photoreel

Legal

Privacy Policy

This policy explains how PhotoReel handles account information, event photographs, guest uploads and the optional Find My Photos face-matching feature.

Last updated: 17 September 2026

1. Who this policy applies to

This Privacy Policy applies when you visit PhotoReel, create or use a workspace, attend an event gallery, upload a photograph, use Find My Photos, or otherwise communicate with us. “PhotoReel”, “we”, “us” and “our” refer to the operator of the PhotoReel service identified on your invoice or order confirmation.

PhotoReel is operated from Singapore. For questions or requests, contact our privacy team at support@vulxe.com.

2. Our role and the organiser’s role

The organisation, photographer or event team that creates an event (the “Organiser”) generally decides why event photographs are collected, who may access them, how long the event remains active and whether guest uploads or face matching are enabled. For that event content, the Organiser is normally the organisation responsible for the personal data and PhotoReel processes it on the Organiser’s behalf.

PhotoReel is independently responsible for personal data used to run our business, including account administration, authentication, billing, platform security, support, legal compliance and service analytics. Requests about a particular event may be referred to its Organiser where the Organiser controls the relevant data.

3. Personal data we collect

  • Account and workspace data: name, email address, organisation name, password hash, role, session and invitation information, settings and support correspondence.
  • Event and media data: event details, photographs, image metadata, captions, moderation status, uploader details and records of favourites, shares, downloads or views.
  • Face-matching data: when enabled, face features derived from event photographs and a selfie or selected image you voluntarily submit to search within that event.
  • Guest-upload data: photographs you submit, upload time, technical metadata and moderation records.
  • Transaction data: package, price, payment status, transaction identifiers and limited billing details. Payment-card information is handled by Stripe and is not stored by PhotoReel.
  • Technical and security data: IP address, device and browser information, request logs, cookie or session identifiers, diagnostics and audit events.

4. How we use personal data

We use personal data where reasonably necessary to:

  • provide, secure, maintain and troubleshoot the service;
  • create accounts, authenticate users and manage permissions;
  • host, display, moderate, search, deliver and delete event media;
  • process purchases and administer event entitlements;
  • respond to support, privacy and legal requests;
  • prevent fraud, misuse, security incidents and unlawful activity;
  • measure service performance and improve PhotoReel; and
  • comply with law and enforce our agreements.

Depending on the circumstances and applicable law, we rely on your consent, performance of a contract, compliance with legal duties, or our legitimate interests and those of Organisers in operating a safe event-photo service. You may withdraw consent at any time, although this does not affect processing already carried out lawfully.

5. Find My Photos and facial data

Find My Photos is an optional, event-specific matching tool. It is not used to identify you by name, authenticate you, conduct surveillance, or search across unrelated events. You choose whether to submit a selfie or another image and must have permission from every person clearly depicted in the submitted image.

The submitted search image is stored temporarily, compared with face features indexed from photographs in that event, and scheduled for deletion immediately after the search. If immediate deletion fails, an automated storage lifecycle is configured to remove temporary selfie objects within one day. Search counters, security logs and limited records of the search may be retained without retaining the submitted selfie.

Face matching is probabilistic and may return incorrect or incomplete results. Do not use it for decisions affecting a person’s rights, eligibility, safety, employment, credit or access to services. Where law requires explicit consent for biometric processing, the Organiser must provide appropriate notice and obtain that consent before enabling the feature.

6. How we disclose personal data

We may disclose personal data only as reasonably necessary to:

  • the relevant Organiser and its authorised photographers, team members and service providers;
  • cloud, storage, content-delivery, security and face-matching providers, including Amazon Web Services and Cloudflare;
  • payment providers, including Stripe;
  • email or communications providers used for service messages;
  • professional advisers, insurers, auditors and transaction parties under appropriate confidentiality obligations; and
  • courts, regulators, law-enforcement bodies or other parties when required by law or necessary to protect rights, safety and security.

We do not sell personal data. We do not use event photographs or submitted selfies to train general-purpose artificial-intelligence models.

7. International transfers

PhotoReel and its service providers may process data outside your country. We use contractual, organisational and technical safeguards intended to provide protection comparable to that required under applicable law, including Singapore’s Personal Data Protection Act 2012 (“PDPA”), where required.

8. Retention and deletion

We retain personal data only for as long as reasonably necessary for the purposes described in this policy, the Organiser’s documented instructions, the event hosting period, dispute resolution, security, backup and legal obligations. Event retention may vary by package and Organiser settings. An Organiser can delete an event, which initiates deletion of its database records, stored originals and event-specific face index.

Residual copies may remain temporarily in encrypted backups, logs or caches and are isolated from ordinary use until overwritten under their retention schedules. We may retain de-identified or aggregated information that no longer identifies an individual.

9. Security

We use measures designed to protect personal data, including access controls, tenant separation, encryption in transit and at rest, restricted cloud storage, short-lived upload and download links, audit logging and deletion controls. No system is completely secure; you should use a unique password and promptly report suspected misuse.

10. Your choices and rights

Subject to applicable law, you may ask to access, correct, delete or receive a copy of your personal data; withdraw consent; restrict or object to certain processing; or complain about our handling of your data. Contact us at the address in section 1 and describe the event, Organiser and photograph where relevant. We may need to verify your identity and may refer event-content requests to the Organiser.

You may also complain to the Personal Data Protection Commission of Singapore or your local data-protection authority. Some rights are subject to lawful exceptions, including the rights and safety of other people and obligations to preserve evidence.

11. Children and young people

PhotoReel is not directed to children for independent account use. Organisers are responsible for notices, permissions and safeguards appropriate to events involving minors. A parent or legal guardian should submit any face-search image for a child unless applicable law permits the child to consent independently. Contact us if you believe a child’s data has been handled without appropriate authority.

12. Cookies and custom domains

We use cookies and similar storage necessary for authentication, security, preferences and core service operation. An Organiser may present a PhotoReel gallery through its own domain and may provide additional notices or links. Third-party sites and services have their own privacy practices, which we do not control.

13. Changes and contact

We may update this policy to reflect service, legal or operational changes. We will post the revised policy with a new “Last updated” date and provide additional notice where required. Questions and complaints may be sent to support@vulxe.com.