Privacy Policy

Last updated:

Our Commitment to Your Privacy

At KnotShots, your wedding photos are precious and personal. We are committed to protecting your privacy and handling your data with the utmost care and transparency. This policy explains what information we collect, how we use it, and your rights regarding your data.

1. Information We Collect

Account Information

When you create an account, we collect:

  • Email address (for login and communications)
  • Password (encrypted and never stored in plain text)
  • Account creation date and last login time

Event Information

When you create a wedding event, we collect:

  • Event name (e.g., "Sarah & John's Wedding")
  • Event date and location
  • Custom guest access PIN (if you enable guest uploads)

Photos & Media

When you or your guests upload photos:

  • Photo files (JPEG, PNG, HEIC, etc.)
  • Video files (MP4, MOV, etc.)
  • Upload timestamp and file metadata (size, type)
  • IP address of uploader (for security and abuse prevention)

Payment Information

When you subscribe to a paid plan:

  • Billing name and email
  • Payment information is processed by Stripe (we never see your full card details)
  • Subscription status and billing history

Usage Data

To improve our service, we collect:

  • Device information (browser type, operating system)
  • IP address and general location (country/region)
  • Pages visited and features used
  • Performance and error logs

2. How We Use Your Information

We use your information to:

  • Provide the Service: Store and display your wedding photos, manage events, and enable guest uploads
  • Process Payments: Handle subscriptions, billing, and refunds via Stripe
  • Send Communications: Welcome emails, subscription receipts, and important service updates
  • Improve the Service: Analyze usage patterns to fix bugs and add features
  • Security & Abuse Prevention: Detect and prevent unauthorized access, spam, and malicious uploads
  • Customer Support: Respond to your questions and troubleshoot technical issues

We will NEVER: Sell your data, use your photos for advertising, or share your information with third parties for marketing purposes.

3. Data Storage & Security

Photo Storage

Your wedding photos are stored in Cloudflare R2, a secure cloud storage service:

  • Private Bucket: Photos are NOT publicly accessible. Direct URLs will not work.
  • Encryption at Rest: All files are encrypted using AES-256 encryption on disk
  • Encryption in Transit: All data transfers use HTTPS/TLS encryption
  • Temporary Access Links: Photos are accessed via signed URLs that expire after 24 hours
  • Complete Isolation: Your photos are stored in event-specific folders. Other customers cannot access your media.

Database Security

Account and event information is stored in a secure PostgreSQL database:

  • Passwords are hashed using industry-standard bcrypt algorithm
  • Database access is restricted to authenticated application servers only
  • All queries use parameterized statements to prevent SQL injection
  • Multi-tenant isolation ensures customers cannot access each other's data

Infrastructure

KnotShots is hosted on:

  • Vercel: Application hosting with automatic HTTPS and DDoS protection
  • Cloudflare R2: Photo storage with global edge network
  • Vercel Postgres: Secure, managed database with automated backups

4. Photo Privacy & Access

Who Can See Your Photos?

  • You: Full access to view, download, and delete photos via your dashboard
  • Your Guests: Can view and download photos only if you provide them with the guest access PIN
  • KnotShots Staff: Can access photos ONLY for technical support purposes (see below)
  • Nobody Else: Photos are private and not indexed by search engines or accessible to the public

Administrative Access

As the service provider, KnotShots administrators have technical access to the storage infrastructure for operational purposes. This is standard practice for all cloud storage services (Google Photos, Dropbox, iCloud, etc.).

Our Policy: We only access customer photos when:

  • Responding to a specific customer support request
  • Investigating reported abuse or Terms of Service violations
  • Troubleshooting technical issues affecting your account
  • Required by law (e.g., valid legal subpoena)

All administrative access is logged and audited for security purposes.

Guest Access Controls

You control who can upload and view photos:

  • Share your unique guest PIN privately (don't post publicly)
  • Guests can only access events for which they have the PIN
  • You can change your PIN anytime to revoke access
  • Access links expire after 24 hours for security

5. Third-Party Services

KnotShots uses the following trusted third-party services:

Stripe (Payment Processing)

All payment information is processed directly by Stripe. We never see or store your full credit card details.

  • Purpose: Process subscriptions, billing, and refunds
  • Data shared: Email, billing name, subscription plan
  • Privacy Policy: stripe.com/privacy

Resend (Email Delivery)

Transactional emails (welcome, receipts, notifications) are sent via Resend.

Cloudflare R2 (Photo Storage)

Photos and videos are stored in Cloudflare's secure object storage.

Vercel (Hosting & Infrastructure)

Application hosting, database, and infrastructure management.

6. Your Rights & Choices

You have the following rights regarding your data:

Access Your Data

View all your account information, events, and photos anytime via your dashboard.

Download Your Photos

Download individual photos or entire events. You own your photos—we're just storing them for you.

Delete Your Data

You can delete:

  • Individual Photos: Delete specific photos from your gallery anytime
  • Entire Events: Delete an event and all associated photos permanently
  • Your Account: Request account deletion via email to hello@knotshots.qzz.io

⚠️ Deletion is permanent and cannot be undone. Please download your photos before deleting.

Export Your Data

Request a copy of all your data in machine-readable format by emailing hello@knotshots.qzz.io

Opt-Out of Emails

You can unsubscribe from marketing emails (we don't send many), but we'll still send:

  • Important service updates and security notifications
  • Subscription receipts and billing notices
  • Responses to your support requests

Update Your Information

Change your email, password, or event details anytime via your dashboard.

7. Data Retention

Active Accounts

We retain your data as long as your account is active and you maintain your subscription.

Canceled Subscriptions

If you cancel your paid subscription:

  • Your account is marked as cancelled - access blocked immediately
  • Photos are retained for 30 days, then permanently deleted
  • You should download your photos before cancellation or contact support within 30 days

Deleted Accounts

When you request account deletion:

  • Photos: Permanently deleted within 30 days
  • Account Data: Removed from active systems within 30 days
  • Backups: Purged from backups within 90 days
  • Billing Records: Retained for 7 years for tax and legal compliance

Inactive Accounts

Accounts inactive for 2+ years may be deleted after email notification. We'll give you 90 days notice to download your photos before deletion.

8. Contact Us

If you have questions about this Privacy Policy or how we handle your data:

KnotShots Privacy Team

Email: hello@knotshots.qzz.io

We typically respond within 48 hours. For urgent security matters, please include "URGENT" in the subject line.

9. Children's Privacy

KnotShots is not intended for children under 13. We do not knowingly collect information from children. If you believe a child has provided us with personal information, please contact us immediately.

10. International Users

KnotShots is operated from the United States. If you access our service from outside the U.S., your data may be transferred to and stored in the United States or other countries where our service providers operate.

For users in the European Economic Area (EEA), we comply with GDPR requirements including data minimization, purpose limitation, and your rights to access, rectify, and delete your data.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We'll notify you of significant changes via:

  • Email notification to your registered address
  • Prominent notice in your dashboard
  • Updated "Last Updated" date at the top of this page

Your continued use of KnotShots after changes take effect constitutes acceptance of the updated policy.

12. California Privacy Rights

If you're a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to know what personal information we collect and how it's used
  • Right to delete your personal information (with certain exceptions)
  • Right to opt-out of sale of personal information (we don't sell your data)
  • Right to non-discrimination for exercising your privacy rights

To exercise these rights, contact us at hello@knotshots.qzz.io

This Privacy Policy is effective as of October 26, 2025. By using KnotShots, you agree to this policy.