Legal

Privacy Policy

Last updated: April 2026

This Privacy Policy explains how Moments ("we", "us", "our") collects, uses, and protects your personal information when you use our website at momentsphotos.co.uk and our event photo sharing platform.

We are committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who we are

Moments is operated by Gabriele Sinis, based in the United Kingdom. We are registered with the Information Commissioner's Office (ICO) under registration number ZC121497. If you have any questions about this policy or how we handle your data, you can contact us at hello@momentsphotos.co.uk.

2. What information we collect

We collect the following types of information:

3. How we use your information

We use your information to:

4. Legal basis for processing

We process your data under the following legal bases:

5. Who we share your data with

We use the following trusted third-party services to operate our platform:

We do not sell your personal data to any third parties.

6. Photo storage and guest data

Photos uploaded by guests are stored securely via Cloudinary and are only accessible to people with the event link and guest password. Event albums become read-only the day after the event date. All photos and event data are permanently deleted 30 days after the event date. Organisers can download all photos as a ZIP file at any time during this period.

Guest names and email addresses are collected solely for the purpose of identifying photo contributions within the event app. They are not used for any marketing purposes.

7. Data retention

8. Your rights

Under UK GDPR, you have the right to:

To exercise any of these rights, contact us at hello@momentsphotos.co.uk. We will respond within 30 days.

9. Cookies

Our website uses two types of cookies:

You can change your cookie preference at any time by clearing your browser's local storage. For more information on managing cookies, visit ico.org.uk.

10. Security

We take security seriously. All data is transmitted over HTTPS, passwords are never stored in plain text, and we use industry-standard services (Supabase, Stripe) that are themselves compliant with relevant security standards.

11. Children's privacy

Our service is not directed at children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

12. Changes to this policy

We may update this Privacy Policy from time to time. We will notify registered users of any significant changes by email. The date at the top of this page shows when the policy was last updated.

13. Complaints

If you are unhappy with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.