Legal
Privacy Policy
Last updated: 22 June 2026
Operator: Gateway Management Group Ltd, 2nd Floor, Didsbury House, 748–754 Wilmslow Road, Manchester, M20 2DW. Company number 10058487. ICO registration number ZB101892. Contact: hello@confettiframe.com.
This Privacy Policy explains how the Operator (the legal entity named above) collects and processes personal data when you (the Customer/Owner) and your guests use Confetti Frame. We comply with the UK GDPR and the EU GDPR where applicable.
1. Roles
- Operator as controller for your account data (email, name, billing details, login activity).
- Operator as processor for guest-submitted photos, videos, and display names — the Owner is the controller of that data, and we process it on the Owner's documented instructions (the event's configured sharing mode and curation choices).
2. What we collect
From the Owner
- Email address, display name, optional avatar (via Google sign-in or email/password).
- Event details: names, date, venue, welcome note, cover photo.
- Billing information processed by Stripe (we do not store full card numbers).
- Server logs: IP address, browser, device, timestamps — for security and abuse prevention.
From guests
- A display name (chosen by the guest; a pseudonym is fine).
- An opaque contributor cookie set on the guest's device so subsequent uploads in the same event are grouped together.
- The photo and video files the guest uploads, and limited metadata (file type, size, timestamp).
- Server logs as above.
3. Why we process it (lawful basis)
- Contract — to provide the Service to the Owner who has purchased a plan.
- Legitimate interests — to keep the Service secure, prevent abuse, and improve product quality (we balance these against your rights).
- Consent — for any optional marketing emails. There are no marketing emails sent by default.
- Legal obligation — to comply with tax, accounting, and law-enforcement requests.
4. Where the data lives
We process data in the United Kingdom and the European Economic Area. Specifically:
- Photos and videos are stored on Cloudflare R2 (EU region).
- Account data and event metadata are stored in our managed Postgres database (Lovable Cloud, hosted by Supabase in the EU).
- Payments are processed by Stripe (UK / Ireland).
- Transactional emails are sent by our email infrastructure provider.
Where any sub-processor transfers data outside the UK/EEA, we rely on the UK International Data Transfer Agreement and/or EU Standard Contractual Clauses with appropriate safeguards.
5. How long we keep it
- Guest photos and videos: for the duration of the Owner's plan archive window (3 months on Private Vault, 12 months on Live Celebration from event activation), then permanently deleted from active systems within 30 days.
- Account data: for as long as the account exists, plus 7 years for financial records as required by HMRC.
- Server logs: typically 90 days.
6. Sharing
We do not sell personal data. We share data only with sub-processors strictly necessary to run the Service (hosting, storage, email, payments) and with law-enforcement when legally compelled.
7. Your rights
Under UK/EU GDPR you have the right to access, rectify, erase, restrict, port, and object to processing of your personal data. To exercise any of these, email hello@confettiframe.com. We respond within 30 days. You may also complain to the UK Information Commissioner's Office (ico.org.uk) or your local EU supervisory authority.
8. Guests' rights
Guests can request removal of their uploads at any time by emailing hello@confettiframe.com or by asking the event Owner. The Owner can hide or delete any upload from the dashboard.
9. Children
The Service is not directed to children under 13. We do not knowingly collect personal data from children under 13. If guests appear in uploaded photos, the Owner is responsible for ensuring appropriate consent is in place.
10. Security
We use TLS in transit, encrypted-at-rest object storage, signed upload URLs, role-based access controls, and Row-Level Security on the database. No system is perfectly secure; we'll notify affected users and the ICO within 72 hours of becoming aware of a notifiable breach.
11. Cookies
See our Cookie Notice for the categories of cookies used.
12. Contact
Privacy questions: hello@confettiframe.com.