Privacy Policy
Last updated:
Our Commitment to Your Privacy
At KnotShots, your wedding photos are precious and personal. We are committed to protecting your privacy and handling your data with the utmost care and transparency. This policy explains what information we collect, how we use it, and your rights regarding your data.
1. Information We Collect
Account Information
When you create an account, we collect:
- Email address (for login and communications)
- Password (encrypted and never stored in plain text)
- Account creation date and last login time
Event Information
When you create a wedding event, we collect:
- Event name (e.g., "Sarah & John's Wedding")
- Event date and location
- Custom guest access PIN (if you enable guest uploads)
Photos & Media
When you or your guests upload photos:
- Photo files (JPEG, PNG, HEIC, etc.)
- Video files (MP4, MOV, etc.)
- Upload timestamp and file metadata (size, type)
- IP address of uploader (for security and abuse prevention)
Payment Information
When you subscribe to a paid plan:
- Billing name and email
- Payment information is processed by Stripe (we never see your full card details)
- Subscription status and billing history
Usage Data
To improve our service, we collect:
- Device information (browser type, operating system)
- IP address and general location (country/region)
- Pages visited and features used
- Performance and error logs
2. How We Use Your Information
We use your information to:
- Provide the Service: Store and display your wedding photos, manage events, and enable guest uploads
- Process Payments: Handle subscriptions, billing, and refunds via Stripe
- Send Communications: Welcome emails, subscription receipts, and important service updates
- Improve the Service: Analyze usage patterns to fix bugs and add features
- Security & Abuse Prevention: Detect and prevent unauthorized access, spam, and malicious uploads
- Customer Support: Respond to your questions and troubleshoot technical issues
We will NEVER: Sell your data, use your photos for advertising, or share your information with third parties for marketing purposes.
3. Data Storage & Security
Photo Storage
Your wedding photos are stored in Cloudflare R2, a secure cloud storage service:
- Private Bucket: Photos are NOT publicly accessible. Direct URLs will not work.
- Encryption at Rest: All files are encrypted using AES-256 encryption on disk
- Encryption in Transit: All data transfers use HTTPS/TLS encryption
- Temporary Access Links: Photos are accessed via signed URLs that expire after 24 hours
- Complete Isolation: Your photos are stored in event-specific folders. Other customers cannot access your media.
Database Security
Account and event information is stored in a secure PostgreSQL database:
- Passwords are hashed using industry-standard bcrypt algorithm
- Database access is restricted to authenticated application servers only
- All queries use parameterized statements to prevent SQL injection
- Multi-tenant isolation ensures customers cannot access each other's data
Infrastructure
KnotShots is hosted on:
- Vercel: Application hosting with automatic HTTPS and DDoS protection
- Cloudflare R2: Photo storage with global edge network
- Vercel Postgres: Secure, managed database with automated backups
4. Photo Privacy & Access
Who Can See Your Photos?
- You: Full access to view, download, and delete photos via your dashboard
- Your Guests: Can view and download photos only if you provide them with the guest access PIN
- KnotShots Staff: Can access photos ONLY for technical support purposes (see below)
- Nobody Else: Photos are private and not indexed by search engines or accessible to the public
Administrative Access
As the service provider, KnotShots administrators have technical access to the storage infrastructure for operational purposes. This is standard practice for all cloud storage services (Google Photos, Dropbox, iCloud, etc.).
Our Policy: We only access customer photos when:
- Responding to a specific customer support request
- Investigating reported abuse or Terms of Service violations
- Troubleshooting technical issues affecting your account
- Required by law (e.g., valid legal subpoena)
All administrative access is logged and audited for security purposes.
Guest Access Controls
You control who can upload and view photos:
- Share your unique guest PIN privately (don't post publicly)
- Guests can only access events for which they have the PIN
- You can change your PIN anytime to revoke access
- Access links expire after 24 hours for security
5. Third-Party Services
KnotShots uses the following trusted third-party services:
Stripe (Payment Processing)
All payment information is processed directly by Stripe. We never see or store your full credit card details.
- Purpose: Process subscriptions, billing, and refunds
- Data shared: Email, billing name, subscription plan
- Privacy Policy: stripe.com/privacy
Resend (Email Delivery)
Transactional emails (welcome, receipts, notifications) are sent via Resend.
- Purpose: Deliver account and subscription emails
- Data shared: Email address, name, email content
- Privacy Policy: resend.com/legal/privacy-policy
Cloudflare R2 (Photo Storage)
Photos and videos are stored in Cloudflare's secure object storage.
- Purpose: Store and serve your wedding photos securely
- Data shared: Photo files, metadata
- Privacy Policy: cloudflare.com/privacypolicy
Vercel (Hosting & Infrastructure)
Application hosting, database, and infrastructure management.
- Purpose: Host the KnotShots application and database
- Data shared: Account data, usage logs, application data
- Privacy Policy: vercel.com/legal/privacy-policy
6. Your Rights & Choices
You have the following rights regarding your data:
Access Your Data
View all your account information, events, and photos anytime via your dashboard.
Download Your Photos
Download individual photos or entire events. You own your photos—we're just storing them for you.
Delete Your Data
You can delete:
- Individual Photos: Delete specific photos from your gallery anytime
- Entire Events: Delete an event and all associated photos permanently
- Your Account: Request account deletion via email to hello@knotshots.qzz.io
⚠️ Deletion is permanent and cannot be undone. Please download your photos before deleting.
Export Your Data
Request a copy of all your data in machine-readable format by emailing hello@knotshots.qzz.io
Opt-Out of Emails
You can unsubscribe from marketing emails (we don't send many), but we'll still send:
- Important service updates and security notifications
- Subscription receipts and billing notices
- Responses to your support requests
Update Your Information
Change your email, password, or event details anytime via your dashboard.
7. Data Retention
Active Accounts
We retain your data as long as your account is active and you maintain your subscription.
Canceled Subscriptions
If you cancel your paid subscription:
- Your account is marked as cancelled - access blocked immediately
- Photos are retained for 30 days, then permanently deleted
- You should download your photos before cancellation or contact support within 30 days
Deleted Accounts
When you request account deletion:
- Photos: Permanently deleted within 30 days
- Account Data: Removed from active systems within 30 days
- Backups: Purged from backups within 90 days
- Billing Records: Retained for 7 years for tax and legal compliance
Inactive Accounts
Accounts inactive for 2+ years may be deleted after email notification. We'll give you 90 days notice to download your photos before deletion.
8. Contact Us
If you have questions about this Privacy Policy or how we handle your data:
KnotShots Privacy Team
Email: hello@knotshots.qzz.io
We typically respond within 48 hours. For urgent security matters, please include "URGENT" in the subject line.
9. Children's Privacy
KnotShots is not intended for children under 13. We do not knowingly collect information from children. If you believe a child has provided us with personal information, please contact us immediately.
10. International Users
KnotShots is operated from the United States. If you access our service from outside the U.S., your data may be transferred to and stored in the United States or other countries where our service providers operate.
For users in the European Economic Area (EEA), we comply with GDPR requirements including data minimization, purpose limitation, and your rights to access, rectify, and delete your data.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We'll notify you of significant changes via:
- Email notification to your registered address
- Prominent notice in your dashboard
- Updated "Last Updated" date at the top of this page
Your continued use of KnotShots after changes take effect constitutes acceptance of the updated policy.
12. California Privacy Rights
If you're a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information we collect and how it's used
- Right to delete your personal information (with certain exceptions)
- Right to opt-out of sale of personal information (we don't sell your data)
- Right to non-discrimination for exercising your privacy rights
To exercise these rights, contact us at hello@knotshots.qzz.io
This Privacy Policy is effective as of October 26, 2025. By using KnotShots, you agree to this policy.