Privacy Policy
Last updated: September 2026
1. Controller
Ingo Christ
snaplounge
Luisenstraße 15
44787 Bochum
E-Mail: [email protected]
Phone: +49 234 544 856 80
2. Overview of Data Processing
The following overview summarizes the types of data processed and the purposes of their processing and refers to the data subjects.
- Inventory data (e.g., names, addresses)
- Contact data (e.g., email, phone numbers)
- Content data (e.g., photos, videos, text entries)
- Usage data (e.g., pages visited, access times)
- Meta/communication data (e.g., device IDs, IP addresses)
- Payment data (processed by Stripe, not stored by us)
- Statistics and marketing data (only with your consent, see section 4)
3. Legal Basis
We process your personal data on the following legal bases:
- Consent (Art. 6 Abs. 1 S. 1 lit. a DSGVO) — e.g., when guests upload photos
- Contract performance (Art. 6 Abs. 1 S. 1 lit. b DSGVO) — e.g., providing the booked event gallery
- Legitimate interests (Art. 6 Abs. 1 S. 1 lit. f DSGVO) — e.g., ensuring operations, server log files, abuse prevention
4. Cookies and Consent (§ 25 TTDSG)
Our website stores information on your device (cookies, localStorage) or reads it from there. Anything that is not strictly necessary is only used after you have explicitly agreed in the cookie banner (§ 25 (1) TTDSG, Art. 6(1)(a) GDPR). We distinguish three categories:
- Necessary (always active) — Without these the site does not work: login and session (Firebase Authentication), abuse and bot protection (Firebase App Check, Cloudflare Turnstile), language setting, and storing your cookie decision itself. Legal basis: § 25 (2) no. 2 TTDSG and Art. 6(1)(b) or (f) GDPR — no consent required.
- Statistics (only with consent) — Audience measurement to understand how snaplounge is used: Google Analytics 4 (section 14) and Sentry Session Replay (section 16).
- Marketing (only with consent) — Measurement and optimization of our advertising: Meta Pixel (section 15).
Withdrawal at any time: You can withdraw your consent at any time with effect for the future, or change individual categories later — via the "Cookie settings" link in the footer of every page. Withdrawing is therefore just as easy as giving consent (Art. 7(3) GDPR). The lawfulness of processing carried out before withdrawal remains unaffected.
Storage duration: We store your cookie decision locally in your browser until you change it or clear your browser data. The storage durations of the individual services are described in the respective sections.
5. Server Log Files
When you access our website, our infrastructure providers automatically collect information in server log files that your browser transmits automatically:
- IP address (full, deleted after 30 days)
- Browser type and version
- Operating system
- Referrer URL (previously visited page)
- Date and time of the server request
Purpose: Ensuring smooth operations, detecting and preventing attacks, technical error analysis.
Legal basis: Art. 6 Abs. 1 lit. f DSGVO (legitimate interest in operational security).
Storage duration: 30 days, then automatic deletion.
6. Hosting, CDN & Security (Cloudflare)
Our website is served via Cloudflare Pages. Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA) acts as a Content Delivery Network (CDN), DNS provider, and security service (DDoS protection, Web Application Firewall). Each page request routes data (including your IP address) through Cloudflare servers.
Third-country transfer: Cloudflare is certified under the EU-US Data Privacy Framework (DPF). Additionally, EU Standard Contractual Clauses (SCCs) are in place. More information:
https://www.cloudflare.com/privacypolicy/
7. Bot Protection (Cloudflare Turnstile)
In forms (e.g., login, enquiries) we use Cloudflare Turnstile, a CAPTCHA alternative by Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA). Turnstile checks in the background whether an input comes from a human or an automated script. Technical data from your browser is processed for this — in particular IP address, browser and device information, and interaction patterns. Cloudflare sets a short-lived identifier in the browser for this purpose.
Purpose: Defense against spam, automated requests, and abuse of our forms.
Legal basis: Art. 6 Abs. 1 lit. f DSGVO (legitimate interest in abuse-free operation). Turnstile is technically necessary to provide the service (§ 25 (2) no. 2 TTDSG) and therefore runs independently of cookie consent.
Recipients: Cloudflare, Inc.
Third-country transfer: USA — Cloudflare is certified under the EU-US Data Privacy Framework; additionally, EU Standard Contractual Clauses (SCCs) are in place.
Storage duration: The verification identifier is only valid for the respective session; according to Cloudflare, Turnstile data is not stored longer than necessary and is not used for advertising purposes.
https://www.cloudflare.com/privacypolicy/
8. Firebase & Cloud Services (Google)
We use Google Firebase (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) for:
- Firebase Authentication — Registration and login (email, Google Sign-In)
- Cloud Firestore — Storage of event data, user settings
- Firebase App Check — Protection against automated abuse
Data processing primarily takes place on Google servers in the EU (region europe-west). However, Google may access data from other regions for support, diagnostics, and infrastructure management.
Third-country transfer: Google LLC is certified under the EU-US Data Privacy Framework (DPF). Additionally, EU Standard Contractual Clauses (SCCs) are in place.
https://firebase.google.com/support/privacy
9. Abuse Protection (Google reCAPTCHA Enterprise via Firebase App Check)
To ensure that only our genuine app and website can access our servers, we use Firebase App Check with Google reCAPTCHA Enterprise (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; for the USA: Google LLC). reCAPTCHA Enterprise runs invisibly in the background and evaluates technical signals to determine whether a request comes from a human or an automated script. This transmits, among other things, IP address, browser and device information, referrer, and mouse and keyboard interactions to Google. Google sets or reads its own cookies for this purpose.
Purpose: Protection against automated abuse, manipulation of uploads, and unauthorized access to our interfaces.
Legal basis: Art. 6 Abs. 1 lit. f DSGVO (legitimate interest in the security of our systems and the photos entrusted to us). The service is technically necessary for secure operation (§ 25 (2) no. 2 TTDSG) and therefore runs independently of cookie consent. We use it exclusively for abuse protection, not for advertising or audience measurement.
Recipients: Google Ireland Limited, Google LLC.
Third-country transfer: USA — Google LLC is certified under the EU-US Data Privacy Framework; additionally, EU Standard Contractual Clauses (SCCs) are in place.
Storage duration: Deletion follows Google's specifications; the attestation tokens issued by App Check are only valid for a few hours.
https://policies.google.com/privacy
10. Image Storage (Cloudflare R2)
Uploaded photos and videos are stored in Cloudflare R2 (S3-compatible object storage). Storage takes place in the EU region.
Important notice: Photos in an event gallery are accessible to anyone who has the event code or event link. The event code does not constitute comprehensive access protection. The host is responsible for sharing the event code only with authorized persons and informing guests about photo visibility.
The storage duration depends on the booked package (90 days to 24 months). After the download phase ends, data remains accessible for another 30 days (grace period with optional paid extension); afterwards it is permanently and automatically deleted.
11. Photos, Consent & Host Responsibility
snaplounge is a technical platform that enables hosts to create event galleries. The host is responsible under data protection law for:
- informing guests before the event that photos may be uploaded via snaplounge and may be visible in a shared gallery
- ensuring that persons depicted in photos consent to being photographed and published (right to one's own image)
- sharing the event code only with authorized persons
- moderating and, if necessary, deleting inappropriate or unlawful content
Guests who upload photos thereby confirm that they hold the necessary rights to the photos and that depicted persons consent to the upload.
12. Payment Processing (Stripe)
For payments, we use the payment service provider Stripe (Stripe Inc., 354 Oyster Point Blvd, South San Francisco, CA 94080, USA / Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland). During a purchase, your payment data is transmitted directly to Stripe and processed there. We do not have access to your complete credit card or bank details.
Third-country transfer: Stripe Inc. is certified under the EU-US Data Privacy Framework (DPF). Additionally, EU Standard Contractual Clauses (SCCs) are in place.
https://stripe.com/privacy
13. Email Delivery (Amazon SES)
For sending emails we use Amazon Simple Email Service (Amazon SES), a service of Amazon Web Services, Inc. (410 Terry Avenue North, Seattle, WA 98109, USA). Delivery runs via the AWS Europe region (eu-central-1, Frankfurt). Your email address is transmitted to Amazon SES for this purpose.
Types of emails: We send (a) transactional emails (e.g., login codes, booking confirmations, invitations, notice of upcoming end of the storage period) and (b) service/reminder emails to hosts and participants of an event. Promotional reminders (e.g., offers to extend the storage period) are sent to existing customers based on § 7 (3) UWG or your consent.
Objection / unsubscribe: You may object to promotional and non-essential reminder emails at any time — via the unsubscribe link in each such email or in your account settings. Purely transactional emails (e.g., the notice before final deletion of your data) are not affected.
Third-country transfer: AWS is certified under the EU-US Data Privacy Framework (DPF); additionally, EU Standard Contractual Clauses (SCCs) are in place.
https://aws.amazon.com/privacy/
14. Audience Measurement (Google Analytics 4)
We use Google Analytics 4 (property G-743ZS8LWSF) from Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). Google Analytics uses cookies and similar technologies to evaluate how our website is used — e.g., which pages are visited, how long visitors stay, and which channel they came from. We have activated IP anonymization (anonymize_ip: true): your IP address is truncated by Google before further processing.
Purpose: Audience measurement and improvement of our services.
Legal basis: Exclusively your consent (Art. 6(1)(a) GDPR, § 25 (1) TTDSG). Without consent to the "Statistics" category, Google Analytics is not loaded.
Recipients: Google Ireland Limited, Google LLC.
Third-country transfer: Data may be transferred to Google LLC in the USA. This is based on the EU Standard Contractual Clauses (SCCs); Google LLC is additionally certified under the EU-US Data Privacy Framework.
Storage duration: Analytics cookies expire after 24 months at the latest; user-level data is deleted by Google after 14 months.
Withdrawal: at any time via "Cookie settings" in the footer.
https://policies.google.com/privacy
15. Meta Pixel (Facebook & Instagram)
We advertise snaplounge via Facebook and Instagram. For this we use the Meta Pixel (ID 1395463201787948) from Meta Platforms Ireland Limited (Merrion Road, Dublin 4, D04 X2K5, Ireland). The pixel records which of our pages you visit and which actions you take (e.g., page view, start of a booking) and — if you are logged in to Facebook or Instagram — associates these events with your account there. Usage data as well as meta/communication data such as IP address, browser and device information, and cookie identifiers are transmitted.
Server-side transmission (Conversions API): In addition to the pixel, we transmit completed bookings directly from our server to Meta. This covers the purchase amount, the plan booked, an order reference and your email address — the latter exclusively as an irreversible cryptographic hash (SHA-256), never in plain text. Meta matches this hash against its users’ accounts in order to attribute the purchase to the preceding ad. The order reference is sent by both the pixel and the server so that Meta recognises both reports as the same purchase and does not count it twice. This transmission likewise only takes place with your consent to the “Marketing” category; if you have not granted it or have withdrawn it, it does not occur.
Purpose: Measuring the success of our advertising, optimizing delivery, and showing relevant ads (retargeting).
Legal basis: Exclusively your consent (Art. 6(1)(a) GDPR, § 25 (1) TTDSG). Without consent to the "Marketing" category, the pixel is not loaded.
Recipients: Meta Platforms Ireland Limited, Meta Platforms, Inc.
Joint controllership: We and Meta are joint controllers for the collection and transmission of data by the pixel (Art. 26 GDPR). We have concluded the agreement provided by Meta ("Controller Addendum") for this purpose. Meta alone is responsible for the subsequent further processing of the data in its own systems. You can exercise your data subject rights with us as well as with Meta; information about processing at Meta is available directly from Meta.
Third-country transfer: Data may be transferred to Meta Platforms, Inc. in the USA. This is based on the EU Standard Contractual Clauses (SCCs); Meta Platforms, Inc. is additionally certified under the EU-US Data Privacy Framework.
Storage duration: Pixel cookies expire after 90 days at the latest. How long Meta stores the data afterwards is determined by Meta.
Withdrawal: at any time via "Cookie settings" in the footer.
https://www.facebook.com/privacy/policy
16. Error Monitoring (Sentry)
So that we can notice and fix crashes and errors, we use Sentry (Functional Software, Inc. dba Sentry, 45 Fremont Street, San Francisco, CA 94105, USA). We explicitly use Sentry's European region: all data goes to ingest.de.sentry.io and is stored and processed in the EU (Germany).
a) Error reports (without consent): If a technical error occurs, your browser transmits an error report to Sentry. It contains the error message including technical context (page visited, browser and device information, IP address, time) and, where applicable, your user ID so that the same error can be linked across reports. The legal basis is our legitimate interest in the stability and security of our service (Art. 6(1)(f) GDPR); this monitoring is technically necessary for secure operation and therefore runs independently of cookie consent.
b) Session Replay (only with consent): In addition, Sentry can create a technical recording of the page flow ("Session Replay") so we can understand which steps led to an error. We only enable this feature if you have consented to the "Statistics" category (Art. 6(1)(a) GDPR, § 25 (1) TTDSG). All text and all media are masked or blocked before transmission (maskAllText: true, blockAllMedia: true) — so no photo content, names, email addresses, or other entries are transmitted, only placeholders and the structural flow. Only a portion of sessions is recorded, plus sessions in which an error occurs.
Recipients: Functional Software, Inc. dba Sentry (processing in the EU region).
Third-country transfer: Storage takes place in the EU. Access from the USA in the context of support and maintenance cannot be ruled out; EU Standard Contractual Clauses (SCCs) are in place with Sentry for this.
Storage duration: Error reports and replays are automatically deleted after 90 days.
Withdrawal: You can disable Session Replay at any time via "Cookie settings" in the footer. You may object to error monitoring under Art. 21 GDPR.
https://sentry.io/privacy/
17. Fonts (self-hosted)
We use the fonts "Inter" and "Playfair Display", which originally come from Google Fonts. These fonts are delivered from our own servers (self-hosted). For our own fonts, no connection to Google servers is established, no IP address is transmitted to Google and no cookies are set. This does not affect the abuse protection described in section 9 (reCAPTCHA Enterprise): it is delivered by Google inside its own embedded frame and loads further resources from Google servers itself, including its own font. We have no technical influence over this.
18. Sample Images (Unsplash)
On our demo page we show sample photos that are loaded via the Unsplash image CDN (Unsplash Inc., 400-460 Richmond St. W, Toronto, ON M5V 1Y1, Canada). When these images are displayed, your browser establishes a direct connection to Unsplash; your IP address and technical browser data are transmitted to Unsplash. We do not use Unsplash on any other page.
Purpose: Illustrative display of a sample gallery without real guest photos.
Legal basis: Art. 6 Abs. 1 lit. f DSGVO (legitimate interest in a meaningful, fast-loading product demo).
Recipients: Unsplash Inc.
Third-country transfer: Canada — an adequacy decision of the EU Commission exists for Canada, so no additional safeguards are required.
Storage duration: We do not store any data ourselves for this; Unsplash's server logs are subject to their privacy policy.
https://unsplash.com/privacy
19. Image Moderation (Google Cloud Vision API)
To protect guests and hosts from unlawful or offensive content, uploaded photos may be checked automatically for problematic content. For this we use the Google Cloud Vision API ("SafeSearch") provided by Google Ireland Limited. The image is transmitted from our storage to Google, analysed automatically and returned with ratings for the categories adult content, violence, racy content, spoof (manipulated imagery) and medical content. No facial recognition or identification of depicted persons takes place; the result is solely a likelihood rating per category.
Currently this check is performed only for events for which AI moderation has been booked (Premium, Deluxe and Individual packages) and for which the host has enabled at least one of the moderation filters. Otherwise, no photo leaves our storage for this purpose.
Purpose: Detecting and flagging unlawful or offensive image content in event galleries so that the host can review it before publication.
Legal basis: Art. 6 Abs. 1 lit. f DSGVO (legitimate interest in abuse-free operation and in protecting participants from offensive content).
Recipients: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (where applicable Google LLC, USA, as a sub-processor).
Third-country transfer: Processing may also take place on servers in the USA. Google LLC is certified under the EU-US Data Privacy Framework (DPF); in addition, EU Standard Contractual Clauses (SCCs) are in place.
Storage duration: According to the provider, Google does not store the transmitted images beyond the check itself and does not use them to train its own models. We store the result of the check together with the photo in the event gallery; it is deleted together with the event.
https://cloud.google.com/vision/docs/data-usage
20. Your Rights
You have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent (Art. 7(3) GDPR)
To exercise your rights, please contact: [email protected]
21. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data. The competent supervisory authority is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW).
22. Changes
We reserve the right to update this privacy policy to ensure it always complies with current legal requirements or to implement changes to our services. The new privacy policy will then apply to your next visit.