privacy Policy and understand how we handle your personal data.