Privacy Policy
Last updated: {date}
This Privacy Policy describes how SparkShot collects, uses, and protects your personal data in compliance with the General Data Protection Regulation (GDPR) and French data protection laws (Loi Informatique et Libertés).
1. Data Controller
The data controller is the operator of SparkShot. For any data protection inquiries, contact: {email}
2. Data Collected
For organizers (account holders): email address, authentication provider details (Google or email), token balance and purchase history, events created, themes and overlays uploaded. For participants (no account required): first name (self-declared, not verified), photos taken during the event (original and AI-generated), device identifier (anonymized hash for photo ownership). Technical data automatically collected: IP address (logs only, not stored long-term), browser type and language preference, session data.
3. Legal Basis for Processing
We process personal data based on: (a) Legitimate interest — providing and improving the service; (b) Consent — participants consent to photo processing by taking a photo; (c) Contractual necessity — processing organizer data to provide the service; (d) Legal obligations — retaining transaction records as required by French commercial law.
4. Data Sharing
Your data may be shared with: (a) AI processing provider — photos are sent to a third-party AI service for transformation (their data processing terms apply); (b) Cloud storage provider — photos are stored on secure cloud infrastructure; (c) Hosting provider — the application is hosted on a third-party platform; (d) Payment processor — for token purchases. We do not sell personal data. We do not use photos for advertising or AI training.
5. Data Retention
Event photos: retained as long as the event exists, deleted when the event is deleted or the organizer's account is closed. Account data: retained until account deletion. Transaction records: retained for the legally required period (10 years under French commercial law). Technical logs: retained for a maximum of 12 months.
6. Your Rights (GDPR Articles 15-22)
You have the right to: (a) Access — obtain a copy of your personal data; (b) Rectification — correct inaccurate data; (c) Erasure — request deletion of your data ("right to be forgotten"); (d) Restriction — limit how we process your data; (e) Portability — receive your data in a structured format; (f) Object — object to processing based on legitimate interest. To exercise these rights, contact: {email}. We will respond within 30 days. You may also lodge a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés).
7. International Transfers
Some of our service providers may process data outside the European Economic Area. These transfers are covered by Standard Contractual Clauses or adequacy decisions as required by GDPR.
8. Security
We implement appropriate technical and organizational measures to protect your data, including: encrypted communications (HTTPS/TLS), secure authentication (OAuth, email verification codes), access controls and data isolation between events, regular security reviews.
9. Cookies & Local Storage
SparkShot uses: session cookies (essential, for authentication), localStorage (language preference, participant session data). We do not use tracking cookies or third-party analytics cookies.
10. Minors
SparkShot organizer accounts are restricted to individuals aged 16 or older. Event participants under 16 should have their legal guardian's authorization before using the service. Event organizers are responsible for ensuring appropriate consent for minors at their events.