DRAFT — this policy is a template and is not legal advice. Have it reviewed by a lawyer and replace every [bracketed] placeholder before publishing.

Last updated: 20.07.2026.

Privacy Policy

This Privacy Policy explains how [Naziv pravnog subjekta / Legal entity name] (“Confetti”, “we”, “us”) collects, uses and protects personal data when you use Confetti at www.confetti.ba and related services (the “Service”).

We act as the data controller for account and billing data. For photos and videos uploaded to a private event gallery, the event owner (the photographer or event host who created the event) is the controller of that content, and we process it on their behalf as a processor.

1. Data we collect

  • Account data: name, email address, a hashed password, and — for photographers — optional profile details you choose to add (city, phone, website, social links, short bio, avatar image) and your dashboard language preference.
  • Event data: event titles, dates, client/couple names, gallery and upload settings, and PINs (stored only as hashes).
  • Uploaded media: photos and videos uploaded by you or by your guests, plus optional guest name/email and technical metadata (file type/size, timestamps, a hashed IP for rate-limiting and abuse prevention).
  • Billing data: your plan and subscription status, and the email used at checkout. Payments are processed by our payment provider (Payhip) — we do not receive or store your full card details.
  • Technical data: essential cookies (login/session and language preference) and standard server logs.

2. How we use data

  • To provide the Service: create events, generate guest-upload links and QR codes, host galleries, and deliver media to authorised viewers.
  • To enable moderation and delivery by the event owner (hiding, deleting, restoring, organising and downloading media).
  • To operate billing, plan limits and trial logic.
  • For security, abuse prevention, rate-limiting and troubleshooting.
  • To communicate with you about your account and, where you have opted in, the optional homepage photographer spotlight.

3. Legal bases (GDPR)

Where the GDPR applies, we rely on: performance of a contract (providing the Service to account holders); our legitimate interests (security, service improvement, preventing abuse); consent (guest uploads, and appearing in the photographer spotlight — which you can withdraw at any time); and compliance with legal obligations.

4. Guest uploads and the event owner

When a guest scans a QR code and uploads media, that media is added to the event owner’s private gallery. The event owner decides who can view the gallery, what stays visible, and when it is deleted. Guests should only upload content they have the right to share, and should not upload content of others without their agreement. If you are an event owner, you are responsible for having a lawful basis to collect and share guest content and for honouring requests from people who appear in it.

5. Sharing and processors

We do not sell your personal data. We share data only with service providers who help us run the Service, under appropriate agreements:

  • Supabase — authentication and database hosting.
  • Cloudflare R2 — object storage for media.
  • Vercel — application hosting and delivery.
  • Payhip — payment processing.
  • An email delivery provider — transactional emails.
  • These providers may process data outside your country, including outside the EU/EEA, under safeguards such as standard contractual clauses where required.

6. Retention

  • One-time (couple) plan: guest uploads open for 30 days from the event date; private gallery access for up to 90 days from the event date.
  • Deleted media is soft-deleted and recoverable for 7 days, then permanently removed from storage.
  • Account data is kept while your account is active and deleted (or anonymised) on request or after account closure, subject to any legal retention obligations.

7. Your rights

Subject to applicable law, you may request access to, correction or deletion of your personal data, restriction of or objection to processing, and data portability, and you may withdraw consent at any time. To exercise these rights, contact us at [kontakt@confetti.ba]. You also have the right to lodge a complaint with your data protection authority. For content inside a private gallery, please also contact the event owner, who controls that content.

8. Security

We use encryption in transit (HTTPS), PIN protection for galleries and uploads, access controls, and rate-limiting. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your data and to review our safeguards over time.

9. Children

The Service is intended for adults creating and managing events. Event galleries may contain images of children captured at events; the event owner is responsible for having the right to collect and share such images. We do not knowingly create accounts for individuals under the age required by local law.

10. Cookies

We use essential cookies needed to keep you logged in and to remember your language preference. We do not use these for advertising. If we later add analytics or non-essential cookies, we will update this policy and, where required, ask for consent.

11. Changes

We may update this policy from time to time. Material changes will be reflected by an updated date at the top of this page and, where appropriate, communicated to account holders.

12. Contact

[Naziv pravnog subjekta / Legal entity name], [Adresa / Registered address]. Email: [kontakt@confetti.ba].