Privacy Policy
Effective: 25 July 2026
1. Controller
Bernd BogenriederAm Horben 5
88437 Sulmingen
Germany
For privacy requests, please use the contact form and choose a clear subject such as “Privacy request”.
2. How SnapKey works
A Host creates a photo space and may connect a personal Google Drive, Microsoft OneDrive or Dropbox account. Guest images pass through SnapKey only for the technical upload process and are stored in the connected Host account. SnapKey stores the metadata required to operate QR access, permissions and sharing, but does not use its own permanent image storage.
Depending on the event and purpose, the Host may separately be responsible for deciding why images of guests are collected and shared. Guests should contact the Host first about the Host’s intended use of event photos.
3. Data we process
4. Purposes and legal bases
- Providing requested functions: creating photo spaces, authenticating Masters, transferring images, applying permissions and delivering protected galleries (Art. 6(1)(b) GDPR where a contract applies).
- Security and reliable operation: preventing misuse, diagnosing failures and protecting accounts, QR links and infrastructure (Art. 6(1)(f) GDPR).
- Contact and support: responding to enquiries and documenting their resolution (Art. 6(1)(b) or Art. 6(1)(f) GDPR).
- Legal obligations: retaining or disclosing information where required by applicable law (Art. 6(1)(c) GDPR).
- Consent: where a Host or guest is expressly asked to consent, processing is based on Art. 6(1)(a) GDPR and consent may be withdrawn for the future.
5. Cloud storage and OAuth
Connecting a provider redirects the Host to that provider’s official authorization page. SnapKey requests only the scopes shown there and uses the resulting tokens to create or use an application folder, upload files, retrieve authorized images and process requested deletions. Tokens are encrypted at rest and removed from SnapKey when the Host disconnects the provider.
SnapKey’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
The selected provider processes data under its own privacy policy: Google, Microsoft or Dropbox.
6. Hosting and recipients
SnapKey is delivered using Cloudflare infrastructure. Cloudflare may process network, security and request data to deliver and protect the service. See the Cloudflare Privacy Policy.
Data is disclosed only where needed to operate the service, at the Host’s direction, with service providers acting for us, or where legally required. SnapKey does not sell personal data and does not use uploaded photos to train artificial-intelligence models.
7. International transfers
Cloudflare and the selected cloud provider may process data outside Germany or the European Economic Area. Depending on the provider and service configuration, transfers may rely on an adequacy decision, the EU–US Data Privacy Framework, standard contractual clauses or another lawful safeguard. The provider’s privacy policy contains current details.
8. Cookies and local identifiers
SnapKey uses only technically necessary cookies:
- snapkey_guest: recognizes a guest’s own uploads on that browser; up to one year.
- snapkey_master: keeps a Master authenticated; up to 12 hours.
- snapkey_share: remembers successful access to a protected gallery; up to 6 hours.
- snapkey_admin: protects the global administration session; up to 12 hours.
These identifiers are required for access control and service security. No advertising or cross-site tracking cookies are used.
9. Retention and deletion
Data is retained only as long as necessary for the photo space, support request, security purpose or applicable legal duty. Application activity-log entries are automatically removed after 30 days. Master and protected-gallery sessions expire automatically. Protected sharing links currently expire after the period shown when created.
Deleting a photo through SnapKey removes its SnapKey metadata after requesting deletion from the cloud provider. Disconnecting a cloud account deletes stored OAuth credentials from SnapKey but does not delete files in that provider account. Contact us to request deletion of a photo space or support message. Provider backups and recovery windows remain governed by the selected provider.
10. Security
SnapKey uses encrypted HTTPS connections, random access tokens, password hashing, encrypted OAuth tokens, time-limited sessions, permission checks and private-by-default guest galleries. No internet service can guarantee absolute security. Hosts should use strong, unique passwords and protect Master QR codes and sharing credentials.
11. Your rights
Subject to the legal requirements, you may request access, correction, deletion, restriction, portability or objection to processing. You may withdraw consent for future processing and lodge a complaint with a competent data-protection supervisory authority. We may need information to verify your identity and locate the relevant photo space or upload.
12. Children and images of other people
SnapKey is not directed at children acting independently. Hosts and uploaders must ensure that any required permission from parents, guardians or depicted persons has been obtained before collecting or sharing their images.
13. Changes
This policy may be updated when the service, providers or legal requirements change. The current version and effective date will remain available on this page.